Grid Network Security via Label Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In commercial grid networks, data security is compromised when malicious code on intermediate computer systems intercepts data passing through, even with fully secured physical links, due to inadequate encryption and authentication measures.
Innovation Solution
A method and system that maps unique identifiers of clients and computing resources to security labels, storing these mappings in a repository for authenticating access requests, ensuring secure communication by matching identical security labels across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is transmitted through intermediate computer systems in a network, then network connectivity and data routing are enabled, but security is compromised when malicious code on intermediate systems intercepts data
Solution Approach 1:
The patent applies preliminary anti-action by establishing security labels and access policies before data transmission occurs. The system pre-configures security parameters including origin labels, destination labels, and intermediate system labels, creating a protective framework that prevents malicious interception before it can occur. This is evident in the method of assigning security labels to data packets and comparing them against predefined policies at intermediate systems.
Solution Approach 2:
The patent uses security labels as an intermediary mechanism to enable secure data transmission through intermediate computer systems. These labels act as mediators that carry security information through the network, allowing intermediate systems to verify and enforce access policies without compromising the underlying data. The security label system mediates between the need for network routing and the requirement for security protection.
2Reliability
If standard network security measures like encryption are used, then data confidentiality is protected, but security breaches still occur when intermediate systems with malicious code intercept data
Solution Approach 1:
The patent implements preliminary action by establishing a comprehensive security label framework before data transmission begins. Security labels are assigned to data packets containing origin, destination, and intermediate system identifiers. Access policies are pre-configured to define which intermediate systems can access which data based on these labels. This preliminary setup creates multiple layers of verification that prevent malicious code from successfully intercepting data, as the system proactively identifies and blocks unauthorized access attempts before they can compromise confidentiality.
3Reliability
If security labels are mapped to unique identifiers of clients and computing resources, then authentication capability is enhanced, but system complexity increases due to mapping management
Solution Approach 1:
The patent applies universality by designing security labels that serve multiple functions simultaneously. A single security label structure contains origin identifiers, destination identifiers, and intermediate system identifiers, eliminating the need for separate labeling systems for each function. The same label mechanism is used for authentication, authorization, and routing decisions. This multi-functional approach enhances authentication capability while reducing the overall complexity that would result from implementing separate mapping systems for each security function.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A method for securing a commercial grid network involves receiving a lease request from a client to lease a computing resource selected from multiple computing resources in the commercial grid network, mapping a unique identifier of the client to a security label selected from multiple unmapped security labels to obtain a client-label mapping based on the lease request, mapping a unique identifier of the computing resource to the security label to obtain a resource-label mapping based on the lease request, storing the client-label mapping and the resource-label mapping in a security label repository to obtain stored security label mappings, and authenticating, by the commercial grid network, an access request from the client to the computing resource using the stored security label mappings.