Service Oriented Security Framework for Compartmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current compartmented high assurance networks face inconsistencies in security mechanisms, lacking multi-factor authentication, content adjudication, and user-to-workstation binding, which can lead to unauthorized access and disclosure of classified information.

Innovation Solution

A comprehensive security framework that integrates user-to-workstation binding, providing consistent security across all collaborative applications through a service-oriented architecture, utilizing a digitally signed browser application to access user and workstation certificates, and implementing adjudication services for chat, email, and VoIP content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security barriers are eroded between users, LANs, and applications to facilitate collaboration, then ease of operation is improved, but reliability deteriorates due to inconsistent and inadequate security mechanisms

Engineering Contradiction:
Improvecollaboration facilitationVSAvoidsecurity consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments security validation into distinct components: user authentication, workstation authentication, and content adjudication. Each component operates independently but contributes to the overall security framework, allowing collaboration across segmented networks while maintaining consistent security validation at each layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security framework introduces intermediary services including a security token service (STS) that issues security tokens, and content adjudication services that mediate between users and compartmented data. These intermediaries ensure consistent security validation without preventing collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional security mechanisms are used without user-to-workstation binding, then device complexity is reduced, but harmful factors increase due to unauthorized access risks

Engineering Contradiction:
Improvesecurity mechanism simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary authentication actions by binding users to specific workstations before accessing compartmented data. The security framework validates both user credentials and workstation credentials in advance, establishing a trusted relationship that prevents unauthorized access without adding complex runtime security mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security framework changes the authentication parameters from simple user credentials to a composite validation including user certificates, workstation certificates, and content caveats. This parameter enhancement provides stronger security against unauthorized access while maintaining a relatively simple implementation through standard cryptographic techniques.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multi-factor authentication and content adjudication are implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security framework implements universal authentication mechanisms that work across multiple collaborative applications including chat, email, and file sharing. The same user-to-workstation binding and content adjudication services provide multi-factor authentication throughout the system, improving reliability without requiring separate complex authentication systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9576146B2Service oriented secure collaborative system for compartmented networks
Publication Date: 2017.02.21 RAYTHEON CO
  • US9576146B2 patent drawing
  • US9576146B2 patent drawing
  • US9576146B2 patent drawing

AI summary

A system receives a request to store a document in a database, receives a user security token, analyzes the document to determine an adjudicated security level for the document, compares the user security token to the adjudicated security level, stores the document when the user security token is equal to the adjudicated security level, when the user security token is not equal to the adjudicated security level, queries the user as to whether the document should be stored with the adjudicated security level, receives a response to the query from the user, stores the document when the user agrees to store the document with the adjudicated security level, and when the user does not agree to store the document with the adjudicated security level, transmits a message to a security officer and quarantine the document.