One-Way Ethernet Connection Device for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Ethernet network connections lack a simple and reliable method to restrict information flow from a less secure computer to a highly secure computer, as current solutions like filter software and firewalls are vulnerable to unauthorized access and complex to implement.

Innovation Solution

A one-way connection device is introduced between Ethernet interfaces, using a line-integrity signal to maintain network operation while preventing unauthorized data transfer, employing an analog amplifier and a lowpass filter to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a connection is interrupted to prevent unauthorized information flow from the second computer to the first computer, then security is improved, but the line-integrity signal cannot be verified and Ethernet interface operation is degraded

Engineering Contradiction:
ImprovesecurityVSAvoidEthernet interface operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The connection between Ethernet interfaces is segmented into two separate paths: one for data transmission (transmit terminals to receive terminals) and another for line-integrity signaling (receive terminals only). This segmentation allows the data path to be restricted while maintaining the signaling path intact, resolving the contradiction between security and operational reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The external receive terminals of the first transceiver serve as an intermediary point that receives both the line-integrity signal and is connected to the connection member. This intermediary structure allows the integrity signal to pass through while the data connection remains controlled, enabling both security and operational functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If filter software or firewalls are used to restrict information flow, then security is improved, but the devices become complex and vulnerable to hidden channels

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security function is extracted from complex software-based solutions (firewalls and filters) and implemented through a simple physical connection structure. By taking out the security control mechanism from the software domain and embedding it in the hardware connection topology itself, the solution achieves security without the complexity and vulnerabilities of software-based approaches.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/software-based security system (firewalls and filters requiring processing and configuration) with an electrical/physical connection structure that inherently provides security through its topology. This substitution eliminates the complexity of software management while maintaining security functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a switch member is used to allow selective transmission, then security is improved, but the structure becomes complex and requires modifications to Ethernet interface structure and software

Engineering Contradiction:
ImprovesecurityVSAvoidstructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of using a switch member that actively controls transmission based on conditions, the patent inverts the approach by using a passive connection structure where security is achieved by what is NOT connected. The external transmit terminals of the second transceiver are deliberately left unconnected to the external receive terminals of the first transceiver, providing security through absence of connection rather than active switching control.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7515603B2One-way connection device suitable for use in an ethernet network
Publication Date: 2009.04.07 SAFRAN ELECTRONICS & DEFENSE (FR)
  • US7515603B2 patent drawing
  • US7515603B2 patent drawing
  • US7515603B2 patent drawing

AI summary

A one-way connection device between at least a first Ethernet interface and a second Ethernet interface respectively comprising a first transmitter-receiver and a second transmitter-receiver each provided with external message transmit terminals and external message receive terminals, the device comprising a connection member for connecting the external transmit terminals of the first transmitter-receiver to the external receive terminals of the second transmitter-receiver, and a line-integrity signal transmit member connected to the external receive terminals of the first transmitter-receiver, the external transmit terminals of the second transmitter-receiver being kept disconnected from the external receive terminals of the first transmitter-receiver.