Multi-Level Security Database Metadata Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-based security gateways and databases face performance issues due to slow processing of large data files and data replication complexities, leading to increased latency and complexity in multi-level security environments.

Innovation Solution

Separating metadata from data and storing raw data in a Storage Area Network (SAN) environment, with metadata stored in dedicated servers behind a multi-level security gateway, which controls authorizations and decryption keys, reducing the need for data replication and improving performance across multiple security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data files are replicated in each security domain for sharing, then data accessibility is improved, but system complexity and configuration management problems increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments data into two distinct types: metadata (stored in the MLS database behind the gateway) and actual data content (stored in the SAN). This segmentation allows the system to manage different types of information separately, reducing the complexity of replicating entire data files across security domains while maintaining accessibility through metadata references.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the actual data content from the MLS database and stores it externally in a SAN environment. Only metadata (filenames, security classifications, access controls) remains in the database. This extraction eliminates the need to replicate large data files across security domains, reducing system complexity while preserving data accessibility through metadata-based retrieval.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If data files are replicated in each security domain for sharing, then data accessibility is improved, but processing speed decreases

Engineering Contradiction:
Improvedata accessibilityVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

By segmenting data into metadata and content, the system only replicates small metadata records across security domains rather than large data files. This dramatically reduces processing time and improves productivity while maintaining data accessibility through efficient metadata-based lookup and retrieval from the SAN.

Inventive Principle:
Principle #1Segmentation

3Reliability

If large data files are processed by security gateways, then security control is maintained, but performance decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts actual data content from the gateway processing path and stores it in the SAN. The gateway only processes small metadata files to enforce security policies, determine access controls, and manage decryption keys. This extraction maintains security control while dramatically improving performance by eliminating bottleneck processing of large data files through the gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If separate SAN storage is provided for each security domain, then data security is improved, but storage costs increase

Engineering Contradiction:
Improvedata securityVSAvoidstorage resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges storage resources by providing a single SAN environment that stores data for multiple security domains. Security is maintained through metadata-based access controls and decryption key management by the MLS gateway, rather than physical separation. This consolidation reduces storage costs and resource duplication while maintaining data security through logical isolation and encryption.

Inventive Principle:
Principle #5Merging (Combining)

5Adaptability or versatility

If data replication is performed across security levels, then data sharing is improved, but storage requirements increase

Engineering Contradiction:
Improvedata sharingVSAvoidstorage capacity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential metadata (filenames, security classifications, access permissions) and replicates it across security domains, while the actual data content resides in a single SAN location. This approach enables data sharing through metadata-based access while minimizing storage requirements by avoiding duplication of large data files across multiple domains.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2319225B1Secure high performance multi-level security database systems and methods
Publication Date: 2016.12.07 THE BOEING CO

AI summary

In accordance with one or more embodiments of the present disclosure, systems and methods described herein provide for transferring data over one or more networks. A storage area network is adapted to communicate with the one or more networks. A first component is adapted to route data to and from the storage area network. A second component is adapted to route data to and from the storage area network. A gateway component is adapted to control the routing of data between the first and second components and the storage area network. The storage area network is adapted to separate metadata from the data and store the metadata in a secure server positioned behind the gateway component.