Secure Domain Interface for Multi-Domain Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions, such as VLANs and MACsec, are inadequate for securely segregating multiple security domains over shared network media, as they can be vulnerable to attacks and are costly to implement and manage, especially for commercial enterprises and industrial systems.
Innovation Solution
A system and method for secure transfer of security domains across shared media, which involves a secure domain interface that appends a data frame with a security domain identifier and internal routing data to generate an internal data packet, and then appends a source address and authentication code to create an open network data frame, ensuring secure routing and authentication across multiple security domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical separation of network devices is implemented to ensure security, then security assurance is improved, but device cost and system complexity increase significantly
Solution Approach 1:
The patent segments the network into multiple security domains with distinct security policies, allowing each domain to be managed independently while sharing physical infrastructure. This enables security assurance without requiring complete physical separation of all devices.
Solution Approach 2:
The patent creates a multi-functional network infrastructure that can simultaneously support multiple security domains with different security requirements on shared physical media, eliminating the need for separate physical networks for each security domain.
2Ease of manufacture
If VLANs are used to segment network infrastructure, then ease of deployment is improved, but security reliability deteriorates due to vulnerability to attacks
Solution Approach 1:
The patent introduces an intermediary security domain interface that sits between VLAN segments and provides robust security enforcement. This intermediary layer prevents direct VLAN vulnerabilities while maintaining the ease of VLAN deployment for basic segmentation.
Solution Approach 2:
The patent creates a composite security architecture that combines VLAN technology with enhanced security mechanisms, leveraging the ease of VLAN deployment while adding layers of security protection to overcome VLAN vulnerabilities.
3Reliability
If MACsec is implemented for link layer security, then security assurance is improved, but adaptability to multiple security domains deteriorates
Solution Approach 1:
The patent extends security from the link layer to the network layer by introducing security domain interfaces that operate at higher protocol layers. This dimensional change allows MACsec to be combined with network-layer security mechanisms, enabling support for multiple security domains while maintaining link-layer security assurance.
Data Source
AI summary
This disclosure provides systems, methods, and computer program products for secure transfer of security domains across shared media. A secure domain interface is associated with a security domain. The secure domain interface receives a secure network data packet and appends a first data frame. A security interface receives the internal data packet and appends a second data frame to the internal data packet. The second data frame generates an open network data frame securely including payload and routing information from the secure network data packet. The security interface receives open network data frames, authenticates and extracts internal data packets, and routes internal data packets to the secure domain interface. The secure domain interface receives internal data packets, authenticates and extracts secure network data packets, and routes secure network data packets to secure network devices in the security domain.


