Partitioning Communication System Using Separation Kernel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems face challenges in achieving high security assurance levels due to the presence of covert channels, which can lead to illicit information flows and degrade system performance, and physical separation methods are costly and cumbersome.

Innovation Solution

A Partitioning Communication System (PCS) that uses a separation kernel to partition nodes and control inter-node communications, enforcing security policies through channel connectivity and resource management policies, and employing cryptography for confidentiality, while managing resources to prevent illicit flows and covert channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical separation methods are used to prevent covert channels, then security assurance level is improved, but system cost and complexity increase

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the communication system into multiple partitions, each with its own communication channels. The separation kernel enforces partition boundaries to prevent covert channels, achieving security through logical segmentation rather than physical separation. This reduces system complexity while maintaining high security assurance levels.

Inventive Principle:
Principle #1Segmentation

2Reliability

If covert channels are closed by clearing cache storage and assigning fixed CPU time quanta, then security assurance level is improved, but system performance degrades

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments communication channels into partition-specific channels enforced by a separation kernel. This prevents covert channels by design rather than through performance-degrading workarounds like cache clearing or fixed CPU time quanta. The segmented architecture maintains system performance while achieving high security assurance levels.

Inventive Principle:
Principle #1Segmentation

3Reliability

If resource sharing is avoided to eliminate covert channels, then security assurance level is improved, but system efficiency and resource utilization decrease

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a separation kernel as an intermediary that manages resource sharing between partitions. The kernel enforces partition boundaries and controls access to shared resources, eliminating covert channels while maintaining efficient resource utilization. This intermediary approach allows secure resource sharing without degrading system efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7474618B2Partitioning communication system
Publication Date: 2009.01.06 OBJECTIVE INTERFACE SYSTEMS
  • US7474618B2 patent drawing
  • US7474618B2 patent drawing
  • US7474618B2 patent drawing

AI summary

A system and method for communicating data between two nodes defines a plurality of separate partitions on each node and assigns one or more subjects to at least one of the plurality of the separate partitions. The subjects in each node communicate data with each other over one or more channels. For communicating the data, the present invention separates data communications on a channel from that of other channels. More specifically, each node runs under the control of a separation kernel (SK) that partitions the nodes to define the subjects according to an SK configuration data. A partitioning communication system (PCS) separates the communications channels according to a PCS configuration data.