Multi-Level Network Security via Virtual Host Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems lack the capability to support multiple security levels over shared networks, necessitating complex and costly hardware and software solutions, which is particularly challenging in the transportation industry where software applications have varying safety criticality and security levels.
Innovation Solution
A system and method that utilize a node with a protected address space and protocol stack to route and process packets with unencrypted data, allowing for multi-level security by isolating data within virtual hosts with unique IP addresses and separate memory allocations, eliminating the need for dedicated hardware resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware and software encryption techniques are used to ensure security, then confidentiality and integrity of electronic data are improved, but device complexity and cost increase
Solution Approach 1:
The patent segments the network into multiple virtual networks, each with its own security level. The network stack is divided into virtual network stacks that are isolated from each other, allowing different security policies to be applied to different segments without affecting the entire system.
Solution Approach 2:
The patent introduces a new dimension of security by implementing multi-level security through virtualization. Instead of relying solely on encryption at the data level, it creates multiple layers of network abstraction (virtual network stacks) that provide security at the network protocol level, adding a dimensional approach to security rather than just point-to-point encryption.
2Reliability
If multiple dedicated hardware resources are allocated to support multiple security levels, then security isolation is improved, but device complexity and cost increase
Solution Approach 1:
The patent merges multiple security levels into a single physical network infrastructure by using virtualization. Multiple virtual network stacks share the same physical network interface and hardware resources, eliminating the need for separate dedicated hardware for each security level while maintaining security isolation through software-based virtualization boundaries.
Solution Approach 2:
The patent makes the network interface and hardware resources universal by allowing them to serve multiple security levels simultaneously. The single network interface can handle traffic for multiple virtual networks with different security requirements, making the hardware multi-functional rather than dedicated to a single security level.
3Reliability
If multiple dedicated software applications and resources are used for different security levels, then security level isolation is improved, but device complexity increases
Solution Approach 1:
The patent segments the software architecture into multiple virtual network stacks, each handling a specific security level. This segmentation allows different security policies and protocols to be implemented in separate software layers while sharing common underlying hardware resources.
Solution Approach 2:
The patent introduces virtual network stacks as intermediary layers between the application layer and the physical network interface. These virtual stacks act as mediators that translate and route traffic between different security levels, providing security isolation without requiring direct dedicated hardware for each application.
4Reliability
If encryption is applied to all data on the network, then confidentiality is improved, but processing overhead and productivity decrease
Solution Approach 1:
The patent applies security measures locally to specific virtual networks and traffic flows rather than encrypting all data uniformly. Each virtual network stack can apply encryption and security protocols only to the traffic that requires it, leaving other traffic to be processed more efficiently without encryption overhead.
Solution Approach 2:
The patent changes the security parameter from uniform encryption of all data to selective security application based on virtual network classification. By modifying the security parameter to be variable rather than constant, the system can adjust the level of security and processing overhead based on the specific requirements of each virtual network.
Data Source
AI summary
A method of communicating information in a system having multi-level security requirements includes receiving a packet having unencrypted data, routing the packet to a host, and processing the packet at the host such that data from the packet is maintained in the protected address space associated with the host. The host includes a number of virtual hosts, each having a unique internet protocol (IP) address, a protected address space, and a protocol stack.


