WO2016118224A1 - Multi-level security domain separation using soft-core processor embedded in an fpga - Google Patents
Multi-level security domain separation using soft-core processor embedded in an fpga Download PDFInfo
- Publication number
- WO2016118224A1 WO2016118224A1 PCT/US2015/061415 US2015061415W WO2016118224A1 WO 2016118224 A1 WO2016118224 A1 WO 2016118224A1 US 2015061415 W US2015061415 W US 2015061415W WO 2016118224 A1 WO2016118224 A1 WO 2016118224A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- security domain
- data
- classification level
- rules
- fpga
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/76—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/74—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2113—Multi-level security, e.g. mandatory access control
Definitions
- One or more aspects of embodiments according to the present invention relate to processing information of different classification levels, where Mandatory Access Control (MAC) is required to restrict data from exposure to unauthorized security domains, and more particularly to a system and method for processing data of different classification levels.
- MAC applies to information where each piece of information is associated with a classification level, and system users are not allowed to change the association of data with classification levels or the access policy of domains to classification levels.
- DAC Discretionary Access Control
- DAC Discretionary Access Control
- a user can change the authorization of a user to a piece of information.
- classifications and security domains are databases of different company departments (order processing, engineering, finance) or DoD classification levels (top-secret, secret, unclassified).
- aspects of embodiments of the present disclosure are directed toward a system and method for operating multiple security domains on one circuit card assembly, using a field-programmable gate array (FPGA) with an embedded security domain separation gate providing the MAC between multiple soft-core CPUs also embedded in the FPGA.
- the FPGA is segregated into two or more security domains with no data paths between soft-core CPUs in each security domain except through the security domain separation gate.
- the security domain separation gate applies rules to any information to be transmitted between the security domains to avoid transmission of malicious content and to avoid transmission of information of a certain classification level to a security domain at a lower classification level.
- Use of soft-core CPUs in a single FPGA to handle information in each security domain provides the cost effectiveness, flexibility, adaptability and compactness lacking from related art by introducing a single chip security domain separation and processing option.
- a system for performing operations on data in two different security domains including a field-programmable gate array (FPGA), the FPGA including: a first security domain having a first classification level, the first security domain including: first processing circuitry and a first soft-core processor, and a second security domain having a second classification level, the second security domain including: second processing circuitry and a second soft-core processor, and one or more security domain separation gates connected to the first security domain and to the second security domain, the one or more security domain separation gates configured: to receive first data from the first security domain and transmit the first data to the second security domain when the first data complies with a first set of rules, and to receive second data from the second security domain and transmit the second data to the first security domain when the second data complies with a second set of rules, the only data paths between the first security domain and the second security domain being through the security domain separation gates.
- FPGA field-programmable gate array
- the first security domain and the second security domain are physically disconnected except for data paths through the security domain separation gates.
- the second classification level is a higher classification level than the first classification level.
- the first set of rules permits unrestricted flow of information.
- the first set of rules requires that information transmitted from the first security domain to the second security domain be structured in messages complying with a format specified in a message dictionary.
- the second set of rules prohibits the transmission of information from the second security domain to the first security domain. [0012] In one embodiment, the second set of rules requires that information transmitted from the first security domain to the second security domain be free of suspect words and phrases, the suspect words and phrases being stored in a rules file.
- the system includes a first external processor external to the FPGA, the first external processor having a classification level being the same as the first classification level.
- the system includes a first memory device and a second memory device, the first memory device having a classification level being the same as the first classification level, the second memory device having a classification level being the same as the second classification level, each of the first memory device and the second memory device including an address bus and a data bus, wherein the address bus and the data bus of the first memory device are connected only to the first security domain of the FPGA and to the . first external processor, and the address bus and the data bus of the second memory device are connected only to the second security domain of the FPGA.
- the system includes a memory arbiter in the first security domain of the FPGA, wherein the address bus and the data bus of the first memory device are connected to the memory arbiter.
