Separate GPUs for MILS Security Domain Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Multiple Independent Levels of Security (MILS) systems face security vulnerabilities due to shared graphics processing units (GPUs) across different security domains, leading to potential malicious interactions and increased testing costs and time.
Innovation Solution
Implementing separate GPUs and associated memory for each security domain, along with a separation kernel to isolate access and prevent covert channels, allowing individual application windows from each domain to be displayed on a single monitor in a flexible manner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If a single GPU is shared between multiple security domains, then resource utilization is improved, but security vulnerability increases due to potential covert channels
Solution Approach 1:
The patent divides the single shared GPU into multiple separate GPUs, with each GPU dedicated to a specific security domain. This segmentation eliminates the covert channels that arise from shared resource access while still allowing multiple domains to coexist on the same physical platform. Each domain has its own isolated GPU, preventing malicious interactions through the graphics processing unit.
2Object-affected harmful factors
If separate GPUs are provided for each security domain, then security isolation is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple separate GPUs into a unified system where each GPU is dedicated to a specific security domain but all GPUs operate under a single host system. This combining approach provides security isolation through separate GPU instances while avoiding the complexity of completely independent systems, as the GPUs share common memory spaces and control mechanisms through the host.
3Reliability
If extensive testing is performed to ensure security between domains, then reliability is improved, but production time and cost increase
Solution Approach 1:
The patent introduces a host system as an intermediary that manages multiple security domains with separate GPUs. The host provides a controlled environment where domains are isolated through separate GPU instances, eliminating the need for extensive pairwise testing between domains. The host acts as a mediator that ensures security isolation is built-in through the architecture rather than verified through extensive testing.
Data Source
AI summary
A system and method is provided to permit a first computer to interact with computers in different security domains without forming covert channels. Separate GPUs are provided for each computer. An image routing map (IRM) determines which security domain is the subject of an I/O event to determine to which security domain to send the I/O event. A response is transmitted to the associated GPU and multiplexor and another response used to update the IRM, which is then provided to the MUX. The MUX uses the updated IRM to adjust the content on the monitor. Content from the security domains are able to be displayed on the monitor and in a similar manner as by the computer in each security domain.


