Secure Gateway With Manual Physical Switch For Unidirectional Data Flow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure network gateways for manufacturing sites connected to the internet are vulnerable to unauthorized access, as they rely on complex software firewalls that are difficult to administer and update, posing risks to production data and processes.

Innovation Solution

A gateway apparatus that uses a network coupling device with a manual or mechanical switch to block data transmission on the physical layer, ensuring secure unidirectional data flow from the manufacturing site to the cloud storage, eliminating the need for software that can be manipulated or incorrectly configured.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software firewalls are used to protect manufacturing sites from internet attacks, then security protection is provided, but the system becomes complex to administer and update

Engineering Contradiction:
Improvesecurity protectionVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based physical switching devices. The mechanical switch physically opens or closes electrical circuits to block or permit data transmission, eliminating the need for complex software firewall configurations and updates while maintaining security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The gateway device is segmented into distinct functional components: network interface devices for connecting to different networks, a network coupling device for protocol conversion, and physical switching devices for security control. This segmentation allows each component to perform its specific function independently, simplifying administration.

Inventive Principle:
Principle #1Segmentation

2Reliability

If software firewalls are used to protect manufacturing sites, then security protection is provided, but regular updates are required

Engineering Contradiction:
Improvesecurity protectionVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based physical switching devices. The mechanical switch physically opens or closes electrical circuits to block or permit data transmission, eliminating the need for complex software firewall configurations and updates while maintaining security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If data transmission is allowed from manufacturing site to cloud storage, then data access is enabled, but unauthorized external access becomes possible

Engineering Contradiction:
Improvedata access capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway device serves as an intermediary between the manufacturing site network and the cloud storage network. It controls and filters data transmission in both directions, enabling legitimate data access while blocking unauthorized external access attempts through its network coupling and physical switching mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses physical switching devices to control data transmission paths. The mechanical switch provides tangible, observable control over data flow, making it clear when transmission is blocked or permitted, thereby preventing unauthorized access while maintaining necessary data accessibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3229439B1Secure gateway
Publication Date: 2018.11.21 MB CONNECT LINE GMBH FERNWARTUNGSSYST
  • EP3229439B1 patent drawingFigure 1
  • EP3229439B1 patent drawingFigure 2

AI summary

Gateway device (100), adapted to couple a first network with a second network, comprising: - a first network interface device (102) coupled by a first interface to a first network and having a second interface; - a second network interface device (104) coupled by a first interface with the second network and having a second interface; - a network coupling device (103) adapted to transmit in a first status no data from the second interface of the second network interface device (104) to the second interface of the first network interface device (102) on the physical layer and adapted to transmit in a second status data from the second interface of the first network interface device (102) to the second interface of the second network interface device (104); wherein said network coupling device (103) includes a switching device (126, 128) coupled to a conductor (130, 134) coupling the second interface of the first network interface device (102) and second network interface device (104); wherein the switching device (126, 128) is connected such to the conductor (130, 134) that the conductor can not transmit data in a first state of the switching device and that the conductor can transmit data in a second state of the switching device and wherein said switching device (126, 128) is controlled by a manual switch (127) operated by a user.