Virtual Machine Segmentation for Multi-Level Security Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Aircraft data processing systems face challenges in integrating security functions with commercial hardware and software while maintaining confidentiality, integrity, and availability, especially in coexisting with sensitive data and functionalities that require various levels of security or responsibility.
Innovation Solution
A software component utilizing multiple virtual machines and a hypervisor to manage security levels, allowing for the implementation of various security functions on a single machine, independent of hardware platforms, with authentication and data transfer filtering to ensure security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple functions with different security levels are integrated into a single data processing system, then system versatility and resource utilization improve, but security risk and system complexity increase
Solution Approach 1:
The system is segmented into multiple virtual machines, each isolated and dedicated to specific functions with defined security levels. This segmentation allows versatile functionality while maintaining security boundaries, as each virtual machine operates independently with controlled access to resources and data.
2Ease of manufacture
If commercial hardware and software are used to reduce costs and improve compatibility, then ease of manufacture and adaptability improve, but security control and system reliability deteriorate
Solution Approach 1:
A hypervisor layer is introduced as an intermediary between the commercial hardware/software infrastructure and the security-critical functions. This hypervisor provides standardized interfaces and security management, enabling the use of commercial products while maintaining controlled security boundaries and isolation.
3Productivity
If security functions are integrated into operational processes, then operational efficiency improves, but system complexity and maintenance requirements increase
Solution Approach 1:
Security functions are merged with operational processes within the virtualized environment, allowing both to coexist in the same physical infrastructure. The virtual machines provide logical separation while sharing physical resources, reducing overall system complexity compared to completely separate security and operational systems.
Data Source
AI summary
A software component for automated processing of multi-usage data, implementing functions requiring various levels of security or limits of responsibility. The software component includes a plurality of virtual machines, each virtual machine being adapted for executing at least one function requiring a level of security or a limit of responsibility which is predetermined and a hypervisor adapted for controlling execution of the plurality of virtual machines.


