Multi-Domain Blockchain Network for Secure Cross-Domain Data Flow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems fail to provide secure, end-to-end provenance and control for data flowing between different security domains, risking unauthorized data spillage between networks with varying security classifications.

Innovation Solution

A blockchain network architecture that spans across multiple security domains, utilizing a single logical network with isolated blockchain peer nodes and an intermediate block creator to ensure data compliance with cross-domain security policies, preventing unauthorized data transfer through smart contracts and domain controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional guard systems are used to control data flow between security domains, then data security control is improved, but system complexity and lack of end-to-end provenance tracking worsen

Engineering Contradiction:
Improvedata security controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain network as an intermediary layer between security domains. Domain controllers in each security domain communicate with the blockchain network, which acts as a neutral mediator to validate and track data flow. This resolves the contradiction by providing automated security control through smart contracts while the blockchain's distributed ledger automatically tracks provenance, eliminating the need for complex manual guard systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The blockchain network provides continuous feedback mechanisms through its immutable ledger, recording all data flow events across security domains. This feedback loop enables automatic verification of security policies and end-to-end provenance tracking, improving reliability while reducing complexity through automated validation rather than manual monitoring systems.

Inventive Principle:
Principle #23Feedback

2Productivity

If direct connection between security domains is established, then data access efficiency is improved, but unauthorized data spillage risk worsens

Engineering Contradiction:
Improvedata access efficiencyVSAvoidunauthorized data spillage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The blockchain network serves as an intermediary between security domains, allowing domain controllers to access and verify data flow information without direct peer-to-peer connections between domains. This maintains security isolation while enabling efficient data access through the mediating blockchain ledger that records all cross-domain events.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Smart contracts are pre-configured with security policies before data flow occurs. These contracts automatically validate and control data exchange between domains, preventing unauthorized spillage before it can occur. The preliminary setup of security rules in the blockchain enables efficient automated enforcement without requiring complex real-time negotiation between domains.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If isolated blockchain peer nodes are used in each security domain, then security isolation is improved, but network connectivity and data propagation worsen

Engineering Contradiction:
Improvesecurity isolationVSAvoiddata propagation speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The shared blockchain network acts as a mediator that connects isolated domain controllers. Each domain maintains security isolation through its own domain controllers that only communicate with the blockchain, not directly with other domains. The blockchain's distributed consensus mechanism enables fast data propagation across all domains while preserving security boundaries, as the immutable ledger automatically replicates validated events to all participants.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11196771B2Multi-domain blockchain network with data flow control
Publication Date: 2021.12.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11196771B2 patent drawing
  • US11196771B2 patent drawing
  • US11196771B2 patent drawing

AI summary

An example operation may include one or more of receiving an endorsed storage event from a first security domain that conforms to a first security policy and that is isolated from a second security domain that conforms to a second security policy which is different than the first security policy, determining that the storage event satisfies a cross-domain security policy based on the first and second security policies, creating a cross-domain data block which stores the storage event that satisfies the cross-domain security policy as a blockchain transaction, and transmitting the cross-domain data block to a first blockchain node included in the first security domain and a second blockchain node included in the second security domain.