Secure Network Server Web Configuration via Segmented Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-assurance security products face management complexity due to primitive command line interfaces, which are difficult for users to navigate, especially when compared to graphical user interfaces and web-based controls available in lower-assurance products.

Innovation Solution

Implementing a secure network server with an embedded web server outside its trusted security functionality, allowing configuration through a web interface while maintaining trusted security functionality, and using a command line interface for critical actions to ensure compliance with high-assurance requirements like EAL-7.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a primitive command line interface is used within trusted security functionality, then security assurance level is maintained, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidadministrator interface usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system divides the administrator interface into two separate components: a web-based graphical interface for configuration and a command line interface within the trusted security functionality for critical actions. This segmentation allows each interface to serve its specific purpose without compromising the security assurance level while improving overall usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A web server operating outside the trusted security functionality serves as an intermediary between the administrator and the secure network server. This intermediary provides a user-friendly web interface for configuration while the trusted security functionality remains protected and accessible only through the command line interface for critical operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a web-based graphical user interface is implemented, then ease of operation improves, but device complexity increases

Engineering Contradiction:
Improveadministrator interface usabilityVSAvoidtrusted security functionality complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system architecture is segmented to place the web server and web-based graphical interface outside the trusted security functionality boundary. This allows the complex web interface to exist without increasing the complexity of the trusted security functionality, as the two operate in separate security domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The web server acts as an intermediary layer that handles all web-based interactions and configuration tasks. By positioning this intermediary outside the trusted security functionality, the complexity of the web interface does not propagate into or increase the complexity of the trusted security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7890755B2High-assurance web-based configuration of secure network server
Publication Date: 2011.02.15 THE BOEING CO
  • US7890755B2 patent drawing
  • US7890755B2 patent drawing
  • US7890755B2 patent drawing

AI summary

A secure network server having an embedded Hyper-Text Transfer Protocol (HTTP) server that is not within its trusted security functionality and that is used to configure the SNS security and networking features.