- a method for controlling data flow between two security domains in a system including a field-programmable gate array (FPGA), the FPGA including: a first security domain having a first classification level, the first security domain including: first processing circuitry and a first soft-core processor, and a second security domain having a second classification level, the second security domain including: second processing circuitry and a second soft-core processor, and one or more security domain separation gates connected to the first security domain and to the second security domain, the one or more security domain separation gates configured: to receive first data from the first security domain and transmit the first data to the second security domain when the first data complies with a first set of rules, and to receive second data from the second security domain and transmit the second data to the first security domain when the second data complies with a second set of rules, the only communication paths between the first security domain and the second security domain being through the security domain separation gates, the method including: receiving, by a security domain separation gate of the one or
- the first classification level is a higher classification level than the second classification level, and the first set of rules prohibits the transmission of data.
- the second classification level is a higher classification level than the first classification level, and the first set of rules allows unrestricted transmission of data.
- the second classification level is a higher classification level than the first classification level
- the first set of rules allows transmission only of data structured in messages and complying with a format specified in a message dictionary.
- the first classification level is a higher classification level than the second classification level, and the first set of rules allows transmission of data only when information to be transmitted from the first security domain to the second security domain is free of suspect words and phrases stored in a rules file.
- FIG. 1 is a block diagram of a multi-level security system according to an embodiment of the present invention.
- FIG. 2 is a block diagram of a multi-level security system according to another embodiment of the present invention.
- FIG. 3 is a flowchart of a method for transmitting data from one security domain to another according to an embodiment of the present invention.
- a first element in a circuit when referred to as being "physically disconnected" from a second element, there is an absence of conductive paths to carry data between the two elements, and there are no processor-controlled switches that could, if turned on, establish such paths.
- An element may be referred to as being “physically disconnected” from a second element even though shared conductors (not configured to carry data) supply power to both elements or re-programming of a field-programmable gate array (FPGA) may be capable of establishing a data path between them.
- FPGA field-programmable gate array
- a related art high-assurance guard may be used between computer systems handling data from different security domains; the HAG is a dedicated device that manages the flow of traffic in both directions and ensures that data restricted to a single domain cannot cross to another and be inadvertently disclosed.
- CCA circuit card assembly
- a circuit card assembly used to process classified telephone calls may process the voice data of the telephone calls in a top-secret security domain and status and control data in a secret security domain, and it may be necessary to pass control commands, e.g., ringup, hangup, from the secret security domain to the top-secret security domain, and status data, e.g., phone busy, from the top-secret security domain to the secret security domain.
- Embodiments of the present invention provide an extremely effective approach for implementing security domain separation through the use of soft-core processors embedded within a field-programmable gate array (FPGA) along with an FPGA security domain separation gate function as well as other design features embedded within the same FPGA.
- the soft-core processors implement security domain specific processing in different execution spaces while the FPGA guarantees separation through the use of controlled interfaces including a security domain separation gate to enforce MAC and ensure only allowed information can pass between domains.
- multi-level security domain separation is implemented on a single circuit card assembly 105 through the use of an FPGA 1 10 with multiple soft-core processors 130 embedded inside it.
- the FPGA 1 10 includes two security domains, e.g., a secret security domain 1 15 and a top-secret security domain 120, and separates the two security domains using a security domain separation gate 125; in one embodiment, this function is part of the overall FPGA design and is not implemented in software.
- the security domain separation gate 125 is less vulnerable to an attack in which an attacker may substitute malicious software for the software that ordinarily would execute in the system.
- An FPGA 1 10 also may have other provisions for enhancing the security of the system, such as including directional data paths in the security domain separation gate 125.
- a security domain separation gate may include multiple data paths, e.g., one or more paths from the secret security domain 1 15 to the top-secret security domain 120, and one or more paths from the top-secret security domain 120 to the secret security domain 1 15. Each path may implement a separate set of rules.
- a directional data path may be established by connecting an output on a first side of the boundary between the security domains to an input on a second side of the boundary, thereby allowing data to flow in that path only from the first side to the second side of the boundary.
