Multi-Level Gate-Level Information Flow Tracking for Timing Channel Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information flow tracking methods are inadequate for detecting and preventing timing channels in embedded systems, particularly in multi-level security environments, as they are limited to two-level linear security lattices and fail to capture hardware-specific timing channels effectively.
Innovation Solution
The expansion of Gate-Level Information Flow Tracking (GLIFT) to support multi-level security lattices, allowing for the creation of a hardware design that can simulate and enforce security policies across multiple security levels, using a logic function based on the security lattice to track information flows and prevent unauthorized data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional two-level information flow tracking is used, then implementation is simpler, but it cannot detect timing channels in multi-level security systems
Solution Approach 1:
The patent segments the security tracking system into multiple independent levels (e.g., top secret, secret, confidential, unclassified) with separate tracking registers for each level. This segmentation allows the system to detect timing channels at each security level independently while maintaining overall system reliability, resolving the contradiction between detection capability and complexity.
Solution Approach 2:
The patent extends the tracking mechanism from a two-level binary system to an n-level hierarchical dimension. By adding security level as a new dimension to the tracking registers and logic, the system can simultaneously track information flows across multiple security levels, enabling timing channel detection without overwhelming complexity through systematic extension of the original framework.
2Difficulty of detecting and measuring
If Gate-Level Information Flow Tracking is expanded to multi-level security lattices, then timing channel detection improves, but hardware design complexity increases
Solution Approach 1:
The patent incorporates security level tracking registers and labeling logic directly into the hardware design at the gate level during synthesis. By performing the tracking setup in advance as part of the design process rather than adding it later, the system enables timing channel detection while managing hardware complexity through integrated rather than additive implementation.
Solution Approach 2:
The patent introduces security level labels as intermediary elements that mediate between different security domains. These labels act as intermediaries that track information flow across multiple levels without requiring direct complex interactions between all levels, simplifying the hardware design while maintaining comprehensive detection capability.
3Reliability
If strict information flow isolation is enforced, then security is improved, but system productivity decreases
Solution Approach 1:
The patent applies information flow tracking selectively at critical points in the hardware where security violations are most likely to occur, such as data transfers between security domains and timing-sensitive operations. By implementing tracking partially rather than uniformly across all operations, the system maintains strong security where needed while minimizing performance overhead in less critical paths.
Data Source
AI summary
A preferred method for providing multi-level security to a gate level information flow receives or specifies a security lattice having more than two security levels. The security lattice defines how security levels relate to each other. A hardware design implementing information flows including flows having security levels specified by the security lattice is received. Logic is created for testing the hardware design in view of the security lattice. A logic function is created based upon the hardware design and the logic for testing to implement the security lattice. Another method receives a hardware design in a hardware description language. At least a portion of the hardware design is synthesized to gate level primitives. Functional component tracking logic supporting more than two-security levels is built from the gate level primitives. Functional components in the hardware design are simulated with the functional component tracking logic.


