One-Way Switch Circuit for Isolated Secure-Site Data Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
One-way transmission systems face bottlenecks due to the limitations of sending nodes, which can become overwhelmed by multiple signals with different protocols, and there is a risk of devices at secure sites infecting each other during diagnosis or firmware upgrades, compromising security.
Innovation Solution
A switch device with a one-way link circuit, incorporating components like diode circuits, fibers, or field programmable gate arrays, that creates isolated subnets and allows multiple computing devices to connect to the input terminal, ensuring unidirectional data flow and preventing cross-infection between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single sending node is used to transmit multiple signals with different protocols, then the one-way link structure is simple, but the sending node becomes a bottleneck and requires large computing resources
Solution Approach 1:
The patent divides the sending node function into multiple independent sending nodes (first sending node, second sending node, etc.), each handling specific protocols or signal types. This segmentation allows parallel processing of different protocols without a single bottleneck, resolving the contradiction between structural simplicity and transmission capacity.
Solution Approach 2:
Each sending node is designed with multi-functionality to handle multiple protocols (e.g., TCP, UDP, MQTT, CoAP), reducing the need for separate dedicated nodes for each protocol. This universal design maintains structural simplicity while increasing overall transmission capacity through protocol aggregation at each node.
2Adaptability or versatility
If devices in the secure site are connected for diagnosis or firmware upgrades, then device functionality is improved, but the risk of cross-infection between devices increases
Solution Approach 1:
The patent introduces a receiving node as an intermediary between the secure site devices and the external network. This intermediary enables diagnosis and firmware upgrade functions while maintaining security isolation, as the receiving node acts as a controlled gateway that prevents direct device-to-device communication and potential cross-infection.
Solution Approach 2:
The network is segmented into isolated subnets within the secure site, where devices in different subnets cannot directly communicate. This segmentation allows specific devices to be connected for maintenance functions through controlled pathways while preventing lateral movement of potential infections across the entire secure site.
3Reliability
If the sending node converts bi-directional protocols to unidirectional protocols, then one-way transmission security is achieved, but the computing resource requirement increases
Solution Approach 1:
The protocol conversion function is segmented and distributed across multiple sending nodes rather than concentrated in a single node. Each sending node handles conversion for specific protocol pairs or signal types, distributing the computational load and reducing the energy consumption per node while maintaining overall security.
Solution Approach 2:
The patent uses multiple sending nodes that can replicate the protocol conversion functionality. Instead of one high-power node performing all conversions, multiple lower-power nodes perform conversions in parallel, reducing the computing resource requirement per node while achieving the same security outcome.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution guarantees the security of the secure site by preventing data transmission from unsecure sites and resolves bottlenecks by enabling multiple device connections, ensuring that devices within the secure site do not infect each other, thus maintaining the site's integrity.
Implementation Method 1
the one-way link circuit is implemented by at least one of the followings: a diode circuit, a fiber, a RJ45 connector, and a field programmable gate array
Implementation Method 2
the one-way link circuit is implemented by at least one of the followings: a diode circuit, a fiber, a RJ45 connector, and a field programmable gate array
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A switch device is provided. The switch device includes a switch and a one-way link circuit, wherein the switch including a first port, a second port, and a third port. The third port coupled to the second port via a first path and coupled to the first port via a second path. An input terminal of the one-way link circuit is coupled to the first port.