Relay-Based Secure Data Transfer Between Closed and Open Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in securely providing data from closed networks to communication terminals in open networks, particularly in factory settings where old processing devices may be vulnerable to viruses, and there is a risk of virus spread when connecting to open networks.
Innovation Solution
A communication system that uses a relay and information providing device to manage connections through a router with firewall functions, allowing data transfer from a closed network to an open network while preventing reverse connections, and implementing authentication and anti-virus measures to ensure secure data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If direct connection between closed network and open network is established, then data transfer speed is improved, but virus infection risk increases
Solution Approach 1:
The patent introduces a relay device as an intermediary between the closed network (factory network) and open network (external network). The relay receives connection requests from communication terminals in the open network, authenticates them, and establishes connections to information providing devices in the closed network only when authentication succeeds. This mediator approach allows data transfer while blocking direct connections that could propagate viruses.
Solution Approach 2:
The relay device performs authentication of communication terminals before allowing any data transfer to occur. The connection request must be authenticated by the relay before the information providing device in the closed network is contacted. This preliminary authentication action prevents unauthenticated devices from accessing the closed network, thereby reducing virus infection risk while maintaining legitimate data transfer capability.
2Adaptability or versatility
If connection request from open network to closed network is allowed, then information accessibility is improved, but security control deteriorates
Solution Approach 1:
The relay device serves as a security intermediary that controls all connection requests from the open network to the closed network. It authenticates communication terminals and manages connection establishment, allowing information accessibility for authenticated devices while maintaining strict security control through centralized authentication and connection management.
Solution Approach 2:
The relay device implements a feedback mechanism where connection requests from the open network are first submitted to the relay for authentication. The relay provides feedback by authenticating or rejecting connection requests before they reach the closed network. This feedback loop ensures that only authenticated devices can access information, balancing accessibility with security control.
3Reliability
If authentication process is implemented for connection requests, then security is improved, but connection establishment time increases
Solution Approach 1:
The relay device performs authentication as a preliminary action before connection establishment. By authenticating communication terminals in advance and maintaining authentication state, the system ensures security while enabling rapid connection establishment for authenticated devices. The authentication is performed once during connection request processing, after which subsequent data transfers can proceed without repeated authentication delays.
Data Source
AI summary
An information providing device arranged in a first network is provided including: an association storage section for storing user identification information and session identification information; a confirmation request transmitting section for transmitting, to a relay arranged in a second network, a confirmation request for confirming whether the relay has stored a connection request; an information receiving section for receiving information included in the connection request; a terminal authentication section for determining whether authentication of the communication terminal is permitted if the session identification information is not included in the information received; a session identification information assigning section for assigning session identification information when the authentication is determined to be permitted; a session identification information transmitting section for transmitting the session identification information to the relay; and an information providing section for providing information to the communication terminal if the session identification information is included in the information received.


