Unified File System for Air-Gapped Endpoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current air gapping security solutions using virtual machine technologies do not provide a complete defense against malicious code and limit user experience due to restrictions on installing software and interacting with multiple file systems, leading to confusion and potential security breaches.
Innovation Solution
A unified file system approach is implemented on an air-gapped endpoint, where a hypervisor monitors and intercepts file system operations across multiple security zones, blocking unauthorized access and displaying file system dialog windows in the appropriate zone, providing a seamless user experience while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual machine isolation is implemented to secure air-gapped endpoints, then security against malicious code is improved, but user experience deteriorates due to restricted software installation and limited UX features
Solution Approach 1:
The patent introduces a file system dialog window interceptor as an intermediary layer between the user interface and the virtual machine file systems. This interceptor captures file dialog events, determines the appropriate security zone based on the originating application, and presents a unified file system view that spans multiple VMs. Users can access files from different security zones through a single interface without directly interacting with individual VM file systems, thus maintaining security while improving usability.
2Reliability
If multiple separate file systems are maintained for different security zones, then security isolation is improved, but user productivity deteriorates due to confusion and time-consuming file management
Solution Approach 1:
The patent merges multiple separate file systems from different security zones into a single unified file system view presented to the user. The file system dialog window interceptor aggregates file browsing capabilities across multiple VMs, allowing users to access files from secure and non-secure zones through a single interface. This eliminates the need for users to manually switch between different file systems while maintaining underlying security isolation through controlled access mechanisms.
3Reliability
If the host operating system is restricted to prevent malicious code installation, then security is improved, but ease of operation deteriorates as users cannot install applications or change settings
Solution Approach 1:
The patent segments the operating system functionality into multiple virtual machines with different security zones. The host OS runs a restricted guest OS in a VM for application installation and user operations, while the actual host OS remains protected and air-gapped. This segmentation allows users to install and configure applications in the guest VM environment without compromising the security of the host OS, effectively resolving the contradiction between security restriction and operational flexibility.
Data Source
AI summary
A system and method for providing a unified file system on an air-gapped endpoint are provided. The method included monitoring a plurality of security zones, instantiated on the air-gapped endpoint, to intercept at least one file system operation to access files on a first security zone; determining if the detected file system operation triggers a display of the file system dialog window effecting a second security zone; and when the file system dialog window effecting the second security zone, blocking the display of the file system dialog window in the first security zone; and displaying the file system dialog window in the second security zone.


