High-Assurance Data Tagger for I/O Feeds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition to net-centric operations in command and control systems requires reliable and trustworthy data tagging to enforce security policies across the battlespace, ensuring that data from input/output devices is securely tagged at the source to prevent enemy attacks and ensure informed decision-making.

Innovation Solution

A high-assurance data tagging method and system that executes a tagging application on a microprocessor, generates and attaches a tag to message data using a message authentication scheme like HMAC, and encapsulates the data with an authentication mechanism to prohibit modification, allowing downstream components to enforce routing policies and control access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is tagged at the source with high-assurance authentication mechanisms, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by implementing authentication mechanisms and tagging data at the source (input/output devices) before data enters the command and control system. This ensures security policies are enforced upfront, preventing unauthorized or malicious data from propagating through the network, thereby improving security reliability while distributing the complexity burden to edge devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the security enforcement function into distributed tagging devices at various input/output sources throughout the battlespace. Each device independently applies authentication and tagging to its own data stream, rather than requiring a centralized security checkpoint. This segmentation improves overall system security reliability while making each individual device's complexity manageable.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication mechanisms are applied to all data messages, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication mechanisms are applied in advance at the data source before messages enter the command and control system. By performing authentication upfront during data generation rather than at each processing stage, the patent ensures data integrity while minimizing repeated processing delays throughout the system lifecycle.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are enforced at downstream components, then access control is improved, but system vulnerability increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security tagging at the source, so that when downstream components receive data, the authentication and security attributes are already embedded in the messages. This preliminary action reduces the vulnerability of downstream components by eliminating the need for them to perform complex authentication operations, while still maintaining strong access control through the pre-applied security policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8161281B1High assurance data tagger for I/O feeds
Publication Date: 2012.04.17 ROCKWELL COLLINS INC
  • US8161281B1 patent drawing
  • US8161281B1 patent drawing
  • US8161281B1 patent drawing

AI summary

The present invention is a method and system for high-assurance data tagging for input/output feeds. The method may include executing a high-assurance tagging application on a microprocessor (e.g., the microprocessor being designed for use in a high-assurance embedded system). Further, the method may include analyzing a message with the high-assurance tagging application and generating and attaching a tag to the message. In addition, the method may include binding the tag to the message by applying a message authentication scheme and providing a mechanism for down-stream applications to identify information about data included in the message by reference to the tag.