Cryptographic Storage Architecture for Multi-Level Security Domain Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-level storage architectures for sensitive data face challenges in managing multiple security domains efficiently, particularly in airborne platforms where size, weight, and power (SWAP) constraints are significant, and there is a need for a partitioned large capacity storage architecture that supports multiple security domains with reduced SWAP.

Innovation Solution

A method and system that employs a cryptographic storage architecture with a file interface to process attributes associated with data, encrypting and decrypting data based on classification levels, and using a bypass channel for non-data attributes, allowing secure storage and retrieval of data across multiple classification levels on shared storage media.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant hardware operating at different classification levels is used to process multiple security domains, then data confidentiality and security domain separation are ensured, but size, weight, and power (SWAP) increase which is prohibitive in airborne platforms

Engineering Contradiction:
Improvedata confidentialityVSAvoidSWAP
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The patent combines multiple security domain processing capabilities into a single storage device by implementing multiple encryption contexts within one cryptographic module. Different classification levels (e.g., unclassified, confidential, secret) are handled through separate encryption contexts rather than separate hardware systems, allowing multiple security domains to coexist in shared storage media without increasing SWAP.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic module is designed to perform multiple functions across different security domains simultaneously. A single storage device can store and retrieve data from multiple classification levels by switching between different encryption contexts, making the system universal rather than requiring dedicated hardware for each security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Weight of moving object

If a partitioned storage architecture with multiple encryption contexts is implemented, then SWAP is reduced for multiple security domains, but system complexity increases due to multi-level encryption management

Engineering Contradiction:
ImproveSWAPVSAvoidencryption management
Core Design Contradiction:
Weight of moving objectVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer (the storage device with multiple encryption contexts) that manages the complexity of multi-level encryption. This intermediary handles key management, encryption context switching, and data routing between different security domains, shielding the user from the underlying complexity while enabling SWAP reduction through shared storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic functionality is segmented into multiple independent encryption contexts within a single module. Each context can be independently configured and managed for different classification levels, allowing modular handling of encryption complexity rather than a monolithic system that would be harder to manage.

Inventive Principle:
Principle #1Segmentation

3Weight of moving object

If multiple security domains are processed on shared storage media, then SWAP is reduced, but ensuring separation and confidentiality for each domain becomes more challenging

Engineering Contradiction:
ImproveSWAPVSAvoiddomain separation
Core Design Contradiction:
Weight of moving objectVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by assigning unique encryption contexts to specific locations or partitions within the storage device. Each classification level has its own encrypted space with dedicated cryptographic keys, ensuring that data from different security domains remains physically separated and confidentially protected within the shared storage media.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9846784B1Multi-level storage system and method
Publication Date: 2017.12.19 ROCKWELL COLLINS INC
  • US9846784B1 patent drawing
  • US9846784B1 patent drawing
  • US9846784B1 patent drawing

AI summary

A data storage system is provided. The system includes an electronic storage architecture configured to be coupled to a computing system and a storage medium. The architecture mediates the storing and accessing of data at the storage medium in response to the commands to write or read data. The architecture includes a file interface configured to process at least one attribute associated with data. The architecture includes a crypto interface configured to encrypt and decrypt the data based on the at least one attribute. The at least one attribute specifies a classification level of the data. The crypto interface includes cryptographic functions. Each cryptographic function is associated with a different classification level. The architecture includes a storage interface configured to provide a mapping between partitions on the storage medium and the cryptographic functions. Each of the partitions is associated with a different classification level.