One-Way Data Interface for Secure ArchestrA Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of secure and non-secure networks for transferring ArchestrA data poses significant security risks due to potential unauthorized data flow and malware introduction, as direct connections can compromise firewall security and introduce malware into secure systems.
Innovation Solution
A one-way data interface system utilizing a one-way data link with a send server and a receive server, coupled with standalone servers in both security domains, ensures secure data transfer from a secure ArchestrA Galaxy and Historian in a high-security domain to a corporate network in a less secure domain, using a TCP-based one-way transfer system to enforce unidirectional data flow and prevent reverse data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a direct connection is used to couple the corporate business network to the process control network, then data transfer capability is improved, but security is worsened due to potential firewall compromise and malware introduction
Solution Approach 1:
The system segments the network into distinct security domains (secure process control network and less secure corporate business network) and introduces intermediate devices (one-way transfer device, send server, receive server) that physically separate the domains while enabling controlled data transfer. This segmentation prevents direct compromise between networks.
Solution Approach 2:
The patent introduces intermediary servers and a one-way transfer device that act as mediators between the secure and non-secure networks. The send server receives data from the secure network, the one-way transfer device transfers it unidirectionally, and the receive server delivers it to the corporate network, eliminating direct connections and potential firewall compromises.
2Reliability
If data copying is used to transfer data from the process control network to the corporate network, then security is improved by avoiding direct connections, but malware introduction risk worsens due to media coupling with the secure network
Solution Approach 1:
The one-way transfer device acts as an intermediary that physically prevents malware from the corporate network from reaching the secure process control network. The unidirectional nature of the device ensures that while data can flow from secure to non-secure, any malware in the corporate network cannot propagate back to the secure environment.
3Reliability
If a one-way data link is used to enforce unidirectional data flow, then security is improved by preventing unauthorized data flow, but device complexity worsens due to hardware-based unidirectional enforcement
Solution Approach 1:
The patent replaces complex hardware-based one-way link mechanisms with a software-based solution using servers and protocol enforcement. Instead of relying on physical unidirectional constraints, the system uses TCP protocol modifications and server-side control to achieve unidirectional data transfer, reducing hardware complexity while maintaining security.
Data Source
AI summary
A system for transmitting ArchestrA information from a first network in a first security domain to a second network in a second security domain. A first stand-alone server within the first security domain retrieves information via the first network from a first ArchestrA Galaxy and/or from a first historian in the first security domain and forwards the retrieved information to a send server coupled to the first network. The send server forwards the received information received to a receive server via a one-way data link. The receive server receives the information from the send server and forwards the received information to a second stand-alone server via the second network. The second stand-alone server receives the information from the receive server and forwards the information to a second ArchestrA Galaxy and/or to a second historian in the second security domain.


