Software Data Diode TCP Proxy with UDP for Secure WAN Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional IT-based remote connectivity technologies are costly and inefficient for securing machine operations in distributed non-IT environments, leading to unmanaged security and loss of data plane security, especially when machines connect to remote applications across a WAN or Internet.
Innovation Solution
Implementing a software data diode-TCP proxy with UDP across a WAN using uni-directional semantics and symmetric key encryption through data diode proxies at both ends of a point-to-point link, employing a uni-directional protocol like UDP to ensure secure one-way information flow and eliminate backchannel communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IT-based remote connectivity technologies (VPN, agent-based solutions) are used for machine operations, then security management is provided, but the control plane overhead for maintaining privacy and authentication is prohibitively expensive and does not scale to distributed non-IT environments
Solution Approach 1:
The patent extracts the authentication and privacy management functions from the data plane by implementing a separate control plane that handles security operations. This separation allows security management to be maintained while reducing the overhead burden on the data plane, enabling scalable deployment in distributed environments.
Solution Approach 2:
The patent introduces a control plane as an intermediary layer between the data plane and security management functions. This mediator handles authentication and privacy maintenance, allowing the data plane to focus on efficient data transmission without bearing the full burden of security overhead.
2Reliability
If hardware data diodes are used to restrict information flow one way, then malware traversal risk is eliminated, but the solution is prohibitively expensive and not suitable for distributed environments
Solution Approach 1:
The patent replaces physical hardware data diodes with a software-based implementation that achieves the same unidirectional data flow restriction. This substitution dramatically reduces deployment costs while maintaining the core security function of preventing malware traversal, making the solution viable for distributed environments.
Solution Approach 2:
The patent creates a software copy of the hardware data diode functionality, implementing the unidirectional restriction logic in software rather than requiring physical hardware devices. This allows the security function to be replicated across multiple distributed locations at minimal cost.
3Reliability
If air-gapped isolation is used for machine security, then security is maintained, but operational flexibility and remote connectivity are lost
Solution Approach 1:
The patent segments the network communication into control plane and data plane, allowing the control plane to handle authentication and security management while the data plane enables unidirectional data flow. This segmentation allows machines to maintain security isolation while enabling controlled remote connectivity for operations and monitoring.
Data Source
AI summary
Disclosed herein are various systems, apparatuses, software, and methods relating to data diode-TCP proxy with a User Datagram Protocol (UDP) across a wide area network (WAN) comprising providing a WAN data diode using a uni-directional semantics protocol, providing a set of data diode proxies in either end of a point-to-point WAN link, providing a symmetric key encryption semantics to extend the WAN data diode securely across a WAN that is specified, wherein the symmetric key encryption semantics are implemented through the set of data diode proxies on either end of the point-to-point WAN link, employing a unidirectional protocol in communication transmitted using the WAN, and, with data diode proxies, terminating one or more data channels on either end of the point-to-point WAN link or transporting a requisite information across the WAN over the uni-directional protocol.