- the security domain separation gate 125 prevents information of the higher classification level from being transmitted into the lower-level security domain. For example, if the FPGA 110 includes two security domains, e.g., a secret security domain 1 15 and a top- secret security domain 120, then the security domain separation gate 125 may allow information to flow without restriction from the secret security domain 1 15 to the top-secret security domain 120, but it may permit information to flow from the top-secret security domain 120 to the secret security domain 115 only when the information complies with certain rules.
- the rules prohibit any flow of information from the top- secret security domain 120 to the secret security domain 1 15 and allow unrestricted flow of information from the secret security domain 1 15 to the top-secret security domain 120; in such an embodiment, the security domain separation gate 125 acts as a data diode.
- the rules specify that the information to be transmitted from the top-secret security domain 120 to the secret security domain 1 15 may contain only messages that satisfy a pre-defined set of conditions.
- the rules are pre-built and stored in a file (i.e., generated before the system starts operating) and loaded into the FPGA 1 10 at runtime.
- the FPGA 1 10 reads the rules file in order to determine the parameters that allow the security domain separation gate to determine if messages are allowed to cross domains.
- the security domain separation gate 125 performs a rules check on all messages queued for transmission between the two domains (e.g., messages placed in a buffer by a soft-core processor or processing circuitry in one domain, for transmission to another domain via the security domain separation gate 125), to ensure that only allowed data can pass between the two domains.
- Data being passed from a security domain with a higher classification level to a security domain with a lower classification level is "downgraded", or checked to make sure that it does not contain any information not at the lower classification level.
- messages queued for transmission from the domain with a lower classification level to the domain with a higher classification level are checked by the security domain separation gate 125 to verify that they comply with the rules, to reduce the risk that a message may contain malicious code or provide a return path for a covert channel.
- the security domain separation gate performs a "dirty words" or "suspect words and phrases” check.
- the security domain separation gate checks each text message queued for transmission from one security domain to another for words or phrases in a list of words and phrases indicating a likelihood that that message contains information of a certain classification level, and transmits the message only if the classification level is the same as or lower than that of the destination domain.
- the list of words and phrases may be part of the rules file.
- a processor is a circuit that reads instructions from memory external to the processor and executes the instructions
- a soft-core processor 130 is a processor constructed from basic elements in the FPGA 110 by programming the connections in the FPGA 1 10.
- a processor is distinct from another functional block that may be implemented in the FPGA 1 10 with registers and logic, which may process data without the use of instructions stored in, and read from, memory outside the functional block.
- Such other functional blocks may be referred to herein as FPGA processing 135 or "processing circuitry”.
- Each domain within the FPGA 1 10 may contain one or more soft-core processors 130 running software required for data processing in that domain.
- Each soft-core processor 130 implements processing required for the domain in which it is executing, and this processing may be separated into multiple soft-core processors 130 within a single FPGA 1 10 depending on the implementation needs.
- a soft-core processor 130 may implement software running on top of a real-time operating system (RTOS) or on "bare-metal" (i.e., without an RTOS).
- RTOS real-time operating system
- bare-metal i.e., without an RTOS
- a soft-core processor 130 in a top- secret domain is not wired within the FPGA 1 10 to a data or address bus in a secret domain in the FPGA 1 10. This is illustrated in FIG. 1 by the absence of direct connections between the secret security domain 1 15 and the top-secret security domain 120, the only communication path between the two domains being through the security domain separation gate 125.
- the circuit card assembly 105 may have one or more input/output (I/O) interfaces 140 in each security domain.
- several security domain separation gates 125 provide parallel communication paths between two security domains in the FPGA 110, and an FPGA 1 10 may contain more than two security domains.
- an FPGA 1 10 may contain three security domains: a first, unclassified security domain; a second, secret security domain; and a third, top-secret security domain.
- each domain may also contain a volatile or non-volatile memory device 210 dedicated to that domain for storing data; the FPGA 110 physically restricts access to these memory devices 210 to only the FPGA function or soft-core processors 130 that are in the same security domain, e.g., data or address busses are not provided connecting a processor in one security domain to memory dedicated to another security domain.
