Multilevel Secure Communication via Encryption-Based Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial off-the-shelf processor implementations typically only provide two levels of security separation, which is insufficient for supporting multilevel secure communication systems requiring more than two security classifications.

Innovation Solution

A system with a shared network and multiple processors, where each processing unit is classified into one of several security classifications and assigned unique encryption keys and algorithms, ensuring that only authorized communications occur by enforcing encryption-based separation among different security classifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If commercial off-the-shelf processor implementations are used, then hardware cost is reduced, but security classification levels are limited to two levels

Engineering Contradiction:
Improvesecurity classification levelsVSAvoidencryption key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the network communication into multiple security domains by assigning different encryption keys to processing units with different security classifications. Each processing unit operates with its own encryption key, creating logically separate secure channels within the shared network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Commercial off-the-shelf processors are made multi-functional by enabling them to operate at multiple security classification levels through the assignment of different encryption keys. The same physical hardware can handle classified, unclassified, and secret information simultaneously by switching between different encryption key pairs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If encryption keys are assigned to each processing unit, then security is maintained, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidencryption key assignment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each processing unit is assigned specific encryption keys appropriate to its security classification level. The encryption key assignment is localized to each processing unit's security domain, allowing security to be enforced at the local level while maintaining overall system security through consistent key management policies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9660966B1Multilevel secure communication systems with encryption based separation
Publication Date: 2017.05.23 ROCKWELL COLLINS INC
  • US9660966B1 patent drawing
  • US9660966B1 patent drawing
  • US9660966B1 patent drawing

AI summary

Multilevel secure communication systems and methods for providing multilevel security to such communication systems are disclosed. More specifically, communication systems and methods configured in accordance with the inventive concepts disclosed herein may be utilized to provide support for N levels of secure communications using processors (may also be referred to as nodes) that may only have (N−M) levels of security separation (where N and M are integers and M is strictly less than N). In other words, processors that have less than N levels of security separation may be configured to form a communication system that is capable of supporting N levels of secure communication.