Partitioning Communication System Using Separation Kernel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems face challenges in achieving high security assurance levels due to the presence of covert channels, which can lead to illicit information flows and degrade system performance, and physical separation methods are costly and cumbersome.
Innovation Solution
A Partitioning Communication System (PCS) that uses a separation kernel to partition nodes and control inter-node communications, enforcing security policies through channel connectivity and resource management policies, and employing cryptography for confidentiality, while managing resources to prevent illicit flows and covert channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical separation methods are used to prevent covert channels, then security assurance level is improved, but system cost and complexity increase
Solution Approach 1:
The patent applies segmentation by dividing the communication system into multiple partitions, each with its own communication channels. The separation kernel enforces partition boundaries to prevent covert channels, achieving security through logical segmentation rather than physical separation. This reduces system complexity while maintaining high security assurance levels.
2Reliability
If covert channels are closed by clearing cache storage and assigning fixed CPU time quanta, then security assurance level is improved, but system performance degrades
Solution Approach 1:
The patent segments communication channels into partition-specific channels enforced by a separation kernel. This prevents covert channels by design rather than through performance-degrading workarounds like cache clearing or fixed CPU time quanta. The segmented architecture maintains system performance while achieving high security assurance levels.
3Reliability
If resource sharing is avoided to eliminate covert channels, then security assurance level is improved, but system efficiency and resource utilization decrease
Solution Approach 1:
The patent introduces a separation kernel as an intermediary that manages resource sharing between partitions. The kernel enforces partition boundaries and controls access to shared resources, eliminating covert channels while maintaining efficient resource utilization. This intermediary approach allows secure resource sharing without degrading system efficiency.
Data Source
AI summary
A system and method for communicating data between two nodes defines a plurality of separate partitions on each node and assigns one or more subjects to at least one of the plurality of the separate partitions. The subjects in each node communicate data with each other over one or more channels. For communicating the data, the present invention separates data communications on a channel from that of other channels. More specifically, each node runs under the control of a separation kernel (SK) that partitions the nodes to define the subjects according to an SK configuration data. A partitioning communication system (PCS) separates the communications channels according to a PCS configuration data.


