Wide Area Network Access Management Computer for Classified IP Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dynamic operational environments, there is a need to securely connect classified computers to IP networks while preventing inadvertent disclosure of sensitive information, as connecting these devices to acquire or manage IP network access is against security policy.

Innovation Solution

A wide area network access management computer that enables classified computers secured by a NSA HAIPE device to communicate over IP networks by interfacing between the NSA HAIPE device and the IP network, using various connectivity options and protocols, allowing secure access without direct connection to the public IP network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a classified computer connects directly to the IP network to acquire or manage network access, then network access capability is improved, but security policy compliance deteriorates due to potential inadvertent disclosure of sensitive information

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an unclassified computer as an intermediary device between the classified computer and the IP network. This intermediary handles all network access functions including acquiring network access, configuring connection parameters, and managing communication protocols. The classified computer remains isolated from direct network exposure while the intermediary performs all necessary network interactions, thus maintaining both network access capability and security policy compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a classified computer is isolated from the IP network to maintain security, then security policy compliance is improved, but network connectivity deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork connectivity
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system segments the computing environment into distinct security zones: a classified computer isolated in a secure zone, an unclassified intermediary computer in a transition zone, and the public IP network in an unsecured zone. This segmentation allows the classified computer to maintain its security isolation while the intermediary computer handles all network-facing functions, effectively bridging the gap between security requirements and network connectivity needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unclassified computer serves as a mediator that enables network connectivity for the isolated classified computer. It performs all necessary network functions including obtaining network access, configuring connection parameters, and managing communication protocols. The classified computer achieves network connectivity indirectly through this intermediary without ever directly exposing itself to the IP network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If an intermediary computer is introduced to enable secure network access, then security policy compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The unclassified intermediary computer is configured to autonomously perform all network access functions without requiring manual intervention or complex configuration from the classified computer side. It automatically acquires network access, configures connection parameters, and manages communication protocols. This self-service capability simplifies the overall system operation despite the added architectural layer, as the intermediary handles complexity internally while presenting a simple interface to the classified computer.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9485277B2Wide area network access management computer
Publication Date: 2016.11.01 SIGMA DEFENSE SYST LLC
  • US9485277B2 patent drawing
  • US9485277B2 patent drawing
  • US9485277B2 patent drawing

AI summary

A system and method for connecting a classified internet protocol (IP) network to a public IP network including an unclassified computing device. The unclassified computing device is a wide area network access management computer which directly connects to a National Security Agency (NSA) High Assurance Internet Protocol Encryptor (HAIPE) device and interfaces between the IP network and the classified IP network. The wide area network access management computer includes a graphical user interface, an internal data network communications interface, an external data network communications interface and a processing unit. The processing unit operates the network interfaces and presents information to the graphical user interface and interprets user input from the graphical user interface. The processing unit also performs the processing and protocols associated with the internal and external networks, performs client processing and allows the user to interact with services on any of the attached networks.