Content-Based Routing for Multi-Level Security Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network communications fail to provide specific metadata or content to requesting systems at appropriate security levels, as they can only transmit data packets classified at the highest security level, unable to individually classify metadata or content within data packets.
Innovation Solution
A security component identifies the security level of content metadata, a content router creates routing tables using metadata and interest profiles, and a content filter sanitizes the metadata according to the requesting system's security level before providing it, enabling content-based routing with high assurance multi-level security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network communications transmit data packets classified at the highest security level, then security is maintained, but specific metadata or content cannot be provided to requesting systems at appropriate security levels
Solution Approach 1:
The patent segments data packets into multiple components, classifying metadata and content individually at different security levels rather than treating the entire packet as a single unit. This allows selective routing of different segments to appropriate requesting systems based on their security clearances.
Solution Approach 2:
The patent applies different security classifications to different parts (metadata vs. content) of the data packet based on their specific security requirements. Each component receives appropriate security treatment tailored to its sensitivity, rather than applying a uniform classification to the entire packet.
2Reliability
If conventional network communications provide entire data packets at the highest security level, then all content is secured, but requesting systems receive information they cannot process or do not need
Solution Approach 1:
The patent extracts and separates metadata from content within data packets, allowing the metadata to be routed and delivered to requesting systems that have appropriate security clearances, while higher-classified content remains protected and delivered only to authorized systems.
Solution Approach 2:
The patent introduces a content router as an intermediary component that sits between the data source and requesting systems. This router examines security classifications of individual metadata and content components, then intelligently routes them to appropriate systems based on their security clearances and interests.
3Reliability
If conventional network communications transmit all content at the highest security level, then security is maintained, but network bandwidth is wasted transmitting information that requesting systems cannot access
Solution Approach 1:
The patent performs preliminary classification and tagging of metadata and content components with security level identifiers before routing. This advance preparation allows the content router to quickly determine which components can be delivered to which requesting systems without requiring full transmission of all high-security content.
Solution Approach 2:
The patent implements partial transmission by delivering only the portion of data (metadata) that requesting systems are authorized to receive, rather than transmitting the entire high-security data packet. This avoids wasting bandwidth on content that cannot be accessed.
Data Source
AI summary
Content Based Routing with High Assurance MLS (multi-level security) methods and systems are described. In an embodiment, a security component receives content from a content provider. The security component can identify a security level of content metadata located within the content received from the content provider. A content router can receive a content descriptor from the content provider and an interest profile from a requesting system. The content router can utilize algorithms to create routing tables based on metadata in the content descriptor, and the interest profile. The content router can provide the content metadata to the requesting system based on the interest profile. A content filter can filter or sanitize the content metadata according to a security level of the requesting system before providing the content metadata to the requesting system.


