One-Way Secure Link Data Validation Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks handling confidential data, existing systems with one-way links lack effective mechanisms for secure data transmission and validation, particularly in preventing malicious software and unauthorized access.

Innovation Solution

A data security engine is placed between one-way links to validate data by testing for viruses, content filtering, and authenticating sources, with optional physical switching to ensure secure transmission over separate time periods, preventing simultaneous data transfer and impeding hacker attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted over one-way links without intermediate validation, then transmission speed is maintained, but security against malicious software and unauthorized access deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A data security engine is introduced as an intermediary device between the transmitting computer and receiving computer. This engine validates data by performing security tests including virus detection, content filtering, and authentication of data sources. The intermediary validates data without creating bidirectional communication paths, thus maintaining one-way link security while adding validation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical switches are used to disconnect one-way links, then security against hacker attacks is improved, but transmission time and system complexity increase

Engineering Contradiction:
Improvesecurity against attacksVSAvoidtransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Physical switches are used to periodically connect and disconnect one-way links in time-synchronized intervals. During transmission time windows, links are connected to allow data flow; during non-transmission periods, links are disconnected to prevent unauthorized access. The system operates in periodic cycles of connection and disconnection, with multiple time windows within each cycle.

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If data validation and security tests are performed, then malicious software detection is improved, but data transmission speed deteriorates

Engineering Contradiction:
Improvemalicious software detectionVSAvoiddata transmission speed
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Security tests including virus detection, content filtering, and authentication are performed in advance during designated time windows before data is forwarded to the receiving computer. The data security engine validates incoming data buffers during transmission time windows, so that by the time data needs to be forwarded, validation is already complete. This preliminary validation approach prevents malicious software from reaching the receiving computer while minimizing impact on overall transmission speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10063517B2One way secure link
Publication Date: 2018.08.28 WATERFALL SECURITY SOLUTIONS LTD
  • US10063517B2 patent drawing
  • US10063517B2 patent drawing
  • US10063517B2 patent drawing

AI summary

A method for secure communications between a transmitting computer and a receiving computer includes transmitting data from the transmitting computer over a first one-way link to a data security engine, receiving and validating the data within the data security engine, and, after validating the data, transmitting the data from the data security engine to the receiving computer over a second one-way link.