Cross-Domain Security Token Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security systems, particularly those used in cross-domain environments, are inflexible, costly to update, and struggle to effectively enforce security policies due to stringent government requirements and complex architectures, making it difficult to protect networks with varying security levels.
Innovation Solution
A method and apparatus that involve a service node receiving requests from a validation system to apply policy services to messages, generating tokens by encrypting assertions using a private key associated with the service node, and sending these tokens along with the messages to validate transmission between networks with different security levels, enabling modular enforcement of network security policies and incorporation of external security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security nodes are configured with complex analyses and specialized configurations, then security enforcement capability is improved, but system flexibility and ease of update deteriorate
Solution Approach 1:
The patent segments the security enforcement function into separate policy service nodes that can be independently updated from the cross-domain guard. The guard only validates tokens generated by these service nodes, allowing the complex security analyses to be performed in modular components that can be updated without modifying the guard itself.
Solution Approach 2:
The patent introduces tokens as an intermediary mechanism between the cross-domain guard and the policy service nodes. These tokens encapsulate the results of complex security analyses and allow the guard to enforce security policies without needing to perform the complex analyses itself, thereby maintaining flexibility while ensuring security.
2Reliability
If network security nodes perform complex analyses, then security effectiveness is improved, but update cost and complexity increase
Solution Approach 1:
The patent extracts the complex security analysis functionality from the cross-domain guard and places it in separate policy service nodes. This allows the guard to remain simple and easy to update while the complex analyses are performed in dedicated services that can be independently modified and updated.
Solution Approach 2:
The patent creates a dynamic architecture where policy service nodes can be added, removed, or updated independently of the cross-domain guard. The guard dynamically validates tokens generated by these services, allowing the security effectiveness to evolve without requiring complex updates to the guard itself.
3Reliability
If cross-domain guards enforce security policies with high specialization, then security level protection is improved, but ease of operation and maintenance deteriorates
Solution Approach 1:
The patent implements a model where policy service nodes independently generate and sign tokens that the cross-domain guard validates. This self-service architecture allows the security services to be maintained and updated independently, reducing the operational burden on the guard and simplifying maintenance activities.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach allows for efficient and quick implementation of new network security technologies, facilitates modular cross-domain security solutions, and incorporates external security services, reducing the cost and complexity of updating and maintaining network security systems.
Implementation Method 1
generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node
Data Source
AI summary
In certain embodiments, a method includes receiving from a validation system a request to apply a first policy service to a message. The validation system determines whether the message may be transmitted to a second network by validating a plurality of tokens associated with the message. The method includes receiving at least one result from a policy service engine of applying the first policy service to the message and determining at least one predefined assertion based on the received at least one result. The message includes generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node. The method includes sending the message and the first token to the validation system.


