IP Library Granted Patent US 8,353,022
Granted Patent B1
US 8,353,022 · App. 13/488,028 · Granted Jan 8, 2013

Bilateral communication using multiple one-way data links

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,353,022
App. No.
13/488,028
Granted
Jan 8, 2013
Kind
B1
Abstract

A bilateral data transfer system comprising a first node, a second node, a first one-way link for unidirectional transfer of first data from the first node to the second node, and a second one-way link for unidirectional transfer of second data from the second node to the first node, wherein the unidirectional transfer of the first data across the first one-way link and the unidirectional transfer of the second data across the second one-way link are independently administered by the bilateral data transfer system. Under such bilateral data transfer system, each of the one-way data links may be subject to separately administered security restrictions and data filtering processes. Hence, it enables secure bilateral communications across different network security domains.

Claims (75)

1. A bilateral data transfer system comprising:

a first node;

a second node;

a first one-way link for unidirectional transfer of first data from the first node to the second node; and

a second one-way link for unidirectional transfer of second data from the second node to the first node,

wherein the first node comprises:

one or more processors;

a memory storing a first data sending application, a second data receiving application and a first session managing application;

and wherein the one or more processors are configured to execute:

the first data sending application for sending the first data to the second node over the first one-way link;

the second data receiving application for receiving the second data from the second node over the second one-way link; and

the first session managing application for blocking the first data from the second data receiving application and for blocking the second data from the first data sending application, and

wherein the second node comprises:

one or more processors;

a memory storing a first data receiving application, a second data sending application and a second session managing application;

wherein the one or more processors are configured to execute:

the first data receiving application for receiving the first data from the first node over the first one-way link;

the second data sending application for sending the second data to the first node over the second one-way link; and

the second session managing application for blocking the first data from the second data sending application and for blocking the second data from the first data receiving application, so that the unidirectional transfer of the first data across the first one-way link and the unidirectional transfer of the second data across the second one-way link are independently administered by the bilateral data transfer system, wherein:

the first data comprises a request for data from a remote terminal client; and

the second data comprises requested data from a remote terminal server.

2. The data transfer system of claim 1 , further comprising:

a first data sending configuration file and a first data receiving configuration file for filtering and routing the first data, wherein the first data sending configuration file is accessible by the first data sending application and the first data receiving configuration file is accessible by the first data receiving application; and

a second data sending configuration file and a second data receiving configuration file for filtering and routing the second data, wherein the second data sending configuration file is accessible by the second data sending application and the second data receiving configuration file is accessible by the second data receiving application.

3. The data transfer system of claim 1 , further comprising the remote terminal client connected to the first node and the remote terminal server connected to the second node.

4. The data transfer system of claim 1 , wherein the first data sending and receiving applications and the second data sending and receiving applications are configured to respectively apply different security constraints to the unidirectional transfer of the first data over the first one-way link and the unidirectional transfer of the second data over the second one-way link.

5. The data transfer system of claim 1 , further comprising a first data routing configuration file associated with the first session managing application and a second data routing configuration file associated with the second session managing application.

6. The data transfer system of claim 3 , wherein the second session managing application is configured to control a connection between the second node and the remote terminal server so that the remote terminal server cannot initiate the connection.

7. A non-transitory machine readable medium having instructions stored on at least one of a first node and a second node, wherein the first node and the second node are interconnected by a first one-way link for unidirectional transfer of first data from the first node to the second node and a second one-way link for unidirectional transfer of second data from the second node to the first node, the instructions, when executed by the at least one of the first and the second nodes, causing the first and the second nodes to separately administer the unidirectional transfer of the first data from the first node to the second node via the first one-way link and the unidirectional transfer of the second data from the second node to the first node via the second one-way link, wherein the first data comprises a request for data from a remote terminal client connected to the first node and the second data comprises requested data from a remote terminal server connected to the second node.

8. The non-transitory machine readable medium of claim 7 , wherein the step to separately administer by the first and the second nodes comprises the steps to:

filter and route the first data using a first data transfer configuration file; and

filter and route the second data using a second data transfer configuration file.

9. The non-transitory machine readable medium of claim 8 , wherein:

the first data transfer configuration file comprises a first data sending configuration file in the first node and a first data receiving configuration file in the second node; and

the second data transfer configuration file comprises a second data sending configuration file in the second node and a second data receiving configuration file in the first node.

10. The non-transitory machine readable medium of claim 7 , wherein the instructions, when executed by the at least one of the first and the second nodes, further cause:

the first node to further administer bilateral communications with the remote terminal client; and

the second node to further administer bilateral communications with the remote terminal server.

11. The non-transitory machine readable medium of claim 10 , wherein the bilateral communications between the first node and the remote terminal client are TCP-based.

12. The non-transitory machine readable medium of claim 10 , wherein the bilateral communications between the second node and the remote terminal server are TCP-based.

13. The non-transitory machine readable medium of claim 7 , wherein the step to separately administer by the first and the second nodes comprises the step to apply different security constraints to the unidirectional transfer of the first data from the first node to the second node via the first one-way link and the unidirectional transfer of the second data from the second node to the first node via the second one-way link.

