Trust Module for Multi-Network Secure Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern network communication systems, maintaining security and reliability across networks with different security levels is challenging due to the use of off-shore manufactured hardware components and proprietary authentication/encryption schemes, leading to potential security breaches and communication impediments.

Innovation Solution

A trust module manages secure communication across multiple networks by providing a control channel for encrypted communication rules, distributing public and private keys, and authenticating control information, enabling secure communication between networks with different security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If off-shore manufactured hardware components are used to reduce network costs, then cost is reduced, but security reliability deteriorates due to un-trusted sources

Engineering Contradiction:
ImprovecostVSAvoidsecurity reliability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a trust module as an intermediary component that mediates between untrusted off-shore hardware and the secure network environment. This trust module verifies the authenticity of hardware components and establishes secure communication channels, allowing the system to use cost-effective off-shore components while maintaining security through the intermediary verification layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each network uses proprietary authentication and encryption schemes, then security customization is improved, but intercommunication difficulty increases among networks

Engineering Contradiction:
Improvesecurity customizationVSAvoidintercommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The trust module serves multiple networks with different proprietary security schemes simultaneously, providing a universal interface for authentication and encryption. It can handle various authentication protocols and encryption standards from different manufacturers while presenting a unified security model, enabling intercommunication between networks that would otherwise be incompatible.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If ad hoc authentication management is used among various networks, then implementation flexibility is improved, but security breach risk increases due to lack of central administration

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidsecurity breach risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple distributed authentication management functions into a single centralized trust module. This consolidation maintains the flexibility of ad hoc implementation where each network can join independently, while simultaneously providing centralized security oversight that prevents security breaches through unified policy enforcement and monitoring.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9774630B1Administration of multiple network system with a single trust module
Publication Date: 2017.09.26 ROCKWELL COLLINS INC
  • US9774630B1 patent drawing
  • US9774630B1 patent drawing
  • US9774630B1 patent drawing

AI summary

A trust module suitable for providing and managing network administration across multiple networks with different security levels. The trust module comprises an administration module to provide secure communication rules between and among the networks that define the manner in which the networks exchange secure communication over a data channel. The administration module includes a user interface to enable an administrator to define the secure communication rules and an encryption module to encrypt the secure communication rules. Advantageously, the trust module of the present invention allows for secure communication and attestation across an unsecure network and a secure network.