Virtual Machine Data Transfer Isolation for Secure External Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating external devices into IT infrastructure poses security risks, allowing unauthorized access and unwanted data exchange, which existing technologies fail to adequately address.

Innovation Solution

A computer module with a hypervisor managing multiple virtual machines, where each virtual machine has dedicated memory areas and a data transfer program to securely process and format data, ensuring no direct data access between machines, using a hypervisor and data transfer program to isolate and format data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external devices are integrated into IT infrastructure to enable data exchange, then connectivity and data transmission capability are improved, but security risks increase allowing unauthorized access and unwanted data exchange

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A data transfer program acts as an intermediary between external devices and the IT infrastructure. This program receives data from external devices, extracts only the necessary payload information, and forwards it to authorized virtual machines. The intermediary prevents direct access to the IT infrastructure while enabling controlled data exchange, thus resolving the contradiction between connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments data into different components (headers, metadata, payload) and only extracts and transmits the necessary payload portions to authorized virtual machines. This segmentation allows selective data transmission, enabling data exchange functionality while filtering out potentially harmful or unnecessary data, thus maintaining security while preserving adaptability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If direct data access between virtual machines is allowed to simplify data transmission, then ease of operation is improved, but security is worsened due to potential unauthorized access

Engineering Contradiction:
Improvedata transmission simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The data transfer program serves as a mandatory intermediary for all data transmissions between virtual machines and external devices. It simplifies the operation by automatically extracting payloads and routing data according to pre-configured rules, while simultaneously maintaining security by preventing direct access and enforcing authorization policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data transfer program automatically performs data extraction, validation, and routing without requiring manual intervention. It self-manages the security policies and authorization checks, making the system easy to operate while maintaining strong security controls through automated enforcement of access rules.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4614320B1Computer module and computer-implemented method for data transmission
Publication Date: 2026.04.22 CONGATEC GMBH
  • EP4614320B1 patent drawingFigure 1
  • EP4614320B1 patent drawingFigure 2
  • EP4614320B1 patent drawingFigure 3

AI summary

The invention relates to a computer module (1) and a computer-implemented method for secure data transmission from an external device (G) by means of a data transfer program (4) installed on a virtual machine (VM1) of the computer module (1).