Unified Network Switch with Outer Layer Security Wrapper
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network switches are inadequate for supporting enterprise security systems that require data isolation between multiple security domains, as they operate within a single security domain and are cumbersome to reconfigure across different domains.
Innovation Solution
A high assurance unified switching device with a modular, standards-compliant extensible network switch design, incorporating an inner layer router and an outer layer security wrapper, uses cryptographic key pairs to encrypt and decrypt data packets, ensuring isolation between security domains and allowing for secure routing and reconfiguration without physical cable changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network switches are used for multiple security domains, then data isolation between security domains is not provided, but using multiple separate switches increases device complexity and reconfiguration difficulty
Solution Approach 1:
The patent combines multiple security domain handling capabilities into a single unified network switch. The switch integrates multiple security wrappers, each dedicated to a specific security domain, within one device. This allows the single switch to handle data packets from multiple security domains while maintaining data isolation through the individual security wrappers, eliminating the need for multiple separate switches.
Solution Approach 2:
The unified network switch is segmented into multiple independent security wrappers, with each wrapper dedicated to a specific security domain. This segmentation allows each wrapper to independently process and isolate data packets for its assigned security domain while being part of a single unified device, thus achieving both data isolation and reduced device complexity.
2Adaptability or versatility
If conventional network switches are used for reconfiguration between security domains, then physical cable reconnection is required, but this process is time-consuming and reduces operational efficiency
Solution Approach 1:
The unified network switch implements dynamic reconfiguration capability where security wrappers and their associated security domains can be reassigned and reconfigured through software control without physical cable changes. The switch can dynamically assign input and output ports to different security domains as needed, allowing rapid adaptation between different security domain configurations.
Solution Approach 2:
The patent replaces the mechanical cable plugging and unplugging process with electronic/software-based port assignment and security wrapper configuration. Instead of physically reconnecting cables to different switches, the system uses software to dynamically assign ports to different security domains, eliminating the time-consuming mechanical reconfiguration process.
3Reliability
If multiple network switches are used for different security domains, then data isolation is maintained, but network resource mobility between domains becomes cumbersome
Solution Approach 1:
The unified network switch provides universal handling of multiple security domains within a single device. Each security wrapper within the switch can be configured to handle specific security domains, and the same physical ports and internal routing resources can be dynamically assigned to different security domains as needed, enabling easy resource mobility while maintaining data isolation.
Data Source
AI summary
Disclosed is a high assurance unified switching device corresponding to a modular, standards-compliant extensible network switch supporting multiple security domains with data isolation of multiple data packets obtained from the multiple security domains. The device may comprise an inner layer router and an outer layer security wrapper (outer layer router). The ports on the outer layer router are configured for different security domains and assigned corresponding key pairs. The ports use the assigned key pairs for encrypting data packets prior to routing and decrypt the data after routing such that there is an isolation of data packets of different security domains. A routed packet arriving at the wrong port cannot be decrypted and therefore is dropped.


