Hardware Relay for Secure Command Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional one-way links in secure communication systems prevent data from entering a protected facility but lack control over small information flows from external networks, risking malware-triggered attacks and buffer overflow vulnerabilities.

Innovation Solution

A hardware-actuated data relay system with digital signature verification and hardware-based command filtering, allowing controlled and authenticated command inputs to a protected destination, preventing unauthorized changes to the system's configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-way link is used to prevent data from entering a protected facility, then security against external attacks is improved, but the ability to receive authenticated commands from external networks is lost

Engineering Contradiction:
Improvesecurity against external attacksVSAvoidability to receive authenticated commands
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A hardware relay device is introduced as an intermediary between the external network and the protected facility. This relay receives commands from the network, verifies their authenticity using digital signatures, and then selectively activates data paths to allow only authenticated commands to reach the protected destination. The relay acts as a trusted mediator that enables secure two-way communication while maintaining the one-way link's protective properties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If software-based filtering is used to control command inputs, then flexibility in command processing is improved, but vulnerability to malware and buffer overflow attacks increases

Engineering Contradiction:
Improveflexibility in command processingVSAvoidvulnerability to malware and buffer overflow attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based command filtering with hardware-based filtering implemented in the relay device. The hardware filter is configured with a whitelist of authorized commands and physically blocks any command not on the whitelist from reaching the protected facility. This hardware implementation eliminates the security vulnerabilities associated with software processing while maintaining the ability to control and filter command inputs effectively.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If digital signature verification is implemented in hardware, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware relay structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication function is segmented and integrated directly into the hardware relay device rather than being implemented as a separate software module. The relay contains dedicated hardware logic for receiving and verifying digital signatures, which is tightly coupled with the command filtering function. This segmentation approach consolidates multiple security functions into a single hardware unit, reducing overall system complexity while maintaining strong authentication capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10432404B2Remote control of secure installations
Publication Date: 2019.10.01 WATERFALL SECURITY SOLUTIONS LTD
  • US10432404B2 patent drawing
  • US10432404B2 patent drawing
  • US10432404B2 patent drawing

AI summary

Communication apparatus includes a one-way, hardware-actuated data relay, which includes a first hardware interface configured to receive a command from a communications network and a second hardware interface configured to convey the received command to a protected destination when the relay is actuated. A decoder includes a third hardware interface configured to receive a digital signature for the command from the communications network and hardware decoding logic coupled to verify the digital signature and to actuate the relay upon verifying the digital signature, whereby the command is conveyed via the second hardware interface to the protected destination.