One-Way Data Link Print Spooling for Secure Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security devices, such as firewalls, do not provide sufficient protection against unauthorized data disclosure in high-security computer networks, and existing unidirectional data transfer systems face challenges in routing and queuing print jobs due to enforced unidirectionality, which prevents bilateral communications like error messages or busy signals.

Innovation Solution

A system for printing that utilizes a one-way data link with a send platform configured to convert print jobs into printable files and send them across a one-way data link to a print spooling platform, where the print files are managed and sent to printers, using print server proxy and print file capture applications, and incorporating file scanning for security and anti-virus checks, ensuring secure and controlled data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security devices such as firewalls are used, then data transfer functionality is maintained, but protection against unauthorized data disclosure is insufficient

Engineering Contradiction:
Improveprotection against unauthorized data disclosureVSAvoidnetwork security architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional bidirectional communication model by implementing a unidirectional data link where data flows only from the unsecured network to the secured network. This physical inversion of data flow direction eliminates the possibility of unauthorized data disclosure while maintaining necessary data transfer functionality.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent segments the network into distinct unsecured and secured zones connected by a unidirectional data link. This segmentation isolates the secured network from potential security breaches while allowing controlled data import, effectively protecting against unauthorized data disclosure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If unidirectional data link is implemented to enhance security, then unauthorized data disclosure is prevented, but bilateral communication for print job management is lost

Engineering Contradiction:
Improvenetwork securityVSAvoidprint job routing and queuing
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-processing print jobs into a format suitable for unidirectional transmission before they cross the data link. The send platform prepares complete print job packages including all necessary information, eliminating the need for subsequent bidirectional communication for job management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary unidirectional data link between the send platform and receive platform. This intermediary enables print job transmission while maintaining security, as it physically prevents any reverse communication while still allowing the necessary data flow for print management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If unidirectional data link is used for print job transfer, then data security is improved, but error message and status signal transmission is prevented

Engineering Contradiction:
Improvedata securityVSAvoiderror messages and busy signals
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by embedding all necessary error handling and status information within the forward-directed data stream. The send platform includes error message capabilities and status indicators in the initial print job transmission, eliminating the need for reverse communication to convey such information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the limitation of unidirectional communication into a benefit by designing the print job format to include all necessary information in the forward direction. The enforced one-way data flow becomes a security feature that simplifies the system architecture while maintaining full error message and status signal functionality through careful data packaging.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS9081520B2Remote print file transfer and spooling application for use with a one-way data link
Publication Date: 2015.07.14 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9081520B2 patent drawing
  • US9081520B2 patent drawing
  • US9081520B2 patent drawing

AI summary

A system for printing includes one or more printers, a send platform, a print spooling platform coupled to the one or more printers, and a one-way data link enforcing unidirectional data transfer from the send platform to the print spooling platform, wherein the send platform is configured to receive a print job, convert the print job into a print file in a printable format for the one or more printers, and send the print file to the print spooling platform across the one-way data link, and the print spooling platform is configured to receive the print file from the one-way data link, control spooling of the print file for the one or more printers, and send the print file to the one or more printers, and wherein the one or more printers cannot communicate to the send platform.