Communication System Segregating Data by Security Level
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional communication systems require separate media and trusted software for segregating data communications at different security levels, leading to increased complexity, cost, and the need for costly reevaluation of security when software is modified.
Innovation Solution
A communication system using internal encryption with specific encryptors and decryptors at each data source and destination to segregate and maintain data signals at different security levels on common media, primarily relying on hardware for security functions and allowing software modifications without reevaluating system security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate communication media are provided for each security level, then data communications at different security levels are segregated and maintained compartmentalized, but the weight, complexity, power requirements, and cost of the communication system substantially increase
Solution Approach 1:
The patent merges multiple security level communications onto a single communication medium by using a encryptor that can generate different encryption keys for different security levels. The encryptor receives data communications and applies appropriate encryption based on the security level, allowing multiple encrypted streams to coexist on the same medium while maintaining segregation through cryptographic means rather than physical separation.
Solution Approach 2:
The patent changes the parameter of encryption key selection based on security level requirements. The encryptor is configured to select different encryption keys or algorithms depending on the classified security level of the incoming data, thereby maintaining security segregation through parameter variation rather than through separate physical media.
2Reliability
If separate communication media are provided for each security level, then data communications at different security levels are segregated and maintained compartmentalized, but the weight, complexity, power requirements, and cost of the communication system substantially increase
Solution Approach 1:
The patent combines multiple security level transmissions onto a single communication medium, eliminating the need for multiple separate media. The encryptor handles different security levels by selecting appropriate encryption keys, allowing the system to use one medium instead of multiple media, thereby reducing system weight.
3Reliability
If trusted software is used for segregating data communications and maintaining compartmentalization, then the data communications are securely transferred within the system, but whenever the trusted software is modified, the security of the communication system must be reevaluated, which is both time-consuming and costly
Solution Approach 1:
The patent replaces software-based security mechanisms with a hardware encryptor that performs encryption and segregation functions. The encryptor is a hardware device that automatically selects appropriate encryption keys based on security level metadata, eliminating the need for trusted software modifications and the associated security reevaluation process.
4Reliability
If multiple separate communication media are used for different security levels, then security compartmentalization is maintained, but the cost of the communication system substantially increases
Solution Approach 1:
The patent merges multiple security level communications onto a single medium, eliminating the need to manufacture and deploy multiple separate communication media. The encryptor handles security segregation through cryptographic key selection, reducing system cost by consolidating infrastructure.
Data Source
AI summary
A communication system is provided for distributing communications within the system while maintaining each communication at one of a plurality of different security levels. The system uses internal encryption to encode all data signals with an encryption which is specific to the security level of the particular data signal being encoded. The internal encryption is designed to segregate all data signals in the system and to maintain the segregated data signals compartmentalized while being transferred on data streams within the system via common media.


