Multi-Tiered SecDevOps Repository with Security Labeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing a secure development operations (SecDevOps) system within a multi-tier, multi-compartmented network is challenging due to the need to manage multiple security classifications and access rights, especially in classified environments where traditional DevOps approaches are hindered by security policies and formal access requirements.

Innovation Solution

A method and system that compartmentalize the SecDevOps environment based on security classifications, allowing tenants with appropriate clearances to access, copy, and edit sub-programs across projects, using a multi-tiered repository structure with enterprise security modules to control access, and employing security labeling services to manage and replicate sub-programs across different security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional DevOps system is implemented in a classified environment with security policies and formal access requirements, then security control and access management are improved, but system complexity and difficulty of implementation increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the DevOps environment into multiple security compartments (tiers) based on classification levels. Each compartment contains repositories and resources accessible only to tenants with appropriate security clearances. This segmentation enables fine-grained access control while maintaining a unified DevOps platform, resolving the contradiction between security control and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a security module as an intermediary between tenants and classified resources. This module automatically manages access rights by evaluating tenant clearance levels against resource classification labels, eliminating the need for manual access adjudication while maintaining strict security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control is strictly enforced for classified information, then information security is improved, but collaboration efficiency and information sharing speed decrease

Engineering Contradiction:
Improveinformation securityVSAvoidcollaboration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service access control where the security module automatically authenticates tenants and grants access to appropriate resources based on their clearance levels and the classification labels of resources. This eliminates manual access adjudication and allows secure, efficient collaboration without compromising information security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The DevOps platform provides universal access control mechanisms that work across all classification levels and tenant types. The same platform supports multiple security clearances and collaboration scenarios simultaneously, maintaining both security and collaboration efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple security classifications and access rights are managed, then security compliance is improved, but operational simplicity and ease of use decrease

Engineering Contradiction:
Improvesecurity complianceVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security module serves as an intermediary that handles all security compliance operations automatically. It manages multiple classification levels and access rights without requiring manual intervention, maintaining operational simplicity while ensuring security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses classification labels as parameters that automatically determine access rights. By changing the label parameter on resources, the system can control access without complex operational procedures, maintaining simplicity while enforcing compliance.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If sub-programs are replicated across multiple repositories with different security levels, then accessibility and reusability are improved, but access control complexity increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments repositories into different security tiers and uses classification labels to organize sub-programs. This segmentation enables sub-programs to be replicated across multiple repositories with different access levels while maintaining clear access control through the security module, which automatically manages permissions based on tenant clearance and resource labels.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11665174B2Method and system for multi-tiered, multi-compartmented DevOps
Publication Date: 2023.05.30 RAYTHEON CO
  • US11665174B2 patent drawing
  • US11665174B2 patent drawing

AI summary

A method of providing a secure development operations system that can accommodate multiple projects, multiple tenants, and multiple security classifications includes creating a first sub-program with the first sub-program being part of a first project and designating the first sub-program with a first security classification label. The method also includes transferring the first sub-program to a first repository of the development operations system with the first repository being configured to contain sub-programs associated with the first project and transferring a copy of the first sub-program to a second repository of the development operations system. The second repository is configured to contain sub-programs from multiple projects and sub-programs that have different security classification labels.