Virtual Cross-Domain Data Transfer on Single Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cross-domain solutions require multiple server computers and specialized hardware, leading to increased costs, reliability issues, and maintenance overhead.
Innovation Solution
A cross-domain system utilizing a single server computer with multiple virtual machines and network interface cards, along with one-way or hypervisor-based communication links, to facilitate secure data transfer between different security domains without the need for multiple physical servers or hardware-based links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple server computers and specialized hardware are used for cross-domain solutions, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines multiple server functions into a single server computer by running multiple virtual machines (send node, receive node, and intermediate nodes) concurrently on one physical server. This consolidation maintains the security architecture of multiple nodes while eliminating the need for multiple physical servers and specialized hardware, thus reducing device complexity and cost while preserving security through virtualized isolation.
Solution Approach 2:
The single server computer is designed to perform multiple functions by hosting different virtual machines that each execute specific cross-domain communication tasks. The server acts as both send node, receive node, and intermediate node at different times, making it a universal platform that replaces multiple specialized hardware components while maintaining security through role-based virtual machine configurations.
2Reliability
If multiple server computers are used for cross-domain solutions, then security is improved, but maintenance overhead and cost increase
Solution Approach 1:
By consolidating multiple server functions into one physical server through virtualization, the patent reduces maintenance overhead from managing multiple physical machines to managing a single system. The virtual machines can be managed, updated, and monitored through centralized software control, eliminating the need for separate hardware maintenance while preserving security through virtualized isolation boundaries.
3Reliability
If specialized transmit/receive card sets are used for one-way data link, then security is improved, but cost and device complexity increase
Solution Approach 1:
The patent uses software-based virtual machine instances to replicate the functionality of specialized transmit and receive card sets without requiring physical hardware copies. Each virtual machine emulates the behavior of dedicated security nodes, providing the same security functions through software simulation rather than specialized hardware, thus reducing the quantity of physical components needed.
Solution Approach 2:
The patent replaces the mechanical/hardware-based one-way data link system with a software-based virtualization approach. Instead of using physical transmit/receive card sets with dedicated hardware links, the system uses virtual network interfaces and software-defined communication channels that emulate the same security behavior, eliminating the need for specialized hardware components.
Data Source
AI summary
Three embodiments of one-way cross-domain systems for transferring information from a client in a first security domain to a server in a second separate security domain are disclosed. In addition, three embodiments of bilateral cross-domain systems for transferring first information from a client in a first security domain to a server in a second separate security domain and second information from the server in the second separate security domain to the client in the first security domain are also disclosed. Each of the one-way and bilateral cross-domain systems is based upon a single computer server which employs a number of virtual machines to implement send and receive servers. The single computer server also implements one (for the one-way cross-domain systems) or two (for the bilateral cross-domain systems) virtual one-way data links in either virtual machines or within the hypervisor portion of the operating system.


