Cross-Domain Solution Architecture with Formally Verified Microkernel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Cross-Domain Solutions (CDS) in military information systems lack formal verification, leading to untrustworthy data confidentiality protection, restricted accessibility, and limited deployability, particularly due to expensive and specialized hardware, which hinders secure data transfer across differing security domains.
Innovation Solution
A CDS architecture utilizing a formally verified microkernel and hardware-based Trusted Execution Environment (TEE) within a single host, incorporating data diodes for unidirectional data flow and a guard for additional security, ensuring immutable communication channels and remote deployability on commodity hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If formally verified microkernel and TEE are used to ensure data confidentiality, then trustworthiness is improved, but device complexity increases
Solution Approach 1:
A formally verified microkernel serves as an intermediary layer between the TEE and security domains, providing mathematically proven trust boundaries that manage data flow while maintaining system complexity at acceptable levels through abstraction
2Reliability
If specialized hardware is used for secure data transfer, then data confidentiality protection is improved, but accessibility deteriorates
Solution Approach 1:
The TEE architecture provides universal security functionality that can be deployed across commodity hardware platforms, enabling secure cross-domain data transfer without requiring specialized hardware for each deployment scenario
3Reliability
If expensive specialized hardware is used for CDS, then security is improved, but deployability deteriorates
Solution Approach 1:
The solution replaces expensive specialized hardware with commodity hardware running a formally verified microkernel in TEE, achieving equivalent security through software-based trust boundaries that can be deployed on standard, cost-effective platforms
4Reliability
If data diodes are used for unidirectional data flow control, then data confidentiality is improved, but information flow capability deteriorates
Solution Approach 1:
Data flow is segmented into unidirectional channels through data diodes, with separate pathways for different security domains, allowing confidential information to flow securely in controlled directions while maintaining overall system information exchange capabilities
Data Source
AI summary
A cross-domain solution architecture includes a higher-security domain and a lower-security domain. The higher-security domain (i) processes data on a higher-security level, and (ii) includes a hardware-based trusted executed environment (TEE) running a formally verified microkernel. The lower-security domain (i) processes data on a lower-security level having lower security than the higher-security level, and (ii) includes a trusted computer base (TCB). The TCB operates in the higher-security domain and the lower-security domain to pass data from the lower-security domain to the higher-security domain through a first data diode, and to pass data from the higher-security domain to the lower-security domain through a second data diode.


