Non-Overlapping Network Topologies for Security-Level Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking technologies struggle to efficiently construct non-overlapping communication topologies that respect security levels on a common networking infrastructure, leading to high costs and excessive weight/volume due to multiple separate networks required for different security levels.

Innovation Solution

A distributed network fabric with multiple interconnected networking nodes, each with multiple ports, and a topology manager that constructs two or more non-overlapping topologies within the fabric, ensuring that at least two of the topologies lack overlapping infrastructure within the bounds defined by restriction criteria and security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate and distinct communication networks are used for each security level, then security isolation is ensured, but cost and infrastructure weight/volume increase significantly

Engineering Contradiction:
Improvesecurity isolationVSAvoidinfrastructure weight
Core Design Contradiction:
ReliabilityVSWeight of stationary object

Solution Approach 1:

The patent combines multiple security level networks into a single shared physical infrastructure while maintaining logical separation through non-overlapping topology construction. Different security levels (e.g., unclassified, secret, top secret) share the same physical nodes and links, but the topology manager ensures that communication paths for different security levels do not overlap, thus achieving both cost reduction and security isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the shared network infrastructure into non-overlapping topological layers for different security levels. The topology manager divides the network graph into separate non-overlapping subgraphs, where each subgraph corresponds to a specific security level. This segmentation ensures that traffic from different security levels traverses disjoint paths, maintaining security isolation while sharing physical resources.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate and distinct communication networks are used for each security level, then security isolation is ensured, but cost increases due to multiple networking infrastructures

Engineering Contradiction:
Improvesecurity isolationVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security level networks into a single unified infrastructure, reducing the number of physical devices, cables, and networking components needed. Instead of maintaining three separate networks for different security levels, a single shared network is used with software-based topology management that enforces security boundaries through non-overlapping path construction.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a topology manager as an intermediary component that mediates between the shared physical infrastructure and security requirements. The topology manager receives security level information and dynamically constructs non-overlapping topologies, acting as a mediator that enables security isolation without requiring separate physical networks for each security level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Weight of stationary object

If non-overlapping topologies are constructed on a common networking infrastructure, then cost and infrastructure weight are reduced, but ensuring security level isolation becomes more difficult

Engineering Contradiction:
Improveinfrastructure weightVSAvoidtopology construction complexity
Core Design Contradiction:
Weight of stationary objectVSDevice complexity

Solution Approach 1:

The topology manager serves as an intermediary that automates the complex process of constructing non-overlapping topologies. It takes as input the network graph and security level requirements, then automatically computes disjoint paths for different security levels using graph theory algorithms, eliminating the need for manual topology design and reducing construction complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The topology manager employs feedback mechanisms to iteratively refine topology constructions. It monitors security level requirements and adjusts path assignments to ensure non-overlapping constraints are met. The system provides feedback about topology validity and security compliance, enabling automatic correction of configuration issues and simplifying the overall construction process.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12348405B2Non-overlapping secured topologies in a distributed network fabric
Publication Date: 2025.07.01 NANT HOLDINGS IP LLC
  • US12348405B2 patent drawing
  • US12348405B2 patent drawing
  • US12348405B2 patent drawing

AI summary

Networks comprising multiple non-overlapping communication topologies are presented. The networks can include a fabric of interconnected network nodes capable of providing multiple communication paths among edge devices. A topology manager constructs communication topologies according to restriction criteria based on required security levels (e.g., top secret, secret, unclassified, etc.). Established topologies do not have overlapping networking infrastructure to within the bounds of the restriction criteria as allowed by the security levels.