Network Interconnection Using Content Checkers and Unidirectional Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for connecting computer networks, such as data diodes, face challenges in controlling data flow, managing transmission errors, and maintaining security, particularly when trying to prevent bidirectional communication between networks with different security classifications, which leads to increased management overheads and vulnerabilities.

Innovation Solution

The apparatus comprises three or more network interface machines connected with bidirectional links and at least two content checkers, using unidirectional communications links to manage data flow and error recovery without compromising security, allowing only appropriate data to be transmitted between networks while enabling bidirectional communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data diodes are used to provide unidirectional data connection, then network security and data integrity are improved, but bidirectional communication capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidbidirectional communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the communication path into multiple unidirectional links (first unidirectional link for data transmission, second unidirectional link for acknowledgements and flow control) separated by content checkers. This segmentation allows bidirectional communication functionality while maintaining unidirectional security properties at each link level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Content checkers are introduced as intermediary components between the unidirectional links. These intermediaries validate and filter data content, enabling controlled bidirectional communication while preserving the security guarantees of unidirectional data flow at each segment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If equipment is connected to a management system, then management and monitoring capability are improved, but unidirectional link security deteriorates due to bypass risk

Engineering Contradiction:
Improvemanagement capabilityVSAvoidunidirectional link security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A dedicated management interface machine acts as an intermediary for management system connections. This intermediary is itself protected by unidirectional links and content checkers, allowing management functionality while preventing direct bypass of the secure unidirectional data paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management interface operates in a separate dimensional space from the data plane, using distinct unidirectional links and content checkers. This separation allows management activities without compromising the security of data transmission paths.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If applications implement custom protocols for flow control and error recovery, then communication control is improved, but system complexity and burden increase

Engineering Contradiction:
Improvecommunication controlVSAvoidapplication level protocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The unidirectional links are designed to automatically support flow control and error recovery mechanisms through the second unidirectional link, allowing applications to communicate without implementing custom protocols. The system provides these services automatically, reducing application burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The second unidirectional link serves multiple functions including acknowledgements, flow control signals, and error recovery communications. This multi-functional design eliminates the need for application-specific custom protocols while maintaining comprehensive communication control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If separate management systems are used for each side of the diode, then unidirectional security is maintained, but cost and operational error risk increase

Engineering Contradiction:
Improveunidirectional securityVSAvoidmanagement system scale
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple management functions for different sides of the diode are merged into a single management interface machine. This consolidation reduces the number of separate management systems needed while maintaining security through the use of protected unidirectional links and content checkers for management traffic.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2865156B1Apparatus and method for connecting computer networks
Publication Date: 2017.10.11 DEEP SECURE LTD
  • EP2865156B1 patent drawingFigure 1
  • EP2865156B1 patent drawingFigure 2
  • EP2865156B1 patent drawingFigure 3

AI summary

Apparatus (104) for connecting two or more computer networks having two or more network interface machines (201, 202, 203) each arranged to be connected to a respective computer network with a bidirectional communications link (105, 106, 107) enabling the network interface machine to receive data from and transmit data to the computer network. The network interface machines are connected together with at least one content checker (210, 211) to enable data to be transmitted from one network interface machine to another, and arranged such that data transmitted from one network interface machine to another network interface machine must pass via a content checker. Each network interface machine is arranged to transmit flow control data. The network interface machines are connected to the content checkers only by unidirectional communications links. This provides an interconnection between networks with different security classifications with the advantages of bidirectional communication links but avoiding the risks of such links.