Data Guard Bi-Directional Channel for Secure MLS Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for transferring data between security domains are unacceptably slow and unreliable, particularly in Multi Level Secure (MLS)/Multiple Independent Levels of Security (MILS) environments, due to the need for expensive data diodes and manual tuning, which results in incomplete or erroneous data being used by decision makers.

Innovation Solution

Establishing a reliable high assurance communications channel using a data guard that enables bi-directional data transfer between security domains through a UDP upchannel and TCP backchannel, allowing for acknowledgement of data receipt and retransmission of missed packets, thereby eliminating the need for multiple data diodes and improving data reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one way data transfer is enforced for security purposes, then security is improved, but data transfer reliability deteriorates because the sender does not know which packets were successfully transmitted

Engineering Contradiction:
Improvedata transfer reliabilityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the communication channel into two separate unidirectional channels: an upchannel for data transfer from lower to higher security domains, and a backchannel for acknowledgments from higher to lower security domains. This segmentation allows each channel to have its own optimized protocol while maintaining overall security constraints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data guard acts as an intermediary that receives data from the lower security domain, transmits it to the higher security domain, and then relays acknowledgments back to the sender. This intermediary enables reliable communication while maintaining the security boundary between domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple data diodes are used to transfer data between security domains, then data transfer capacity is improved, but system cost and complexity increase

Engineering Contradiction:
Improvedata transfer capacityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple unidirectional data diodes into a single bidirectional data guard that handles both data transmission and acknowledgment relay. This consolidation reduces hardware requirements while maintaining data transfer capacity and reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data guard performs multiple functions: it acts as a data diode for secure data transfer from lower to higher security domains, and simultaneously serves as a communication endpoint for relaying acknowledgments back to senders. This multi-functionality eliminates the need for separate dedicated hardware for each direction.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual tuning is performed on data diodes to minimize packet loss, then data transfer reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata transfer reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic feedback through the backchannel, where the data guard receives acknowledgments from the higher security domain and uses this information to determine whether retransmission is necessary. This automated feedback loop eliminates manual tuning while ensuring reliable data transfer.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The communication system performs self-adjustment through automated acknowledgment processing. The data guard automatically determines whether packets were successfully transmitted based on received acknowledgments and initiates retransmission without manual intervention, making the system easy to operate while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8024788B2Method and apparatus for reliable, high speed data transfers in a high assurance multiple level secure environment
Publication Date: 2011.09.20 THE BOEING CO
  • US8024788B2 patent drawing
  • US8024788B2 patent drawing
  • US8024788B2 patent drawing

AI summary

A method and apparatus for passing data from a first application at a first security level to a second application in a second security level higher than the first security level is disclosed. A backchannel communications link is established between the first application and the second application, and the backchannel link is used to transmit information such as an acknowledgement message from the second application to the first application.