Perimeter Network File Exchange with Dual Consent Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing file exchange methods between networks lack secure and controlled data flow, particularly in remote maintenance scenarios, as they are vulnerable to unauthorized access and manipulation.

Innovation Solution

A system that transfers files through a perimeter network with firewalls, using accessible and inaccessible storage areas on data servers, requiring consent from release computers in both networks to ensure secure exchange, and includes checks for data technology risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct file exchange between networks is implemented, then file transfer speed is improved, but security against unauthorized access and manipulation deteriorates

Engineering Contradiction:
Improvefile transfer speedVSAvoidsecurity against unauthorized access
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

A perimeter network with data servers acts as an intermediary between the first network and second network. Files are transferred through this intermediate zone rather than directly between networks, enabling security checks and controlled access while maintaining transfer functionality. The perimeter network mediates the exchange, preventing direct unauthorized access between the two networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the file transfer process into multiple stages: initial transfer to accessible storage area, security verification by release computers, then transfer to inaccessible storage area. This segmentation allows speed optimization in each stage while ensuring security checks are performed at designated points, resolving the contradiction between fast transfer and secure exchange.

Inventive Principle:
Principle #1Segmentation

2Reliability

If file transfer is controlled through multiple release computers and storage area transitions, then security against manipulation is improved, but transfer time increases

Engineering Contradiction:
Improvesecurity against manipulationVSAvoidtransfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Release computers perform security verifications and approvals in advance before the file is fully transferred to the final destination. The file is moved to an intermediate accessible storage area first, allowing release computers to verify and approve the transfer before committing the file to the inaccessible storage area. This preliminary action ensures security while minimizing the time the file is in transit.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes the accessibility of storage areas during the transfer process. The file starts in an accessible storage area where it can be quickly transferred and verified, then moves to an inaccessible storage area for final secure storage. This dynamic transition optimizes both transfer speed and security by matching the storage accessibility to the transfer stage.

Inventive Principle:
Principle #15Dynamics

3Reliability

If networks are segregated through firewalls and perimeter networks, then security control is improved, but network accessibility and ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The perimeter network with data servers serves as an intermediary that maintains network segregation while providing ease of operation. Users can transfer files to the accessible storage area of the perimeter network as if accessing a local resource, without needing to understand or configure firewall rules. The intermediary handles the security control transparently, maintaining both security and ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9923868B2Working method for a system and system
Publication Date: 2018.03.20 FUJITSU SIEMENS COMP GMBH
  • US9923868B2 patent drawing
  • US9923868B2 patent drawing
  • US9923868B2 patent drawing

AI summary

A system includes a first network with a first computer and a first release computer; a second network with a second computer and a second release computer; a perimeter network with a first data server and a second data server; wherein the first network and the second network connect via a firewall to the perimeter network; the first data server has a storage area accessible to the first computer and a storage area inaccessible to the first computer and the second computer; and the system is configured to carry out the method.