Cross-Domain Validators for One-Way Secure Data Flow
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cross-domain solutions (CDS) face limitations in enabling seamless, secure information flow and user interaction across multiple security domains while maintaining strict isolation and compliance with mandatory security policies, particularly in systems like field programmable gate arrays (FPGA) and application-specific integrated circuits (ASIC).
Innovation Solution
A Monitoring and Inspection Device (MIND) system incorporating two classes of validators, including domain-specific and stateful cross-domain validators, implements secure protocol parsers using LangSec tools to ensure high-assurance, one-way information flow and context tracking, leveraging hardware and software combinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional cross-domain solutions are used to enable information flow between security domains, then information transfer capability is improved, but security isolation and compliance with mandatory security policies deteriorate
Solution Approach 1:
The patent introduces a guard CDS as an intermediary component that mediates information flow between security domains. The guard parser acts as a mediator that validates and controls data packets crossing domain boundaries, ensuring that information transfer occurs only through approved channels while maintaining security isolation. This resolves the contradiction by providing a controlled pathway that enables productivity without compromising reliability.
Solution Approach 2:
The system segments the cross-domain communication function into distinct components: domain-specific validators for individual domain rules, cross-domain validators for inter-domain policy enforcement, and guard CDS for boundary control. This segmentation allows each component to specialize in specific security aspects, enabling comprehensive security isolation while maintaining information transfer capability through coordinated operation of segmented components.
2Reliability
If strict isolation between security domains is maintained, then security compliance is improved, but user interaction capability across domains deteriorates
Solution Approach 1:
The guard CDS is designed as a universal component that handles multiple security domain interactions through a single interface. It provides multi-functional capabilities including parsing, validation, and policy enforcement across different domains, allowing users to interact with multiple domains from a single computer while maintaining security compliance. This resolves the contradiction by providing universal access points that simplify user operation without compromising security isolation.
3Reliability
If guard CDS is deployed at the edge of physical networks to control information flow, then security policy enforcement is improved, but system complexity and deployment difficulty deteriorate
Solution Approach 1:
The guard parser is designed with self-service capabilities including automatic protocol specification parsing, automated grammar generation from LangSec specifications, and self-configuration through formal proofs. This reduces deployment complexity by eliminating manual configuration steps and enabling the system to automatically enforce security policies based on provided specifications, resolving the contradiction between strong policy enforcement and simple deployment.
4Reliability
If formal proofs and LangSec tools are used to generate secure parsers, then parser security and accuracy are improved, but development time and computational resources deteriorate
Solution Approach 1:
The system performs preliminary actions by pre-defining protocol specifications and security policies in formal languages before parser generation. LangSec tools use these pre-defined specifications to automatically generate proven correct parsers, eliminating the need for time-consuming manual parser development and testing. This resolves the contradiction by shifting the time investment to the specification phase, where changes are less costly, while enabling rapid generation of secure parsers through automated tools.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A secure communication path device includes a first secure communication validator (Validator A) providing a one-way communication path (130A) from a security domain (240) by implementing a secure protocol parser (122, 123, 124, 125, 126), a second secure communication validator (Validator B) providing a one-way communication path (130B) from a second security domain (242) by implementing a secure second protocol parser. Each validator including respective serial/de-serializer units (212, 214, 216, 218) providing a unidirectional communication path from their respective security domain. The device hardware segregating respective communications of the security domains within the secure communication path device.