Unidirectional Data Diode with Exclusive Buffer for Secure Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a challenge in securely transmitting data from non-secure networks to security-critical networks, as existing solutions do not adequately ensure the high security requirements for bidirectional data flow, particularly for updating configurations or installing updates in security-critical systems.

Innovation Solution

A computing system with unidirectional input and output data diodes, a data lock with a buffer that can be exclusively connected to either the interface device or the computing device, and transmission sessions initiated by the computing device, ensuring hardware and software separation, and encrypted data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data diodes are used for unidirectional data transmission from non-secure to secure networks, then security is improved, but bidirectional data flow capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidbidirectional data flow capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The data transmission path is segmented into multiple unidirectional channels: an input data path with input data diode for secure-to-non-secure transmission, and an output data path with output data diode for non-secure-to-secure transmission. This segmentation allows each direction to have dedicated security measures while enabling bidirectional communication overall.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A gateway device acts as an intermediary between secure and non-secure networks. The gateway contains a data lock with buffer that temporarily stores data from the non-secure network, then forwards it through the output data diode to the secure network only after validation, enabling controlled bidirectional flow while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data lock with buffer is used to control data flow direction, then security is improved, but data transmission speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The data lock performs preliminary validation and buffering of data from non-secure networks before forwarding to secure networks. By pre-processing and validating data in the buffer, the system ensures security requirements are met before data enters the secure network, preventing security breaches while enabling efficient data flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The buffer in the data lock maintains continuous data flow by storing incoming data and releasing it at appropriate times through the output data diode. This buffering mechanism ensures that data transmission continues without interruption despite the unidirectional constraints and security validation requirements.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If transmission sessions initiated by computing device are required, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The computing device in the secure network autonomously initiates transmission sessions and controls the data flow through the data lock. This self-service mechanism allows the secure system to maintain control over when and how data is received from non-secure networks, ensuring security policies are enforced automatically without requiring manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The transmission session mechanism provides feedback loops where the computing device requests data, the interface device responds with available data, and the session is terminated when data transfer is complete. This structured feedback ensures secure data exchange while maintaining operational control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11805099B2Computing system and method for operating a computing system
Publication Date: 2023.10.31 SIEMENS MOBILITY GMBH
  • US11805099B2 patent drawing
  • US11805099B2 patent drawing
  • US11805099B2 patent drawing

AI summary

A computing system has a computing device. The computing system has an input data path, which unidirectionally connects an interface device to the computing device, and an output data diode, which unidirectionally connects the computing device to the interface device. The input data path has a data lock which is connected to the interface device by a first terminal and to the computing device by a second terminal. The data lock has a storage unit for storing data and is configured such that the storage unit can be selectively connected solely to the first or second terminal but not to both terminals simultaneously. The computing device accepts data from the interface device solely if the data is transmitted to the computing device from the interface device via the input data path within a transmission session initiated by the computing device using the output data diode.