Receive-Only Network Device for Air-Gapped Network Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network probing methods that establish two-way communication with network nodes expose highly secure, air-gapped networks to malicious attacks and data injection risks, compromising their security.

Innovation Solution

A receive-only network device that physically disconnects its transmit channel and uses unidirectional hardware buffers to ensure one-way communication, enabling network attribute extraction without transmitting data, thus preventing malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If two-way communication is established with network nodes for network probing, then network identification capability is improved, but network security is compromised due to exposure to malicious attacks and data injection risks

Engineering Contradiction:
Improvenetwork identification capabilityVSAvoidnetwork security
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The network device is segmented into separate transmit and receive channels, with the transmit channel being physically disconnected. This allows the device to receive and analyze network traffic for identification purposes while eliminating the ability to inject malicious data into the network, thus resolving the contradiction between identification capability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The harmful transmit function is extracted and removed from the network device by physically disconnecting the transmit channel. This extraction eliminates the security risk of data injection while preserving the beneficial receive function that enables network identification through passive traffic analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If a receive-only network device is used for network probing, then network security is improved by preventing data injection, but network attribute extraction capability may be limited

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork attribute extraction capability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The device performs preliminary actions by capturing and storing network traffic data in buffers before analysis. This allows comprehensive network attribute extraction to be performed on stored data without requiring active transmission, thus maintaining both security and full identification capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device creates copies of network traffic data by buffering received frames for later analysis. This copying mechanism enables thorough network attribute extraction from stored copies without requiring the device to transmit any data, thus preserving security while maintaining full identification capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250240291A1Secure identification of air-gapped networks using one-way communication
Publication Date: 2025.07.24 SHEBA IMPACT LTD
  • US20250240291A1 patent drawing
  • US20250240291A1 patent drawing
  • US20250240291A1 patent drawing

AI summary

Disclosed herein are receive-only network devices and methods for use for securely identifying a network. The receive-only network device comprised a network physical layer (PHY) circuit configured to establish a physical layer connection to a network via one or more wired transmission mediums and a controller electrically coupled to a receive channel of the PHY via a unidirectional hardware buffer configured to transfer electronic signals received from the PHY and block electronic signals received from the controller. The controller is configured to receive from the PHY one or more link layer frames transmitted by one or more network controllers of the network and intercepted by the PHY, extract one or more network attributes of the network from the one or more intercepted link layer frames, identify the network at least partially according to the one or more extracted network attributes, and present the identity of the network to a user.