TDMA Bus Security Isolation via Virtual Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communications systems require separate physical systems for each security level, leading to inefficient use of bandwidth and limited networking capabilities, as they rely on centralized switching with separate cabling and physical separation of signals, which restricts the number of possible connections.

Innovation Solution

A time division multiple access (TDMA) bus architecture that allows multiple levels of security by assigning matching transmit and receive time slots to ports and channels based on their security levels, using a single cable for connection and enabling virtual switches dedicated to specific security levels, with a high assurance control source ensuring secure communication between matching security level devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate physical systems are used for each security level, then security requirements are met, but bandwidth efficiency deteriorates and device complexity increases

Engineering Contradiction:
Improvesecurity level separationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security level communications into a single shared physical bus system. Instead of maintaining separate physical systems for each security level, the invention allows multiple security domains to coexist on the same bus infrastructure, using logical separation mechanisms (time slot assignments, security labels) to maintain security boundaries while sharing physical resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The bus system is designed to serve multiple security levels simultaneously through a universal infrastructure. The same physical bus can carry traffic for different security domains (e.g., Top Secret, Secret, Unclassified) by dynamically assigning time slots and applying appropriate security policies, making the system multi-functional rather than requiring dedicated systems for each level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If centralized switching with separate cabling is used, then security isolation is achieved, but networking capability deteriorates and the number of connections is limited

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetworking capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a temporal dimension to security isolation by using time-division multiplexing. Instead of relying solely on physical separation in space (separate cabling), the system achieves security isolation by assigning specific time slots to different security levels on the shared bus. This adds the time dimension to the traditional spatial separation approach, enabling more flexible networking while maintaining security boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The invention creates virtual copies of switching functionality for each security level within the shared bus system. Rather than requiring physical duplicate switching infrastructure for each security domain, the system implements virtual switches that replicate switching behavior logically, allowing multiple security domains to have their own switching fabric over the same physical medium.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If physical separation of signals is used, then security certification is simplified, but the number of possible connections deteriorates

Engineering Contradiction:
Improvesecurity certificationVSAvoidnumber of connections
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system changes the parameter of signal separation from physical (spatial) to temporal. By transitioning from physical signal separation to time-based signal separation, the system maintains security certification benefits while dramatically increasing connection flexibility. The same physical infrastructure can support numerous connections by dynamically allocating time slots, whereas physical separation would require separate infrastructure for each connection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7751566B2Apparatus using a time division multiple access bus for providing multiple levels of security in a communications system
Publication Date: 2010.07.06 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US7751566B2 patent drawing
  • US7751566B2 patent drawing
  • US7751566B2 patent drawing

AI summary

Systems including both distributed and centralized architectures for providing multiple levels of security using “virtual” switches. Ports and channels are assigned the same time slots on a TDMA bus only when they have matching security levels.