Secure Deterministic Fabric Segregates Data Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems face challenges in managing data traffic across multiple security levels, leading to communication latency and performance degradation when integrating classified data links with varying security clearances, such as 'top secret,' 'secret,' and 'unclassified,' due to the need for multiple security guards and authentication processes.

Innovation Solution

A system utilizing secure deterministic fabric (SDF) with multiple fabric switches, each carrying data segregated according to specific security levels, and multi-level security processing elements to verify credentials and allow communication between switches, while also incorporating safety monitoring and encryption-based separation to ensure data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security guards and authentication processes are used to manage data traffic across different security levels, then security is improved, but communication latency increases and performance degrades

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments data traffic into separate fabric switches based on security levels (e.g., top secret, secret, unclassified). Each fabric switch handles only its designated security level, eliminating the need for multiple security guards to inspect every data packet. This segmentation maintains security while reducing communication latency by allowing direct routing within each security domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces fabric switches as intermediary devices that automatically route data between different security levels based on pre-established security credentials. Instead of using multiple security guards to manually authenticate each transmission, the fabric switches act as automated intermediaries that enforce security policies, thereby reducing latency while maintaining security integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security guards and authentication processes are used to manage data traffic across different security levels, then security is improved, but performance degrades

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting the network into dedicated fabric switches for each security level, the system eliminates the performance overhead of multiple authentication checks. Each fabric switch operates independently at its designated security level, enabling high-speed data transmission without the performance degradation caused by repeated security guard interventions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fabric switches are configured with pre-established security credentials that enable them to automatically authenticate and route data without external security guard intervention. This self-service capability allows the system to maintain security while achieving high performance, as the fabric switches independently enforce security policies without requiring external authentication for each data packet.

Inventive Principle:
Principle #25Self-service

3Loss of time

If data is segregated by security levels using separate fabric switches, then communication latency is reduced, but device complexity increases

Engineering Contradiction:
Improvecommunication latencyVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

Each fabric switch is designed as a universal device capable of handling multiple security levels through configuration rather than requiring separate hardware for each level. The fabric switches can be programmed with different security credentials and routing tables to serve different security domains, reducing overall system complexity while maintaining low latency through dedicated routing paths.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8880868B1Secure deterministic fabric for safe and secure product design
Publication Date: 2014.11.04 ROCKWELL COLLINS INC
  • US8880868B1 patent drawing
  • US8880868B1 patent drawing
  • US8880868B1 patent drawing

AI summary

A secure deterministic fabric includes switches that segregate data traffic requiring disparate levels of authentication or having different safety levels. Data may be segregated physically, utilizing different hardware; or virtually, by allocating certain assets such as memory blocks exclusively for certain levels of authentication. The secure deterministic fabric may include elements for safety monitoring and multi-level security monitoring.