Configurable Data Guard for High-Throughput Cross-Domain Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cross-domain solutions (CDSs) face limitations in achieving high throughput and low latency, struggling to scale beyond 10 Gb/sec and often experiencing millisecond latencies, which are inadequate for upcoming 100 Gb/sec data rates and real-time applications, while also being inflexible and costly to reconfigure for changing security requirements.

Innovation Solution

A configurable data guard (CDG) implemented on a hardware-based programmable logic device, utilizing ASICs or FPGAs, with pre-configured arrays of generic comparison and action operations, allows for efficient enforcement of complex data guard rules through guard primitives, enabling high data rates and low latency while facilitating flexible reconfiguration without recompiling HDL code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing CDSs are implemented in software on general purpose processors, then flexibility in configuring security rules is improved, but throughput is limited to below 10 Gb/sec and latency increases to milliseconds

Engineering Contradiction:
Improveflexibility in configuring security rulesVSAvoidthroughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent replaces software-based security rule enforcement on general purpose processors with hardware-based enforcement using FPGAs and ASICs. This substitution of mechanical/software systems with hardware systems enables throughput scaling to 100 Gb/sec and beyond while maintaining configurability through hardware description languages and reconfigurable logic elements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments security rule enforcement into discrete, configurable components including guard primitives, comparison operations, and action operations that can be independently configured and combined. This segmentation allows flexible rule configuration while enabling parallel processing in hardware to achieve high throughput.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If existing CDSs are implemented in software on general purpose processors, then ease of configuration is improved, but latency increases to milliseconds which is inadequate for real-time applications

Engineering Contradiction:
Improveease of configurationVSAvoidlatency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces software-based configuration and enforcement with hardware-based systems that provide both ease of configuration through HDL descriptions and extremely low latency processing. The hardware implementation executes security rules in parallel at line rate, reducing latency from milliseconds to microseconds or nanoseconds while maintaining configurability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If existing CDSs are implemented in software, then adaptability to changing security requirements is improved, but reconfiguration is costly and time-consuming

Engineering Contradiction:
Improveadaptability to changing security requirementsVSAvoidreconfiguration cost and time
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements dynamic reconfigurability using FPGAs that allow security rules to be modified in the field through HDL code updates without hardware replacement. This dynamic approach enables adaptability to changing security requirements while reducing reconfiguration costs and time compared to fixed hardware implementations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal hardware platform using FPGAs and ASICs that can enforce multiple different security rules and policies through reconfiguration. This universal implementation allows a single device to adapt to various security requirements, reducing the need for multiple specialized devices and lowering overall reconfiguration costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If data is isolated and prevented from egressing secure networks, then security is improved, but ability to communicate with less secure networks is lost

Engineering Contradiction:
ImprovesecurityVSAvoidability to communicate with less secure networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a configurable data guard as an intermediary device between secure and less secure networks. This intermediary enforces security policies by filtering, inspecting, and controlling data flow between networks of different security domains, allowing secure data to egress when policies permit while maintaining security through hardware-based enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9760731B2Configurable cross-domain information assurance
Publication Date: 2017.09.12 CROGA INNOVATIONS LTD
  • US9760731B2 patent drawing
  • US9760731B2 patent drawing
  • US9760731B2 patent drawing

AI summary

Methods for configuring and utilizing a configurable data guard (CDG) implemented on a hardware-based programmable logic device are disclosed. The CDG may include integrated circuit portions comprising a plurality of arrays of generic comparison operations and a plurality of arrays of generic action operations. The CDG may receive a data guard configuration. The CDG may perform an authentication and integrity check procedure on the received data guard configuration. The CDG may configure a plurality of guard primitives based on the data guard configuration. Each guard primitive may be configured from at least one generic comparison operation and at least one generic action operation. The guard primitives may be used to enforce the complex data guard rules that correspond to the data guard configuration.