Secure Network Aggregation Protocol for Multi-Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networked computer systems, the overhead created by individual containers with separate network connections and classification levels leads to inefficiencies in managing secure communication across multiple users and remote systems.

Innovation Solution

A system and architecture that aggregates secure data and assigns specific communication ports to maintain distinct, secure communication channels over a single network connection, utilizing dynamic sub-carrier modules and host processors to manage and encrypt data across hybrid virtual and physical networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual containers are assigned separate network connections and classification levels, then security and isolation between users are improved, but network overhead and complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate network connections into a single shared network connection while maintaining logical separation through virtual channels. Each container shares the physical network infrastructure but operates in isolated logical channels, reducing physical complexity while preserving security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the single network connection into multiple virtual channels or lanes, each dedicated to specific containers or traffic types. This logical segmentation maintains isolation and security while utilizing shared physical infrastructure, thereby reducing overall network overhead.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple separate network connections are used for each container, then communication security is maintained, but network resource utilization decreases

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent makes a single network connection universal by enabling it to serve multiple containers simultaneously through virtual channel multiplexing. The shared connection handles traffic from multiple sources with appropriate security enforcement, improving resource utilization while maintaining isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent nests multiple virtual communication channels within a single physical network connection. Each container's traffic is encapsulated within the shared connection infrastructure, allowing secure multi-tenant communication over unified physical media.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If separate network connections are established for each container, then isolation between classification levels is ensured, but system scalability is limited

Engineering Contradiction:
ImproveisolationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic channel allocation where virtual communication lanes can be allocated, reallocated, or adjusted based on container needs without physical reconfiguration. This dynamic approach allows the system to scale by logically adding channels to existing connections rather than requiring new physical infrastructure.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11310273B2Secure network aggregation protocol
Publication Date: 2022.04.19 ROCKWELL COLLINS INC
  • US11310273B2 patent drawing
  • US11310273B2 patent drawing
  • US11310273B2 patent drawing

AI summary

A system and architecture for containing unique protocols to establish multiple layers of secure communication within a network. Secure data is aggregated, and containers are assigned specific communication ports to maintain distinct, secure communication channels over a single network connection. Each security level is defined by a tenant; each tenant is assigned a unique range of ports for use over the network.