Bidirectional Gateway Low-Speed Link Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing gateways between high and low security communication networks lack sufficient security measures to ensure the integrity and authenticity of data flows from the low security network to the high security network, particularly in critical contexts like avionics where absolute security is required.

Innovation Solution

A bidirectional gateway with a low-speed return path using a unique communication protocol and cryptographic authentication, combined with a firewall for filtering and rate control, ensures secure data transmission from the low security network to the high security network by reducing data throughput and employing asymmetric key mechanisms for verification and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a bidirectional gateway is used to allow data transmission from low security network to high security network, then communication functionality is improved, but security level deteriorates

Engineering Contradiction:
Improvecommunication functionalityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The gateway is divided into separate processing units: a first processing unit for receiving and authenticating data from the low-security network, and a second processing unit for forwarding authenticated data to the high-security network. This segmentation isolates security-critical functions from potential attack vectors, allowing bidirectional communication while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication mechanism acts as an intermediary between the low-security and high-security networks. The first processing unit verifies data authenticity before forwarding to the second processing unit, which then transmits to the high-security network. This intermediary layer enables communication functionality while preventing unauthorized data from compromising the high-security network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional firewall filtering is used for data security, then ease of operation is improved, but security level deteriorates

Engineering Contradiction:
Improvefirewall configurationVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the security parameter from simple packet filtering (traditional firewall) to cryptographic authentication verification. The processing units authenticate data based on security credentials and authentication tokens rather than relying solely on IP addresses and port numbers, significantly raising the security level while maintaining operational simplicity through automated authentication processes.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If data authentication and encryption mechanisms are implemented, then security level is improved, but device complexity deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway processing units are designed to perform multiple functions: data reception, authentication verification, encryption/decryption, and forwarding. By consolidating these functions into unified processing units rather than separate dedicated components, the system achieves high security levels while controlling overall device complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2204034B1Bidirectional gateway with enhanced security level
Publication Date: 2019.04.03 SAFRAN ELECTRONICS & DEFENSE (FR)
  • EP2204034B1 patent drawingFigure 1~2
  • EP2204034B1 patent drawingFigure 3~5

AI summary

A secure gateway allows bidirectional communication between two communication networks. A first high-security network and a second network whose security is lower. The gateway is bidirectional with enhanced security level between a high-security communication network and a low-security communication network. For this purpose, the return pathway from the low-security network to the high-security network comprises a low-speed link. The physical layer of this low-speed link differs from the physical layers involved both in the high-security network and in the low-security network. This low-speed link is endowed with a linking layer according to a protocol which differs from the protocols used on the linking layers used both on the high-security network and on the low-security network. Advantageously, the linking layer of the low-speed link is furnished with an authentication protocol making it possible to guarantee the origin of the data.