HRoT Device Cross-Domain Isolation via Segmented Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cross-domain solutions face limitations in providing effective isolation and security when transferring information between domains with different security measures, particularly due to unsecured network connections, which can introduce security threats.

Innovation Solution

A security system utilizing a Hardware Root of Trust (HRoT) device with dual communication channels, one for unclassified and one for classified information, enables secure communication, monitoring, and counter-attack measures, including snapshot capture, analysis, and distribution of counter-attack measures, while maintaining isolation and authenticating devices through a Trusted Platform Module (TPM).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualization technologies are used to provide isolation in cross-domain solutions, then a single computational resource can process both classified and unclassified information, but physical and logical isolation cannot be adequately provided

Engineering Contradiction:
Improveability to process both classified and unclassified informationVSAvoidphysical and logical isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system divides the computational resource into separate virtual machines (classified VM and unclassified VM) that operate independently. Each VM is assigned specific security domains and communication channels, ensuring that classified and unclassified information processing occurs in isolated segments with enforced boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security device is introduced as an intermediary component between the classified and unclassified domains. This security device enforces isolation policies, controls information flow, and monitors communications, providing the necessary physical and logical separation while allowing controlled interaction between domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If the same physical connection is used for both classified and unclassified communications, then resource utilization is improved, but security threats can be introduced through unsecured network connections

Engineering Contradiction:
Improvecomputational resource utilizationVSAvoidsecurity threats from unsecured connections
Core Design Contradiction:
Use of energy by moving objectVSObject-affected harmful factors

Solution Approach 1:

The physical connection is segmented into separate virtual communication channels through virtualization. The classified VM communicates through encrypted channels while the unclassified VM uses standard networks, allowing both to share physical infrastructure without exposing classified communications to unsecured networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security device acts as an intermediary that manages and protects the shared physical connection. It implements security policies, encrypts classified communications, and prevents unauthorized access, thereby enabling resource sharing while protecting against security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If network connectivity is provided to the security device for key management and security reporting, then communication capabilities are improved, but the device may be exposed to security attacks

Engineering Contradiction:
Improvekey management and security reporting communicationVSAvoidsecurity attacks on the security device
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security device is assigned different security qualities to different communication functions. Key management and security reporting communications are provided with appropriate network access and protection levels, while the device maintains hardened security boundaries that prevent attacks from propagating to critical functions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security device implements pre-configured security measures and monitoring capabilities that detect and respond to attacks before they can compromise the device. Security policies and protective mechanisms are established in advance to cushion against potential attacks on the networked security device.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11178159B2Cross-domain solution using network-connected hardware root-of-trust device
Publication Date: 2021.11.16 NIGHTWING GROUP LLC
  • US11178159B2 patent drawing
  • US11178159B2 patent drawing
  • US11178159B2 patent drawing

AI summary

The concepts, systems and methods described herein are directed towards a security system. The system is provided to include a Hardware Root of Trust (HRoT) device comprising a processor and memory that is configured for connection and authentication to first and second host devices which are configured to communicate via a first communication channel having a first security level and a second communication channel having a second security level which is more secure than the first security level. The HRoT device is configured to: connect the first and second host devices via the second communication channel; and monitor the security of the first and second host devices over the second communication channel.