Cross-Domain Hub for Secured and Non-Secured Data Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-users of secure mobile devices face challenges in integrating non-secured data sources with secured systems due to differing security classification levels, leading to blocked data flow and potential loss of critical information.

Innovation Solution

A hub device is configured to receive data packets from both secured and non-secured client devices, performing guard processes to ensure integrity and security, allowing non-secured data to be processed and forwarded to a host device while maintaining the security of secured data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-secured data sources are integrated with secured systems, then the effectiveness and mission completion ability of field-users is improved, but the security classification level differences block data flow between secured and non-secured devices

Engineering Contradiction:
Improvedata integration capabilityVSAvoidsecurity classification compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A cross-domain hub is introduced as an intermediary device between secured and non-secured data sources. The hub receives data from both secured devices (at higher classification levels) and non-secured devices (at lower classification levels), performs appropriate guard processes based on data origin, and forwards validated data to the destination. This mediator resolves the contradiction by enabling data flow across classification boundaries while maintaining security through protocol enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If guard processes are performed on data packets from non-secured devices, then the integrity and security of the system is maintained, but the complexity of data processing increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cross-domain hub applies different guard processes to data packets based on their origin and security classification. Data from secured devices undergoes one type of validation, while data from non-secured devices undergoes more stringent guard processes. This localized differentiation of processing intensity resolves the contradiction by maintaining high security for critical data while reducing unnecessary processing complexity for already-secured data.

Inventive Principle:
Principle #3Local quality

3Reliability

If data flow is blocked between different security classification levels, then the security of secured devices is protected, but the ability to share critical information is lost

Engineering Contradiction:
Improvesecurity protectionVSAvoidinformation sharing capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The cross-domain hub serves as a controlled intermediary that enables information sharing between secured and non-secured domains. Instead of complete blocking, the hub selectively permits data flow after applying appropriate guard processes, thus preventing information loss while maintaining security protection through controlled access rather than total isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10999262B1High assurance tactical cross-domain hub
Publication Date: 2021.05.04 ARCHITECTURE TECH CORP
  • US10999262B1 patent drawing
  • US10999262B1 patent drawing
  • US10999262B1 patent drawing

AI summary

In general, the techniques of this disclosure describe a hub device that is configured to receive data packets from both secured client devices and non-secured client devices. The hub device may send the data packets from the secured client devices to a host device. For the data packets from the non-secured client devices, the hub device may first process the data packets to ensure the integrity of the received non-secure data packets and then send the non-secure data packets to the host device once the hub device determines that the non-secure data packets meet some threshold level of integrity.