Secure Computing Module Isolating COTS Processors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current commercial-off-the-shelf (COTS) network components fail to meet the stringent security requirements for military multi-level applications, necessitating a system that provides a secure and trusted computing environment using widely available and cost-effective components.
Innovation Solution
A system incorporating a High Assurance Controller (HAC) subsystem and a Secure Computing Module (SCM) to control COTS processor resource access, enforce security partitioning, and manage shared resources, ensuring only authenticated applications execute on the trusted environment while untrusted applications run on an untrusted host, with stringent authentication protocols and cryptographic security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized components are employed to meet stringent military security standards, then security reliability is improved, but device complexity and cost increase
Solution Approach 1:
The system segments the computing environment into trusted and untrusted domains, with the HAC subsystem managing resource access between them. This segmentation allows COTS components to be used in the untrusted domain while maintaining security through the trusted domain boundary, resolving the contradiction between security reliability and device complexity.
Solution Approach 2:
The HAC subsystem acts as an intermediary between COTS processors and shared resources. It mediates resource access by enforcing security policies and controlling which processors can access which resources, thereby enabling COTS components to meet military security standards without requiring modifications to the components themselves.
2Ease of manufacture
If COTS components are used to reduce cost, then ease of manufacture is improved, but security reliability deteriorates
Solution Approach 1:
The system divides the computing environment into trusted and untrusted segments. COTS components operate in the untrusted segment while critical security functions are isolated in the trusted segment managed by the HAC subsystem. This segmentation enables cost-effective COTS components to be used while maintaining security reliability through proper isolation.
Solution Approach 2:
The HAC subsystem serves as an intermediary that bridges COTS components and secure resources. It provides authentication and access control mechanisms that enable COTS components to access secure resources without compromising security, thus achieving both ease of manufacture and security reliability.
3Device complexity
If COTS processors access shared resources directly, then device complexity is reduced, but security reliability deteriorates due to lack of access control
Solution Approach 1:
The HAC subsystem is introduced as an intermediary between COTS processors and shared resources. It manages access control by authenticating processors and controlling resource allocation, thereby maintaining security reliability without significantly increasing device complexity through its modular design.
Solution Approach 2:
The HAC subsystem provides multiple functions including authentication, access control, resource management, and timesharing within a single integrated component. This multi-functionality reduces the need for separate security mechanisms, thereby maintaining ease of manufacture while improving security reliability.
Data Source
AI summary
The present invention is directed to a system for providing a trusted environment for untrusted computing systems. The system may include a HAC subsystem managing shared resources and a trusted bus switch for controlling a COTS processor to access the shared resources. The shared resources such as memory and several I/O resources reside on the trusted side of the trusted bus switch. Alternatively, the system may include a SCM as an add-on module to an untrusted host environment. Only authenticated applications including COTS OS execute on the SCM while untrusted applications execute on the untrusted host environment. The SCM may control secure resource access from the untrusted host through a plug-in module interface. All secure resources may be maintained on the trusted side of the plug-in module interface.


