Virtual Air Gap for Secure Cyber Range Console Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in controlling access to cyber range virtual environments while maintaining internal network security, as individuals with access to these environments may pose a threat to network security, making it difficult to balance sufficient access with utmost security measures.

Innovation Solution

A system comprising a user device, a secure console host platform, and a virtual air gap, where user authentication occurs in the virtual air gap, physically separate from the user device and cyber-range host platform, with a broker authenticating and authorizing connections between the secure console host platform and the cyber-range host platform, ensuring secure access through multiple firewalls and a virtual kill switch to prevent unauthorized access and malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individuals are granted access to the cyber range virtual environment, then sufficient cyber range access is enabled for simulating cyber-attacks and testing recovery techniques, but internal network security is compromised as these individuals may pose a threat to network security

Engineering Contradiction:
Improvecyber range accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the network into distinct segments: the internal network, the cyber range network, and a buffer zone. By segmenting the network infrastructure, users can access the cyber range while being physically isolated from the internal network, thus enabling cyber range operations without compromising internal network security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A buffer zone is introduced as an intermediary between the internal network and the cyber range network. This buffer zone contains authentication services and acts as a mediator that allows secure access to the cyber range while preventing direct access to the internal network, thereby resolving the security conflict

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a physical air gap is implemented to isolate the cyber range from the internal network, then network security is enhanced, but access control and authentication become more complex

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Authentication services are placed within the buffer zone, which acts as an intermediary that bridges the physical air gap. This allows authentication to occur without requiring physical network connectivity between the internal network and cyber range, maintaining security while simplifying access control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions from requiring physical network connectivity for authentication to using wireless authentication mechanisms. By changing the dimension of communication (from wired to wireless), the system maintains the physical air gap while enabling seamless authentication processes

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If the cyber range host platform is physically separated from the internal network, then malware spread is prevented, but console access control becomes more difficult

Engineering Contradiction:
Improvemalware spread preventionVSAvoidconsole access control
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The buffer zone serves as an intermediary that enables console access control without requiring direct physical connectivity. Authentication and authorization services in the buffer zone manage console access while the physical separation prevents malware spread, resolving the contradiction between security and operational ease

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10958670B2Processing system for providing console access to a cyber range virtual environment
Publication Date: 2021.03.23 BANK OF AMERICA CORP
  • US10958670B2 patent drawing
  • US10958670B2 patent drawing
  • US10958670B2 patent drawing

AI summary

Aspects of the disclosure relate to processing systems that generate a virtual air gap to facilitate improved techniques for establishing console access to a cyber range virtual environment. The computing platform may receive a request to generate a virtual air gap to facilitate brokering of a connection between a secure console host platform and a cyber range host platform. The computing platform may generate the virtual air gap, which may include a built-in kill switch. The computing platform may implement the virtual air gap, which may be configured to receive requests to establish a connection between the secure console host platform and the cyber range host platform and to grant the secure console host platform access to a broker. The broker may establish the connection, and the computing platform may terminate the connection in response to activation of the built-in kill switch.