Cross-Domain Data Filter Update Without Policy Impact

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cross-domain solutions lack the ability to update data filters without affecting constrained file attributes, limiting the flexibility and security of data transfer between networks with differing security domains.

Innovation Solution

A cross-domain solution with servers having a hardened operating system, allowing for the update of data filters without altering security policies, where custom filters can be loaded into placeholders and quarantined if not legitimate, maintaining confidentiality by positioning them within the higher security domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data filters are fixed at deployment in conventional CDS systems, then security policies are maintained, but the ability to update filters is lost

Engineering Contradiction:
Improvesecurity policy integrityVSAvoidfilter update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the filter management into two independent parts: the hardened operating system that maintains security policies, and the filter files that can be updated separately. This allows filters to be updated without affecting the integrity of the security policies in the hardened OS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The filter files are extracted from the hardened operating system and stored as separate files in the file system. This extraction allows filters to be updated independently while the hardened OS remains unchanged and maintains security policy integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If custom data filters are distributed widely, then filter functionality is improved, but confidentiality is compromised

Engineering Contradiction:
Improvefilter functionalityVSAvoidfilter confidentiality
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system uses an intermediary mechanism where filter placeholders are installed in the lower security domain, but the actual custom filter code remains in the higher security domain. The placeholder acts as a mediator that allows the filter to function without exposing the confidential filter code to the lower security domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If data filters are made configurable, then flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvefilter configurabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated verification mechanisms. When a custom filter is installed, the system automatically verifies its legitimacy by checking if it is a valid replacement for a placeholder. This automation reduces the complexity of managing configurable filters without requiring manual verification processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9380023B2Enterprise cross-domain solution having configurable data filters
Publication Date: 2016.06.28 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9380023B2 patent drawing
  • US9380023B2 patent drawing
  • US9380023B2 patent drawing

AI summary

A cross-domain system for transferring files from a client to a server. A first server in the first network domain receives and stores files from the client via the first network. The received files are processed based on predetermined instructions stored in an associated file. The processed received files are transmitted to a second server via a one-way data link. The second server in the second network domain receives and stores the processed received files. The received files are further processed based on predetermined instructions stored in an associated file. The further processed received files are transmitted to the server via the second network. The two associated files are stored in permanent memory with security policies which prevent the files from disrupting operation of the first and second servers, respectively. The security policies allow the associated files to be overwritten to update the processing performed by the associated server.