Service Negotiation Plane for Cross-Enclave Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies do not allow for control of a network system across an encryption boundary or a network boundary, limiting the ability to establish communication between networks of different security enclaves.

Innovation Solution

The implementation of a Service Negotiation Plane that facilitates service negotiation between multiple client networks by forwarding messages through control interfaces with data guards, enabling secure communication across encryption and network boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional waveform-based or encryption key-based methods are used to determine security enclave membership, then security verification between networks can be established, but communication between networks of different security enclaves is blocked

Engineering Contradiction:
Improvesecurity verificationVSAvoidcross-network communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a Service Negotiation Plane as an intermediary layer between networks of different security enclaves. This plane includes service negotiation entities that can establish service-level agreements and facilitate communication without requiring the networks to share the same security enclave status. The intermediary enables cross-enclave communication by negotiating services at a higher abstraction level rather than requiring direct waveform or key matching between security enclaves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If networks of different security enclaves are isolated to maintain security boundaries, then security confidentiality is preserved, but networks cannot discover or communicate with each other

Engineering Contradiction:
Improvesecurity confidentialityVSAvoidnetwork discovery capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent adds a new dimensional layer (Service Negotiation Plane) above the traditional security enclave boundaries. This allows networks to interact in a new dimension without breaching the original security boundaries. Networks can discover and negotiate services through this elevated plane while their core security enclaves remain isolated, thus preserving confidentiality while enabling discovery and communication capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If strict security enclave boundaries are enforced using traditional methods, then security integrity is maintained, but service negotiation and control across networks is impossible

Engineering Contradiction:
Improvesecurity integrityVSAvoidservice negotiation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the communication system into multiple layers: the original security enclave layer and the new Service Negotiation Plane layer. This segmentation allows service negotiation to occur at the upper layer without compromising the security integrity of the lower layer. The Service Negotiation Plane can perform service discovery, agreement establishment, and control functions while the underlying security boundaries remain intact and enforced.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250184720A1Communications security architecture implementing a service negotiation plane channel
Publication Date: 2025.06.05 L3HARRIS TECH INC
  • US20250184720A1 patent drawing
  • US20250184720A1 patent drawing
  • US20250184720A1 patent drawing

AI summary

A cross-network communication system includes a plurality of client networks. The cross-network communication system includes a Service Negotiation Plane configured to forward messages between the plurality of client networks via a plurality of control interfaces, each of which corresponds to one of the plurality of client networks. Each of the plurality of control interfaces includes a first data guard that belongs to the corresponding client network. The first data guard is configured to prevent exfiltration of classified information or permit only particular types of messages to traverse the Service Negotiation Plane.