Unidirectional Data Diodes for Secure Multi-Source Viewing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for viewing information from different data sources with varying security classifications either isolate networks, preventing data exchange, or merge data on a single computer, risking contamination of unclassified data with classified information.

Innovation Solution

A data processing system utilizing a display unit, multiple data processing units, and unidirectional data diodes that allow data to flow only from lower-ranked to higher-ranked units, preventing data from higher-ranked sources from entering lower-ranked domains, enabling simultaneous viewing of data from isolated sources while maintaining separation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data from different security classifications are merged on a single computer system, then the user can view both types of data simultaneously, but there is a risk that unclassified data may be contaminated with classified information

Engineering Contradiction:
Improveability to view data from different sources simultaneouslyVSAvoiddata security and confidentiality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the computer into multiple isolated network segments or virtual machines, each dedicated to a specific security classification level. Data from different sources remains physically or logically separated within these segments, preventing contamination while allowing simultaneous access through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted intermediary system or secure gateway is introduced between different security domains. This mediator controls and monitors data flow, ensuring that unclassified data cannot be accidentally contaminated with classified information while still enabling users to view both types of data through the intermediary interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate computers are used for different security levels, then data security is maintained, but the user cannot exchange data or perform research across different networks

Engineering Contradiction:
Improvedata security and confidentialityVSAvoidability to exchange data and perform research across networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Multiple isolated network systems are merged into a single integrated system that maintains logical separation of security domains. The system combines the security benefits of isolated networks with the functionality of a unified system, allowing data exchange and research activities across different security levels through controlled interfaces and protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system is designed with multi-functionality to handle different security classification levels within a single platform. It provides universal access capabilities that allow users to interact with multiple security domains while maintaining appropriate security boundaries, enabling data exchange and research across networks without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If isolated networks are used to protect confidential information, then data confidentiality is maximized, but users are prevented from accessing information outside their network

Engineering Contradiction:
Improvedata confidentialityVSAvoidability to access information from external sources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A secure intermediary interface is provided that allows users in isolated networks to access external information sources without breaking security boundaries. The intermediary acts as a controlled gateway, filtering and monitoring all external access requests to ensure confidentiality is maintained while enabling necessary information access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access capabilities by security level, allowing users to access information appropriate to their classification level while maintaining isolation from higher-security domains. This segmentation enables controlled access to external sources without compromising the integrity of confidential information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2193470B1Method and apparatus for simultaneous viewing of two isolated data sources
Publication Date: 2017.11.08 THE BOEING CO
  • EP2193470B1 patent drawingFigure 1
  • EP2193470B1 patent drawingFigure 2
  • EP2193470B1 patent drawingFigure 3

AI summary

A method and apparatus for simultaneously displaying data from different sources. A data processing system includes a display unit, data processing units, and data diodes. The display unit has controls that are capable of generating control signals and the display unit is capable of simultaneously displaying the data from the different sources. The data processing units are arranged in a hierarchy of rankings. Each data processing unit is capable of accessing one of the sources. The data diodes are in the connections carrying control signals from the controls to data processing units and are in connections from one data processing unit to another data processing unit. Data is capable of moving only from a lower ranked data processing unit to a higher ranked data processing unit. Data is prevented from moving from a higher ranked data processing unit from a lower ranked data processing unit.