Secure Deterministic Fabric Switch for Multi-Level Security Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional secure computing platforms operate under a single level of security, which is inefficient and costly, requiring dedicated equipment and certification challenges when multiple security levels are needed, such as in military aircraft with both military and civil systems, leading to logistical and weight issues due to physical separation and redundant resources.

Innovation Solution

A Secure Deterministic Fabric (SDF) switch system that allows reconfigurable multiple levels of security within a single platform by dynamically assigning security levels to processing resources and payloads on power-up, using a SDF switch element connected to a Remote Interface Unit (RIU) and General Purpose Processor (GPP), with a control module for managing power and configuration compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical separation and dedicated equipment are used to maintain multiple security levels, then security isolation is improved, but device complexity and weight increase

Engineering Contradiction:
Improvesecurity isolationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security levels into a single processing system using a reconfigurable fabric switch that can dynamically partition processing resources among different security classifications. This merging approach eliminates the need for separate physical systems while maintaining security isolation through software-based partitioning and controlled data flow paths.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The fabric switch serves multiple functions by supporting different security levels simultaneously and reconfiguring to accommodate various mission requirements. A single processing element can be dynamically assigned to different security levels based on operational needs, making the system universal rather than dedicated to specific security classifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated equipment and wiring are installed for each security level, then security isolation is improved, but weight and cost increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidweight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

Multiple security level infrastructures are merged into a single shared fabric switching system. The same physical wiring and processing elements are reused across different security levels through time-multiplexed and space-multiplexed partitioning, eliminating redundant weight while maintaining isolation through controlled access paths.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If processing resources are permanently assigned to specific security levels, then security isolation is improved, but adaptability decreases

Engineering Contradiction:
Improvesecurity isolationVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static, permanent assignments to dynamic, reconfigurable resource allocation. The fabric switch can be reconfigured in real-time to assign processing elements to different security levels based on mission requirements, allowing the same hardware to adapt to varying operational needs while maintaining security boundaries through controlled data paths.

Inventive Principle:
Principle #15Dynamics

4Reliability

If redundant processing elements are installed for different security levels, then security isolation is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity isolationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Redundant processing elements are eliminated by merging security level separation into the fabric switching fabric itself. The switching fabric creates logical partitions and isolated data paths, allowing a single set of processing elements to serve multiple security levels without requiring duplicate hardware for each classification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9659192B1Secure deterministic fabric switch system and method
Publication Date: 2017.05.23 ROCKWELL COLLINS INC
  • US9659192B1 patent drawing
  • US9659192B1 patent drawing
  • US9659192B1 patent drawing

AI summary

A Secure Deterministic Fabric (SDF) switch architecture and design may provide a cost effective reconfigurable Multiple Single Levels (MSL) of Security implementation that is low risk to certify and may not require recertification after an initial certification evaluation. The SDF switch enables assignment of processing resources and attached payloads to a specific security level fabric for use by an operational system. The assignment of defined security levels is commanded by a SDF control and status module without changing certification, aircraft wiring, or revising hardware. The processing resources are statically assigned during power up on a per mission basis or dynamically reassigned between security levels during a mission as processing requirements may change as a result of mission stage. The SDF switch supports mission defined security configurations for individual security level operational payload processing.