Secure Data Communication via Unidirectional Datagram Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote monitoring of critical assets in infrastructure, such as power plants, faces challenges in maintaining data security over network connections, requiring effective methods to protect sensitive information from malicious entities.

Innovation Solution

A system and method for two-way secure data communication between servers within a critical infrastructure, involving decryption, verification, and encryption of data using unique datagrams transmitted via unidirectional serial links, with retransmission requests when data is not verified, ensuring secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted over network connections for remote monitoring, then remote access capability is improved, but data security deteriorates

Engineering Contradiction:
Improveremote monitoring capabilityVSAvoiddata security threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments data transmission into unidirectional datagram flows between isolated network zones. Each datagram is a discrete, verified data unit that travels through physically separated communication channels, preventing lateral movement of threats while maintaining monitoring capabilities across the infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including datagram verification mechanisms, encryption layers, and protocol translation services that mediate between the remote monitoring requirements and security constraints. These intermediaries verify data integrity, encrypt sensitive information, and control the flow of data between isolated network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption and verification processes are implemented, then data security is improved, but processing time deteriorates

Engineering Contradiction:
Improvedata protection levelVSAvoiddata processing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing encryption keys, pre- verifying data formats, and pre-configuring communication protocols before actual data transmission occurs. Configuration information and security parameters are set in advance, reducing the computational overhead during time-critical data exchange operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting encryption algorithms, datagram size limits, and verification strictness based on the criticality and type of data being transmitted. Less sensitive data may use lighter verification, while critical infrastructure data receives enhanced protection, optimizing the balance between security and processing speed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If unidirectional serial links are used for data transmission, then data integrity is improved, but communication flexibility deteriorates

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system compensates for the unidirectional limitation by implementing multi-dimensional communication strategies: multiple unidirectional links operate in parallel between different network zones, and the protocol layer provides bidirectional control through carefully orchestrated request-response sequences. This maintains data integrity while achieving functional flexibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8838955B2Two-way, secure, data communication within critical infrastructures
Publication Date: 2014.09.16 BAKER HUGHES CO
  • US8838955B2 patent drawing
  • US8838955B2 patent drawing
  • US8838955B2 patent drawing

AI summary

Systems and methods for two-way, secure, data communication within critical infrastructures are usable to protect critical infrastructure information while allowing real-time monitoring and remote access. Such communication systems and methods can be used to protect critical data by, for example, providing a single point of access via unidirectional, serial, non-routable connections. Additionally, data flow may be controlled by a first server that is not accessible outside of the critical infrastructure.