Programmable Logic Device One-Way Link for Secure Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices in secure sites can inadvertently transmit malicious information to unsecure sites during firmware upgrades or maintenance, posing a risk of infection to unsecure site devices.

Innovation Solution

A communication system employing a programmable logic device with a one-way link circuit and a watchdog timer to filter data packets based on a filtering rule, ensuring that only compliant data packets are transmitted from the secure site to the unsecure site, and rebooting the server if malicious activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a one-way link is implemented to transmit data from secure site to unsecure site, then data transmission capability is improved, but the risk of malicious information transmission increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidmalicious information transmission risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the secure site and unsecure site. This gateway includes a processor that filters data packets based on predetermined rules before transmission. The gateway acts as a mediator that allows legitimate data flow while blocking malicious information, thus resolving the contradiction between maintaining transmission capability and preventing harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the gateway continuously monitors data packets transmitted from the secure site and compares them against filtering rules. When malicious packets are detected, the system can trigger alerts or block transmissions. This feedback loop ensures that data transmission remains productive while harmful factors are identified and prevented from reaching the unsecure site.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If firmware upgrading or maintenance is performed on devices in secure site, then device functionality is improved, but vulnerability to attacks increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing filtering rules and security configurations in the gateway before firmware upgrading or maintenance operations are performed on secure site devices. The gateway is pre-configured to recognize and block potential malicious transmissions that may occur during vulnerable periods, thus maintaining reliability while allowing functionality improvements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides beforehand cushioning by creating a protective buffer zone through the gateway's filtering mechanism. During firmware upgrading or maintenance when devices are vulnerable, the gateway's pre-configured rules act as a cushion that prevents malicious information from reaching the unsecure site, thus protecting reliability while allowing adaptive maintenance operations.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Object-affected harmful factors

If data filtering is implemented at the gateway, then security against malicious information is improved, but data transmission efficiency decreases

Engineering Contradiction:
Improvesecurity against malicious informationVSAvoiddata transmission efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies partial action by implementing selective filtering at the gateway. Instead of examining every single data packet in detail, the system applies filtering rules only to packets that match specific patterns or criteria associated with potential malicious information. This partial filtering approach maintains security while minimizing the impact on overall data transmission efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4016957B1Communication system and communication method for one-way transmission
Publication Date: 2023.05.10 BLACKBEAR (TAIWAN) IND NETWORKING SECURITY LTD
  • EP4016957B1 patent drawingFigure 1~2
  • EP4016957B1 patent drawingFigure 3~4
  • EP4016957B1 patent drawingFigure 5

AI summary

A communication system and a communication method for one-way transmission are provided. The communication method includes: transmitting a filtering rule to a programmable logic device by a server; receiving a signal and obtaining data from the signal by the server; packing the data to generate at least one data packet by the server; transmitting the at least one data packet to the programmable logic device by the server; and determining, according to the filtering rule, whether to output the at least one data packet by the programmable logic device.