Content Router for High Assurance MLS Metadata Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network communications fail to provide specific metadata or content to requesting systems at appropriate security levels, as they can only transmit entire data packets at the highest security level and cannot individually classify metadata or content within data packets.

Innovation Solution

A security component identifies the security level of content metadata, a content router creates routing tables based on metadata and interest profiles, and a content filter sanitizes the metadata according to the requesting system's security level before providing it, enabling content-based routing with high assurance multi-level security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network communications transmit entire data packets at the highest security level, then security is maintained, but specific metadata or content cannot be provided to requesting systems at appropriate security levels

Engineering Contradiction:
ImprovesecurityVSAvoidcontent specificity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data packets into individual classifiable elements (metadata and content) that can be separately classified and routed. The content router divides incoming data into discrete units that can be independently evaluated against security levels and interest profiles, enabling selective transmission of specific metadata or content to requesting systems at appropriate security levels rather than transmitting entire packets at the highest security level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different security classifications to different portions of data within a packet. The content router evaluates each metadata or content element individually and applies appropriate security filtering and routing decisions to specific portions of the data based on the requesting system's security level and interest profile, rather than applying a uniform security level to the entire packet.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional network communications transmit all content at the highest security level, then security requirements are met, but network bandwidth is wasted transmitting information not needed by the requesting system

Engineering Contradiction:
Improvesecurity complianceVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the specific metadata or content elements that match the requesting system's interest profile and security level from the original data packet. The content router identifies and extracts relevant portions of data, filtering out unnecessary information before transmission. This extraction process eliminates bandwidth waste by sending only the specific information needed rather than transmitting entire high-security packets when lower-security content would suffice.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by transmitting only a subset of the available data - specifically, only those metadata or content elements that are both relevant to the requesting system's interest profile and appropriate for its security level. This partial transmission approach avoids the excessive action of sending complete high-security packets when only specific portions are needed, thereby conserving network bandwidth while maintaining security compliance.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If conventional network communications cannot individually classify metadata or content, then system complexity is reduced, but specific content cannot be provided to requesting systems

Engineering Contradiction:
Improveclassification capabilityVSAvoidcontent delivery precision
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-classifying metadata and content elements with security level identifiers before routing. The security component identifies and tags security levels of individual metadata and content elements in advance, creating a structured format that enables the content router to efficiently evaluate and route specific elements based on requesting system requirements without requiring complex real-time classification decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary components (security component and content router) that facilitate individual classification and routing of metadata and content elements. The security component acts as an intermediary that identifies security levels of individual elements, while the content router serves as an intermediary that matches elements against interest profiles and security requirements. These intermediaries enable precise content delivery without requiring the requesting system itself to perform complex classification tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2225865B1Content based routing with high assurance mls
Publication Date: 2016.05.11 THE BOEING CO
  • EP2225865B1 patent drawingFigure 1
  • EP2225865B1 patent drawingFigure 2
  • EP2225865B1 patent drawingFigure 3

AI summary

A content based routing system which is able to route content contained within data packets according to content metadata located within the respective content is disclosed. The content router receives a content descriptor from the provider and an interest profile from the requesting system. Based on metadata in the content descriptors and the interest profile, the content router creates routing tables and provides the content metadata to the requesting system based on the interest profile. The content metadata is filtered or sanitized according to a security level of the requesting system before the content metadata is provided to the requesting system.