Software Data Diode TCP Proxy with UDP for Secure WAN Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IT-based remote connectivity technologies are costly and inefficient for securing machine operations in distributed non-IT environments, leading to unmanaged security and loss of data plane security, especially when machines connect to remote applications across a WAN or Internet.

Innovation Solution

Implementing a software data diode-TCP proxy with UDP across a WAN using uni-directional semantics and symmetric key encryption through data diode proxies at both ends of a point-to-point link, employing a uni-directional protocol like UDP to ensure secure one-way information flow and eliminate backchannel communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IT-based remote connectivity technologies (VPN, agent-based solutions) are used for machine operations, then security management is provided, but the control plane overhead for maintaining privacy and authentication is prohibitively expensive and does not scale to distributed non-IT environments

Engineering Contradiction:
Improvesecurity managementVSAvoidcontrol plane overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and privacy management functions from the data plane by implementing a separate control plane that handles security operations. This separation allows security management to be maintained while reducing the overhead burden on the data plane, enabling scalable deployment in distributed environments.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a control plane as an intermediary layer between the data plane and security management functions. This mediator handles authentication and privacy maintenance, allowing the data plane to focus on efficient data transmission without bearing the full burden of security overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware data diodes are used to restrict information flow one way, then malware traversal risk is eliminated, but the solution is prohibitively expensive and not suitable for distributed environments

Engineering Contradiction:
Improvemalware protectionVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces physical hardware data diodes with a software-based implementation that achieves the same unidirectional data flow restriction. This substitution dramatically reduces deployment costs while maintaining the core security function of preventing malware traversal, making the solution viable for distributed environments.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a software copy of the hardware data diode functionality, implementing the unidirectional restriction logic in software rather than requiring physical hardware devices. This allows the security function to be replicated across multiple distributed locations at minimal cost.

Inventive Principle:
Principle #26Copying

3Reliability

If air-gapped isolation is used for machine security, then security is maintained, but operational flexibility and remote connectivity are lost

Engineering Contradiction:
Improvesecurity isolationVSAvoidremote connectivity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network communication into control plane and data plane, allowing the control plane to handle authentication and security management while the data plane enables unidirectional data flow. This segmentation allows machines to maintain security isolation while enabling controlled remote connectivity for operations and monitoring.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11394812B2Methods and systems of a software data diode-TCP proxy with UDP across a WAN
Publication Date: 2022.07.19 IOTIUM INC
  • US11394812B2 patent drawing
  • US11394812B2 patent drawing
  • US11394812B2 patent drawing

AI summary

Disclosed herein are various systems, apparatuses, software, and methods relating to data diode-TCP proxy with a User Datagram Protocol (UDP) across a wide area network (WAN) comprising providing a WAN data diode using a uni-directional semantics protocol, providing a set of data diode proxies in either end of a point-to-point WAN link, providing a symmetric key encryption semantics to extend the WAN data diode securely across a WAN that is specified, wherein the symmetric key encryption semantics are implemented through the set of data diode proxies on either end of the point-to-point WAN link, employing a unidirectional protocol in communication transmitted using the WAN, and, with data diode proxies, terminating one or more data channels on either end of the point-to-point WAN link or transporting a requisite information across the WAN over the uni-directional protocol.