Network Gateway State Switching for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies fail to adequately protect internal networks from computer attacks originating from external networks, particularly in the Industrial Internet of Things (IIoT), where remote servers are vulnerable to various cyber threats.

Innovation Solution

Implementing a network gateway with a security monitor that switches between a 'safe' and 'work' state to control access to trusted and untrusted memory, allowing secure unidirectional data transfer while denying access to sensitive areas during data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the gateway allows access to trusted memory during data transfer, then data transfer functionality is improved, but security against external network attacks deteriorates

Engineering Contradiction:
Improvedata transfer functionalityVSAvoidsecurity against external network attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The gateway dynamically switches between two operational states: a first state where trusted memory is accessible for data transfer, and a second state where trusted memory is protected from external network access. This dynamic state transition allows the system to adapt its security posture based on operational requirements, resolving the contradiction between data transfer functionality and security protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The gateway implements periodic state transitions between the first state (trusted memory accessible) and the second state (trusted memory protected). During data transfer operations, the gateway operates in the first state, then transitions to the second state to protect against external attacks, creating a periodic cycle of accessibility and protection that balances functionality and security.

Inventive Principle:
Principle #19Periodic action

2Object-affected harmful factors

If the gateway restricts access to trusted memory to protect security, then security level is improved, but data transfer capability deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoiddata transfer capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The gateway employs dynamic state management where the accessibility of trusted memory is not fixed but changes based on operational context. During authorized data transfer operations, the gateway transitions to a state that permits trusted memory access, thereby maintaining data transfer capability while upholding security through controlled, temporary access rather than permanent restriction.

Inventive Principle:
Principle #15Dynamics

3Productivity

If the gateway maintains continuous access to trusted memory for data transfer, then data transfer efficiency is improved, but vulnerability to attacks increases

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The gateway implements periodic state transitions between accessible and protected modes. During data transfer operations, the gateway maintains continuous access to trusted memory for efficiency, then periodically transitions to a protected state to reduce vulnerability to attacks, creating a rhythm of high-efficiency transfer followed by security reinforcement.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The gateway prepares for potential attacks by transitioning to a protected state beforehand, cushioning against vulnerabilities before they can be exploited. This proactive state management allows the system to maintain high data transfer efficiency during authorized operations while pre-positioning security protections to mitigate attack risks.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP4167523A1Network gateway and method for transferring data from a first network to a second network
Publication Date: 2023.04.19 AO KASPERSKY LAB
  • EP4167523A1 patent drawingFigure 1A
  • EP4167523A1 patent drawingFigure 1B
  • EP4167523A1 patent drawingFigure 1C

AI summary

A method for transferring data from a first network to a second network using a gateway includes setting, by a security monitor, a state of the gateway to a first state indicating to a destination agent that access is granted to trusted memory and denied to the second network and untrusted memory. The destination agent is configured, while the gateway is in the first state, based on parameters stored in the trusted memory, to transfer data received from a source agent to the second network. The state of the gateway is changed to a second state indicating to the destination agent that access is denied to the trusted memory and granted to the second network and the untrusted memory. Transfer of the data from the source agent of the first network to the destination agent of the second network is controlled, while the gateway is in the second state.