Nested Encryption for Secure Coalition Wargame Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Joint coalition military exercises face challenges in secure data sharing due to security conflicts and insufficient data protection, where national entities may not trust existing cryptographic solutions for protecting sensitive information, leading to a binary proposition of either full protection or vulnerability.

Innovation Solution

A system and method that utilize a local computing resource to organize exercise data into protected and shared portions, pre-encrypting the protected portion with local encryption/decryption keys inaccessible to others, and encrypting the full dataset with host infrastructure keys for secure transmission through a shared network, ensuring only authorized entities can access sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all data is shared through the network, then data sharing and training effectiveness are improved, but data security and national defense protection deteriorate

Engineering Contradiction:
Improvedata sharing effectivenessVSAvoiddata security vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system divides exercise data into distinct segments: shared data portions that can be accessed by all coalition partners and protected data portions that remain encrypted and accessible only to the local entity. This segmentation allows selective data sharing while maintaining security for sensitive information, resolving the contradiction between data sharing effectiveness and data security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested encryption where the protected data portion is encrypted with local decryption keys, and the entire data set (including the encrypted protected portion) is then encrypted with infrastructure decryption keys. This nested encryption structure allows the protected data to be securely transmitted through the shared network while maintaining both local and infrastructure-level security, enabling data sharing without compromising national defense secrets.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If US cryptographic solutions are used for data protection, then US national security is improved, but trust from coalition partners deteriorates

Engineering Contradiction:
ImproveUS cryptographic securityVSAvoidcoalition partner trust
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments data into protected and shared portions, allowing coalition partners to trust the infrastructure-level encryption (using US cryptographic solutions) for shared data while maintaining the ability to protect sensitive portions with local cryptographic keys. This segmentation enables coalition partners to have confidence in US cryptographic security for common data while preserving their ability to maintain independent security for critical information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The infrastructure encryption layer acts as an intermediary that provides a common trust foundation for all coalition partners using US cryptographic solutions, while local encryption layers serve as additional intermediaries for specific protected data. This multi-layer intermediary structure allows coalition partners to trust the US cryptographic infrastructure for general data protection while maintaining their own security interests through local encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If data is encrypted with local keys only, then national security protection is improved, but data sharing capability deteriorates

Engineering Contradiction:
Improvenational security protectionVSAvoiddata sharing capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system implements nested encryption where local encryption keys protect the protected data portion, and infrastructure encryption keys protect the entire data set including the locally encrypted portion. This nested structure enables national security protection through local key control while maintaining data sharing capability, as coalition partners can decrypt the infrastructure layer and access shared data portions without needing access to local decryption keys.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

By segmenting data into protected and shared portions with different encryption requirements, the system enables national security protection for sensitive data while maintaining data sharing capability for unclassified portions. The segmented structure allows selective decryption and access based on data classification and recipient authorization.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240283778A1System and method for securing and controlling nationally protected wargame training data flows through a shared network
Publication Date: 2024.08.22 ROCKWELL COLLINS INC
  • US20240283778A1 patent drawing
  • US20240283778A1 patent drawing
  • US20240283778A1 patent drawing

AI summary

A system and method for controlling nationally protected data flows (e.g., wargame data, training data) through a shared network locally encrypts a protected portion of shared data (e.g., ACMI/weapons flyout data) flowing through a shared network infrastructure. The protected portion is pre-encrypted according to local encryption keys controlled by a local entity (e.g., a nation or multi-national coalition partners) but not shared with other infrastructure partners or participants. The partially encrypted dataset is then fully encrypted (according to host/infrastructure encryption keys accessible to all infrastructure participants) for travel through the security infrastructure via secure datalink. All network destinations having access to the infrastructure keys can decrypt and access the nonprotected portion, but only those network destinations (e.g., other aircraft or vehicles) affiliated with the local entity and/or having access to the local encryption keys may decrypt and access the protected data portion.