Secure Computing Module for COTS Processor Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current commercial-off-the-shelf (COTS) network components fail to meet the stringent security standards required for military applications, necessitating a system that provides a secure and trusted computing environment using widely available and cost-effective components.

Innovation Solution

A system incorporating a High Assurance Controller (HAC) subsystem and a Secure Computing Module (SCM) to control COTS processor resource access, enforce security partitioning, and manage secure resource access, utilizing a trusted bus switch and cryptographic engines to ensure secure communication and prevent malware infiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized components are employed to meet stringent military security standards, then security assurance level is improved, but cost and device complexity increase significantly

Engineering Contradiction:
Improvesecurity assurance levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the computing environment into distinct security domains using a separation kernel that partitions the operating system into multiple security levels. Each partition operates with defined access rights, allowing COTS components to be used while maintaining security boundaries that meet military standards without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A separation kernel acts as an intermediary layer between COTS components and the security requirements. This kernel provides the necessary security enforcement mechanisms while allowing unmodified COTS applications to run in partitioned environments, thus avoiding the need for specialized military-grade hardware while maintaining security assurance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If specialized components are used to meet military security standards, then security assurance level is improved, but cost increases due to limited market potential

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The separation kernel provides universal security enforcement that works across multiple COTS platforms and operating systems. This multi-functional approach allows the same security mechanism to protect diverse applications and hardware configurations, enabling widespread adoption of COTS components while maintaining consistent security assurance levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system replaces expensive specialized military components with inexpensive COTS components that can be rapidly produced and updated. The separation kernel provides the necessary security assurance without requiring costly specialized hardware, allowing for easier manufacturing and broader market availability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of manufacture

If COTS components are used to reduce cost, then ease of manufacture and cost-effectiveness are improved, but security assurance level deteriorates

Engineering Contradiction:
Improvecost-effectivenessVSAvoidsecurity assurance level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system segments the execution environment into isolated partitions where COTS components can operate with defined security boundaries. The separation kernel enforces access controls between partitions, allowing cost-effective COTS components to be used while maintaining security assurance through architectural isolation rather than relying on expensive specialized hardware.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If COTS components are used to reduce device complexity, then device complexity and cost are improved, but security assurance level and reliability deteriorate

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity assurance level
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The separation kernel serves as an intermediary that adds security enforcement capabilities to simple COTS components. Rather than requiring complex specialized hardware, the kernel provides the necessary security mediation between unmodified COTS applications and security requirements, maintaining low device complexity while achieving high security assurance levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7716720B1System for providing secure and trusted computing environments
Publication Date: 2010.05.11 ROCKWELL COLLINS INC
  • US7716720B1 patent drawing
  • US7716720B1 patent drawing
  • US7716720B1 patent drawing

AI summary

The present invention is directed to a system for providing a trusted environment for untrusted computing systems. The system may include a HAC subsystem managing shared resources and a trusted bus switch for controlling a COTS processor to access the shared resources. The shared resources such as memory and several I/O resources reside on the trusted side of the trusted bus switch. Alternatively, the system may include a SCM as an add-on module to an untrusted host environment. Only authenticated applications including COTS OS execute on the SCM while untrusted applications execute on the untrusted host environment. The SCM may control secure resource access from the untrusted host through a plug-in module interface. All secure resources may be maintained on the trusted side of the plug-in module interface.