Air-Gapped Encryption Modules for Remote Transfer Across Less Secure Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods struggle to securely transfer data between secure networks through less secure networks, especially with the increasing need for remote data transfer and the impracticality of using portable devices like FLASH drives.
Innovation Solution
A system utilizing dedicated, selectively air-gapped encryption modules with dual encryption keys for secure networks, ensuring data is doubly encrypted and decrypted through less secure networks, maintaining security by isolating encryption modules from shared memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transferred through less secure networks to enable remote work, then productivity and ease of operation are improved, but security and reliability deteriorate
Solution Approach 1:
The system segments the encryption process into two independent modules: an upstream encryption module that encrypts data before transmission, and a downstream encryption module that decrypts data after reception. These modules are physically separated and never simultaneously connected to the shared memory, creating temporal and spatial segmentation that prevents unauthorized access while enabling secure remote data transfer through less secure networks
Solution Approach 2:
The shared non-volatile memory module serves as an intermediary storage medium between the upstream and downstream encryption modules. Data is encrypted by the upstream module, stored in the shared memory, then decrypted by the downstream module. This intermediary approach allows data transfer through less secure networks while maintaining security through the air-gapped architecture
2Reliability
If encryption modules are isolated from shared memory to maintain security, then reliability is improved, but device complexity increases
Solution Approach 1:
The system employs periodic action through manual user control of the programmable resource router. The user periodically connects either the upstream or downstream encryption module to the shared memory, but never both simultaneously. This periodic, alternating connection pattern maintains security by ensuring the air-gap is never bridged, while the simple manual control mechanism keeps the system architecture relatively straightforward despite the security requirements
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosure relates to systems, methods and computer readable for generating double encryption of data through discrete modules that are air gapped at every stage. Furthermore, the transceivers disclosed can operate in "off-line" mode which can be adapted to communicate with any network access terminal regardless of the intermediate connecting network.