High-Assurance Data Tagger for I/O Feeds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The transition to net-centric operations in command and control systems requires reliable and trustworthy data tagging to enforce security policies across the battlespace, ensuring that data from input/output devices is securely tagged at the source to prevent enemy attacks and ensure informed decision-making.
Innovation Solution
A high-assurance data tagging method and system that executes a tagging application on a microprocessor, generates and attaches a tag to message data using a message authentication scheme like HMAC, and encapsulates the data with an authentication mechanism to prohibit modification, allowing downstream components to enforce routing policies and control access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is tagged at the source with high-assurance authentication mechanisms, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by implementing authentication mechanisms and tagging data at the source (input/output devices) before data enters the command and control system. This ensures security policies are enforced upfront, preventing unauthorized or malicious data from propagating through the network, thereby improving security reliability while distributing the complexity burden to edge devices.
Solution Approach 2:
The patent segments the security enforcement function into distributed tagging devices at various input/output sources throughout the battlespace. Each device independently applies authentication and tagging to its own data stream, rather than requiring a centralized security checkpoint. This segmentation improves overall system security reliability while making each individual device's complexity manageable.
2Reliability
If authentication mechanisms are applied to all data messages, then data integrity is improved, but processing time increases
Solution Approach 1:
Authentication mechanisms are applied in advance at the data source before messages enter the command and control system. By performing authentication upfront during data generation rather than at each processing stage, the patent ensures data integrity while minimizing repeated processing delays throughout the system lifecycle.
3Reliability
If security policies are enforced at downstream components, then access control is improved, but system vulnerability increases
Solution Approach 1:
The patent implements preliminary security tagging at the source, so that when downstream components receive data, the authentication and security attributes are already embedded in the messages. This preliminary action reduces the vulnerability of downstream components by eliminating the need for them to perform complex authentication operations, while still maintaining strong access control through the pre-applied security policies.
Data Source
AI summary
The present invention is a method and system for high-assurance data tagging for input/output feeds. The method may include executing a high-assurance tagging application on a microprocessor (e.g., the microprocessor being designed for use in a high-assurance embedded system). Further, the method may include analyzing a message with the high-assurance tagging application and generating and attaching a tag to the message. In addition, the method may include binding the tag to the message by applying a message authentication scheme and providing a mechanism for down-stream applications to identify information about data included in the message by reference to the tag.


