MILS Network Interface Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing interconnection networks fail to maintain partition and security separation for information with different security levels, allowing unclassified information to potentially be transmitted to unsecured environments when connecting partitioned processing environments.

Innovation Solution

An interconnection network system that encodes information with classification levels and uses network interface modules to verify and route data words to appropriate processing environments, ensuring secure transmission by utilizing a switched fabric topology with serializer/deserializer devices and router blocks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If typical interconnection networks are used to connect processing environments, then network connectivity and data transmission capability are improved, but partition and security separation is compromised allowing unclassified information to be transmitted to unsecured environments

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity separation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The interconnection network is segmented into separate unclassified and classified network portions. The classified network portion includes classified nodes and unclassified network nodes, while the unclassified network portion includes only unclassified nodes. This segmentation ensures that classified information remains isolated from unclassified environments, preventing security breaches while maintaining necessary connectivity between authorized nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network interface module serves as an intermediary between classified and unclassified networks. This module examines classification levels of data words, verifies them against the processing environment's security level, and routes data accordingly. The intermediary enforces security policies without requiring manual intervention, allowing controlled information flow while maintaining network connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate processing environments are used for unclassified and classified information, then security separation is maintained, but device complexity and interconnection difficulty increase

Engineering Contradiction:
Improvesecurity separationVSAvoidinterconnection network complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network interface module performs multiple functions: it examines classification levels, verifies security compliance, and routes data words to appropriate destinations. This multi-functional design consolidates what would otherwise require separate mechanisms, reducing overall system complexity while maintaining robust security separation between classified and unclassified environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If classification level verification is implemented at network nodes, then security separation is enforced, but data transmission speed and network throughput decrease due to additional processing

Engineering Contradiction:
Improvesecurity verificationVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Classification level information is encoded in the data words themselves before transmission, rather than being verified after receipt. This preliminary encoding allows the network interface module to quickly examine and verify classification levels during the routing process, minimizing additional processing time while ensuring security. The verification action is performed in advance of potential security breaches, maintaining both speed and security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7509434B1Embedded MILS network
Publication Date: 2009.03.24 ROCKWELL COLLINS INC
  • US7509434B1 patent drawing
  • US7509434B1 patent drawing
  • US7509434B1 patent drawing

AI summary

A method for transmitting information having different classification levels within an interconnection network includes transmitting a data word having encoded information that indicates a classification level to a processing environment having a classification level. The encoded information is examined to ascertain the indicated classification level. The classification level of the processing environment is verified by comparing it with the indicated classification level, and the data word is delivered to the processing environment upon verification. An interconnection network for transmitting the data words includes a switched fabric topology with serializer/deserializer devices interconnected by router blocks. A node for connecting to the interconnection network includes a network interface module linking the interconnection network and the processing environment. The network interface module examines data words to ascertain their classification level and verifies the classification level of the processing environment. The network interface module delivers the data words to the processing environment upon verification.