Secure Domain Interface for Multi-Domain Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions, such as VLANs and MACsec, are inadequate for securely segregating multiple security domains over shared network media, as they can be vulnerable to attacks and are costly to implement and manage, especially for commercial enterprises and industrial systems.

Innovation Solution

A system and method for secure transfer of security domains across shared media, which involves a secure domain interface that appends a data frame with a security domain identifier and internal routing data to generate an internal data packet, and then appends a source address and authentication code to create an open network data frame, ensuring secure routing and authentication across multiple security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical separation of network devices is implemented to ensure security, then security assurance is improved, but device cost and system complexity increase significantly

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple security domains with distinct security policies, allowing each domain to be managed independently while sharing physical infrastructure. This enables security assurance without requiring complete physical separation of all devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a multi-functional network infrastructure that can simultaneously support multiple security domains with different security requirements on shared physical media, eliminating the need for separate physical networks for each security domain.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If VLANs are used to segment network infrastructure, then ease of deployment is improved, but security reliability deteriorates due to vulnerability to attacks

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary security domain interface that sits between VLAN segments and provides robust security enforcement. This intermediary layer prevents direct VLAN vulnerabilities while maintaining the ease of VLAN deployment for basic segmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a composite security architecture that combines VLAN technology with enhanced security mechanisms, leveraging the ease of VLAN deployment while adding layers of security protection to overcome VLAN vulnerabilities.

Inventive Principle:
Principle #40Composite materials

3Reliability

If MACsec is implemented for link layer security, then security assurance is improved, but adaptability to multiple security domains deteriorates

Engineering Contradiction:
Improvesecurity assuranceVSAvoidmulti-domain support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends security from the link layer to the network layer by introducing security domain interfaces that operate at higher protocol layers. This dimensional change allows MACsec to be combined with network-layer security mechanisms, enabling support for multiple security domains while maintaining link-layer security assurance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10491569B1Secure transfer of independent security domains across shared media
Publication Date: 2019.11.26 ALTEREDNETS CYBER SOLUTIONS INC
  • US10491569B1 patent drawing
  • US10491569B1 patent drawing
  • US10491569B1 patent drawing

AI summary

This disclosure provides systems, methods, and computer program products for secure transfer of security domains across shared media. A secure domain interface is associated with a security domain. The secure domain interface receives a secure network data packet and appends a first data frame. A security interface receives the internal data packet and appends a second data frame to the internal data packet. The second data frame generates an open network data frame securely including payload and routing information from the secure network data packet. The security interface receives open network data frames, authenticates and extracts internal data packets, and routes internal data packets to the secure domain interface. The secure domain interface receives internal data packets, authenticates and extracts secure network data packets, and routes secure network data packets to secure network devices in the security domain.