MILS Network Digest Verification Using COTS Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional communication networks face high overhead due to data encryption and require separate customized hardware for multiple independent levels of security (MILS) networks, increasing costs and certification burdens.
Innovation Solution
Implementing a keyed digest system that embeds a security level representative key within messages, allowing MILS nodes to recalculate and verify the digest, thereby ensuring data separation without the need for customized switches, using commercial-off-the-shelf hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full message encryption is implemented in MILS networks, then data security is improved, but system overhead and certification costs increase significantly
Solution Approach 1:
The patent extracts the security verification function from the switch hardware and relocates it to the network nodes. Nodes independently calculate digests of received messages and verify them against embedded digests, eliminating the need for complex encryption hardware in switches while maintaining security through distributed verification at the node level.
Solution Approach 2:
The patent introduces a digest verification mechanism as an intermediary security check. Instead of relying on complex encryption/decryption operations, a simplified digest calculation and comparison process mediates security verification, reducing computational overhead while maintaining security guarantees through cryptographic hash functions.
2Reliability
If customized hardware switches are used for MILS networks, then secure data separation is achieved, but system cost and certification expenses increase
Solution Approach 1:
The patent makes standard COTS switches universal by implementing software-based digest verification in network nodes. The same switch hardware can handle multiple security domains without customization, as security verification is performed independently by nodes using cryptographic digests embedded in messages, allowing one switch design to serve multiple classification domains.
Solution Approach 2:
The patent uses cryptographic digest copies of messages as a lightweight security mechanism. Instead of duplicating complex security hardware for each domain, nodes create and verify digest copies of messages, providing security verification functionality through software rather than hardware replication.
3Reliability
If separate hardware is required for each classification domain, then security isolation is maintained, but component overhead and costs increase
Solution Approach 1:
The patent merges multiple security domain handling capabilities into a single switch infrastructure. By implementing digest verification in software at the node level rather than through dedicated hardware switches for each domain, the system combines the functionality of multiple specialized switches into one general-purpose switch, reducing hardware component quantity while maintaining security isolation through cryptographic verification.
Data Source
AI summary
The present invention is a MILS network system employing functional separation of messages without customized switches. The MILS network system may maintain separation of data while eliminating a requirement of full message encryption. In an embodiment of the invention, a function may be employed whereby a keyed digest of a message is created. The function may receive a message and a key, and may emit a keyed digest value. The key may be representative of a particular level of security, thus promoting the separation of data. Messages may include an embedded keyed digest when sent through a switch to a MILS node. At the MILS node, the keyed digest may be recalculated, if it matches, the message may be passed to a host.


