Shared Memory Isolation for Cross-Domain Secure Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for managing data transfers between domains with varying security clearances are inefficient, time-consuming, and prone to electrostatic discharge, limiting data flow and increasing manual intervention, especially when transferring sensitive data.
Innovation Solution
A hardware configuration using SAS expanders and HBA cards to connect unclassified and classified domains to a shared memory, with write-blocking for classified data and read/write access for unclassified data, along with programmable circuitry for data access and change detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual data transfer methods are used between domains with different security clearances, then data security can be maintained, but data transfer efficiency is reduced and manual intervention is increased
Solution Approach 1:
A shared memory device is introduced as an intermediary between the unclassified domain and classified domain. The unclassified domain writes data to the shared memory, and the classified domain reads from it, eliminating the need for manual data transfer while maintaining security through controlled access paths.
Solution Approach 2:
The system segments data transfer operations into distinct write and read paths. The unclassified domain has write-only access to prevent unauthorized writing of classified data, while the classified domain has read-only access to prevent unauthorized reading of unclassified data, allowing automated high-volume transfers while maintaining security.
2Reliability
If disconnected hardware configurations are used to prevent electrostatic discharge, then data security is improved, but connection stability and data flow are reduced
Solution Approach 1:
The shared memory device serves as an intermediary that maintains persistent electrical connections between domains while isolating them electrically. This allows continuous stable connections without direct electrical contact between the unclassified and classified domains, preventing electrostatic discharge while maintaining connection stability.
3Adaptability or versatility
If write access is allowed for both domains, then data flow flexibility is improved, but security is compromised due to potential unauthorized data transfer
Solution Approach 1:
Different access permissions are assigned to different domains based on their security requirements. The unclassified domain is granted write-only access to the shared memory, while the classified domain is granted read-only access. This localized differentiation of access rights maintains security while enabling flexible automated data flow in the appropriate direction.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and apparatus to manage transmissions between domains and memory are disclosed. An example apparatus comprises memory, a first domain having a first classification, the first domain conductively coupled to the memory, the first domain including a first bus adapter enabling transmission of first data to the memory, the first data associated with the first domain, and a first expander to facilitate the transmission of the first data to the memory, the memory to store the first data, and a second domain conductively coupled to the memory, the second domain having a second classification, the second domain including a second bus adapter enabling access of the first data from the memory, the second bus adapter preventing second data from exiting the second domain, the second data associated with the second domain, and a second expander to facilitate the access of the first data from the memory.