Cross Domain Filtration for Secure Multi-Core Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing environments face challenges in securely segregating and filtering data across multiple security domains, particularly in ensuring that data is not inadvertently exposed to incorrect destinations, which poses security risks in IoT devices and dispersed networks with varying security levels.
Innovation Solution
A cross-domain filtration and segregation system is implemented using a multicore processing unit with a Memory Management Unit (MMU) to provide unidirectional data transfer and filtering, ensuring that data originates from and is destined for the proper domains, utilizing egress and ingress filter tasks and cross-domain filter tasks to enforce security policies and maintain data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is shared between multiple domains in a computing environment, then data accessibility and processing capability are improved, but security risks and data exposure to incorrect destinations increase
Solution Approach 1:
The patent introduces a cross-domain filtration system as an intermediary component between different security domains. This filtration system acts as a mediator that inspects, validates, and controls data transfer requests between domains with different security levels, preventing unauthorized data exposure while allowing legitimate cross-domain communication to proceed
Solution Approach 2:
The patent segments the computing environment into distinct security domains with isolated memory spaces. Each domain is separated by security boundaries that prevent direct access between domains. The filtration system operates at these boundaries to control data flow, thereby maintaining security isolation while enabling managed data sharing through validated cross-domain requests
2Reliability
If cross-domain filtration and segregation systems are implemented, then data security and integrity are improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent implements self-service mechanisms where the filtration system automatically evaluates data transfer requests against predefined security policies without requiring manual intervention. The system autonomously makes decisions about data flow based on domain attributes and policy rules, reducing operational complexity while maintaining strong security controls
Solution Approach 2:
The patent establishes security policies and domain attributes in advance before data transfer occurs. The filtration system uses these pre-configured policies to automatically evaluate and approve or deny data transfer requests. By performing security checks before data exposure, the system prevents security issues rather than responding to them, reducing the complexity of real-time security management
3Object-affected harmful factors
If multiple filter tasks are implemented for cross-domain data transfer, then data security is improved, but processing time and system resource consumption increase
Solution Approach 1:
The patent implements a hierarchical filtration approach where different levels of filtering are applied selectively based on the security requirements of the data and domains involved. Not all data transfers require the full spectrum of filter tasks, allowing the system to use partial filtering for lower-risk transfers and reserve comprehensive filtering for high-security domains, thereby reducing unnecessary processing time
Data Source
AI summary
A computing device with a multicore processing unit and a memory management unit (MMU) may provide multi-order failure resistant data isolation and segregation with a cross domain filtration system. The multicore processing unit may include a first processor, a second processor, and a third processor. A first processor may process data via an egress filter task(s). The MMU may allow the egress filter task(s) to write the data to a first segregated physical memory location. A second processor may perform filtering of the data via a cross domain filter task(s). The MMU may allow the cross domain filter task(s) to read from the first segregated physical memory location and write to a second segregated physical memory location. A third processor may process the data via an ingress filter task(s). The MMU may allow the ingress filter task(s) to read the data from the second segregated physical memory location.


