Secure Computing Module for COTS Processor Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current commercial-off-the-shelf (COTS) network components fail to meet the stringent security standards required for military applications, necessitating a system that provides a secure and trusted computing environment using widely available and cost-effective components.
Innovation Solution
A system incorporating a High Assurance Controller (HAC) subsystem and a Secure Computing Module (SCM) to control COTS processor resource access, enforce security partitioning, and manage secure resource access, utilizing a trusted bus switch and cryptographic engines to ensure secure communication and prevent malware infiltration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized components are employed to meet stringent military security standards, then security assurance level is improved, but cost and device complexity increase significantly
Solution Approach 1:
The system divides the computing environment into distinct security domains using a separation kernel that partitions the operating system into multiple security levels. Each partition operates with defined access rights, allowing COTS components to be used while maintaining security boundaries that meet military standards without requiring complete system redesign.
Solution Approach 2:
A separation kernel acts as an intermediary layer between COTS components and the security requirements. This kernel provides the necessary security enforcement mechanisms while allowing unmodified COTS applications to run in partitioned environments, thus avoiding the need for specialized military-grade hardware while maintaining security assurance.
2Reliability
If specialized components are used to meet military security standards, then security assurance level is improved, but cost increases due to limited market potential
Solution Approach 1:
The separation kernel provides universal security enforcement that works across multiple COTS platforms and operating systems. This multi-functional approach allows the same security mechanism to protect diverse applications and hardware configurations, enabling widespread adoption of COTS components while maintaining consistent security assurance levels.
Solution Approach 2:
The system replaces expensive specialized military components with inexpensive COTS components that can be rapidly produced and updated. The separation kernel provides the necessary security assurance without requiring costly specialized hardware, allowing for easier manufacturing and broader market availability.
3Ease of manufacture
If COTS components are used to reduce cost, then ease of manufacture and cost-effectiveness are improved, but security assurance level deteriorates
Solution Approach 1:
The system segments the execution environment into isolated partitions where COTS components can operate with defined security boundaries. The separation kernel enforces access controls between partitions, allowing cost-effective COTS components to be used while maintaining security assurance through architectural isolation rather than relying on expensive specialized hardware.
4Device complexity
If COTS components are used to reduce device complexity, then device complexity and cost are improved, but security assurance level and reliability deteriorate
Solution Approach 1:
The separation kernel serves as an intermediary that adds security enforcement capabilities to simple COTS components. Rather than requiring complex specialized hardware, the kernel provides the necessary security mediation between unmodified COTS applications and security requirements, maintaining low device complexity while achieving high security assurance levels.
Data Source
AI summary
The present invention is directed to a system for providing a trusted environment for untrusted computing systems. The system may include a HAC subsystem managing shared resources and a trusted bus switch for controlling a COTS processor to access the shared resources. The shared resources such as memory and several I/O resources reside on the trusted side of the trusted bus switch. Alternatively, the system may include a SCM as an add-on module to an untrusted host environment. Only authenticated applications including COTS OS execute on the SCM while untrusted applications execute on the untrusted host environment. The SCM may control secure resource access from the untrusted host through a plug-in module interface. All secure resources may be maintained on the trusted side of the plug-in module interface.


