Software Multi-Protocol Gateway for Cross-Domain Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Cross Domain Solutions (CDS) require hardware-based 'guards' with isolation diodes, which are cumbersome and add to the load carried by units in the field, while also being an additional point of failure.
Innovation Solution
A software-based multi-protocol gateway (MPG) system that validates data against a predefined schema and forwards it unidirectionally to a receiver endpoint without providing any responses, eliminating the need for hardware-based isolation diodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based guards with isolation diodes are used for cross domain communications, then data security is improved, but device complexity and portability are worsened
Solution Approach 1:
The patent replaces the hardware-based isolation diode system with a software-based multi-protocol gateway (MPG) system. The MPG uses software validation against predefined schemas and unidirectional communication protocols to achieve data security without requiring physical isolation hardware. This substitution eliminates the need for cumbersome hardware components while maintaining security through software-based validation and controlled data flow.
2Reliability
If hardware-based guards with isolation diodes are used for cross domain communications, then data security is improved, but ease of operation is worsened
Solution Approach 1:
The patent replaces the hardware-based isolation diode system with a software-based multi-protocol gateway (MPG) system. The MPG uses software validation against predefined schemas and unidirectional communication protocols to achieve data security without requiring physical isolation hardware. This substitution eliminates the need for cumbersome hardware components while maintaining security through software-based validation and controlled data flow.
3Reliability
If hardware-based guards with isolation diodes are used for cross domain communications, then data leakage prevention is improved, but productivity is worsened
Solution Approach 1:
The patent replaces the hardware-based isolation diode system with a software-based multi-protocol gateway (MPG) system. The MPG uses software validation against predefined schemas and unidirectional communication protocols to achieve data security without requiring physical isolation hardware. This substitution eliminates the need for cumbersome hardware components while maintaining security through software-based validation and controlled data flow.
Solution Approach 2:
The MPG system is designed to handle multiple communication protocols and data types through a single software platform. It can validate and forward various types of data (emails, files, messages) across different security domains using the same infrastructure, eliminating the need for separate hardware solutions for different communication needs.
4Reliability
If hardware-based guards with isolation diodes are used for cross domain communications, then data validation capability is improved, but device complexity is worsened
Solution Approach 1:
The patent replaces the hardware-based isolation diode system with a software-based multi-protocol gateway (MPG) system. The MPG uses software validation against predefined schemas and unidirectional communication protocols to achieve data security without requiring physical isolation hardware. This substitution eliminates the need for cumbersome hardware components while maintaining security through software-based validation and controlled data flow.
Data Source
AI summary
A computer-implemented method, in accordance with one aspect of the present invention, includes receiving, by a sender multi-protocol gateway (MPG) implemented in software, data from a sender application for transmission to a receiver endpoint. The data is validated against a predefined schema definition by the sender MPG. In response to successfully validating the data, a service request is made, by the sender MPG, using preconfigured information. An endpoint of the service request is a receiver MPG configured to forward the validated data to a receiver application in communication with the receiver endpoint. The receiver MPG is configured to not reply in any way to the sender MPG and sender application in response to receiving the service request.


