Cross-domain object model for secure automated information sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cross-domain information flows between network security domains are often hindered by the need for human intervention, leading to inefficiencies and security risks, especially when dealing with sensitive or arbitrary data, as existing automated systems struggle to maintain information integrity and security.

Innovation Solution

A cross-domain object model (CDOM) is introduced, which defines object classes and specifies which fields can be exposed across domains, allowing for automated, sanitized data sharing through CDOM controllers that ensure compliance with security policies, reducing the risk of covert channels and improving scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated cross-domain information sharing is implemented, then productivity and efficiency are improved, but security and information integrity are compromised

Engineering Contradiction:
Improveinformation sharing efficiencyVSAvoidinformation security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a cross-domain object model (CDOM) as an intermediary layer between security domains. The CDOM controller acts as a mediator that receives information from one domain, sanitizes it according to security policies, and forwards it to recipient domains. This intermediary mechanism enables automated information sharing while maintaining security boundaries, resolving the contradiction between productivity improvement through automation and reliability maintenance through security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments information into structured objects with defined fields and attributes. Each object in the CDOM represents a discrete unit of information that can be independently controlled, sanitized, and tracked. This segmentation allows fine-grained security policies to be applied to specific object attributes while enabling automated processing, thus improving productivity without compromising security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual human intervention is used for cross-domain information flow, then information security is maintained, but productivity and operational speed are reduced

Engineering Contradiction:
Improveinformation securityVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The CDOM system implements self-service automation where the object model automatically enforces security policies, sanitizes information, and controls cross-domain flows without human intervention. The system validates objects against the CDOM schema, automatically redacts sensitive fields based on security rules, and propagates approved information across domains. This self-service capability maintains security (matching manual review quality) while dramatically improving productivity by eliminating human bottlenecks.

Inventive Principle:
Principle #25Self-service

3Productivity

If fully automated sharing systems are implemented, then productivity is improved, but device complexity and system architecture become more complex

Engineering Contradiction:
Improveautomation capabilityVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal cross-domain object model that can represent multiple types of information (personnel data, equipment status, operational parameters) through a unified schema. The CDOM controller implements multiple functions including validation, sanitization, transformation, and propagation within a single system component. This universal approach improves productivity by handling diverse information types through one automated system while managing complexity through standardization rather than requiring separate systems for each information type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If cross-domain object mirroring is implemented, then information integrity is maintained, but loss of time for synchronization occurs

Engineering Contradiction:
Improveinformation integrityVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary sanitization and validation of information objects before they are propagated across domain boundaries. The CDOM controller pre-processes objects by validating them against the object model schema, applying security policies, and redacting sensitive fields in advance. This preliminary action ensures information integrity is maintained during synchronization while reducing the time required for real-time validation and processing during the actual cross-domain transfer.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9191391B1Cross-domain object models for securely sharing information between network security domains
Publication Date: 2015.11.17 ARCHITECTURE TECH CORP
  • US9191391B1 patent drawing
  • US9191391B1 patent drawing
  • US9191391B1 patent drawing

AI summary

Techniques are described for controlling transfer of information in a secure manner across multiple network security domains. As described herein, cross-domain sharing may be facilitated by use of a common model that is shared by participants from the different network security domains. An example system is described in which a plurality of network domains comprises a respective set of client computing devices. A cross-domain object model specification specifies object classes for cross-domain objects accessible to the client computing devices. For each of the object classes, the cross-domain object model specification defines a plurality of data fields and specifies which of the data fields of the respective object class can be exposed to each of the respective network domains. A protected object repository positioned within each of the network domains stores an authorized portion of each of the cross-domain objects in accordance with the cross-domain object model specification.