Manifest Transfer Engine for Unidirectional Data Assurance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data integrity protection methods, such as conventional network security devices and software, fail to provide reliable protection against unauthorized data disclosure and malware introduction, especially in high-security environments like government and intelligence networks, due to limitations in unidirectional data transfer systems and the risk of compromised software updates.

Innovation Solution

A system and method utilizing a manifest transfer engine with one-way data links to ensure data integrity by comparing identifying characteristics of information files with stored manifest entries, authenticating files, and segmenting data for secure transfer, while maintaining IP information secrecy and using hash algorithms for error detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security devices such as firewalls are used, then data transmission can be controlled, but they cannot provide sufficiently reliable protection from undesired data disclosure in high security environments

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a one-way data link as an intermediary component between the secure network and external networks. This optical link acts as a mediator that physically enforces unidirectional data flow, allowing data to flow only from the unsecured network to the secure network while blocking any reverse flow. This intermediary device provides reliable protection without requiring complex security policies or authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based security mechanisms (firewalls, access control lists, authentication protocols) with a hardware-based optical one-way link. By substituting the mechanical/optical enforcement of unidirectionality for software-based security controls, the system achieves higher reliability because the unidirectional constraint is physically embedded in the transmission medium rather than being enforced through programmable rules that can be compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If unidirectional data transfer systems are used, then data leakage prevention is improved, but the system cannot support bidirectional communication protocols such as TCP/IP

Engineering Contradiction:
Improvedata leakage preventionVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transfer system into distinct functional components: an encoding device that prepares data for one-way transmission, a one-way data link for unidirectional transfer, and a decoding device that reconstructs the data. This segmentation allows each component to be optimized for its specific function while collectively supporting complex data transfer requirements. The encoding device can implement protocol adaptation, allowing TCP/IP and other bidirectional protocols to be translated into unidirectional data streams suitable for the optical link.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encoding and decoding devices act as intermediaries that translate between bidirectional communication protocols (such as TCP/IP) and the unidirectional optical link protocol. The encoder on the sending side breaks down complex protocol interactions into simple unidirectional data streams, while the decoder on the receiving side reconstructs the original data format. This intermediary translation layer maintains protocol compatibility while enforcing unidirectional transfer constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data is transmitted over networks or stored in storage, then data accessibility is improved, but the risk of data compromise increases over time

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by creating cryptographic hashes of the original data before transmission or storage, and storing these hashes securely. The manifest file containing these pre-computed hashes is prepared in advance and transferred through the one-way link to the receiving system. This preliminary preparation allows for immediate integrity verification upon data arrival without requiring complex real-time monitoring during transmission or storage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the receiving system computes hashes of received data and compares them against the pre-transferred manifest hashes. This feedback loop continuously verifies data integrity throughout the data lifecycle. If any deviation is detected, the system can trigger alerts or corrective actions. The one-way link ensures that the manifest (containing the trusted reference hashes) cannot be tampered with, providing a reliable feedback reference for integrity verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9311329B2System and method for modular and continuous data assurance
Publication Date: 2016.04.12 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9311329B2 patent drawing
  • US9311329B2 patent drawing
  • US9311329B2 patent drawing

AI summary

A system for assuring the integrity of information files includes a first server, a manifest transfer engine and a second server. The first server stores information files and an associated manifest file containing a manifest entry for each stored information file. The manifest transfer engine receives the manifest file and the information files from the first server on a predetermined basis. The manifest transfer engine compares an identifying characteristic of each received information file with the manifest entries in the manifest file and, when there is a match, transfers the associated information file on the output as an authenticated information file. The second server receives the authenticated information file from the manifest transfer engine, optionally segments the authenticated information file, and then generates an associated manifest entry for the received authenticated information file (or segmented information files) and stores the associated manifest entry (or entries) in an updated manifest file.