IP Library › Granted Patent US 11,991,146
Granted Patent B2
US 11,991,146 · App. 17/621,375 · Granted May 21, 2024

Method and transmission device for data transmission between two or more networks

Inventors: Christian Bauer (Munich, DE); Matthias Lorenz (Vechelde, DE); Hermann Seuschek (Munich, DE); Martin Wimmer (Neubiberg, DE)
Assignee: Siemens Mobility GmbH
H04L63/0209H04L63/0428H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,991,146
App. No.
17/621,375
Granted
May 21, 2024
Kind
B2
Abstract

Provided is a method for data transmission between at least one first network and at least one second network, wherein a) for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data are directed by means of a resource allocation unit arranged between the networks, and b) for the establishment of the at least one connection, the resource allocation unit exclusively allocates at least one net access resource, e.g. network cards or network adapters, which can be coupled to the second net, and a one-way communication unit arranged upstream of the net access resource for establishing a feedback-free data transmission direction.

Claims (23)

1. A method for data transmission between at least one first network and at least one second network, wherein

a) for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data is or are directed via a resource allocation unit arranged between the networks,

wherein

b) for the establishment of the at least one connection, the resource allocation unit exclusively allocates at least one network access resource, able to be coupled to the second network, and a one-way communication unit disposed upstream of the network access resource, for predefining a feedback-free data transmission direction.

2. The method as claimed in claim 1 , wherein the at least one first network satisfies a first security requirement and the at least one second network satisfies a second security requirement, different in comparison with the first security requirement.

3. The method as claimed in claim 1 , wherein provision is made of a virtual machine for the data transmission between the networks, which reconstructs payload data from the data received in the one-way communication unit, wherein the payload data are forwarded.

4. The method as claimed in claim 3 , wherein provision is made of a validation unit disposed downstream of the virtual machine, wherein the payload data are validated on the basis of a predefined rule in the validation unit and are forwarded in the event of positive validation.

5. The method as claimed in claim 4 , wherein provision is made of a data lock-keeper disposed downstream of the validation unit, wherein, in the event of negative validation, the data lock-keeper interrupts or prevents the forwarding of the payload data and optionally buffer-stores the payload data.

6. The method as claimed in claim 5 , wherein the data lock-keeper permits a payload data transmission, directed via the virtual machine, from the virtual machine to the data lock-keeper and/or a payload data transmission from the data lock-keeper to the allocated network access resource.

7. A transmission device for data transmission between at least one first network and at least one second network, comprising:

a) at least one communication unit designed to the effect that for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data is or are directed via a resource allocation unit arranged between the networks,

and

b) the resource allocation unit for the establishment of the at least one connection, which is designed to exclusively allocate at least one network access resource, able to be coupled to the second network, and a one-way communication unit disposed upstream of the network access resource for predefining a feedback-free data transmission direction.

8. The transmission device as claimed in claim 7 , wherein the at least one first network satisfies a first security requirement and the at least one second network satisfies a second security requirement, different in comparison with the first security requirement.

9. The transmission device as claimed in claim 7 , further comprising a virtual machine for the data transmission between the networks, which is designed to reconstruct payload data from the data received in the one-way communication unit, wherein the payload data is forwarded.

10. The transmission device as claimed in claim 9 , further comprising a validation unit disposed downstream of the virtual machine, wherein the payload data can be validated on the basis of a predefined rule in the validation unit and can be forwarded in the event of positive validation.

11. The transmission device as claimed in claim 10 , further comprising a data lock-keeper disposed downstream of the validation unit, wherein, in the event of negative validation, the data lock-keeper can interrupt or prevent the forwarding of the payload data and optionally buffer-store the payload data.

12. The method as claimed in claim 11 , wherein the data lock-keeper permits a payload data transmission directed via the virtual machine and/or a payload data transmission from the data lock-keeper to the allocated network access resource.

13. The transmission device as claimed in claim 7 , wherein the network access resource is designed for serial data transmission.

14. A computer program product comprising: a computer readable hardware storage device having computer readable program code stored therein, the program code executable by a processor of a computer system to implement a method for data transmission between at least one first network and at least one second network, wherein

a) for at least one data transmission between the at least one first network and the at least one second network, at least one connection between the first network and the second network is established and a datum or data is or are directed via a resource allocation unit arranged between the networks,

wherein

b) for the establishment of the at least one connection, the resource allocation unit exclusively allocates at least one network access resource, able to be coupled to the second network, and a one-way communication unit disposed upstream of the network access resource, for predefining a feedback-free data transmission direction.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: BAUER, CHRISTIAN; SEUSCHEK, HERMANN; WIMMER, MARTIN
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 060124/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: LORENZ, MATTHIAS
To: SIEMENS MOBILITY GMBH
Reel/Frame 060124/0275 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: SIEMENS AKTIENGESELLSCHAFT
To: SIEMENS MOBILITY GMBH
Reel/Frame 060124/0338 →
Priority Claims (1)
DE 102019209342.6 · Jun 27, 2019 · national
Continuity (1)
Related Publication 20220360558A1 · Nov 10, 2022