Unidirectional Network Bridge with Hardware Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions, such as firewalls, are inadequate in ensuring secure communications between networks, particularly in preventing the compromise of security gateways and failing to meet stringent security requirements, especially when dealing with higher security networks connected via lower security networks.

Innovation Solution

A network bridge device with hardware logic modules and associated processors that enforce unidirectional data flows, implement authentication and verification protocols, and segregate management and audit functions, ensuring secure communication channels between higher security networks via a lower security network by using Message Content Inspection and Message Signing modules, and providing a protocol break for end-to-end communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall device is used to implement security checks between networks, then basic network security is improved, but the security gateway itself becomes vulnerable to compromise and cannot meet stringent security requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall device compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network bridge is divided into distinct hardware logic modules (first network interface controller, second network interface controller, message content inspection module, message signing module) that are spatially separated and functionally independent. This segmentation prevents a single point of failure or compromise, as each module operates in isolation with unidirectional data flow between them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces intermediary hardware modules (message content inspection module and message signing module) that mediate between the network interfaces. These intermediaries verify and authenticate messages before they pass between networks, preventing direct access to critical functions and eliminating the vulnerability of traditional firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional firewall devices implement security checks, then some security requirements are met, but they fail to provide authentication and verification capabilities for high security networks

Engineering Contradiction:
Improvesecurity assuranceVSAvoidauthentication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention replaces traditional software-based firewall mechanisms with hardware logic modules that perform authentication and verification. The message signing module uses cryptographic functions in hardware to provide strong authentication, while the message content inspection module verifies message integrity, replacing inadequate software checks with robust hardware-based security functions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If bidirectional communication is allowed between networks, then communication flexibility is improved, but security compromise risk increases

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network bridge implements asymmetric security controls for bidirectional communication. Messages from the first network undergo authentication by the message signing module and verification by the message content inspection module, while messages from the second network follow a different verification path. This asymmetric treatment maintains communication flexibility while ensuring appropriate security verification for each direction.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The message signing module applies cryptographic signatures to messages before they are transmitted to the other network, and the message content inspection module verifies these signatures in advance before allowing message passage. This preliminary authentication and verification prevents security compromises by validating messages before they can affect the protected network.

Inventive Principle:
Principle #9Preliminary anti-action

4Device complexity

If management functions are integrated with data processing functions, then device complexity is reduced, but security assurance is compromised

Engineering Contradiction:
Improvedevice structureVSAvoidsecurity assurance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The network bridge segments management functions from data processing functions into separate hardware modules. The management network interface and management controller are distinct from the data path components (network interface controllers and message processing modules). This segmentation ensures that management operations cannot compromise data processing security, while maintaining manageable device complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3152881B1Secured network bridge
Publication Date: 2019.12.04 BAE SYSTEMS PLC
  • EP3152881B1 patent drawingFigure 1
  • EP3152881B1 patent drawingFigure 2a~2c
  • EP3152881B1 patent drawingFigure 2d

AI summary

An apparatus and method are provided for implementing one or more security services to messages and data being communicated between a first network and a second network. In particular, a network bridge device is provided for applying communications security services to data passing by means of the device from a first network to a second network, the device having a first network interface for linking to the first network, a second network interface for linking to the second network, and a unidirectional link between the first and second network interfaces within the device incorporating a first hardware logic module, configured to apply one or more predetermined data security functions to message data received via the first network interface, and a second hardware logic module, arranged to apply a predetermined scheme for authentication of the source of messages passing through the device.