Resource Allocation Unit for Unidirectional Network Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data transmission between networks with different security levels, such as industrial control networks and open IT networks, often require additional validation and are not flexible enough to manage varying security requirements effectively.

Innovation Solution

A method for data transmission between networks using a resource allocation unit that exclusively allocates network access resources via a one-way communication unit, such as a network tap or optical data diode, to establish feedback-free unidirectional connections, combined with virtualization for secure data processing and validation, ensuring secure and efficient data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If bidirectional network guards are used to enable secure two-way data transmission between networks with different security levels, then data exchange flexibility is improved, but device complexity increases due to requiring two separate unidirectional data streams with mutual validation

Engineering Contradiction:
Improvedata exchange flexibilityVSAvoidnetwork guard complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the bidirectional network guard into two independent unidirectional network guards, each handling one direction of data flow. This segmentation allows each guard to be simpler while collectively providing bidirectional security, resolving the contradiction between flexibility and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a validation server as an intermediary that performs validation for one direction while the other direction uses a simpler check. This mediator approach enables flexible bidirectional exchange without requiring both directions to have full validation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional validation mechanisms are implemented for data transmission from low-security to high-security networks, then network security is improved, but transmission time increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial validation action by implementing full validation only in one direction (low-security to high-security) while using simpler validation in the reverse direction. This partial approach maintains necessary security without incurring excessive validation time for both directions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The validation server performs preliminary validation of data before it enters the high-security network, ensuring security requirements are met beforehand. This preliminary check prevents unnecessary re-transmissions and maintains efficient data flow while securing the network.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unidirectional data transmission is implemented using data diodes to ensure one-way function, then network security is improved, but adaptability decreases due to restricted bidirectional communication

Engineering Contradiction:
Improveone-way function securityVSAvoidbidirectional data exchange capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges two unidirectional network guards to create a bidirectional communication system. Each guard maintains its unidirectional security properties while their combination enables flexible two-way data exchange, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables flexible and secure data exchange between networks with different security levels by ensuring unidirectional data transmission, preventing unauthorized access, and maintaining network integrity and availability, while allowing for efficient implementation on a single hardware platform.

Implementation Method 1

The one-way communication unit can be embodied for example by means of an optical data diode

Methodology Applied
Scientific EffectOptical data diode: Diode

Implementation Method 2

The one-way communication unit can be embodied for example by means of an optical data diode or alternatively by a passive network tap of a DCU

Methodology Applied
Scientific EffectPassive network tap:

Data Source

PatentUS11991146B2Method and transmission device for data transmission between two or more networks
Publication Date: 2024.05.21 SIEMENS MOBILITY GMBH
  • US11991146B2 patent drawing
  • US11991146B2 patent drawing

AI summary

Provided is a method for data transmission between at least one first network and at least one second network, wherein a) for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data are directed by means of a resource allocation unit arranged between the networks, and b) for the establishment of the at least one connection, the resource allocation unit exclusively allocates at least one net access resource, e.g. network cards or network adapters, which can be coupled to the second net, and a one-way communication unit arranged upstream of the net access resource for establishing a feedback-free data transmission direction.