Communication Isolator Using Signal Conversion for Secure Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security measures, such as software firewalls and uni-directional signal transmission, fail to ensure reliable communication integrity and feedback, making networks vulnerable to cyber threats and sabotage.

Innovation Solution

A communication isolator that physically isolates control systems using bi-directional communication through conversion of digital and analog signals into electrical signals, ensuring only pre-defined signals are exchanged, thereby preventing unauthorized access and cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If software firewall or alert setting is used to monitor and defend intrusion, then security monitoring capability is improved, but network reliability and feedback reception deteriorate

Engineering Contradiction:
Improveintrusion defense capabilityVSAvoidnetwork reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces a dedicated security device as an intermediary component positioned between the control area and security area networks. This device physically receives and processes feedback signals while maintaining network isolation, allowing security monitoring without compromising the reliability of the control network. The intermediary device acts as a buffer that enables security functions without direct integration into the control system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If uni-directional signal transmission is used to prevent intrusion, then security protection is improved, but feedback signal reception and communication reliability deteriorate

Engineering Contradiction:
Improvecyber terrorism preventionVSAvoidfeedback signal loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent segments the communication system into distinct functional zones: a control area network and a security area network, separated by a security device. This segmentation allows unidirectional signal transmission from control to security areas while enabling the security device to independently receive and process feedback signals. The segmentation creates isolated communication paths that prevent intrusion while preserving necessary feedback capabilities through dedicated channels.

Inventive Principle:
Principle #1Segmentation

3Reliability

If bi-directional communication is implemented to enable feedback, then network reliability is improved, but vulnerability to intrusion and cyber threats increases

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidvirus transmission risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security device serves as an intermediary that enables bi-directional communication functionality while maintaining security isolation. It physically receives feedback signals from the control area and processes them in the security area, allowing reliable communication without creating direct bidirectional pathways that could transmit viruses or cyber threats. The intermediary architecture permits necessary feedback while blocking harmful factors through physical separation and controlled signal processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12500689B2Communication isolator for cyber security and communication isolation method of the communication isolator
Publication Date: 2025.12.16 KEPCO ENG & CONSTR CO INC
  • US12500689B2 patent drawing
  • US12500689B2 patent drawing
  • US12500689B2 patent drawing

AI summary

A communication isolator configured to perform network communication with a first control system and a second control system includes a first communication device configured to receive a first communication signal corresponding to a first signal with respect to an output from the first control system, obtain first data by decoding the first communication signal, and generate a second signal corresponding to the first data by using a pre-stored look-up table, and a second communication device configured to receive the second signal from the first communication device, convert the second signal into second data by using the look-up table, encode the second data into a second communication signal, and transmit the second communication signal to the second control system.