Unidirectional Couplers for Compromised State Reporting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In one-way transmission systems, the secure site cannot effectively report a compromised state to the insecure site, as traditional mechanisms lack the ability to notify of attacks or errors during firmware upgrades or server attacks, and prior solutions fail to inform the insecure site of compromised states.

Innovation Solution

A communication system with a communication device that includes an error checking circuit, a data inspection circuit, and unidirectional couplers, which checks packet headers and data for errors, enabling or disabling couplers to report incomplete packets to the receiving server, allowing the system to detect and report compromised states in a redundant manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-way transmission mechanism is used, then security of secure site is maintained, but ability to report compromised state to insecure site is lost

Engineering Contradiction:
Improvesecurity of secure siteVSAvoidcompromised state information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The transmission path is segmented into multiple channels: a primary one-way transmission path for normal data flow, and a secondary feedback path for reporting compromised states. This segmentation allows the system to maintain one-way security while enabling selective information flow back to the insecure site only when compromise is detected.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication device is introduced as an intermediary between the secure site and insecure site. This intermediary monitors the transmission, detects compromised states, and conditionally forwards error information to the insecure site, thus enabling reporting without compromising the fundamental one-way security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If FPGA with content inspection rule is applied, then malicious packets are dropped, but compromised state cannot be reported to insecure site

Engineering Contradiction:
Improvemalicious packet filteringVSAvoidcompromise notification
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system implements a feedback mechanism where the communication device monitors packet transmission, detects when packets are dropped due to FPGA content inspection rules, and generates compromised state information. This feedback loop enables the insecure site to be notified of compromise events without requiring the insecure site to initiate communication.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The communication device is configured in advance to monitor for specific error conditions and compromised states. When malicious packets are dropped by the FPGA, the pre-configured system immediately detects the compromise and prepares notification, enabling rapid response without waiting for post-event analysis.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If error checking and data inspection are performed, then transmission security is improved, but device complexity increases

Engineering Contradiction:
Improvetransmission securityVSAvoidchecking circuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The error checking and inspection functions are segmented into distinct circuit modules: an error checking circuit for header validation, a data inspection circuit for payload verification, and unidirectional couplers for controlled information flow. This modular segmentation makes the complex system more manageable and maintainable while preserving comprehensive security checking.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4106267B1Communication system and communication method for reporting compromised state in one-way transmission
Publication Date: 2024.08.28 BLACKBEAR (TAIWAN) IND NETWORKING SECURITY LTD
  • EP4106267B1 patent drawingFigure 1~2
  • EP4106267B1 patent drawingFigure 3
  • EP4106267B1 patent drawingFigure 4~5

AI summary

A communication system and a communication method for reporting a compromised state in one-way transmission are provided. The communication method includes: receiving a packet by a first port; coupling an error checking circuit to the first port, wherein the error checking circuit checks a header of the packet; coupling a first unidirectional coupler to the first port and the error checking circuit, and coupling a second unidirectional coupler to the first port and the error checking circuit; in response to an error being in the header, disabling the first unidirectional coupler and the data inspection circuit and enabling the second unidirectional coupler by the error checking circuit; receiving the packet from the communication device by a receiving server; and in response to determining the received packet is incomplete by the receiving server, outputting the compromised state by the receiving server.