Persona Switcher for Multi-Level Security Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In tactical environments, devices require multiple security domains and classification levels, but conventional systems struggle to protect against software security threats, especially zero-day vulnerabilities, and fail to allow easy switching between classification levels without hard drive changes, leading to potential data breaches and system downtime.

Innovation Solution

The Shielder system implements minimal system storage partitioning and a software shield with persona switching capabilities, allowing secure and efficient switching between multiple security classifications by reconfiguring hardware and software resources using cryptographic keys, and providing real-time threat detection and rollback to a known good state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple operating systems are implemented on the same device for different security domains, then security classification versatility is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity classification versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides the computing device into multiple isolated personas, each representing a distinct security domain with its own operating system and classification level. Each persona is cryptographically partitioned and independently managed, allowing multiple security classifications to coexist on the same hardware without requiring complex configuration of the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A persona manager component acts as an intermediary that handles persona selection, credential verification, and resource allocation. This mediator abstracts the complexity of managing multiple operating systems, providing a unified interface for users to switch between security domains while the underlying cryptographic partitioning and resource management are handled automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional security protection mechanisms are implemented, then protection against known threats is improved, but response capability to zero-day vulnerabilities deteriorates

Engineering Contradiction:
Improveprotection against known threatsVSAvoidresponse capability to zero-day vulnerabilities
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by creating cryptographic partitions and system snapshots before potential attacks occur. Each persona is pre-configured with its own cryptographic keys and isolated environment, and regular snapshots are taken of system states. When a zero-day vulnerability is detected, the system can immediately restore from a pre-taken snapshot, preventing the vulnerability from affecting the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cryptographic partitioning and persona isolation create a protective cushion against attacks. By isolating each security domain with strong cryptographic boundaries and maintaining ready-to-restore snapshots, the system cushions itself against the impact of zero-day vulnerabilities, allowing rapid recovery without extensive analysis or patching time.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If hard drive switching is used to change classification levels, then security isolation is improved, but switching time and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity isolationVSAvoidswitching time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system merges multiple operating systems and security domains into a single hardware platform, with each persona sharing the underlying hard drive through cryptographic partitioning. This consolidation eliminates the need for physical hard drive switching while maintaining security isolation through software-based cryptographic boundaries and on-demand encryption/decryption of persona-specific data.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If resource allocation is optimized for single persona operation, then processing efficiency is improved, but adaptability to different security domains deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidadaptability to different security domains
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system dynamically allocates hardware resources to different personas based on which persona is currently active. The persona manager monitors system state and reallocates processing power, memory, and I/O resources as needed when switching between personas. This dynamic resource management maintains high processing efficiency for the active persona while preserving the ability to adapt to different security domains through rapid persona switching.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11675889B1Systems and methods for data integrity and confidentiality within a computing system
Publication Date: 2023.06.13 ARCHITECTURE TECH CORP
  • US11675889B1 patent drawing
  • US11675889B1 patent drawing
  • US11675889B1 patent drawing

AI summary

Disclosed herein are embodiments of systems, methods, and products comprise a computing device, which allows a device to be used in different classification levels by powering the device down and booting to a different classified level without the need to switch hard drives. The disclosed software shield and persona switcher (Shielder) module provides independent application environments (personas) for separate security domains while allowing fast transition between personas. Shielder module supports multiple security classification via a minimal system storage partitioning. Shielder module allows efficient collection and reallocation of memory and persistent storage according to need and priority. Shielder module provides secure management of communication media by directing the system communication according to the security profile of the active persona.