Resource Allocation Unit for Unidirectional Network Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure data transmission between networks with different security levels, such as industrial control networks and open IT networks, often require additional validation and are not flexible enough to manage varying security requirements effectively.
Innovation Solution
A method for data transmission between networks using a resource allocation unit that exclusively allocates network access resources via a one-way communication unit, such as a network tap or optical data diode, to establish feedback-free unidirectional connections, combined with virtualization for secure data processing and validation, ensuring secure and efficient data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If bidirectional network guards are used to enable secure two-way data transmission between networks with different security levels, then data exchange flexibility is improved, but device complexity increases due to requiring two separate unidirectional data streams with mutual validation
Solution Approach 1:
The patent segments the bidirectional network guard into two independent unidirectional network guards, each handling one direction of data flow. This segmentation allows each guard to be simpler while collectively providing bidirectional security, resolving the contradiction between flexibility and complexity.
Solution Approach 2:
The patent introduces a validation server as an intermediary that performs validation for one direction while the other direction uses a simpler check. This mediator approach enables flexible bidirectional exchange without requiring both directions to have full validation complexity.
2Reliability
If additional validation mechanisms are implemented for data transmission from low-security to high-security networks, then network security is improved, but transmission time increases
Solution Approach 1:
The patent applies partial validation action by implementing full validation only in one direction (low-security to high-security) while using simpler validation in the reverse direction. This partial approach maintains necessary security without incurring excessive validation time for both directions.
Solution Approach 2:
The validation server performs preliminary validation of data before it enters the high-security network, ensuring security requirements are met beforehand. This preliminary check prevents unnecessary re-transmissions and maintains efficient data flow while securing the network.
3Reliability
If unidirectional data transmission is implemented using data diodes to ensure one-way function, then network security is improved, but adaptability decreases due to restricted bidirectional communication
Solution Approach 1:
The patent merges two unidirectional network guards to create a bidirectional communication system. Each guard maintains its unidirectional security properties while their combination enables flexible two-way data exchange, resolving the contradiction between security and adaptability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enables flexible and secure data exchange between networks with different security levels by ensuring unidirectional data transmission, preventing unauthorized access, and maintaining network integrity and availability, while allowing for efficient implementation on a single hardware platform.
Implementation Method 1
The one-way communication unit can be embodied for example by means of an optical data diode
Implementation Method 2
The one-way communication unit can be embodied for example by means of an optical data diode or alternatively by a passive network tap of a DCU
Data Source
AI summary
Provided is a method for data transmission between at least one first network and at least one second network, wherein a) for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data are directed by means of a resource allocation unit arranged between the networks, and b) for the establishment of the at least one connection, the resource allocation unit exclusively allocates at least one net access resource, e.g. network cards or network adapters, which can be coupled to the second net, and a one-way communication unit arranged upstream of the net access resource for establishing a feedback-free data transmission direction.

