MILS Router Processor Secure Gateway for MLS MSLS Interfacing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secured communication networks face challenges in providing a secure interface between Multiple Levels Security (MLS) and Multiple Single Level Security (MSLS) networks, particularly in maintaining security separation and meeting high certification requirements, due to inadequate interfacing capabilities and high costs associated with additional hardware.

Innovation Solution

A secure gateway/router system is developed, incorporating a MILS router processor with a MILS real-time Operating System and middleware, along with network interface units, to enable secure interfacing between MLS and MSLS networks by routing data based on security labels and utilizing software partitions to enforce security policies across different security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional hardware (host processor, host NIC) is added to provide secure interface between MSLS and MLS networks, then security separation is maintained, but device complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity separationVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple network interface functions and security enforcement mechanisms into a single network interface card. The NIC integrates MLS network interface, MSLS network interface, security partitioning logic, and data labeling capabilities into one unified device, eliminating the need for separate host processors and multiple NICs while maintaining security separation between different security levels

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network interface card is designed with multi-functionality to handle both MLS and MSLS network protocols, enforce security policies, perform data labeling, and route traffic across different security domains. This universal device replaces multiple specialized hardware components, reducing overall system complexity while maintaining security integrity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate network interface cards are used for different security levels, then security certification requirements are met, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity certificationVSAvoidnumber of network interface cards
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network interface card into distinct software partitions (MLS network interface partition, MSLS network interface partition, security partition) that operate independently but share the same physical hardware. This logical segmentation maintains security certification requirements while using a single physical device, avoiding the need for multiple separate NICs

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security partition as an intermediary layer between the MLS and MSLS network interfaces. This security partition enforces security policies, validates data labels, and controls data flow between different security domains, allowing a single NIC to replace multiple security-enforced interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If physical separation of networks is maintained, then security levels are protected, but interfacing capability between MLS and MSLS networks is inadequate

Engineering Contradiction:
Improvesecurity level protectionVSAvoidinterfacing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing security-specific processing at the network interface level. The NIC performs localized security checks, data labeling, and partitioning specific to each security domain (MLS and MSLS) while maintaining physical separation. This allows enhanced interfacing capability with security protection without requiring complete physical isolation

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7607167B1Secure gateway/router
Publication Date: 2009.10.20 ROCKWELL COLLINS INC
  • US7607167B1 patent drawing
  • US7607167B1 patent drawing
  • US7607167B1 patent drawing

AI summary

The present invention is directed to a secure gateway/router system and method for allowing a MLS network which simultaneously contains data of multiple security levels to interface with one of several MSLS networks which is configured to maintain data with a single security level. When the data is within the secure gateway/router system, the separation of the data by security levels, as it was received from the MLS network, is maintained by routing the data to a designated security level network. Secure gateway/router system includes several network interface units. Each network interface unit is configured to interface within a single MSLS network. Each MSLS software partition has a single and simple function to perform in maintaining separation of security levels and provide the data to the network interface unit configured to interface within the designated security level network.