Unidirectional Transmission Device With DMZ Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing transmission devices for secure communication between security-critical and open networks lack effective tamper protection and anomaly detection, particularly vulnerable to attacks from the open network side.

Innovation Solution

A transmission device with a demilitarized zone (DMZ) containing a detection unit, comprising unidirectional transmission units and an intrusion detection system, isolates the detection unit from both networks, allowing for anomaly detection and tamper protection, ensuring unidirectional data flow and localized anomaly analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a detection unit is added to monitor data transmission, then anomaly detection capability is improved, but the device complexity increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection unit is nested within the DMZ, which itself is nested between the first and second unidirectional transmission units. This hierarchical nesting allows the detection unit to be isolated from both networks while remaining integrated into the transmission device, providing anomaly detection capability without directly increasing the complexity of the network interface components.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The DMZ acts as an intermediary zone that mediates between the first network and the second network. The detection unit operates within this intermediary zone, allowing it to monitor data transmission from the first network without being directly accessible from the second network, thus providing detection capability while maintaining security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the detection unit is isolated from both networks to prevent attacks, then tamper protection is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvetamper protectionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The transmission device is segmented into distinct functional zones: the first unidirectional transmission unit connected to the first network, the DMZ containing the detection unit, and the second unidirectional transmission unit connected to the second network. This segmentation isolates the detection unit from direct network access, improving tamper protection while maintaining operational functionality through the structured architecture.

Inventive Principle:
Principle #1Segmentation

3Reliability

If unidirectional transmission units are used to ensure one-way data flow, then security against attacks from the open network is improved, but the adaptability deteriorates

Engineering Contradiction:
Improvesecurity against attacksVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The DMZ serves as an intermediary layer that enables the detection unit to receive and analyze data from the first network unidirectionally while preventing direct access from the second network. This intermediary architecture maintains the security of unidirectional transmission while providing the detection unit with the necessary data access to perform anomaly detection, thus preserving adaptability within security constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407694B2Transmission device for transmitting data
Publication Date: 2025.09.02 SIEMENS MOBILITY GMBH
  • US12407694B2 patent drawing

AI summary

A transmission device for transmitting data between a first network and a second includes: a first unidirectional transmission unit which is coupled to the first network and is configured to exclusively receive data transmitted from the first network to the transmission device, a second unidirectional transmission unit which is coupled to the second network and is configured to exclusively send data from the transmission device to the second network, and an identification unit which is located between the first unidirectional unit and the second unidirectional unit and which is configured to receive the data received by the first unidirectional transmission unit and to identify anomalies in the received data. The provided transmission device achieves the reliable, optimized identification of anomalies in the first network and increases security in the identification unit against manipulation and against attacks or intrusion attempts from the second network.