Multi-Level Network Security via Virtual Host Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack the capability to support multiple security levels over shared networks, necessitating complex and costly hardware and software solutions, which is particularly challenging in the transportation industry where software applications have varying safety criticality and security levels.

Innovation Solution

A system and method that utilize a node with a protected address space and protocol stack to route and process packets with unencrypted data, allowing for multi-level security by isolating data within virtual hosts with unique IP addresses and separate memory allocations, eliminating the need for dedicated hardware resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware and software encryption techniques are used to ensure security, then confidentiality and integrity of electronic data are improved, but device complexity and cost increase

Engineering Contradiction:
Improveconfidentiality and integrity of electronic dataVSAvoidcomplexity of hardware and software solutions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple virtual networks, each with its own security level. The network stack is divided into virtual network stacks that are isolated from each other, allowing different security policies to be applied to different segments without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of security by implementing multi-level security through virtualization. Instead of relying solely on encryption at the data level, it creates multiple layers of network abstraction (virtual network stacks) that provide security at the network protocol level, adding a dimensional approach to security rather than just point-to-point encryption.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple dedicated hardware resources are allocated to support multiple security levels, then security isolation is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidnumber of hardware components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security levels into a single physical network infrastructure by using virtualization. Multiple virtual network stacks share the same physical network interface and hardware resources, eliminating the need for separate dedicated hardware for each security level while maintaining security isolation through software-based virtualization boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the network interface and hardware resources universal by allowing them to serve multiple security levels simultaneously. The single network interface can handle traffic for multiple virtual networks with different security requirements, making the hardware multi-functional rather than dedicated to a single security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple dedicated software applications and resources are used for different security levels, then security level isolation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity level isolationVSAvoidnumber of software components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the software architecture into multiple virtual network stacks, each handling a specific security level. This segmentation allows different security policies and protocols to be implemented in separate software layers while sharing common underlying hardware resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network stacks as intermediary layers between the application layer and the physical network interface. These virtual stacks act as mediators that translate and route traffic between different security levels, providing security isolation without requiring direct dedicated hardware for each application.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If encryption is applied to all data on the network, then confidentiality is improved, but processing overhead and productivity decrease

Engineering Contradiction:
Improveconfidentiality of dataVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies security measures locally to specific virtual networks and traffic flows rather than encrypting all data uniformly. Each virtual network stack can apply encryption and security protocols only to the traffic that requires it, leaving other traffic to be processed more efficiently without encryption overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameter from uniform encryption of all data to selective security application based on virtual network classification. By modifying the security parameter to be variable rather than constant, the system can adjust the level of security and processing overhead based on the specific requirements of each virtual network.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7607011B1System and method for multi-level security on a network
Publication Date: 2009.10.20 ROCKWELL COLLINS INC
  • US7607011B1 patent drawing
  • US7607011B1 patent drawing
  • US7607011B1 patent drawing

AI summary

A method of communicating information in a system having multi-level security requirements includes receiving a packet having unencrypted data, routing the packet to a host, and processing the packet at the host such that data from the packet is maintained in the protected address space associated with the host. The host includes a number of virtual hosts, each having a unique internet protocol (IP) address, a protected address space, and a protocol stack.