Cross-Domain Solution Architecture with Formally Verified Microkernel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Cross-Domain Solutions (CDS) in military information systems lack formal verification, leading to untrustworthy data confidentiality protection, restricted accessibility, and limited deployability, particularly due to expensive and specialized hardware, which hinders secure data transfer across differing security domains.

Innovation Solution

A CDS architecture utilizing a formally verified microkernel and hardware-based Trusted Execution Environment (TEE) within a single host, incorporating data diodes for unidirectional data flow and a guard for additional security, ensuring immutable communication channels and remote deployability on commodity hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If formally verified microkernel and TEE are used to ensure data confidentiality, then trustworthiness is improved, but device complexity increases

Engineering Contradiction:
ImprovetrustworthinessVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A formally verified microkernel serves as an intermediary layer between the TEE and security domains, providing mathematically proven trust boundaries that manage data flow while maintaining system complexity at acceptable levels through abstraction

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If specialized hardware is used for secure data transfer, then data confidentiality protection is improved, but accessibility deteriorates

Engineering Contradiction:
Improvedata confidentiality protectionVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The TEE architecture provides universal security functionality that can be deployed across commodity hardware platforms, enabling secure cross-domain data transfer without requiring specialized hardware for each deployment scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If expensive specialized hardware is used for CDS, then security is improved, but deployability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddeployability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The solution replaces expensive specialized hardware with commodity hardware running a formally verified microkernel in TEE, achieving equivalent security through software-based trust boundaries that can be deployed on standard, cost-effective platforms

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If data diodes are used for unidirectional data flow control, then data confidentiality is improved, but information flow capability deteriorates

Engineering Contradiction:
Improvedata confidentialityVSAvoidinformation flow capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Data flow is segmented into unidirectional channels through data diodes, with separate pathways for different security domains, allowing confidential information to flow securely in controlled directions while maintaining overall system information exchange capabilities

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240086554A1Cross-domain solution architecture
Publication Date: 2024.03.14 THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
  • US20240086554A1 patent drawing
  • US20240086554A1 patent drawing
  • US20240086554A1 patent drawing

AI summary

A cross-domain solution architecture includes a higher-security domain and a lower-security domain. The higher-security domain (i) processes data on a higher-security level, and (ii) includes a hardware-based trusted executed environment (TEE) running a formally verified microkernel. The lower-security domain (i) processes data on a lower-security level having lower security than the higher-security level, and (ii) includes a trusted computer base (TCB). The TCB operates in the higher-security domain and the lower-security domain to pass data from the lower-security domain to the higher-security domain through a first data diode, and to pass data from the higher-security domain to the lower-security domain through a second data diode.