14. A non-transitory machine readable medium having instructions stored on at least one of a first node and a second node, wherein the first node and the second node are interconnected by a first one-way link for unidirectional transfer of first data from the first node to the second node and a second one-way link for unidirectional transfer of second data from the second node to the first node, the instructions, when executed by the first node, causing the first node to:

execute a first data sending application to send the first data to the second node over the first one-way link;

execute a second data receiving application to receive the second data from the second node over the second one-way link; and

execute a first session managing application to block the first data from the second data receiving application and to block the second data from the first data sending application, further the instructions, when executed by the second node, causing the second node to:

execute a first data receiving application to receive the first data from the first node over the first one-way link;

execute a second data sending application to send the second data to the first node over the second one-way link; and

execute a second session managing application to block the first data from the second data sending application and to block the second data from the first data receiving application, so that the unidirectional transfer of the first data across the first one-way link and the unidirectional transfer of the second data across the second one-way link are independently administered by the instructions,

wherein:

the first data comprises a request for data from a remote terminal client connected to the first node; and

the second data comprises requested data from a remote terminal server connected to the second node.

15. The non-transitory machine readable medium of claim 14 , wherein:

the step to execute the first data sending application comprises the step to read a first data sending configuration file to route the first data;

the step to execute the first data receiving application comprises the step to read a first data receiving configuration file to route the first data;

the step to execute the second data sending application comprises the step to read a second data sending configuration file to route the second data; and

the step to execute the second data receiving application comprises the step to read a second data receiving configuration file to route the second data.

16. The non-transitory machine readable medium of claim 14 , wherein:

the step to execute the first session managing application comprises the step to route the first data from the remote terminal client only to the first data sending application and the step to route the second data from the second data receiving application only to the remote terminal client; and

the step to execute the second session managing application comprises the step to route the first data from the first data receiving application only to the remote terminal server and the step to route the second data from the remote terminal server only to the second data sending application.

17. The non-transitory machine readable medium of claim 14 , wherein:

the step to execute the first session managing application comprises the step to implement bilateral TCP communications between the first node and the remote terminal client; and

the step to execute the second session managing application comprises the step to implement bilateral TCP communications between the second node and the remote terminal server.

18. The non-transitory machine readable medium of claim 14 , wherein:

the steps to execute the first data sending application and the first data receiving application comprise the step to apply a first security constraint to the unidirectional transfer of the first data over the first one-way link;

the steps to execute the second data sending application and the second data receiving application comprise the step to apply a second security constraint to the unidirectional transfer of the second data over the second one-way link; and

the first security constraint and the second security constraint are different.

19. The non-transitory machine readable medium of claim 14 , wherein:

the step to execute the first session managing application comprises the step to read a first data routing configuration file; and

the step to execute the second session managing application comprises the step to read a second data routing configuration file.

20. A bilateral data transfer system comprising:

a first one-way link for unidirectional transfer of data from an input end thereof to an output end thereof;

a second one-way link for unidirectional transfer of data from an input end thereof to an output end thereof;

a first node coupled to the input end of the first one-way link and to the output end of the second one-way link, the first node comprising a processor and an associated memory configured to execute a data transfer application to transfer first data to the second node over the first one-way link, a second data receiving application for receiving second data from the second node over the second one-way link, and a first session managing application for blocking the first data from the second data receiving application and for blocking the second data from the first data sending application;

a second node coupled to the output end of the first one-way link and to the input end of the second one-way link, the second node comprising a processor and an associated memory configured to execute a first data receiving application for receiving the first data from the first node over the first one-way link, a second data sending application for transferring the second data to the first node over the second one-way link, and a second session managing application for blocking the first data from the second data sending application and for blocking the second data from the first data receiving application,

wherein the first data comprises a request for data from a remote terminal client, and wherein the second data comprises requested data from a remote terminal server.

Assignments (7)
SECURITY INTEREST Recorded Sep 11, 2024
From: OWL CYBER DEFENSE SOLUTIONS, LLC
To: RGA REINSURANCE COMPANY
Reel/Frame 068938/0313 →
MERGER AND CHANGE OF NAME Recorded Sep 2, 2022
From: OWL CYBER DEFENSE SOLUTIONS, LLC; TRESYS TECHNOLOGY, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 060978/0964 →
CHANGE OF NAME Recorded Jun 20, 2017
From: OWL COMPUTING TECHNOLOGIES, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 042902/0582 →
CORRECTIVE ASSIGNMENT TO CORRECT TO REMOVE THIS DOCUMENT SERVES AS AN OATH/DECLARATION (37 CFR 1.63) FROM THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 041765 FRAME: 0034. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER EFFECTIVE DATE 02/03/2017. Recorded Apr 21, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 042344/0033 →
MERGER Recorded Mar 28, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 041765/0034 →
SECURITY INTEREST Recorded Jan 31, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 041136/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2016
From: MENOHER, JEFFREY; HOPE, JAMES; MRAZ, RONALD
To: OWL COMPUTING TECHNOLOGIES, INC.
Reel/Frame 040689/0418 →