Grid Network Security via Label Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In commercial grid networks, data security is compromised when malicious code on intermediate computer systems intercepts data passing through, even with fully secured physical links, due to inadequate encryption and authentication measures.

Innovation Solution

A method and system that maps unique identifiers of clients and computing resources to security labels, storing these mappings in a repository for authenticating access requests, ensuring secure communication by matching identical security labels across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted through intermediate computer systems in a network, then network connectivity and data routing are enabled, but security is compromised when malicious code on intermediate systems intercepts data

Engineering Contradiction:
Improvenetwork connectivityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by establishing security labels and access policies before data transmission occurs. The system pre-configures security parameters including origin labels, destination labels, and intermediate system labels, creating a protective framework that prevents malicious interception before it can occur. This is evident in the method of assigning security labels to data packets and comparing them against predefined policies at intermediate systems.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent uses security labels as an intermediary mechanism to enable secure data transmission through intermediate computer systems. These labels act as mediators that carry security information through the network, allowing intermediate systems to verify and enforce access policies without compromising the underlying data. The security label system mediates between the need for network routing and the requirement for security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If standard network security measures like encryption are used, then data confidentiality is protected, but security breaches still occur when intermediate systems with malicious code intercept data

Engineering Contradiction:
Improvedata confidentialityVSAvoidmalicious code interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing a comprehensive security label framework before data transmission begins. Security labels are assigned to data packets containing origin, destination, and intermediate system identifiers. Access policies are pre-configured to define which intermediate systems can access which data based on these labels. This preliminary setup creates multiple layers of verification that prevent malicious code from successfully intercepting data, as the system proactively identifies and blocks unauthorized access attempts before they can compromise confidentiality.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security labels are mapped to unique identifiers of clients and computing resources, then authentication capability is enhanced, but system complexity increases due to mapping management

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmapping management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing security labels that serve multiple functions simultaneously. A single security label structure contains origin identifiers, destination identifiers, and intermediate system identifiers, eliminating the need for separate labeling systems for each function. The same label mechanism is used for authentication, authorization, and routing decisions. This multi-functional approach enhances authentication capability while reducing the overall complexity that would result from implementing separate mapping systems for each security function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP1981242B1Method and system for securing a commercial grid network
Publication Date: 2016.03.09 ORACLE AMERICAN INC
  • EP1981242B1 patent drawingFigure 1
  • EP1981242B1 patent drawingFigure 2A
  • EP1981242B1 patent drawingFigure 2B

AI summary

A method for securing a commercial grid network involves receiving a lease request from a client to lease a computing resource selected from multiple computing resources in the commercial grid network, mapping a unique identifier of the client to a security label selected from multiple unmapped security labels to obtain a client-label mapping based on the lease request, mapping a unique identifier of the computing resource to the security label to obtain a resource-label mapping based on the lease request, storing the client-label mapping and the resource-label mapping in a security label repository to obtain stored security label mappings, and authenticating, by the commercial grid network, an access request from the client to the computing resource using the stored security label mappings.