Dual-Layer Encryption for Classified Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Government and military entities face challenges in securely accessing and managing classified IP networks in dynamic operational environments without exposing sensitive information, as connecting classified devices to public IP networks for access or configuration is against security policy.

Innovation Solution

A wide area network access management computer system using NSA-approved CSfC Comprised Solutions, which implements a dual-layer encryption approach with hardware or software components to enable secure communication between classified devices and public IP networks, allowing access to sensitive data without direct connection to the public internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If classified devices are connected to public IP networks for access or configuration, then network accessibility and management capability are improved, but security policy compliance and protection of sensitive information deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system consisting of a classified network interface card and a public network interface card that acts as a mediator between classified devices and public IP networks. This intermediary enables network accessibility while maintaining security isolation, allowing configuration and management operations without direct connection of classified devices to public networks, thus resolving the contradiction between ease of operation and security compliance

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dual-layer encryption is implemented to enable secure communication, then security protection and policy compliance are improved, but device complexity and system configuration difficulty worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into a unified dual-layer encryption system where the classified network interface card and public network interface card work together as an integrated security architecture. This combination provides comprehensive security protection through layered encryption while managing complexity through unified system design, resolving the contradiction between reliability and device complexity

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If classified devices remain isolated from public networks to prevent inadvertent disclosure, then information security is improved, but network connectivity and operational flexibility deteriorate

Engineering Contradiction:
Improveinformation securityVSAvoidnetwork connectivity
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the network interface into distinct classified and public components, with the classified network interface card handling secure communications and the public network interface card handling public network access. This segmentation enables classified devices to maintain isolation for information security while still providing network connectivity through the segmented public interface, resolving the contradiction between information security and adaptability

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11343249B2Secure internal data network communication interfaces
Publication Date: 2022.05.24 SIGMA DEFENSE SYST LLC
  • US11343249B2 patent drawing
  • US11343249B2 patent drawing
  • US11343249B2 patent drawing

AI summary

A system, method, and apparatus for providing secure communications to one or more users through an unclassified network. The system may include a network access management device may have a plurality of internal data network communications interfaces configured to communicate with at least one classified computing device using a National Security Agency (NSA) Commercial Solution for Classified (CSfC) comprised solution and an external data network communications interface configured to communicate with an unclassified network. A network access management device may use an inner NSA CSfC approved tunneling technology, an outer NSA CSfC approved tunneling technology, and a processor configured to perform processing and routing protocols associated with interconnecting the internal data network communications interface and the external data network communications interface.