Uniway Security Gateway Segmented Communication Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Uniway security gateway systems face challenges in securely managing and transmitting data between physically separated devices, as they are vulnerable to data leakage due to the lack of bidirectional data communication, which compromises security and operational efficiency.

Innovation Solution

A uniway security gateway system is implemented with two uniway communication channels for secure data management, utilizing a management data transmission datagram with a header containing a flag and integrity verification tag, generated using an OTP and encryption key derivation function, to ensure secure and efficient data transmission and reception between a secure and control area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a uniway security gateway system uses unidirectional data transmission only, then data leakage is prevented, but management capability between physically separated devices is compromised

Engineering Contradiction:
Improvedata securityVSAvoidmanagement capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments communication into two separate unidirectional channels: one for application data transmission (secure area to control area) and another for management data transmission (control area to secure area). This segmentation allows each channel to maintain unidirectional security while collectively enabling bidirectional management capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A management data transmission datagram structure is introduced as an intermediary mechanism. This datagram includes specific headers with flags and integrity verification tags that enable secure management communication through the unidirectional channel from control area to secure area, acting as a mediator that carries management instructions without compromising the unidirectional security model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If bidirectional communication is implemented, then management efficiency is improved, but data leakage vulnerability increases

Engineering Contradiction:
Improvemanagement efficiencyVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Communication is segmented into distinct unidirectional channels for different data types. Management data travels through a dedicated channel from control area to secure area, while application data flows in the opposite direction. This segmentation enables efficient management operations while maintaining the security guarantee that data can only flow in authorized directions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different communication channels are assigned different quality characteristics: the application data channel is optimized for high-speed data transfer from secure to control area, while the management data channel is optimized for secure command transmission from control to secure area. Each channel has tailored security and performance properties appropriate to its function.

Inventive Principle:
Principle #3Local quality

3Reliability

If integrity verification is performed on all transmitted data, then data reliability is enhanced, but resource utilization increases

Engineering Contradiction:
Improvedata integrityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Integrity verification is applied selectively rather than uniformly. The system performs integrity verification specifically on management data datagrams using OTP-based authentication tags, while application data transmission relies on the inherent security of the unidirectional channel. This localized application of verification reduces overall resource consumption while maintaining reliability where most critical.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The integrity verification mechanism uses OTP (one-time password) that is pre-synchronized between transmitting and receiving devices. Each device can independently generate and verify authentication tags without requiring continuous communication for key exchange, enabling self-service integrity verification that minimizes additional resource overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11470049B2Method of providing communication channel for secure management between physically separated uniway data transmitting device and uniway data receiving device in uniway security gateway system, and uniway data transceiving device for providing two uniway communication channels therefor
Publication Date: 2022.10.11 NICXION CO LTD
  • US11470049B2 patent drawing
  • US11470049B2 patent drawing
  • US11470049B2 patent drawing

AI summary

Provided are a method of providing a communication channel for secure management between a uniway data transmitting device and a uniway data receiving device which are physically separated from each other in a uniway security gateway system, and a uniway data transceiving device for providing two uniway communication channels therefor. The uniway security gateway system includes a uniway data transmitting device located in a secure area and a uniway data receiving device located in a control area, wherein the uniway data transmitting device and the uniway data receiving device provide a first communication channel for transmitting and receiving data in one direction from the secure area to the control area and a second communication channel for transmitting and receiving management data in one direction from the control area to the secure area.