Hardware Gateway for Offline Data Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-based cyber security systems are inadequate in preventing large-scale data breaches, as they allow continuous online access to sensitive information, making them vulnerable to sophisticated cyber-attacks and data theft.

Innovation Solution

A hardware-based cyber security system utilizing a 'HyperWall' gateway that separates online and offline data, preventing direct access to secure data by establishing a unidirectional data flow through temporary storage, ensuring that the offline data storage device is never connected to the online system simultaneously, thereby limiting access and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in massive online data stores accessible at all times, then convenience is improved, but security is worsened because data is always accessible to cybercriminals

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides data storage into separate online and offline components. The offline data storage device stores sensitive data securely offline, while the online system provides user interface and authentication. This segmentation allows data to be accessible online through controlled interfaces while the actual data remains protected offline, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary offline data storage device that acts as a mediator between the online system and sensitive data. This intermediary physically isolates data from continuous online access while still enabling authorized retrieval through controlled connections, thus maintaining both security and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If software-based cyber security systems are used, then ease of implementation is improved, but security against sophisticated attacks is worsened

Engineering Contradiction:
Improvesystem implementationVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system replaces software-based security with a hardware-based security architecture. The offline data storage device uses physical connection controls and hardware-enforced isolation mechanisms rather than software firewalls or encryption alone. This hardware foundation provides security that is independent of software vulnerabilities, addressing the weakness of software-based systems while remaining implementable through standard hardware components.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If continuous connection between online system and data storage is maintained, then data access speed is improved, but vulnerability to data breaches is worsened

Engineering Contradiction:
Improvedata access speedVSAvoiddata breach risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system uses periodic rather than continuous connections between the online system and offline data storage. Connections are established only when data access is required, authenticated, and then terminated. This periodic connection pattern maintains security by minimizing exposure time while still enabling fast data retrieval when needed, resolving the contradiction between speed and security.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10719622B2Cyber security system and method for transferring data between servers without a continuous connection
Publication Date: 2020.07.21 PATEL KALPESH S
  • US10719622B2 patent drawing
  • US10719622B2 patent drawing
  • US10719622B2 patent drawing

AI summary

A cybersecurity system includes a controller that functions as a gateway between an end user device and an offline data storage device. When the end user device wants to access a file on the offline data storage device the controller severs a connection between a temporary storage memory and the end user device, establishes a connection with the offline data storage device, pulls the data from the offline data storage device to a temporary storage memory, then severs the connection with the offline data storage device, then establishes the connection with the end user device and communicates the data from the temporary storage memory to the end user device before overwriting the data in the temporary storage memory.