Partitioned Programmable Circuit for Multi-Level Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current aircraft systems that handle information at a single security level are inefficient and costly, as they require all personnel to have high security clearance, leading to increased maintenance costs and reduced availability of maintenance personnel. Additionally, implementing Multiple Levels of Security (MLS) systems is time-consuming and results in larger, heavier systems that are not ideal for aircraft.

Innovation Solution

A programmable integrated circuit with partitioned sections that control communication between different security levels, allowing only authorized access and processing information with associated security labels, reducing the need for high security clearance among maintenance personnel and optimizing system size and weight.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Multiple Levels of Security (MLS) systems are implemented, then security clearance requirements for personnel are reduced, but system size and weight increase

Engineering Contradiction:
Improvesecurity clearance requirementsVSAvoidsystem weight
Core Design Contradiction:
Adaptability or versatilityVSWeight of stationary object

Solution Approach 1:

The system is divided into multiple security domains (first security domain and second security domain) with distinct processing sections. Each domain handles specific security levels independently, allowing maintenance personnel with lower clearance to work on the first domain while the second domain remains secure. This segmentation enables MLS functionality without requiring a complete system redesign, thus limiting weight increase.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A gateway section is introduced as an intermediary between the first and second security domains. The gateway controls information flow and enforces security policies, enabling secure interaction between different security levels. This intermediary approach allows MLS implementation while keeping the overall system architecture compact and manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If MLS systems are implemented, then personnel availability increases, but system complexity increases

Engineering Contradiction:
Improvepersonnel availabilityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The processing system is segmented into multiple domains with clear security boundaries. The first domain handles lower security level information while the second domain handles higher security level information. This segmentation allows personnel with different clearance levels to independently maintain their respective domains, increasing personnel availability while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security policies and access controls are applied locally to different domains rather than uniformly across the entire system. The first domain allows access by personnel with lower clearance, while the second domain requires higher clearance. This local differentiation enables flexible personnel management while keeping each domain's complexity manageable.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional MLS design methods are used, then security separation is achieved, but system size and expense increase

Engineering Contradiction:
Improvesecurity separationVSAvoidsystem volume
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

Multiple security domains are merged into a single integrated processing system rather than using separate physical systems. The gateway enables secure information flow between domains within the same system boundary, achieving security separation while reducing overall system volume and expense compared to completely separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The processing system is designed to handle multiple security levels simultaneously through a single multi-functional platform. The same physical infrastructure supports both the first security domain and second security domain, reducing the need for duplicate hardware and minimizing system volume while maintaining security separation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2348437B1Multi-level security controls system
Publication Date: 2018.04.18 THE BOEING CO
  • EP2348437B1 patent drawingFigure 1~2
  • EP2348437B1 patent drawingFigure 3
  • EP2348437B1 patent drawingFigure 4

AI summary

A method and apparatus for processing information. First information is received from a first number of devices at a first number of interfaces configured to receive the first information in a first section of a programmable integrated circuit. The first information is sent to a second section in the programmable integrated circuit. Second information is received at a second number of interfaces in the second section from a second number of devices that generates the second information with a plurality of security levels. The first and second sections are partitioned from each other such that communication between the first and second sections is controlled by the second section. The first and second information are processed to form processed information that is sent to a number of network interfaces in which an identification of a security level within a plurality of security levels is associated with the processed information.