Cross-Domain Security Token Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems, particularly those used in cross-domain environments, are inflexible, costly to update, and struggle to effectively enforce security policies due to stringent government requirements and complex architectures, making it difficult to protect networks with varying security levels.

Innovation Solution

A method and apparatus that involve a service node receiving requests from a validation system to apply policy services to messages, generating tokens by encrypting assertions using a private key associated with the service node, and sending these tokens along with the messages to validate transmission between networks with different security levels, enabling modular enforcement of network security policies and incorporation of external security services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security nodes are configured with complex analyses and specialized configurations, then security enforcement capability is improved, but system flexibility and ease of update deteriorate

Engineering Contradiction:
Improvesecurity enforcement capabilityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security enforcement function into separate policy service nodes that can be independently updated from the cross-domain guard. The guard only validates tokens generated by these service nodes, allowing the complex security analyses to be performed in modular components that can be updated without modifying the guard itself.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokens as an intermediary mechanism between the cross-domain guard and the policy service nodes. These tokens encapsulate the results of complex security analyses and allow the guard to enforce security policies without needing to perform the complex analyses itself, thereby maintaining flexibility while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security nodes perform complex analyses, then security effectiveness is improved, but update cost and complexity increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidupdate complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex security analysis functionality from the cross-domain guard and places it in separate policy service nodes. This allows the guard to remain simple and easy to update while the complex analyses are performed in dedicated services that can be independently modified and updated.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a dynamic architecture where policy service nodes can be added, removed, or updated independently of the cross-domain guard. The guard dynamically validates tokens generated by these services, allowing the security effectiveness to evolve without requiring complex updates to the guard itself.

Inventive Principle:
Principle #15Dynamics

3Reliability

If cross-domain guards enforce security policies with high specialization, then security level protection is improved, but ease of operation and maintenance deteriorates

Engineering Contradiction:
Improvesecurity level protectionVSAvoidmaintenance ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a model where policy service nodes independently generate and sign tokens that the cross-domain guard validates. This self-service architecture allows the security services to be maintained and updated independently, reducing the operational burden on the guard and simplifying maintenance activities.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach allows for efficient and quick implementation of new network security technologies, facilitates modular cross-domain security solutions, and incorporates external security services, reducing the cost and complexity of updating and maintaining network security systems.

Implementation Method 1

generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node

Methodology Applied
Scientific EffectEncryption:

Data Source

PatentUS8640189B1Communicating results of validation services
Publication Date: 2014.01.28 EVERFOX HOLDINGS LLC
  • US8640189B1 patent drawing
  • US8640189B1 patent drawing
  • US8640189B1 patent drawing

AI summary

In certain embodiments, a method includes receiving from a validation system a request to apply a first policy service to a message. The validation system determines whether the message may be transmitted to a second network by validating a plurality of tokens associated with the message. The method includes receiving at least one result from a policy service engine of applying the first policy service to the message and determining at least one predefined assertion based on the received at least one result. The message includes generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node. The method includes sending the message and the first token to the validation system.