Separate GPUs for MILS Security Domain Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Multiple Independent Levels of Security (MILS) systems face security vulnerabilities due to shared graphics processing units (GPUs) across different security domains, leading to potential malicious interactions and increased testing costs and time.

Innovation Solution

Implementing separate GPUs and associated memory for each security domain, along with a separation kernel to isolate access and prevent covert channels, allowing individual application windows from each domain to be displayed on a single monitor in a flexible manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If a single GPU is shared between multiple security domains, then resource utilization is improved, but security vulnerability increases due to potential covert channels

Engineering Contradiction:
ImproveGPU resource sharingVSAvoidcovert channels
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent divides the single shared GPU into multiple separate GPUs, with each GPU dedicated to a specific security domain. This segmentation eliminates the covert channels that arise from shared resource access while still allowing multiple domains to coexist on the same physical platform. Each domain has its own isolated GPU, preventing malicious interactions through the graphics processing unit.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If separate GPUs are provided for each security domain, then security isolation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidmultiple GPUs per domain
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges multiple separate GPUs into a unified system where each GPU is dedicated to a specific security domain but all GPUs operate under a single host system. This combining approach provides security isolation through separate GPU instances while avoiding the complexity of completely independent systems, as the GPUs share common memory spaces and control mechanisms through the host.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If extensive testing is performed to ensure security between domains, then reliability is improved, but production time and cost increase

Engineering Contradiction:
Improvesecurity between domainsVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a host system as an intermediary that manages multiple security domains with separate GPUs. The host provides a controlled environment where domains are isolated through separate GPU instances, eliminating the need for extensive pairwise testing between domains. The host acts as a mediator that ensures security isolation is built-in through the architecture rather than verified through extensive testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9715599B2Context aware integrated display keyboard video mouse controller
Publication Date: 2017.07.25 RAYTHEON CO
  • US9715599B2 patent drawing
  • US9715599B2 patent drawing
  • US9715599B2 patent drawing

AI summary

A system and method is provided to permit a first computer to interact with computers in different security domains without forming covert channels. Separate GPUs are provided for each computer. An image routing map (IRM) determines which security domain is the subject of an I/O event to determine to which security domain to send the I/O event. A response is transmitted to the associated GPU and multiplexor and another response used to update the IRM, which is then provided to the MUX. The MUX uses the updated IRM to adjust the content on the monitor. Content from the security domains are able to be displayed on the monitor and in a similar manner as by the computer in each security domain.