Log Data Synchronization via Unidirectional Coupling and Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for synchronizing log data between networks with high security requirements and those with lower security requirements face challenges in ensuring unidirectional data transfer without time delays, maintaining chronological order, and ensuring data integrity and completeness, especially in safety-critical networks where introducing additional components is complex and risky.
Innovation Solution
A method and device that utilize metadata to synchronize log data unidirectionally, including time, integrity, and completeness information, allowing for correct chronological ordering and dependency analysis, with continuous change detection and transmission only of changed data, and optional retransmission of entire datasets for completeness, using a unidirectional coupling unit and cryptographic checksums to ensure integrity and freedom from feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data diodes are used for unidirectional communication, then security and non-interference are improved, but complexity and cost increase
Solution Approach 1:
The patent creates a copy of the log data in the second network without requiring physical data diodes. The log data is replicated and stored in the second network, enabling unidirectional communication while avoiding the complexity and cost of physical data diodes.
Solution Approach 2:
The patent introduces an intermediary mechanism that facilitates unidirectional data transfer between networks. This intermediary approach allows log data to be transferred from the first network to the second network without requiring direct physical connection or complex security infrastructure.
2Ease of operation
If file-based synchronization is used, then data transfer is simplified, but time lag increases
Solution Approach 1:
The patent implements continuous synchronization of log data between networks. Instead of periodic file-based transfers, the system maintains continuous data exchange, eliminating time lags and ensuring real-time availability of log data in the second network.
Solution Approach 2:
The patent performs preliminary actions by pre-synchronizing log data and metadata before actual analysis is needed. This ensures that all necessary data is ready in advance, eliminating delays during subsequent analysis operations.
3Ease of operation
If entire databases are mirrored, then synchronization is simplified, but data volume and storage requirements increase
Solution Approach 1:
The patent extracts only the necessary log data and metadata for synchronization rather than mirroring entire databases. This selective extraction approach reduces data volume and storage requirements while maintaining synchronization functionality.
Solution Approach 2:
The patent segments the synchronization process into distinct components: log data synchronization and metadata synchronization. This segmentation allows for more efficient data transfer and reduced overall data volume compared to complete database mirroring.
4Reliability
If unidirectional coupling is implemented, then feedback interference is eliminated, but error message transmission is prevented
Solution Approach 1:
The patent introduces an intermediary mechanism that enables selective information exchange between networks. This intermediary allows essential feedback information to be transmitted while maintaining the overall unidirectional coupling structure and preventing interference in the safety-critical network.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method and a device for a reaction-free and integrity-protected synchronization of log data between at least one first network (NW1) and a second network (NW2). The log data is copied by means of a monitoring device (5) upon being transmitted from devices (C) to a first log server (LS1) in the first network (NW1). Metadata of the log data is additionally generated in a first managing unit (A1), said metadata comprising time information, integrity information, origin information, and/or completeness information. The copied log data and the corresponding metadata are transmitted to the second network (NW2) via a unidirectional coupling unit (2) in a reaction-free manner. The lot data is checked and ordered chronologically in the second network using the metadata. Thus, a synchronized copy of the log data from the first network (NW1) is promptly provided in the second network (NW2). In the process, the synchronization process is independent of the system times of individual devices (C) or of the network times of different networks.