Non-Overlapping Network Topologies for Security-Level Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networking technologies struggle to efficiently construct non-overlapping communication topologies that respect security levels on a common networking infrastructure, leading to high costs and excessive weight/volume due to multiple separate networks required for different security levels.
Innovation Solution
A distributed network fabric with multiple interconnected networking nodes, each with multiple ports, and a topology manager that constructs two or more non-overlapping topologies within the fabric, ensuring that at least two of the topologies lack overlapping infrastructure within the bounds defined by restriction criteria and security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate and distinct communication networks are used for each security level, then security isolation is ensured, but cost and infrastructure weight/volume increase significantly
Solution Approach 1:
The patent combines multiple security level networks into a single shared physical infrastructure while maintaining logical separation through non-overlapping topology construction. Different security levels (e.g., unclassified, secret, top secret) share the same physical nodes and links, but the topology manager ensures that communication paths for different security levels do not overlap, thus achieving both cost reduction and security isolation.
Solution Approach 2:
The patent segments the shared network infrastructure into non-overlapping topological layers for different security levels. The topology manager divides the network graph into separate non-overlapping subgraphs, where each subgraph corresponds to a specific security level. This segmentation ensures that traffic from different security levels traverses disjoint paths, maintaining security isolation while sharing physical resources.
2Reliability
If separate and distinct communication networks are used for each security level, then security isolation is ensured, but cost increases due to multiple networking infrastructures
Solution Approach 1:
The patent merges multiple security level networks into a single unified infrastructure, reducing the number of physical devices, cables, and networking components needed. Instead of maintaining three separate networks for different security levels, a single shared network is used with software-based topology management that enforces security boundaries through non-overlapping path construction.
Solution Approach 2:
The patent introduces a topology manager as an intermediary component that mediates between the shared physical infrastructure and security requirements. The topology manager receives security level information and dynamically constructs non-overlapping topologies, acting as a mediator that enables security isolation without requiring separate physical networks for each security level.
3Weight of stationary object
If non-overlapping topologies are constructed on a common networking infrastructure, then cost and infrastructure weight are reduced, but ensuring security level isolation becomes more difficult
Solution Approach 1:
The topology manager serves as an intermediary that automates the complex process of constructing non-overlapping topologies. It takes as input the network graph and security level requirements, then automatically computes disjoint paths for different security levels using graph theory algorithms, eliminating the need for manual topology design and reducing construction complexity.
Solution Approach 2:
The topology manager employs feedback mechanisms to iteratively refine topology constructions. It monitors security level requirements and adjusts path assignments to ensure non-overlapping constraints are met. The system provides feedback about topology validity and security compliance, enabling automatic correction of configuration issues and simplifying the overall construction process.
Data Source
AI summary
Networks comprising multiple non-overlapping communication topologies are presented. The networks can include a fabric of interconnected network nodes capable of providing multiple communication paths among edge devices. A topology manager constructs communication topologies according to restriction criteria based on required security levels (e.g., top secret, secret, unclassified, etc.). Established topologies do not have overlapping networking infrastructure to within the bounds of the restriction criteria as allowed by the security levels.


