Virtual OS for Multi-Level Security in Single-Level Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing systems lacking a native multi-level security (MLS) architecture cannot process and communicate information across varying security levels, limiting their use in networks with MLS environments.
Innovation Solution
An external mass storage device with a virtual operating system, executed via a virtualization tool, provides a trusted computing base to enable multi-level security processing and communication in systems without native MLS support, using a base operating system that implements a single security level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a computing system uses a base operating system with single-level security, then the system maintains simplicity and ease of operation, but it cannot process or communicate information across multiple security levels
Solution Approach 1:
The patent implements a nested virtual machine architecture where a first virtual machine (providing multi-level security) is nested within a second virtual machine (providing single-level security). This allows the single-level secure system to host and utilize multi-level security capabilities through virtualization, enabling adaptability without fundamentally redesigning the underlying system architecture.
Solution Approach 2:
The patent introduces a gateway as an intermediary component that bridges the single-level secure environment and the multi-level security virtual machine. The gateway translates and facilitates communication between systems with different security models, allowing the base operating system to interact with multi-level security resources without direct exposure to its complexity.
2Reliability
If a computing system lacks a native trusted computing base, then the system maintains ease of manufacture and deployment, but it cannot enforce security policies or operate in multi-level security networks
Solution Approach 1:
The patent pre-configures the virtual machine with a trusted computing base and multi-level security architecture before deploying it within the host system. By preparing the secure environment in advance through virtualization, the system gains security policy enforcement capabilities without requiring complex modifications to the underlying hardware or base operating system during deployment.
3Reliability
If information is isolated between security domains, then security is maintained, but data flow between different security levels is blocked
Solution Approach 1:
The gateway acts as a controlled intermediary that manages data flow between security domains with different classification levels. It enforces security policies by filtering and routing information appropriately while allowing legitimate data flow between domains, thus maintaining both security isolation and productive communication between different security levels.
Data Source
AI summary
According to an embodiment, a system may comprise a mass storage device that is operable to be coupled to one or more processors. The mass storage device may comprise a base operating system that is operable to be executed by the one or more processors. The base operating system may be operable to implement a single security level. The mass storage device may also comprise a virtual operating system that is operable to be executed by the one or more processors. The virtual operating system may be executed using a virtualization tool that is executed by the base operating system. The virtual operating system may be operable to process information according to a plurality of security levels and communicate the information to one or more computing systems. The information may be communicated according to the plurality of security levels of the information.


