Multilevel Secure Network Routing with Trusted Intermediaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multilevel security (MLS) systems rely on high assurance custom infrastructures or trusted computing elements, which are often low performance, high power, complex, and costly, making it challenging to manage information flow efficiently, especially in high-speed, high-bandwidth environments like global training or simulation systems.

Innovation Solution

A multilevel security network is designed with untrusted nodes, global trusted nodes, and local trusted nodes that route messages with encrypted headers, validate source and destination information, and modify headers to obfuscate sensitive data, while using trusted address management units to regulate communication within allowable memory address ranges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high assurance custom infrastructures or trusted computing elements are used to manage information flow in MLS systems, then security and reliability are improved, but performance deteriorates and system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the information flow management function into separate components: a lightweight security module that handles encryption/decryption and validation, and a separate routing module that handles message forwarding. This segmentation allows each component to be optimized independently, with the security module providing high assurance protection without bottlenecking the high-speed routing operations, thus resolving the contradiction between security reliability and performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted intermediary security module that acts as a mediator between untrusted network nodes and the core routing infrastructure. This intermediary handles all security operations (encryption, decryption, validation) while allowing the routing system to operate at full speed using standard infrastructure, thereby achieving both high security assurance and high performance without requiring expensive trusted computing elements throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If high assurance custom infrastructures are used to facilitate MLS traffic flows, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security functions (encryption, decryption, validation) into a separate, standalone security module that can be implemented using standard software libraries rather than specialized trusted computing hardware. This extraction eliminates the need for complex custom infrastructures and evaluated processors, significantly reducing system complexity and cost while maintaining high security assurance through proper cryptographic protocols and validation mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive, complex trusted computing elements with inexpensive, standard software-based security modules that can be deployed on any general-purpose processor. These modular security components are cost-effective and can be easily updated or replaced without requiring specialized hardware infrastructure, thereby reducing both device complexity and operational cost while maintaining security reliability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If conventional MLS techniques are used, then security clearance management is improved, but information flow management efficiency deteriorates

Engineering Contradiction:
Improvesecurity clearance managementVSAvoidinformation flow management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security clearance management by allowing the security module to adaptively validate and process messages based on the clearance levels of communicating parties. The system dynamically adjusts security operations (encryption strength, validation depth) according to the specific message and user context, enabling efficient information flow management that maintains security clearance integrity while optimizing performance for different operational scenarios rather than using static, overly conservative security measures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10986076B1Information flow enforcement for IP domain in multilevel secure systems
Publication Date: 2021.04.20 ROCKWELL COLLINS INC
  • US10986076B1 patent drawing
  • US10986076B1 patent drawing
  • US10986076B1 patent drawing

AI summary

A multilevel security (MLS) network is disclosed. The MLS network includes untrusted nodes (UTN) capable of receiving messages en route from a source node to a destination node, each message having an unencrypted outer header, an encrypted inner header, and a data payload. UTNs route messages toward their destination as directed by the outer header. Global trusted nodes (GTN) decrypt a portion of the inner header to validate source and destination information before routing the message forward. GTNs further modify the outer header to obfuscate source and destination information from the UTNs. Local trusted nodes (LTN) serve as gateway nodes into a local network. LTNs also validate source and destination information to regulate admission to the local network. LTNs include an address manager which decrypts an additional portion of the inner header to read local address data and generates local messages for routing through the local network.