Communication link
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Sophisticated malware can evade detection by disguising as legitimate software and exploit zero-day vulnerabilities, making it difficult to protect data from cyber threats such as ransomware and spyware.
Innovation Solution
Implementing a communication link with unidirectional data transfer and hardware encryption between a computer system and a data handling device, using hardware encryption devices and data diodes to ensure secure data handling without malware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional malware detection methods are used, then data protection can be attempted, but sophisticated malware can evade detection by disguising as legitimate software and exploiting zero-day vulnerabilities
Solution Approach 1:
The patent applies preliminary action by encrypting data before it enters the data handling device, so that even if malware is present, it cannot access or modify the data. The encryption occurs in advance on the communication link, preventing any potential malware from having the opportunity to steal or corrupt the data, thus resolving the detection difficulty by making data protection independent of detection capabilities.
Solution Approach 2:
The patent introduces an intermediary approach by placing a hardware encryption device on the communication link between the computer system and data handling device. This encryption intermediary ensures that data is protected during transmission without requiring the computer system or data handling device to perform complex detection functions, thereby improving data protection reliability without increasing detection complexity.
2Reliability
If unidirectional links with hardware encryption are implemented, then malware-resistant data handling is achieved, but device complexity increases
Solution Approach 1:
The patent extracts the encryption function from the computer system and data handling device, placing it instead on a dedicated hardware encryption device on the communication link. This separation means that the complexity of encryption is isolated in a dedicated component, while the main systems remain simpler. The unidirectional link with data diode is a simple, well-defined component that adds minimal complexity while providing strong malware resistance.
3Reliability
If hardware encryption devices are used to encrypt data prior to transfer, then secure data handling is provided, but the encryption keys must be managed securely
Solution Approach 1:
The patent uses the hardware encryption device as an intermediary that handles key management independently. The encryption device receives keys from the data handling device, performs encryption, and does not provide the keys back to the computer system. This intermediary approach isolates key management in a secure hardware component, protecting against malware while avoiding the complexity of implementing key management in software on potentially compromised systems.
Data Source
AI summary
A communication link 13 for transferring data between a computer system 19 and a data handling device 11 for the computer system is disclosed herein. The communication link 13 comprises a first unidirectional link 25 for transferring data from the user computer system 19 to the data handling device 11 and comprising a hardware encryption device 53 to encrypt data prior to being received at the data handling device 11; and a second unidirectional link 27 for transferring data from the data handling device 11 to the computer system 19. A computer apparatus 2 including the communication link 13 is also disclosed herein.


