Unified Network Switch with Outer Layer Security Wrapper

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network switches are inadequate for supporting enterprise security systems that require data isolation between multiple security domains, as they operate within a single security domain and are cumbersome to reconfigure across different domains.

Innovation Solution

A high assurance unified switching device with a modular, standards-compliant extensible network switch design, incorporating an inner layer router and an outer layer security wrapper, uses cryptographic key pairs to encrypt and decrypt data packets, ensuring isolation between security domains and allowing for secure routing and reconfiguration without physical cable changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network switches are used for multiple security domains, then data isolation between security domains is not provided, but using multiple separate switches increases device complexity and reconfiguration difficulty

Engineering Contradiction:
Improvedata isolation between security domainsVSAvoidnumber of switches required
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security domain handling capabilities into a single unified network switch. The switch integrates multiple security wrappers, each dedicated to a specific security domain, within one device. This allows the single switch to handle data packets from multiple security domains while maintaining data isolation through the individual security wrappers, eliminating the need for multiple separate switches.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified network switch is segmented into multiple independent security wrappers, with each wrapper dedicated to a specific security domain. This segmentation allows each wrapper to independently process and isolate data packets for its assigned security domain while being part of a single unified device, thus achieving both data isolation and reduced device complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If conventional network switches are used for reconfiguration between security domains, then physical cable reconnection is required, but this process is time-consuming and reduces operational efficiency

Engineering Contradiction:
Improvereconfiguration capability between security domainsVSAvoidreconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The unified network switch implements dynamic reconfiguration capability where security wrappers and their associated security domains can be reassigned and reconfigured through software control without physical cable changes. The switch can dynamically assign input and output ports to different security domains as needed, allowing rapid adaptation between different security domain configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical cable plugging and unplugging process with electronic/software-based port assignment and security wrapper configuration. Instead of physically reconnecting cables to different switches, the system uses software to dynamically assign ports to different security domains, eliminating the time-consuming mechanical reconfiguration process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If multiple network switches are used for different security domains, then data isolation is maintained, but network resource mobility between domains becomes cumbersome

Engineering Contradiction:
Improvedata isolation between security domainsVSAvoidnetwork resource mobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The unified network switch provides universal handling of multiple security domains within a single device. Each security wrapper within the switch can be configured to handle specific security domains, and the same physical ports and internal routing resources can be dynamically assigned to different security domains as needed, enabling easy resource mobility while maintaining data isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11792160B1High assurance unified network switch
Publication Date: 2023.10.17 ARCHITECTURE TECH CORP
  • US11792160B1 patent drawing
  • US11792160B1 patent drawing
  • US11792160B1 patent drawing

AI summary

Disclosed is a high assurance unified switching device corresponding to a modular, standards-compliant extensible network switch supporting multiple security domains with data isolation of multiple data packets obtained from the multiple security domains. The device may comprise an inner layer router and an outer layer security wrapper (outer layer router). The ports on the outer layer router are configured for different security domains and assigned corresponding key pairs. The ports use the assigned key pairs for encrypting data packets prior to routing and decrypt the data after routing such that there is an isolation of data packets of different security domains. A routed packet arriving at the wrong port cannot be decrypted and therefore is dropped.