Cryptographic Labeler for Classified Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure computing systems face challenges in efficiently processing information of different classification levels without intermixing, as they require multiple devices and switching between levels is time-consuming, and proposed solutions like trusted operating systems lack trust.

Innovation Solution

A cryptographic device with physically isolated input and output ports, labeled packets, and a cryptographic module that uses input labels to distinguish and process packets, ensuring high-assurance separation and intermixing of classified information on common pathways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple devices are used for each classification level, then separation of classified information is ensured, but device complexity and processing efficiency deteriorate

Engineering Contradiction:
Improveseparation of classified informationVSAvoidmultiple devices required
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple classification level processing into a single cryptographic device by using physically isolated ports for different classification levels while sharing common processing pathways. The labeler and router components enable a single device to handle multiple classification levels without requiring separate devices for each level, thus reducing device complexity while maintaining separation through physical isolation at the port level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the processing system into physically isolated ports for different classification levels (e.g., TOP SECRET, SECRET ports) while allowing the packets to be routed through common pathways. This segmentation at the port level provides the necessary separation while the shared processing path reduces overall device complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If switching between classification levels is performed, then flexibility is improved, but processing speed deteriorates due to time consumption

Engineering Contradiction:
Improveflexibility in processingVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the labeler mark packets with classification level information at the time of input, before they enter the common processing pathway. This pre-marking eliminates the need for time-consuming classification decisions during processing, as packets are already identified and can be routed directly to appropriate output ports, thus maintaining high processing speed while preserving flexibility.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If packets of different classification levels are intermixed on common pathways, then processing efficiency is improved, but security separation deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity separation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces the labeler as an intermediary component that marks packets with their classification level information before they enter the common pathway. The router acts as another intermediary that uses these labels to direct packets to appropriate output ports. These intermediary components enable safe intermixing on common pathways while maintaining security separation through the labeling and routing mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If trusted operating systems are used to process different classification levels, then processing flexibility is improved, but trustworthiness deteriorates

Engineering Contradiction:
Improveprocessing flexibilityVSAvoidtrustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the software-based trusted operating system approach with a hardware-based solution using physically isolated ports, labelers, and routers. This hardware implementation provides processing flexibility for different classification levels while enhancing trustworthiness through physical isolation that is difficult to compromise, eliminating the need to trust a software operating system's security mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8392983B2Trusted labeler
Publication Date: 2013.03.05 VIASAT INC
  • US8392983B2 patent drawing
  • US8392983B2 patent drawing
  • US8392983B2 patent drawing

AI summary

A cryptographic device and method are disclosed for processing different levels of classified information. Input and output ports are physically isolated on the cryptographic device. Within the cryptographic device, each port has its packets labeled in such a way that it can be processed differently from other packets by a cryptographic module. High-assurance techniques are used to assure labeling and proper processing of the packets. These labeled packets are intermixed on common pathways regardless of level of classification. Despite intermixing, separation of the packets is assured through the process.