Mission Context Routing for Secure Data Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data communication systems primarily focus on internal factors like network congestion and node functionality for routing data, neglecting external factors such as mission concerns and potential risks, which can lead to exposure of confidential data to unauthorized entities or adversaries.

Innovation Solution

The implementation of a Mission Context Routing (MCR) system that determines and configures data routes based on user requests, host context information, and operational contexts, allowing organizations to control network traffic decisions and divert data away from high-risk areas or adversaries by analyzing client identity and unit of work.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional routing based on network congestion and node functionality is used, then network throughput and bandwidth are optimized, but security against unauthorized entities and adversaries is compromised

Engineering Contradiction:
Improvenetwork throughputVSAvoidexposure to unauthorized entities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the routing decision-making process into multiple independent components: traditional network performance metrics (congestion, bandwidth) are separated from security context metrics (adversary information, mission requirements). This segmentation allows each component to be evaluated independently and combined to form a comprehensive routing decision, resolving the contradiction between throughput optimization and security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary routing controller that mediates between traditional network routing protocols and security considerations. This intermediary component receives routing requests, evaluates both performance and security metrics, and determines the final routing path. It acts as a buffer that prevents direct conflict between throughput optimization and security requirements by translating security policies into routing decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If routing decisions are made based solely on internal network factors, then network performance is maintained, but external security risks and mission concerns are neglected

Engineering Contradiction:
Improvenetwork performanceVSAvoidexternal security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges internal network performance metrics with external security context metrics into a unified routing decision framework. The routing controller simultaneously considers traditional factors (congestion, node functionality) and external factors (adversary information, mission requirements), combining them into a single comprehensive evaluation that produces routing decisions satisfying both performance and security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary action by pre-establishing security policies, adversary information databases, and mission context parameters before routing decisions are made. These external security factors are prepared and available in advance, allowing the routing controller to quickly evaluate both performance and security considerations without delaying network operations. The security context is pre-processed and integrated into the routing decision framework proactively.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11228525B2Mission context routing data communication system
Publication Date: 2022.01.18 RAYTHEON CO
  • US11228525B2 patent drawing
  • US11228525B2 patent drawing
  • US11228525B2 patent drawing

AI summary

A data communication system includes a host computing system, a data communication network, and a mission context routing (MCR) system. The host computing system is configured to receive a user request to exchange data between the host computing system and a destination communication device. The data communication network is configured to establish at least one network path to facilitate data exchange between the host computing system and the destination communication device. The MCR system is configured to determine route connection data based on an input selected from a group that includes the user request in context of the activity a user is performing, and an operational context of a network owner entity. Accordingly, the MCR system establishes a designated network path among a plurality of different available network paths of the data communication network based at least in part on the route connection data.