Network Separation Module for LAN Data Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures fail to effectively maintain separation between different departments within an organization, allowing unauthorized data transfer once encrypted data enters the internal domain of a target Local Area Network (LAN).

Innovation Solution

A secure network separation module, integrated into network devices such as routers and switches, tags and validates data packets with network-ids to ensure they are transmitted only between nodes within the same network environment, using a secure Small Form-Factor Pluggable (SFP) transceiver to enforce network environment separation and prevent unauthorized data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted during transfer between LANs, then data security during transmission is improved, but once data enters the internal domain it is decrypted and becomes vulnerable to unauthorized access

Engineering Contradiction:
Improvedata security during transmissionVSAvoidvulnerability to unauthorized access in internal domain
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into distinct network environments using separation modules at network device interfaces. Each separation module maintains independent tagging information for different network environments, allowing encrypted data to maintain its security context throughout the internal domain by preventing decryption of data belonging to other network environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The separation module acts as an intermediary between the encrypted data stream and the internal network domain. It validates tags and controls decryption permissions, ensuring that only authorized network environments can decrypt and access data, thus maintaining security within the internal domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If clear separation between departments is maintained through separate network environments, then unauthorized data transfer is prevented, but network device complexity increases

Engineering Contradiction:
Improveseparation between network environmentsVSAvoidnetwork device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device is segmented into multiple separation modules, with each module responsible for a specific network environment interface. Each module contains its own tagging and validation logic, distributing the complexity across modular components rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses tag parameters attached to data packets to identify network environments. By changing the state of data packets through tagging and validation, the system achieves clear separation without requiring complex structural modifications to the network device architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If tagging and validation of data packets is implemented to enforce network environment separation, then unauthorized data transfer is prevented, but data communication overhead increases

Engineering Contradiction:
Improvenetwork environment separationVSAvoiddata communication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The separation module performs tagging with network environment identifiers in advance, at the point of data packet generation or entry into the network device. This preliminary action allows subsequent validation to be a simple comparison operation rather than a complex analysis, reducing overhead during actual data communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical or procedural verification systems with a lightweight tag-based identification system. Instead of requiring complex authentication protocols for each data packet, the system uses simple tag attachment and comparison, significantly reducing communication overhead while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9515992B2Network environment separation
Publication Date: 2016.12.06 ELTA SYST LTD
  • US9515992B2 patent drawing
  • US9515992B2 patent drawing
  • US9515992B2 patent drawing

AI summary

The presently disclosed subject matter includes, inter alia, a separation module being operatively connectible to a network device operable to facilitate data communication in a communication network, the separation module being configured to control data communication in the communication network, the separation module being assigned with a network-id associating the separation module with a given network environment; the separation module being further configured to tag a data packet received by the network device from a first direction, in order to associate the data packet with a given network environment; and determine whether a tag, associated with a data packet received by the network device from a second direction, is compatible with the assigned network-id, and if it is, remove the tag from the data packet and allow transmission of the data packet.