Unified Display Combining for Secure Computing Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing systems, especially network-connected devices, are vulnerable to attacks, with Virtual Machines and process isolation not being foolproof, leading to potential side channel attacks, particularly in mission-critical applications.
Innovation Solution
A system and method for separating computing systems while allowing them to work together by combining and monitoring their displays, enabling one-way communication and protecting user displays from unwanted data by identifying and blocking malicious content, using secure boot mechanisms and other security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Virtual Machines or process isolation are used to separate computing systems, then system security is improved, but side channel attacks can still penetrate the isolation
Solution Approach 1:
The system is divided into separate computing units with distinct display outputs. Each unit maintains independent processing while their displays are combined through a display combiner, creating physical segmentation that prevents side channel attacks between units while allowing coordinated display output.
Solution Approach 2:
A display combiner acts as an intermediary component that receives display outputs from multiple separated computing units and combines them into a single unified display. This intermediary enables secure separation of computing systems while maintaining display unity and preventing direct communication channels that could be exploited.
2Reliability
If computing systems are separated for security, then attack protection is improved, but the systems cannot work together seamlessly
Solution Approach 1:
The display outputs from multiple separated computing units are merged into a single unified display through the display combiner. This merging occurs at the display level rather than at the computing level, allowing the systems to remain separated for security while presenting a seamless unified interface to the user.
3Measurement precision
If display monitoring is implemented to detect attacks, then attack identification is improved, but system complexity increases
Solution Approach 1:
The attack detection functionality is extracted from the individual computing units and implemented as a separate display monitoring system. This separate monitoring unit observes the combined display output without interfering with the core computing functions, thereby improving attack identification while minimizing added complexity to the computing systems themselves.
4Reliability
If one-way communication is established between separated systems, then security is improved, but communication capability is limited
Solution Approach 1:
Instead of allowing direct communication between computing units, the system inverts the approach by having units communicate through their display outputs. Computing units send information to be displayed, and other units can observe this information through the combined display, creating a one-way communication channel that is secure yet functional.
Data Source
AI summary
A system and method is introduced for separating computing devices that work together. The computing devices appear to the user as a single device such as through using a single display and other I/O means. The output of computing devices such as the display output, may be monitored for unwanted display output to the user which may be filtered from the user. The device displaying unwanted content may then be reverted to a known state. Computing devices may communicate among themselves using display data while remaining separated. Secure services from the cloud to a user device may be offered through the separated computing devices that work together, services that utilizes separating and securing the user I/O from internet connected devices, while allowing to monitor and filter the internet connected devices. These services preferably use a key that is non-extractable for communicating with the secure cloud. Such services from the cloud server may include a secure remote desktop for VDI/DaaS and a secure web browser There is also provided implementation of the system on different architectures using SW only or using some HW additions. Usage examples for vehicles, enterprises and others are described.


