Unidirectional Data Transfer Protocol for Secure Network Segments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing unidirectional data transfer solutions require specialized hardware and drivers, which are costly and ill-suited for cloud-based solutions, often breaking application-layer data and being inefficient in data distribution and management.

Innovation Solution

A hardware-agnostic unidirectional data transfer protocol using control messages to set up and tear down communication sessions, with multiple inbound messages to ensure data integrity and reliability across unidirectional communication channels, allowing application-layer data to be transmitted without specialized hardware, employing start and end control messages, data packets, sequence identifiers, and hashes for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware and driver solutions are used for unidirectional data transfer, then data transfer reliability is improved, but cost and device complexity increase significantly

Engineering Contradiction:
Improvedata transfer reliabilityVSAvoidhardware and driver complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces specialized hardware-based unidirectional data transfer mechanisms with a software protocol implementation. The protocol operates at the application layer using standard network infrastructure, eliminating the need for dedicated hardware devices and drivers while maintaining reliable data transfer through application-layer error handling, acknowledgment messages, and data integrity verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The protocol enables standard network interfaces and general-purpose computing devices to perform unidirectional data transfer functions that previously required specialized hardware. By implementing the protocol in software, the same hardware infrastructure can serve multiple purposes including bidirectional communication, cloud-based solutions, and unidirectional data transfer without requiring dedicated unidirectional hardware devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If specialized hardware solutions are used for unidirectional data transfer, then data transfer security is improved, but adaptability to cloud-based solutions deteriorates

Engineering Contradiction:
Improvedata transfer securityVSAvoidcloud-based solution adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces hardware-based security mechanisms with software-based security protocols that operate at the application layer. This substitution enables cloud-based implementations where security is enforced through protocol-level authentication, encryption, and access control rather than through dedicated hardware security modules, making the solution adaptable to virtualized and cloud environments.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The protocol introduces an application-layer intermediary that mediates data transfer between sending and receiving applications. This intermediary enforces security policies, validates data integrity, and controls the unidirectional flow without requiring specialized hardware, enabling flexible deployment across cloud-based infrastructures and distributed systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware-based unidirectional transfer is used, then data integrity is improved, but ease of operation and data management deteriorate

Engineering Contradiction:
Improvedata integrityVSAvoiddata distribution and management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces hardware-based data integrity mechanisms with software-based error detection and correction protocols. The application-layer protocol includes checksum validation, sequence numbering, and acknowledgment messages that ensure data integrity without requiring specialized hardware, thereby simplifying data distribution and management operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The protocol implements self-service error handling and data validation at the application layer. Applications using the protocol automatically perform error detection, request retransmission of corrupted data, and verify data integrity without requiring specialized hardware assistance, thereby easing operational complexity and improving ease of data management.

Inventive Principle:
Principle #25Self-service

4Reliability

If specialized hardware is used for unidirectional data transfer, then transmission effectiveness is improved, but productivity and efficiency deteriorate due to bottlenecks

Engineering Contradiction:
Improvetransmission effectivenessVSAvoiddata distribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces hardware-based transmission control with software-based protocol mechanisms that operate over standard network infrastructure. This substitution eliminates hardware bottlenecks and enables parallel data processing, improving throughput and efficiency while maintaining reliable transmission through protocol-level error handling and flow control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The protocol moves data transfer control from the lower layers (physical and data link layers) to the application layer, adding a new dimension of software-based control. This dimensional shift enables more flexible and efficient data distribution by leveraging higher-layer processing capabilities and standard network infrastructure rather than being constrained by hardware limitations at lower layers.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11870756B2Reliable data transfer protocol for unidirectional network segments
Publication Date: 2024.01.09 SCI APPL INT CORP
  • US11870756B2 patent drawing
  • US11870756B2 patent drawing
  • US11870756B2 patent drawing

AI summary

A unidirectional transfer protocol allows data to be transmitted from a non-secure network into a secure network. A non-secure gateway may receive data and/or information, intended for the secure network, from one or more devices. The gateway may fragment the data and/or information into smaller chunks and transmit the chunks to a secure gateway via a unidirectional communication channel. The secure gateway may verify the chunks using one or more rules and reassemble the chunks when the data is validated. The reassembled data may be sent across a secure network enclave. The unidirectional transfer protocol may provide a hardware-agnostic solution for transmitting data over a unidirectional communication channel.