Fragmented Cross-Domain Solution for Resource-Constrained Field Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices in the field often lack the computing resources to implement full cross-domain solution (CDS) functionality, leading to unreliable communication across security domains, especially in dynamic and contested environments where network connections are unpredictable and may be disrupted.
Innovation Solution
A fragmented cross-domain solution (F-CDS) distributes CDS functionality across multiple devices, utilizing redundant and heterogeneous nodes to ensure secure and rapid information exchange, with cross-domain discovery and routing techniques identifying assured pipelines and enforcing strong isolation and security guarantees.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full CDS functionality is implemented in field devices, then communication security across domains is improved, but device complexity and resource requirements increase beyond what field devices can provide
Solution Approach 1:
The patent segments CDS functionality into discrete filter components that can be independently deployed across multiple field devices. Instead of implementing a complete CDS solution in each device, the system divides the filtering functionality into separate, manageable units that collectively provide comprehensive security when distributed across the network.
Solution Approach 2:
The patent combines the capabilities of multiple field devices to collectively provide full CDS functionality. By distributing filter components across several devices and coordinating their operation, the system achieves the security of a complete CDS implementation without requiring any single device to possess all necessary resources.
2Ease of operation
If CDS functionality is centralized in enterprise or tactical CDS, then security management is simplified, but communication reliability deteriorates when network connections are disrupted
Solution Approach 1:
The patent enables each field device to possess local CDS filtering capabilities rather than relying solely on centralized security management. This allows devices to autonomously perform security functions even when disconnected from enterprise or tactical CDS, ensuring continuous operation while maintaining security standards through locally-deployed filter components.
3Reliability
If CDS functionality is distributed across multiple field devices, then communication reliability is improved during network disruptions, but system complexity increases
Solution Approach 1:
The patent creates universal filter components that can operate independently in multiple contexts and be deployed across various device types. These standardized filtering units provide multi-functional capability, serving both as standalone security mechanisms and as parts of a distributed CDS system, thereby managing complexity through reuse and standardization.
4Reliability
If redundant F-CDS nodes are deployed, then fault tolerance and security are improved, but resource consumption and system overhead increase
Solution Approach 1:
The patent implements redundancy selectively rather than universally across all devices. By deploying filter components and redundant nodes only where necessary to achieve required security levels and fault tolerance, the system avoids unnecessary resource consumption while maintaining adequate protection through targeted redundancy in critical positions within the distributed architecture.
Data Source
AI summary
Techniques for cross-domain routing using a fractionated cross-domain solution (F-CDS) are disclosed. A first intermediate node operating in a first physical device in an assured pipeline of the F-CDS receives a data item originating at a source node in a first security domain. The first intermediate node applies a first data filter to determine that the data item complies with a data security requirement of the F-CDS. The first intermediate node transmits the data item to a second intermediate node operating in a second physical device in the assured pipeline of the F-CDS. The second intermediate node applies a second data filter to redundantly determine that first data item complies with the data security requirement of the F-CDS. The second intermediate node transmits the data item to a recipient node in a second security domain via the assured pipeline.


