Multi-Class IP Switching for Classified Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The migration from ISDN to IP-based communication systems in video teleconferencing environments, particularly in military and intelligence services, poses significant security challenges due to the need for ensuring secure communication across networks of varying security classifications, compounded by the convergence of voice, data, and video communications onto a common IP network, which is difficult to secure, especially with the use of Internet Protocol (IP) networks.
Innovation Solution
A multi-class IP switching system that includes a coder/decoder for converting analog to digital voice, a switch to isolate non-secure entities, and fiber optic ports for passing classified and unclassified data between classified and unclassified IP networks, operating in secure, non-secure, and configuration/cut-off states, with a controller accessible only in the configuration/cut-off state to manage sensitive parameters and control the switching system's states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a common IP network is used for converged communications (voice, data, video), then infrastructure complexity is reduced and adaptability is improved, but security is worsened due to difficulty in securing the common network
Solution Approach 1:
The system segments the common IP network into multiple virtual switching instances, each dedicated to a specific security classification (e.g., classified, unclassified). The physical switch is divided into multiple virtual switches that operate independently, ensuring that traffic from different security domains is isolated even though they share the same physical infrastructure. This resolves the contradiction by maintaining security boundaries while utilizing a common network platform.
Solution Approach 2:
The patent introduces a controller as an intermediary that manages the virtual switching instances and enforces security policies. The controller acts as a mediator between the physical network infrastructure and the security requirements, dynamically configuring the virtual switches to ensure proper isolation and security compliance. This intermediary layer enables converged communications while maintaining security through centralized control and policy enforcement.
2Adaptability or versatility
If multiple security classifications are supported on the same network, then adaptability is improved, but device complexity is worsened due to need for multiple switching instances
Solution Approach 1:
The patent implements a universal physical switch that can perform multiple functions by hosting different virtual switching instances. Instead of requiring separate physical switches for each security classification, a single multi-functional switch can dynamically create and manage multiple virtual switches, each tailored to specific security requirements. This reduces device complexity while maintaining the ability to support multiple security classifications simultaneously.
Solution Approach 2:
The system employs a nested structure where virtual switching instances are nested within the physical switch infrastructure. Each virtual switch is contained within the physical switch, creating a hierarchical organization where the physical switch provides the underlying infrastructure and the virtual switches provide security-specific functionality. This nesting approach manages complexity by organizing multiple security domains within a unified physical platform.
3Ease of operation
If access to controller is always available for configuration, then ease of operation is improved, but security is worsened due to potential unauthorized access to sensitive parameters
Solution Approach 1:
The system implements dynamic access control where the controller's accessibility changes based on the operational state of the virtual switches. When virtual switches are active and handling traffic, the controller is isolated and inaccessible to prevent unauthorized access. During maintenance or configuration states, controlled access is permitted. This dynamic state management resolves the contradiction by providing ease of operation when needed while ensuring security during operational states.
Solution Approach 2:
The system preemptively isolates the controller from the network during normal operation to prevent potential unauthorized access before it can occur. By default, the controller is in a protected state with access restricted. Configuration access is granted only through controlled mechanisms when the system is in appropriate states. This preliminary protective measure ensures security while still allowing necessary configuration operations under controlled conditions.
Data Source
AI summary
An IP switching system that includes a coder/decoder configured for converting voice between analog and digital; and a first switch coupled to the coder/decoder configured to isolate non-secure entities in a network and comprising a plurality of fiber optic ports; wherein two of the plurality of fiber optic ports are configured to pass classified and unclassified data to one of a classified IP network and an unclassified IP network; and wherein the first switch is configured to operate in a plurality of states including secure, non-secure, and configuration/cut-off. The IP switching system also includes at least one controller connected to the coder/decoder via the first switch such that the at least one controller is accessible to the coder/decoder only when the first switch is in the configuration/cut-off state; wherein the at least one controller is configured to store and retrieve sensitive coder/decoder parameters for operation of the coder/decoder.


