One-Way Data Interface for Secure ArchestrA Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of secure and non-secure networks for transferring ArchestrA data poses significant security risks due to potential unauthorized data flow and malware introduction, as direct connections can compromise firewall security and introduce malware into secure systems.

Innovation Solution

A one-way data interface system utilizing a one-way data link with a send server and a receive server, coupled with standalone servers in both security domains, ensures secure data transfer from a secure ArchestrA Galaxy and Historian in a high-security domain to a corporate network in a less secure domain, using a TCP-based one-way transfer system to enforce unidirectional data flow and prevent reverse data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a direct connection is used to couple the corporate business network to the process control network, then data transfer capability is improved, but security is worsened due to potential firewall compromise and malware introduction

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the network into distinct security domains (secure process control network and less secure corporate business network) and introduces intermediate devices (one-way transfer device, send server, receive server) that physically separate the domains while enabling controlled data transfer. This segmentation prevents direct compromise between networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary servers and a one-way transfer device that act as mediators between the secure and non-secure networks. The send server receives data from the secure network, the one-way transfer device transfers it unidirectionally, and the receive server delivers it to the corporate network, eliminating direct connections and potential firewall compromises.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data copying is used to transfer data from the process control network to the corporate network, then security is improved by avoiding direct connections, but malware introduction risk worsens due to media coupling with the secure network

Engineering Contradiction:
Improvenetwork securityVSAvoidmalware introduction risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The one-way transfer device acts as an intermediary that physically prevents malware from the corporate network from reaching the secure process control network. The unidirectional nature of the device ensures that while data can flow from secure to non-secure, any malware in the corporate network cannot propagate back to the secure environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a one-way data link is used to enforce unidirectional data flow, then security is improved by preventing unauthorized data flow, but device complexity worsens due to hardware-based unidirectional enforcement

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware-based unidirectional enforcement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex hardware-based one-way link mechanisms with a software-based solution using servers and protocol enforcement. Instead of relying on physical unidirectional constraints, the system uses TCP protocol modifications and server-side control to achieve unidirectional data transfer, reducing hardware complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9680794B2Secure one-way interface for archestra data transfer
Publication Date: 2017.06.13 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9680794B2 patent drawing
  • US9680794B2 patent drawing
  • US9680794B2 patent drawing

AI summary

A system for transmitting ArchestrA information from a first network in a first security domain to a second network in a second security domain. A first stand-alone server within the first security domain retrieves information via the first network from a first ArchestrA Galaxy and/or from a first historian in the first security domain and forwards the retrieved information to a send server coupled to the first network. The send server forwards the received information received to a receive server via a one-way data link. The receive server receives the information from the send server and forwards the received information to a second stand-alone server via the second network. The second stand-alone server receives the information from the receive server and forwards the information to a second ArchestrA Galaxy and/or to a second historian in the second security domain.