Content-Based Routing for Multi-Level Security Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network communications fail to provide specific metadata or content to requesting systems at appropriate security levels, as they can only transmit data packets classified at the highest security level, unable to individually classify metadata or content within data packets.

Innovation Solution

A security component identifies the security level of content metadata, a content router creates routing tables using metadata and interest profiles, and a content filter sanitizes the metadata according to the requesting system's security level before providing it, enabling content-based routing with high assurance multi-level security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network communications transmit data packets classified at the highest security level, then security is maintained, but specific metadata or content cannot be provided to requesting systems at appropriate security levels

Engineering Contradiction:
ImprovesecurityVSAvoidcontent delivery flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data packets into multiple components, classifying metadata and content individually at different security levels rather than treating the entire packet as a single unit. This allows selective routing of different segments to appropriate requesting systems based on their security clearances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security classifications to different parts (metadata vs. content) of the data packet based on their specific security requirements. Each component receives appropriate security treatment tailored to its sensitivity, rather than applying a uniform classification to the entire packet.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional network communications provide entire data packets at the highest security level, then all content is secured, but requesting systems receive information they cannot process or do not need

Engineering Contradiction:
Improvesecurity assuranceVSAvoidinformation accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts and separates metadata from content within data packets, allowing the metadata to be routed and delivered to requesting systems that have appropriate security clearances, while higher-classified content remains protected and delivered only to authorized systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a content router as an intermediary component that sits between the data source and requesting systems. This router examines security classifications of individual metadata and content components, then intelligently routes them to appropriate systems based on their security clearances and interests.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional network communications transmit all content at the highest security level, then security is maintained, but network bandwidth is wasted transmitting information that requesting systems cannot access

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork bandwidth efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs preliminary classification and tagging of metadata and content components with security level identifiers before routing. This advance preparation allows the content router to quickly determine which components can be delivered to which requesting systems without requiring full transmission of all high-security content.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial transmission by delivering only the portion of data (metadata) that requesting systems are authorized to receive, rather than transmitting the entire high-security data packet. This avoids wasting bandwidth on content that cannot be accessed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8250360B2Content based routing with high assurance MLS
Publication Date: 2012.08.21 THE BOEING CO
  • US8250360B2 patent drawing
  • US8250360B2 patent drawing
  • US8250360B2 patent drawing

AI summary

Content Based Routing with High Assurance MLS (multi-level security) methods and systems are described. In an embodiment, a security component receives content from a content provider. The security component can identify a security level of content metadata located within the content received from the content provider. A content router can receive a content descriptor from the content provider and an interest profile from a requesting system. The content router can utilize algorithms to create routing tables based on metadata in the content descriptor, and the interest profile. The content router can provide the content metadata to the requesting system based on the interest profile. A content filter can filter or sanitize the content metadata according to a security level of the requesting system before providing the content metadata to the requesting system.