Programmable Logic Device One-Way Link for Secure Data Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices in secure sites can inadvertently transmit malicious information to unsecure sites during firmware upgrades or maintenance, posing a risk of infection to unsecure site devices.
Innovation Solution
A communication system employing a programmable logic device with a one-way link circuit and a watchdog timer to filter data packets based on a filtering rule, ensuring that only compliant data packets are transmitted from the secure site to the unsecure site, and rebooting the server if malicious activity is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a one-way link is implemented to transmit data from secure site to unsecure site, then data transmission capability is improved, but the risk of malicious information transmission increases
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the secure site and unsecure site. This gateway includes a processor that filters data packets based on predetermined rules before transmission. The gateway acts as a mediator that allows legitimate data flow while blocking malicious information, thus resolving the contradiction between maintaining transmission capability and preventing harmful factors.
Solution Approach 2:
The system implements a feedback mechanism where the gateway continuously monitors data packets transmitted from the secure site and compares them against filtering rules. When malicious packets are detected, the system can trigger alerts or block transmissions. This feedback loop ensures that data transmission remains productive while harmful factors are identified and prevented from reaching the unsecure site.
2Adaptability or versatility
If firmware upgrading or maintenance is performed on devices in secure site, then device functionality is improved, but vulnerability to attacks increases
Solution Approach 1:
The patent applies preliminary action by establishing filtering rules and security configurations in the gateway before firmware upgrading or maintenance operations are performed on secure site devices. The gateway is pre-configured to recognize and block potential malicious transmissions that may occur during vulnerable periods, thus maintaining reliability while allowing functionality improvements.
Solution Approach 2:
The system provides beforehand cushioning by creating a protective buffer zone through the gateway's filtering mechanism. During firmware upgrading or maintenance when devices are vulnerable, the gateway's pre-configured rules act as a cushion that prevents malicious information from reaching the unsecure site, thus protecting reliability while allowing adaptive maintenance operations.
3Object-affected harmful factors
If data filtering is implemented at the gateway, then security against malicious information is improved, but data transmission efficiency decreases
Solution Approach 1:
The patent applies partial action by implementing selective filtering at the gateway. Instead of examining every single data packet in detail, the system applies filtering rules only to packets that match specific patterns or criteria associated with potential malicious information. This partial filtering approach maintains security while minimizing the impact on overall data transmission efficiency.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A communication system and a communication method for one-way transmission are provided. The communication method includes: transmitting a filtering rule to a programmable logic device by a server; receiving a signal and obtaining data from the signal by the server; packing the data to generate at least one data packet by the server; transmitting the at least one data packet to the programmable logic device by the server; and determining, according to the filtering rule, whether to output the at least one data packet by the programmable logic device.