Smart NIC Cloud Cross-Domain Security via Software Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional hardware-based cross-domain solutions for secure data transfer are difficult to maintain and operate, and are not feasible for cloud networks due to the need for specialized hardware and physical isolation.

Innovation Solution

A software-implemented cloud-based cross-domain system that uses a network interface card (NIC) with a smart NIC to enable secure one-way traffic into a dedicated network without specialized hardware, employing protocols like UDP for unidirectional communication and machine learning/AI filters for adaptive security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based cross-domain solutions are used to control and inspect data, then security and data control are improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces hardware-based cross-domain solutions with a software-based network interface card (NIC) that implements cross-domain control functions. The NIC uses software protocols (UDP, TCP) and filtering mechanisms to achieve secure data transfer, eliminating the need for specialized physical hardware while maintaining security functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the implementation parameters from hardware-level to software-level operations. By using configurable protocols and filter chains in the NIC, the system allows flexible parameter adjustment for security policies without requiring physical hardware changes, thereby improving ease of operation while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If specialized hardware is used for cross-domain control, then security control is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes specialized hardware with a standard network interface card that uses software-based protocols. The NIC implements cross-domain control through software filtering and protocol conversion (UDP, TCP) rather than dedicated hardware circuits, reducing device complexity and cost while maintaining security control capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent makes the network interface card universal by enabling it to perform multiple functions: data transfer, security filtering, protocol conversion, and cross-domain control. This multi-functionality eliminates the need for separate specialized hardware components, reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If physical isolation is implemented for disconnected networks, then security is improved, but adaptability and ease of manufacture deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical isolation mechanisms with software-based security controls in the NIC. Instead of requiring physical air-gaps or dedicated hardware isolation, the system uses protocol-based filtering and unidirectional communication rules to achieve security, thereby improving adaptability while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces dynamic security policies that can be adjusted based on network conditions and threat levels. The filter chains and protocol configurations in the NIC can be dynamically modified without changing physical infrastructure, enabling the system to adapt to varying security requirements while maintaining disconnected network security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11863455B2Cloud based cross domain system—CDSaaS
Publication Date: 2024.01.02 ORACLE INT CORP
  • US11863455B2 patent drawing
  • US11863455B2 patent drawing
  • US11863455B2 patent drawing

AI summary

In some aspects, a computing device of the virtual cloud network may select one or more filters from a plurality of filters for a data pipeline, the plurality of filters comprising at least one of: a malware filter; a content filter; a signature filter; a content analyzer; a machine learning filter; or an artificial intelligence filter. A sequential order for the one or more selected filters in the data pipeline can be determined. A message may be received in the data pipeline from a network interface card (NIC), the network interface card being configured as a one-way transfer device. The message in the data pipeline may be filtered by passing the message through the one or more selected filters in the determined sequential order. The computing device of the virtual cloud network may provide logs of events occurring in the data pipeline via a logging network.