Relay-Based Secure Data Transfer Between Closed and Open Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securely providing data from closed networks to communication terminals in open networks, particularly in factory settings where old processing devices may be vulnerable to viruses, and there is a risk of virus spread when connecting to open networks.

Innovation Solution

A communication system that uses a relay and information providing device to manage connections through a router with firewall functions, allowing data transfer from a closed network to an open network while preventing reverse connections, and implementing authentication and anti-virus measures to ensure secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct connection between closed network and open network is established, then data transfer speed is improved, but virus infection risk increases

Engineering Contradiction:
Improvedata transfer speedVSAvoidvirus infection risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a relay device as an intermediary between the closed network (factory network) and open network (external network). The relay receives connection requests from communication terminals in the open network, authenticates them, and establishes connections to information providing devices in the closed network only when authentication succeeds. This mediator approach allows data transfer while blocking direct connections that could propagate viruses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The relay device performs authentication of communication terminals before allowing any data transfer to occur. The connection request must be authenticated by the relay before the information providing device in the closed network is contacted. This preliminary authentication action prevents unauthenticated devices from accessing the closed network, thereby reducing virus infection risk while maintaining legitimate data transfer capability.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If connection request from open network to closed network is allowed, then information accessibility is improved, but security control deteriorates

Engineering Contradiction:
Improveinformation accessibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The relay device serves as a security intermediary that controls all connection requests from the open network to the closed network. It authenticates communication terminals and manages connection establishment, allowing information accessibility for authenticated devices while maintaining strict security control through centralized authentication and connection management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The relay device implements a feedback mechanism where connection requests from the open network are first submitted to the relay for authentication. The relay provides feedback by authenticating or rejecting connection requests before they reach the closed network. This feedback loop ensures that only authenticated devices can access information, balancing accessibility with security control.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication process is implemented for connection requests, then security is improved, but connection establishment time increases

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The relay device performs authentication as a preliminary action before connection establishment. By authenticating communication terminals in advance and maintaining authentication state, the system ensures security while enabling rapid connection establishment for authenticated devices. The authentication is performed once during connection request processing, after which subsequent data transfers can proceed without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12035139B2Communication system, information providing device, computer-readable medium, and information providing method
Publication Date: 2024.07.09 E JAN NETWORKS CO
  • US12035139B2 patent drawing
  • US12035139B2 patent drawing
  • US12035139B2 patent drawing

AI summary

An information providing device arranged in a first network is provided including: an association storage section for storing user identification information and session identification information; a confirmation request transmitting section for transmitting, to a relay arranged in a second network, a confirmation request for confirming whether the relay has stored a connection request; an information receiving section for receiving information included in the connection request; a terminal authentication section for determining whether authentication of the communication terminal is permitted if the session identification information is not included in the information received; a session identification information assigning section for assigning session identification information when the authentication is determined to be permitted; a session identification information transmitting section for transmitting the session identification information to the relay; and an information providing section for providing information to the communication terminal if the session identification information is included in the information received.