Cryptographic Labeler for Classified Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure computing systems face challenges in efficiently processing information of different classification levels without intermixing, as they require multiple devices and switching between levels is time-consuming, and proposed solutions like trusted operating systems lack trust.
Innovation Solution
A cryptographic device with physically isolated input and output ports, labeled packets, and a cryptographic module that uses input labels to distinguish and process packets, ensuring high-assurance separation and intermixing of classified information on common pathways.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple devices are used for each classification level, then separation of classified information is ensured, but device complexity and processing efficiency deteriorate
Solution Approach 1:
The patent merges multiple classification level processing into a single cryptographic device by using physically isolated ports for different classification levels while sharing common processing pathways. The labeler and router components enable a single device to handle multiple classification levels without requiring separate devices for each level, thus reducing device complexity while maintaining separation through physical isolation at the port level.
Solution Approach 2:
The patent segments the processing system into physically isolated ports for different classification levels (e.g., TOP SECRET, SECRET ports) while allowing the packets to be routed through common pathways. This segmentation at the port level provides the necessary separation while the shared processing path reduces overall device complexity.
2Adaptability or versatility
If switching between classification levels is performed, then flexibility is improved, but processing speed deteriorates due to time consumption
Solution Approach 1:
The patent applies preliminary action by having the labeler mark packets with classification level information at the time of input, before they enter the common processing pathway. This pre-marking eliminates the need for time-consuming classification decisions during processing, as packets are already identified and can be routed directly to appropriate output ports, thus maintaining high processing speed while preserving flexibility.
3Productivity
If packets of different classification levels are intermixed on common pathways, then processing efficiency is improved, but security separation deteriorates
Solution Approach 1:
The patent introduces the labeler as an intermediary component that marks packets with their classification level information before they enter the common pathway. The router acts as another intermediary that uses these labels to direct packets to appropriate output ports. These intermediary components enable safe intermixing on common pathways while maintaining security separation through the labeling and routing mechanisms.
4Adaptability or versatility
If trusted operating systems are used to process different classification levels, then processing flexibility is improved, but trustworthiness deteriorates
Solution Approach 1:
The patent replaces the software-based trusted operating system approach with a hardware-based solution using physically isolated ports, labelers, and routers. This hardware implementation provides processing flexibility for different classification levels while enhancing trustworthiness through physical isolation that is difficult to compromise, eliminating the need to trust a software operating system's security mechanisms.
Data Source
AI summary
A cryptographic device and method are disclosed for processing different levels of classified information. Input and output ports are physically isolated on the cryptographic device. Within the cryptographic device, each port has its packets labeled in such a way that it can be processed differently from other packets by a cryptographic module. High-assurance techniques are used to assure labeling and proper processing of the packets. These labeled packets are intermixed on common pathways regardless of level of classification. Despite intermixing, separation of the packets is assured through the process.


