Cross-domain object model for secure automated information sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cross-domain information flows between network security domains are often hindered by the need for human intervention, leading to inefficiencies and security risks, especially when dealing with sensitive or arbitrary data, as existing automated systems struggle to maintain information integrity and security.
Innovation Solution
A cross-domain object model (CDOM) is introduced, which defines object classes and specifies which fields can be exposed across domains, allowing for automated, sanitized data sharing through CDOM controllers that ensure compliance with security policies, reducing the risk of covert channels and improving scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated cross-domain information sharing is implemented, then productivity and efficiency are improved, but security and information integrity are compromised
Solution Approach 1:
The patent introduces a cross-domain object model (CDOM) as an intermediary layer between security domains. The CDOM controller acts as a mediator that receives information from one domain, sanitizes it according to security policies, and forwards it to recipient domains. This intermediary mechanism enables automated information sharing while maintaining security boundaries, resolving the contradiction between productivity improvement through automation and reliability maintenance through security controls.
Solution Approach 2:
The patent segments information into structured objects with defined fields and attributes. Each object in the CDOM represents a discrete unit of information that can be independently controlled, sanitized, and tracked. This segmentation allows fine-grained security policies to be applied to specific object attributes while enabling automated processing, thus improving productivity without compromising security.
2Reliability
If manual human intervention is used for cross-domain information flow, then information security is maintained, but productivity and operational speed are reduced
Solution Approach 1:
The CDOM system implements self-service automation where the object model automatically enforces security policies, sanitizes information, and controls cross-domain flows without human intervention. The system validates objects against the CDOM schema, automatically redacts sensitive fields based on security rules, and propagates approved information across domains. This self-service capability maintains security (matching manual review quality) while dramatically improving productivity by eliminating human bottlenecks.
3Productivity
If fully automated sharing systems are implemented, then productivity is improved, but device complexity and system architecture become more complex
Solution Approach 1:
The patent creates a universal cross-domain object model that can represent multiple types of information (personnel data, equipment status, operational parameters) through a unified schema. The CDOM controller implements multiple functions including validation, sanitization, transformation, and propagation within a single system component. This universal approach improves productivity by handling diverse information types through one automated system while managing complexity through standardization rather than requiring separate systems for each information type.
4Reliability
If cross-domain object mirroring is implemented, then information integrity is maintained, but loss of time for synchronization occurs
Solution Approach 1:
The patent performs preliminary sanitization and validation of information objects before they are propagated across domain boundaries. The CDOM controller pre-processes objects by validating them against the object model schema, applying security policies, and redacting sensitive fields in advance. This preliminary action ensures information integrity is maintained during synchronization while reducing the time required for real-time validation and processing during the actual cross-domain transfer.
Data Source
AI summary
Techniques are described for controlling transfer of information in a secure manner across multiple network security domains. As described herein, cross-domain sharing may be facilitated by use of a common model that is shared by participants from the different network security domains. An example system is described in which a plurality of network domains comprises a respective set of client computing devices. A cross-domain object model specification specifies object classes for cross-domain objects accessible to the client computing devices. For each of the object classes, the cross-domain object model specification defines a plurality of data fields and specifies which of the data fields of the respective object class can be exposed to each of the respective network domains. A protected object repository positioned within each of the network domains stores an authorized portion of each of the cross-domain objects in accordance with the cross-domain object model specification.


