Secure Data Transfer Device Using Independent Unidirectional Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure data transfer architectures are vulnerable to attacks due to software flaws and misconfiguration, with limited reliability in one-way communication systems and potential for malicious users to access sensitive data despite physical security measures.

Innovation Solution

A secure data transfer method involving multiple independent transfer interfaces with different technologies, including internal and external interfaces, and data validation steps to ensure that only authorized access and operations are allowed, preventing direct control by malicious users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secure exchange architectures with firewalls and exchange zones are used, then network security is improved, but software vulnerabilities and misconfiguration errors can compromise the entire network

Engineering Contradiction:
Improvenetwork securityVSAvoidsoftware vulnerabilities and misconfiguration errors
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the data transfer process into distinct segments: an initial transfer phase through a first interface to a first processing means, followed by a second transfer phase through a second interface from a second processing means. This segmentation ensures that compromise of one interface does not directly affect the other, as each interface and its associated processing means operate independently with unidirectional data flow between them.

Inventive Principle:
Principle #1Segmentation

2Reliability

If unidirectional communication devices like physical diodes are used, then security is improved, but reliability is limited due to lack of exchange control flows

Engineering Contradiction:
ImprovesecurityVSAvoidexchange control flows
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines the security benefits of unidirectional communication with the functionality of bidirectional control by implementing two separate unidirectional interfaces (first and second interfaces) that work together in sequence. The first interface allows write operations only, while the second interface allows read operations only, creating a merged system that maintains security while enabling complete data transfer control flows.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple exchange zones are implemented, then security against malicious access is improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improveprotection against malicious accessVSAvoidexchange zones and servers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security function from complex multi-zone architectures and implements it through a simplified two-interface system. By removing the need for multiple exchange zones and dedicated servers for each zone, the invention maintains protection against malicious access while significantly reducing device complexity and configuration requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

4Device complexity

If a single transfer interface is used, then device simplicity is maintained, but security is compromised as malicious users who control one interface can directly access data

Engineering Contradiction:
Improvetransfer interfacesVSAvoiddata protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the transfer interface functionality into two distinct interfaces: a first interface for initial data transfer with write capabilities, and a second interface for subsequent data transfer with read capabilities. This segmentation ensures that even if a malicious user gains control of one interface, they cannot directly access data through the other interface, as each interface operates independently with restricted operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2377290B1Method and device for securely transferring digital data
Publication Date: 2022.07.27 ELECTRICITE DE FRANCE
  • EP2377290B1 patent drawingFigure 1A
  • EP2377290B1 patent drawingFigure 1B
  • EP2377290B1 patent drawingFigure 2

AI summary

The invention relates to a device (1) for securely transferring digital data between at least one first computer system and at least one second computer system, including a control means (30) suitable for being connected to at least one storage means (50, 61), a first transfer means (10) connected to said control means (30) and suitable for receiving the digital data from the first computer system and sending said data to the control means (30), a second transfer means (20) connected to said control means (30) and suitable for receiving the digital data from said control means (30) and sending said data to the second computer system, and which is managed independently from said first transfer means (10). The invention also relates to a corresponding transfer method and computer program.