FPGA Soft-Core Security Domain Separation Gate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for processing data across different security domains are costly, lack compactness, and are inefficient in enforcing Mandatory Access Control (MAC) to prevent unauthorized access and malicious data transmission.

Innovation Solution

A system utilizing a field-programmable gate array (FPGA) with embedded soft-core processors and a security domain separation gate to segregate and control data flow between security domains, ensuring that only compliant data is transmitted between domains, thereby enforcing MAC and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate computers with data diodes are used to enforce MAC between security domains, then security control is improved, but system cost and complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security domains and their separation gates into a single FPGA device. The FPGA integrates the security domain separation gate that enforces MAC between different classification levels (e.g., top-secret, secret, unclassified) within one hardware platform, eliminating the need for separate computers and data diodes while maintaining security control

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The FPGA serves multiple functions simultaneously: it acts as the processing platform, the security domain separator, and the MAC enforcement mechanism. The security domain separation gate within the FPGA provides universal MAC control for all data flows between different security domains, replacing multiple dedicated security devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate computers with data diodes are used to enforce MAC, then security control is improved, but device compactness deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem compactness
Core Design Contradiction:
ReliabilityVSVolume of moving object

Solution Approach 1:

The patent combines multiple security domains and separation gates into a single compact FPGA device. The integrated security domain separation gate enforces MAC between different classification levels within one hardware platform, dramatically reducing the physical footprint compared to using separate computers and data diodes

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If data diodes are used to allow unidirectional data flow, then security control is improved, but adaptability deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoiddata flow flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security domain separation gate in the FPGA provides dynamic control of data flow between security domains. Rather than fixed unidirectional data diodes, the system can adaptively configure data flow paths based on classification levels and security policies, allowing flexible bidirectional communication when authorized while maintaining security control

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9971910B2Multi-level security domain separation using soft-core processor embedded in an FPGA
Publication Date: 2018.05.15 RAYTHEON CO
  • US9971910B2 patent drawing
  • US9971910B2 patent drawing
  • US9971910B2 patent drawing

AI summary

A system and method for operating multiple security domains on one circuit card assembly, using a field-programmable gate array (FPGA) with an embedded security domain separation gate providing the MAC between multiple soft-core CPUs also embedded in the FPGA. In one embodiment, the FPGA is segregated into two or more security domains with no data paths between soft-core CPUs in each security domain except through the security domain separation gate. The security domain separation gate applies rules to any information to be transmitted between the security domains to avoid transmission of malicious content and to avoid transmission of information of a certain classification level or type to a security domain at a lower classification level or type.