Virtual Cross-Domain Data Transfer on Single Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cross-domain solutions require multiple server computers and specialized hardware, leading to increased costs, reliability issues, and maintenance overhead.

Innovation Solution

A cross-domain system utilizing a single server computer with multiple virtual machines and network interface cards, along with one-way or hypervisor-based communication links, to facilitate secure data transfer between different security domains without the need for multiple physical servers or hardware-based links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple server computers and specialized hardware are used for cross-domain solutions, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple server functions into a single server computer by running multiple virtual machines (send node, receive node, and intermediate nodes) concurrently on one physical server. This consolidation maintains the security architecture of multiple nodes while eliminating the need for multiple physical servers and specialized hardware, thus reducing device complexity and cost while preserving security through virtualized isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single server computer is designed to perform multiple functions by hosting different virtual machines that each execute specific cross-domain communication tasks. The server acts as both send node, receive node, and intermediate node at different times, making it a universal platform that replaces multiple specialized hardware components while maintaining security through role-based virtual machine configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple server computers are used for cross-domain solutions, then security is improved, but maintenance overhead and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance overhead
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By consolidating multiple server functions into one physical server through virtualization, the patent reduces maintenance overhead from managing multiple physical machines to managing a single system. The virtual machines can be managed, updated, and monitored through centralized software control, eliminating the need for separate hardware maintenance while preserving security through virtualized isolation boundaries.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If specialized transmit/receive card sets are used for one-way data link, then security is improved, but cost and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware components
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses software-based virtual machine instances to replicate the functionality of specialized transmit and receive card sets without requiring physical hardware copies. Each virtual machine emulates the behavior of dedicated security nodes, providing the same security functions through software simulation rather than specialized hardware, thus reducing the quantity of physical components needed.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based one-way data link system with a software-based virtualization approach. Instead of using physical transmit/receive card sets with dedicated hardware links, the system uses virtual network interfaces and software-defined communication channels that emulate the same security behavior, eliminating the need for specialized hardware components.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9880869B2Single computer-based virtual cross-domain solutions
Publication Date: 2018.01.30 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9880869B2 patent drawing
  • US9880869B2 patent drawing
  • US9880869B2 patent drawing

AI summary

Three embodiments of one-way cross-domain systems for transferring information from a client in a first security domain to a server in a second separate security domain are disclosed. In addition, three embodiments of bilateral cross-domain systems for transferring first information from a client in a first security domain to a server in a second separate security domain and second information from the server in the second separate security domain to the client in the first security domain are also disclosed. Each of the one-way and bilateral cross-domain systems is based upon a single computer server which employs a number of virtual machines to implement send and receive servers. The single computer server also implements one (for the one-way cross-domain systems) or two (for the bilateral cross-domain systems) virtual one-way data links in either virtual machines or within the hypervisor portion of the operating system.