TDMA Bus Security Isolation via Virtual Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communications systems require separate physical systems for each security level, leading to inefficient use of bandwidth and limited networking capabilities, as they rely on centralized switching with separate cabling and physical separation of signals, which restricts the number of possible connections.
Innovation Solution
A time division multiple access (TDMA) bus architecture that allows multiple levels of security by assigning matching transmit and receive time slots to ports and channels based on their security levels, using a single cable for connection and enabling virtual switches dedicated to specific security levels, with a high assurance control source ensuring secure communication between matching security level devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate physical systems are used for each security level, then security requirements are met, but bandwidth efficiency deteriorates and device complexity increases
Solution Approach 1:
The patent combines multiple security level communications into a single shared physical bus system. Instead of maintaining separate physical systems for each security level, the invention allows multiple security domains to coexist on the same bus infrastructure, using logical separation mechanisms (time slot assignments, security labels) to maintain security boundaries while sharing physical resources.
Solution Approach 2:
The bus system is designed to serve multiple security levels simultaneously through a universal infrastructure. The same physical bus can carry traffic for different security domains (e.g., Top Secret, Secret, Unclassified) by dynamically assigning time slots and applying appropriate security policies, making the system multi-functional rather than requiring dedicated systems for each level.
2Reliability
If centralized switching with separate cabling is used, then security isolation is achieved, but networking capability deteriorates and the number of connections is limited
Solution Approach 1:
The patent introduces a temporal dimension to security isolation by using time-division multiplexing. Instead of relying solely on physical separation in space (separate cabling), the system achieves security isolation by assigning specific time slots to different security levels on the shared bus. This adds the time dimension to the traditional spatial separation approach, enabling more flexible networking while maintaining security boundaries.
Solution Approach 2:
The invention creates virtual copies of switching functionality for each security level within the shared bus system. Rather than requiring physical duplicate switching infrastructure for each security domain, the system implements virtual switches that replicate switching behavior logically, allowing multiple security domains to have their own switching fabric over the same physical medium.
3Ease of manufacture
If physical separation of signals is used, then security certification is simplified, but the number of possible connections deteriorates
Solution Approach 1:
The system changes the parameter of signal separation from physical (spatial) to temporal. By transitioning from physical signal separation to time-based signal separation, the system maintains security certification benefits while dramatically increasing connection flexibility. The same physical infrastructure can support numerous connections by dynamically allocating time slots, whereas physical separation would require separate infrastructure for each connection.
Data Source
AI summary
Systems including both distributed and centralized architectures for providing multiple levels of security using “virtual” switches. Ports and channels are assigned the same time slots on a TDMA bus only when they have matching security levels.


