One-Way Switch Circuit for Isolated Secure-Site Data Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

One-way transmission systems face bottlenecks due to the limitations of sending nodes, which can become overwhelmed by multiple signals with different protocols, and there is a risk of devices at secure sites infecting each other during diagnosis or firmware upgrades, compromising security.

Innovation Solution

A switch device with a one-way link circuit, incorporating components like diode circuits, fibers, or field programmable gate arrays, that creates isolated subnets and allows multiple computing devices to connect to the input terminal, ensuring unidirectional data flow and preventing cross-infection between devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single sending node is used to transmit multiple signals with different protocols, then the one-way link structure is simple, but the sending node becomes a bottleneck and requires large computing resources

Engineering Contradiction:
Improveone-way link structureVSAvoidsignal transmission capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent divides the sending node function into multiple independent sending nodes (first sending node, second sending node, etc.), each handling specific protocols or signal types. This segmentation allows parallel processing of different protocols without a single bottleneck, resolving the contradiction between structural simplicity and transmission capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each sending node is designed with multi-functionality to handle multiple protocols (e.g., TCP, UDP, MQTT, CoAP), reducing the need for separate dedicated nodes for each protocol. This universal design maintains structural simplicity while increasing overall transmission capacity through protocol aggregation at each node.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If devices in the secure site are connected for diagnosis or firmware upgrades, then device functionality is improved, but the risk of cross-infection between devices increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a receiving node as an intermediary between the secure site devices and the external network. This intermediary enables diagnosis and firmware upgrade functions while maintaining security isolation, as the receiving node acts as a controlled gateway that prevents direct device-to-device communication and potential cross-infection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into isolated subnets within the secure site, where devices in different subnets cannot directly communicate. This segmentation allows specific devices to be connected for maintenance functions through controlled pathways while preventing lateral movement of potential infections across the entire secure site.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the sending node converts bi-directional protocols to unidirectional protocols, then one-way transmission security is achieved, but the computing resource requirement increases

Engineering Contradiction:
Improveone-way transmission securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The protocol conversion function is segmented and distributed across multiple sending nodes rather than concentrated in a single node. Each sending node handles conversion for specific protocol pairs or signal types, distributing the computational load and reducing the energy consumption per node while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses multiple sending nodes that can replicate the protocol conversion functionality. Instead of one high-power node performing all conversions, multiple lower-power nodes perform conversions in parallel, reducing the computing resource requirement per node while achieving the same security outcome.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution guarantees the security of the secure site by preventing data transmission from unsecure sites and resolves bottlenecks by enabling multiple device connections, ensuring that devices within the secure site do not infect each other, thus maintaining the site's integrity.

Implementation Method 1

the one-way link circuit is implemented by at least one of the followings: a diode circuit, a fiber, a RJ45 connector, and a field programmable gate array

Methodology Applied
Scientific EffectDiode circuit: Diode

Implementation Method 2

the one-way link circuit is implemented by at least one of the followings: a diode circuit, a fiber, a RJ45 connector, and a field programmable gate array

Methodology Applied
Scientific EffectOptical fiber transmission: Optical Fibre

Data Source

PatentEP3989441B1Switch device for one-way transmission
Publication Date: 2023.04.26 BLACKBEAR (TAIWAN) IND NETWORKING SECURITY LTD
  • EP3989441B1 patent drawingFigure 1
  • EP3989441B1 patent drawingFigure 2
  • EP3989441B1 patent drawingFigure 3

AI summary

A switch device is provided. The switch device includes a switch and a one-way link circuit, wherein the switch including a first port, a second port, and a third port. The third port coupled to the second port via a first path and coupled to the first port via a second path. An input terminal of the one-way link circuit is coupled to the first port.