Virtual OS for Multi-Level Security in Single-Level Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems lacking a native multi-level security (MLS) architecture cannot process and communicate information across varying security levels, limiting their use in networks with MLS environments.

Innovation Solution

An external mass storage device with a virtual operating system, executed via a virtualization tool, provides a trusted computing base to enable multi-level security processing and communication in systems without native MLS support, using a base operating system that implements a single security level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a computing system uses a base operating system with single-level security, then the system maintains simplicity and ease of operation, but it cannot process or communicate information across multiple security levels

Engineering Contradiction:
Improvemulti-level security capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested virtual machine architecture where a first virtual machine (providing multi-level security) is nested within a second virtual machine (providing single-level security). This allows the single-level secure system to host and utilize multi-level security capabilities through virtualization, enabling adaptability without fundamentally redesigning the underlying system architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a gateway as an intermediary component that bridges the single-level secure environment and the multi-level security virtual machine. The gateway translates and facilitates communication between systems with different security models, allowing the base operating system to interact with multi-level security resources without direct exposure to its complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a computing system lacks a native trusted computing base, then the system maintains ease of manufacture and deployment, but it cannot enforce security policies or operate in multi-level security networks

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent pre-configures the virtual machine with a trusted computing base and multi-level security architecture before deploying it within the host system. By preparing the secure environment in advance through virtualization, the system gains security policy enforcement capabilities without requiring complex modifications to the underlying hardware or base operating system during deployment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If information is isolated between security domains, then security is maintained, but data flow between different security levels is blocked

Engineering Contradiction:
Improvesecurity isolationVSAvoiddata flow efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway acts as a controlled intermediary that manages data flow between security domains with different classification levels. It enforces security policies by filtering and routing information appropriately while allowing legitimate data flow between domains, thus maintaining both security isolation and productive communication between different security levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8468344B2Enabling multi-level security in a single-level security computing system
Publication Date: 2013.06.18 EVERFOX HOLDINGS LLC
  • US8468344B2 patent drawing
  • US8468344B2 patent drawing
  • US8468344B2 patent drawing

AI summary

According to an embodiment, a system may comprise a mass storage device that is operable to be coupled to one or more processors. The mass storage device may comprise a base operating system that is operable to be executed by the one or more processors. The base operating system may be operable to implement a single security level. The mass storage device may also comprise a virtual operating system that is operable to be executed by the one or more processors. The virtual operating system may be executed using a virtualization tool that is executed by the base operating system. The virtual operating system may be operable to process information according to a plurality of security levels and communicate the information to one or more computing systems. The information may be communicated according to the plurality of security levels of the information.