Multi-Core MILS Security Zones with Global Zone Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Multiple Independent Levels of Security (MILS) systems face challenges in securely separating and protecting data with different classification levels, as they can be vulnerable to unauthorized access and are difficult to accredit and prove, while also being costly and inefficient due to the need for separate systems for each classification level.

Innovation Solution

A data security system utilizing a single multi-core processor with multiple processing cores, where each core executes a separate operating system and is assigned to a specific security zone, with a global zone acting as a traffic director and mediator between classification levels, ensuring secure data separation and integrity through encrypted communications and segregated memory partitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate systems are used for each classification level of data, then security isolation is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security zones with different classification levels into a single computer system with a multi-core processor. Each core executes a separate operating system instance for a specific security zone, allowing multiple security domains to coexist and be isolated within one integrated system rather than requiring separate physical systems for each classification level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments the single computer into multiple isolated security zones, with each zone having its own operating system instance running on a dedicated processing core. This segmentation provides strong isolation boundaries while maintaining system integration, allowing data from different classification levels to be processed securely within the same physical system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate systems are used for each classification level of data, then security isolation is improved, but cost increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent consolidates multiple security zones into a single computer system, sharing common hardware resources including the multi-core processor, memory, and I/O interfaces. This merging approach reduces the total quantity of physical systems and resources needed compared to having separate dedicated systems for each classification level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single computer system with multi-core processor performs multiple security functions simultaneously, handling data at different classification levels through different operating system instances. Each core can be assigned to different security zones as needed, providing universal functionality across multiple security domains without requiring specialized hardware for each zone.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If a single system is used for multiple classification levels, then resource efficiency is improved, but security isolation deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system divides the single computer into strongly isolated security zones, with each zone having its own operating system instance on a dedicated processing core. This segmentation maintains strict security boundaries preventing unauthorized data flow between classification levels while utilizing shared hardware resources efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a separation kernel as an intermediary layer that mediates between different security zones and the underlying hardware. The separation kernel enforces security policies, controls data flow between zones, and manages resource allocation, enabling secure multi-level operation on shared resources without compromising isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If existing MILS systems are used, then security separation is provided, but ease of accreditation and verification deteriorates

Engineering Contradiction:
Improvesecurity separationVSAvoidaccreditation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses clear segmentation into discrete security zones with dedicated processing cores and separate operating system instances, creating well-defined security boundaries that are easier to verify and accredit. Each zone can be independently analyzed and certified, simplifying the overall accreditation process compared to more complex integrated security models.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8745385B2System and method for protecting data with multiple independent levels of security
Publication Date: 2014.06.03 EVERFOX HOLDINGS LLC
  • US8745385B2 patent drawing
  • US8745385B2 patent drawing
  • US8745385B2 patent drawing

AI summary

A data security system includes a single central processing unit (CPU), a plurality of different security zones corresponding to different levels of security classification, a plurality of operating systems, a communications interface, a global zone, and a memory coupled to the plurality of security zones and the global zone. The CPU includes a plurality of processing cores and each security zone is associated with a different one of the processing cores. The global zone is communicatively coupled to the communications interface and the plurality of security zones, and is associated with a different one of the processing cores than the plurality of security zones. The global zone directs communications between the communications interface and the plurality of security zones. Each processing core executes a separate one of the plurality of operating systems, thereby providing separate processing capability on the single CPU for each of the different levels of security classification.