Network Apparatus Isolating Data Routes Between Segmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In scenarios where different networks within the same organization need to be isolated to prevent information leakage, existing solutions face challenges such as identical IP addresses causing communication inconveniences and potential data leaks, and the need for multiple network interfaces or routers to manage data flow effectively.

Innovation Solution

A network apparatus with multiple interfaces is designed to control communication routes, using Network Address Translation (NAT) and bridge methods to ensure that data from one network is not transmitted to another, allowing for the shared use of input and output apparatuses while maintaining network isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network interfaces are used to connect different networks, then network isolation is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork isolationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network apparatus as an intermediary device between multiple networks. This apparatus includes multiple network interfaces (first, second, and third network interfaces) that connect to different networks, and contains control logic to manage data transmission routes. The intermediary apparatus prevents direct communication between networks by routing data through controlled paths, ensuring that data from the second network is transmitted to the first network without being transmitted to the third network, and vice versa. This resolves the contradiction by providing network isolation through a dedicated intermediary device rather than requiring each endpoint to have multiple interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication function into separate components: the network apparatus handles inter-network routing and isolation, while client terminals handle local network communication. The network apparatus is divided into distinct network interfaces (first, second, third interfaces) each connected to specific networks, with internal logic that segments data flow control. This segmentation allows network isolation to be achieved without requiring each client terminal to have multiple network interfaces, thus reducing overall system complexity while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a router is provided to separate networks, then information leakage is prevented, but data transmission flexibility is reduced

Engineering Contradiction:
Improveinformation leakage preventionVSAvoiddata transmission flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic data transmission control within the network apparatus. The control logic dynamically determines transmission routes based on data source and destination networks. When data is received from the second network, the system dynamically routes it to the first network interface without transmitting to the third network interface, and vice versa. This dynamic routing provides network isolation like a router while maintaining flexibility by allowing data transmission between specific network combinations based on operational needs, unlike a static router configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the transmission parameter (data route) based on the source and destination networks. The network apparatus monitors data origin and dynamically adjusts the transmission path parameter - directing data from the second network to the first network interface, and data from the third network to the first network interface, while preventing transmission to unauthorized networks. This parameter-based control provides both isolation and flexibility, overcoming the rigid routing of traditional routers.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If input and output apparatuses are provided for respective networks, then network isolation is ensured, but installation space and organizational burden increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidnumber of input and output apparatuses
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple input and output apparatuses from different networks into a single shared apparatus. The network apparatus provides a common interface that client terminals from both the second network and third network can use to access the shared input/output apparatus. This consolidation reduces the total number of input/output devices from two (one per network) to one shared device, reducing installation space and organizational burden while maintaining network isolation through the network apparatus's controlled routing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network apparatus serves multiple functions: it acts as a router for data transmission, an access control point for network isolation, and a gateway for shared input/output apparatus access. By making the network apparatus universal and multi-functional, the patent eliminates the need for separate input/output apparatuses for each network. Client terminals from different networks can universally access the same shared input/output apparatus through the network apparatus, which handles all communication and enforcement of isolation policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10747910B2Network apparatus, input and output apparatus, and program
Publication Date: 2020.08.18 RICOH CO LTD
  • US10747910B2 patent drawing
  • US10747910B2 patent drawing
  • US10747910B2 patent drawing

AI summary

A network apparatus includes: a plurality of network interfaces; a first communication unit configured to communicate with an input and output apparatus in a first network with which a first network interface of the plurality of network interfaces is coupled; a second communication unit configured to communicate with a first device in a second network with which a second network interface of the plurality of network interfaces is coupled; and a third communication unit configured to communicate with a second device in a third network with which a third network interface of the plurality of network interfaces is coupled. When the second communication unit receives data from the second network, the data is transmitted to the first network through the first communication unit without being transmitted to the third network. When the third communication unit receives data from the third network, the data is transmitted to the first network through the first communication unit without being transmitted to the second network.