MILS Middleware Partition for Secure Multi-Level LAN Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Multiple Independent Levels of Security (MILS) systems face challenges in efficiently transferring data between security levels due to complex frame creation and parsing, and the need for separate network interface cards (NICs) increases hardware and power requirements, while commercial off-the-shelf (COTS) stacks complicate security level management.

Innovation Solution

Implementing a middleware partition with security classification management, where frames are forwarded to appropriate internal stacks based on security labels, and security classifications are determined and applied to frames for secure transmission across multiple level Local Area Networks (LANs) using a single NIC, reducing hardware needs and ensuring secure information access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple single level Local Area Networks (LANs) are used to accommodate multiple independent levels of security, then security separation is maintained, but the size, weight, and power requirements of the platform increase

Engineering Contradiction:
Improvesecurity separationVSAvoidplatform weight
Core Design Contradiction:
ReliabilityVSWeight of stationary object

Solution Approach 1:

The patent combines multiple single-level LANs into a single multi-level LAN that can carry traffic for multiple security levels simultaneously. This is achieved by implementing a security-aware network stack that classifies and routes frames according to their security level, allowing one physical network interface to replace multiple separate network interfaces and their associated wiring.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network interface and network stack are designed to be universal, handling multiple security levels through a single interface. The system provides multi-functionality by enabling the same physical network infrastructure to support different security domains through software-based classification and routing rather than requiring dedicated hardware for each security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple single level Local Area Networks (LANs) are used to accommodate multiple independent levels of security, then security separation is maintained, but the power required by the platform increases

Engineering Contradiction:
Improvesecurity separationVSAvoidplatform power
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent combines multiple single-level LANs into a single multi-level LAN that can carry traffic for multiple security levels simultaneously. This is achieved by implementing a security-aware network stack that classifies and routes frames according to their security level, allowing one physical network interface to replace multiple separate network interfaces and their associated wiring.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network interface and network stack are designed to be universal, handling multiple security levels through a single interface. The system provides multi-functionality by enabling the same physical network infrastructure to support different security domains through software-based classification and routing rather than requiring dedicated hardware for each security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If data is transferred from a single level MILS partition to the multiple level LAN using multiple frames, then data transfer is achieved, but the complexity of frame creation and parsing increases

Engineering Contradiction:
Improvedata transferVSAvoidframe creation and parsing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary classification of frames by security level at the point of reception. The network stack examines incoming frames and assigns them to the appropriate security domain before further processing, eliminating the need for complex parsing and re-creation of frames at intermediate stages. This preliminary routing decision simplifies subsequent handling of the data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8132004B2Multiple independent levels of security containing multi-level security interface
Publication Date: 2012.03.06 THE BOEING CO
  • US8132004B2 patent drawing
  • US8132004B2 patent drawing
  • US8132004B2 patent drawing

AI summary

Methods and systems for enabling security in transferring data from a single level MILS partition to the multiple level LAN. When a frame is received from an external stack via a network interface card, the frame contains a security classification, which is compared to the security classifications assigned to a plurality of internal stacks. Once a match is obtained, the frame is forwarded to the internal stack corresponding to the security classification in the frame assigned by the external stack. When a frame is received from one of the plurality of internal stacks, no security classification exists within the frame. A determination of the security classification assigned to the internal stack, which is then written into a security label in the frame. Once the security label is attached to the frame, the frame is sent to the external stack via a network interface card.