Multi-level Secure Information Retrieval via Enterprise Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing multi-level security systems across a federated network of enterprises is challenging due to differing security schemes and 'stove pipe' information systems, which can lead to security leaks if not properly managed.
Innovation Solution
A multi-level secure information retrieval system utilizing a service-oriented architecture with an enterprise access service tool and gateways managed by each enterprise, providing a common interface for accessing information while maintaining security levels and concealing source identities, and using services orchestrated through an enterprise service bus to manage access across multiple enterprises.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-level security systems are implemented across a federated network of enterprises with differing security schemes, then security protection is improved, but system complexity and difficulty of integration increase
Solution Approach 1:
The patent introduces a gateway as an intermediary component that mediates between client applications and data repositories across different enterprises. The gateway receives requests from clients, determines the appropriate security level, and forwards requests to the appropriate enterprise's data repository. This intermediary approach allows multiple enterprises with different security schemes to be integrated without requiring each enterprise to directly implement and manage all security protocols, thereby reducing overall system complexity while maintaining security protection.
2Adaptability or versatility
If information is accessed across multiple enterprises with different security levels, then information availability is improved, but risk of security leaks increases
Solution Approach 1:
The patent implements local quality by assigning different security levels to different data repositories and applying security filtering at the gateway level. Each enterprise's data repository maintains its own security characteristics and access control policies. The gateway applies security level filtering based on the client's authorization level, ensuring that clients can access information from multiple enterprises (improving availability) while each enterprise's security boundaries are preserved (reducing leak risk).
Solution Approach 2:
The system implements feedback mechanisms where the gateway continuously monitors and evaluates security levels of requests and responses. The gateway determines the security level of incoming requests, filters responses based on the client's authorization level, and can log security events. This feedback loop ensures that information availability is maintained while security violations are detected and prevented in real-time.
3Ease of operation
If a common interface is provided for accessing information from multiple enterprises, then ease of operation is improved, but loss of source identity information occurs
Solution Approach 1:
The gateway acts as an intermediary that provides a unified, common interface to client applications for accessing information from multiple enterprises. Clients interact with the gateway using standardized protocols and do not need to know the specific details of each enterprise's data repository structure or access methods (improving ease of operation). The gateway maintains and tracks source identity information internally, associating each request with its originating enterprise and data repository, thus preventing loss of source identity while presenting a simplified interface to clients.
Data Source
AI summary
According to one embodiment, a multi-level secure information retrieval system includes an enterprise access service tool coupled to one or more client applications and at least one gateway managed by an enterprise. The enterprise access service tool executes services operating in a service oriented architecture. The enterprise access service tool receives requests from the client applications, associates each of the requests with one of a plurality of differing security levels, and transmits the requests to the gateway. The gateway transmits the requested information back to the client applications in which the information is filtered by the gateway according to their associated security levels.


