Multi-level Secure Information Retrieval via Enterprise Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing multi-level security systems across a federated network of enterprises is challenging due to differing security schemes and 'stove pipe' information systems, which can lead to security leaks if not properly managed.

Innovation Solution

A multi-level secure information retrieval system utilizing a service-oriented architecture with an enterprise access service tool and gateways managed by each enterprise, providing a common interface for accessing information while maintaining security levels and concealing source identities, and using services orchestrated through an enterprise service bus to manage access across multiple enterprises.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-level security systems are implemented across a federated network of enterprises with differing security schemes, then security protection is improved, but system complexity and difficulty of integration increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component that mediates between client applications and data repositories across different enterprises. The gateway receives requests from clients, determines the appropriate security level, and forwards requests to the appropriate enterprise's data repository. This intermediary approach allows multiple enterprises with different security schemes to be integrated without requiring each enterprise to directly implement and manage all security protocols, thereby reducing overall system complexity while maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If information is accessed across multiple enterprises with different security levels, then information availability is improved, but risk of security leaks increases

Engineering Contradiction:
Improveinformation availabilityVSAvoidrisk of security leaks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by assigning different security levels to different data repositories and applying security filtering at the gateway level. Each enterprise's data repository maintains its own security characteristics and access control policies. The gateway applies security level filtering based on the client's authorization level, ensuring that clients can access information from multiple enterprises (improving availability) while each enterprise's security boundaries are preserved (reducing leak risk).

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where the gateway continuously monitors and evaluates security levels of requests and responses. The gateway determines the security level of incoming requests, filters responses based on the client's authorization level, and can log security events. This feedback loop ensures that information availability is maintained while security violations are detected and prevented in real-time.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If a common interface is provided for accessing information from multiple enterprises, then ease of operation is improved, but loss of source identity information occurs

Engineering Contradiction:
Improveease of accessVSAvoidsource identity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The gateway acts as an intermediary that provides a unified, common interface to client applications for accessing information from multiple enterprises. Clients interact with the gateway using standardized protocols and do not need to know the specific details of each enterprise's data repository structure or access methods (improving ease of operation). The gateway maintains and tracks source identity information internally, associating each request with its originating enterprise and data repository, thus preventing loss of source identity while presenting a simplified interface to clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8359641B2Multi-level secure information retrieval system
Publication Date: 2013.01.22 EVERFOX HOLDINGS LLC
  • US8359641B2 patent drawing
  • US8359641B2 patent drawing
  • US8359641B2 patent drawing

AI summary

According to one embodiment, a multi-level secure information retrieval system includes an enterprise access service tool coupled to one or more client applications and at least one gateway managed by an enterprise. The enterprise access service tool executes services operating in a service oriented architecture. The enterprise access service tool receives requests from the client applications, associates each of the requests with one of a plurality of differing security levels, and transmits the requests to the gateway. The gateway transmits the requested information back to the client applications in which the information is filtered by the gateway according to their associated security levels.