One-Way Data Link for Concurrent Multi-Protocol Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security devices, such as firewalls, do not provide sufficient protection against unauthorized data disclosure in high-security computer networks, and existing unidirectional data transfer systems are limited in their ability to concurrently transfer data streams using multiple transport layer protocols over a single one-way data link.

Innovation Solution

A data transfer system that utilizes a send node and a receive node connected by a one-way data link, employing separate hardware and/or software for each transport layer protocol, with TCP and UDP protocols being simulated using proxy applications to ensure unidirectional data flow, and utilizing hash algorithms for data integrity, allowing concurrent transfer of multiple data streams across the link.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls are used for network security, then basic data protection is provided, but sufficient protection against unauthorized data disclosure in high-security networks is not achieved

Engineering Contradiction:
Improvenetwork security protectionVSAvoidunauthorized data disclosure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces conventional software-based firewall security mechanisms with a physical one-way data link system that uses optical transmitters and receivers to enforce unidirectional data flow. This physical layer substitution provides stronger security guarantees by making reverse data flow physically impossible rather than software-enforced.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a one-way data link as an intermediary between the unsecured external network and the secure internal network. This intermediary component (comprising optical transmitter at the send node and optical receiver at the receive node) mediates all data transfers while maintaining strict unidirectionality, preventing unauthorized data disclosure without requiring complex security software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a one-way data link is used for unidirectional data transfer, then network security is enhanced by preventing data leakage, but the ability to concurrently transfer multiple transport layer protocols over a single link is limited

Engineering Contradiction:
Improvedata transfer securityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transfer process into distinct protocol-handling components at both send and receive nodes. Each transport layer protocol (TCP, UDP, etc.) is processed by dedicated protocol handlers that operate independently on the one-way link, allowing multiple protocols to coexist without interference while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The one-way data link system is designed with universal protocol support capabilities. The send node can accept data streams from multiple transport layer protocols and the receive node can process them accordingly, making the system adaptable to various protocol requirements while maintaining the fundamental unidirectional security property.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8565237B2Concurrent data transfer involving two or more transport layer protocols over a single one-way data link
Publication Date: 2013.10.22 OWL CYBER DEFENSE SOLUTIONS LLC
  • US8565237B2 patent drawing
  • US8565237B2 patent drawing
  • US8565237B2 patent drawing

AI summary

A data transfer application for concurrent transfer of data streams based on two or more transport layer protocols via a single one-way data link. The present invention provides a great degree of routing flexibility by providing seamless network connectivity under a plurality of transport layer protocols, such as TCP and UDP, between multiple source and destination platforms over a single one-way data link.