Hardware Data Diode for Unidirectional Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure network gateways for manufacturing sites connected to the internet are vulnerable to unauthorized access, as they rely on complex software firewalls that are difficult to administer and require frequent updates, posing risks to production data and processes.

Innovation Solution

A gateway apparatus that uses a network coupling device with a manual or mechanical switch to block data transmission on the physical layer, ensuring that no data can be transmitted from a protected network to an unprotected one, eliminating the need for software that can be manipulated, thereby enhancing security by preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software firewalls are used to protect the production site, then security protection is provided, but the system becomes complex to administer and requires frequent updates

Engineering Contradiction:
Improvesecurity protectionVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based firewalls with a hardware-level data diode that enforces unidirectional data flow at the physical layer. This mechanical/hardware approach eliminates the need for complex software configuration, administration, and updates while providing more reliable security protection against unauthorized access to the production site.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The gateway device is segmented into distinct functional components: a first network interface device for the production site, a second network interface device for the company network, and a network coupling device that physically enforces unidirectional data flow. This segmentation isolates the production site from potential attacks while simplifying administration of each component.

Inventive Principle:
Principle #1Segmentation

2Reliability

If software firewalls are used to protect the production site, then security protection is provided, but the software requires frequent updates to maintain security

Engineering Contradiction:
Improvesecurity protectionVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By replacing software firewalls with a hardware data diode that enforces unidirectional data flow at the physical layer, the system eliminates the need for frequent software updates. The hardware-based security mechanism provides continuous protection without requiring maintenance, patching, or configuration updates, thereby eliminating time loss associated with updates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If data diodes with complex right management software are used, then unauthorized access is prevented, but the software is intricate to administer and manipulate

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidadministration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces software-based access control with a hardware data diode that physically enforces unidirectional data flow. This mechanical approach to access control is inherently simple to operate - data can only flow in one direction from the production site to the company network, eliminating the need for complex right management software and its associated administrative complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If unidirectional data transmission is enforced at the physical layer, then security against attacks is improved, but data transmission capability is restricted

Engineering Contradiction:
Improvesecurity against attacksVSAvoiddata transmission flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network gateway is segmented into unidirectional data flow paths, with data transmission allowed only from the production site to the company network. This segmentation provides security by preventing attacks from the company network while still enabling necessary data transmission for monitoring and control purposes. The restricted unidirectional flow is sufficient for the intended application of connecting manufacturing equipment to cloud storage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10291461B2Secure gateway
Publication Date: 2019.05.14 MB CONNECT LINE GMBH FERNWARTUNGSSYST
  • US10291461B2 patent drawing
  • US10291461B2 patent drawing

AI summary

Gateway device (100), adapted to couple a first network with a second network, comprising: a first network interface device (102) coupled by a first interface to a first network and having a second interface; a second network interface device (104) coupled by a first interface with the second network and having a second interface; a network coupling device (103) adapted to transmit in a first status no data from the second interface of the second network interface device (104) to the second interface of the first network interface device (102) on the physical layer and adapted to transmit in a second status data from the second interface of the first network interface device (102) to the second interface of the second network interface device (104); wherein said network coupling device (103) includes a switching device (126, 128) coupled to a conductor (130, 134) coupling the second interface of the first network interface device (102) and second network interface device (104); wherein the switching device (126, 128) is connected such to the conductor (130, 134) that the conductor can not transmit data in a first state of the switching device and that the conductor can transmit data in a second state of the switching device and wherein said switching device (126, 128) is controlled by a manual switch (127) operated by a user.