- one or more memory arbiters 215 may control access to the memory.
- a memory device 210 is entirely within a single security domain but is separated into different regions each with its own access rights, each region corresponding, for example, to a process executing in that security domain.
- a memory device 210 may store soft-core control data which may be passed to a soft-core processor 130 in the same security domain, or passed through the security domain separation gate to other soft-core processors.
- Control data may include, for example, data for setting up communications channels, e.g., Internet Protocol (IP) addresses, or configuration parameters, such as data rates or flow control information.
- IP Internet Protocol
- a memory device 210 may be shared between security domains and a memory arbiter, which instead of being entirely within a single security domain (as shown in FIG. 2) straddles the boundary between security domains.
- This memory arbiter may allow access to a first region of memory only by processors in a first security domain of the FPGA 1 10, and it may allow access to a second region of memory only by processors in a second security domain of the FPGA 1 10, where the first region of memory and the second region of memory do not overlap.
- a memory arbiter is connected to a memory device which contains two non-overlapping regions of memory, a first region in the first security domain and a second region in the second security domain.
- the memory arbiter has processor-side busses connected to the first security domain and to the second security domain, respectively, and memory-side busses connected to the memory device.
- the memory arbiter may have, for example, a first processor-side address bus and a first processor-side data bus, both connected to the first security domain, and a second processor-side address bus and a second processor-side data bus, both connected to the second security domain, and a memory-side address bus and a memory-side data bus, both connected to the memory device.
- the memory arbiter then provides access, for memory access requests received through the first processor-side address bus and the first processor- side data bus, only to the first region of memory, and, for memory access requests received through the second processor-side address bus and the second processor-side data bus, only to the second region of memory.
- Each security domain may extend outside of the FPGA 110, i.e., devices such as processors, within the security domain, may be present external to the FPGA 1 10. These devices may be in direct communication with FPGA elements in the same security domain, and in communication with FPGA elements in other security domains through one or more security domain separation gates 125.
- FIG. 2 shows external processors (CPUs) 220 operating in both security domains 1 15, 120.
- a processor interface may be included in the FPGA for each external CPU.
- I/O Input/output
- the FPGA 1 10 may contain additional functional blocks which may be soft-core processors 130 or processing circuitry 135, and the CCA 105 may contain, e.g., a management interface 240 for control and status information.
- a security domain separation gate is implemented in a softcore processor.
- FIG. 3 summarizes a decision method that may be employed in such an embodiment to determine whether to transmit information from one security domain to another.
- the information to be transmitted is received by the security domain separation gate 125.
- a determination is made whether the requested transmission is from a security domain with a higher classification level to a security domain with a lower classification level. If it is, then, in a step 320, a determination is made whether the information to be transmitted complies with a second set of rules, and, if it does, the information is transmitted in a step 325; otherwise the transmission is denied, in a step 330.
- a "security domain” is a collection of data processing and data storage hardware, the flow of information into and/or out of which is controlled to prevent unacceptable commingling of information of different classification levels.
- exemplary embodiments described herein refer to classification levels, "secret” information, “top-secret” information, and the like, the use of embodiments of the present invention is not limited to military or defense applications.
- embodiments of the present invention may be used in a civilian business context, in which it may be desired to segregate, for example, financial information from engineering information, and information in the two categories may be kept in different security domains.
- a “classification level” refers to the classification of information into categories for the purpose of segregation, and is not limited to classifications such as "secret” and "top- secret.”
- some embodiments of the present invention may be suitable for use in systems in which the classification levels are not ranked, i.e., in which one of two different classification levels is neither a higher classification level nor a lower classification level than the other of the two classification levels.
- An example of such a system may be the above- mentioned business application, in which it may be advantageous to keep certain engineering information out of the finance security domain, and it may also be advantageous to keep certain financial information out of the engineering security domain.
- data is synonymous with “information” and the term “data” may include both information used to convey messages or other content, as well as control information including commands used, for example, to configure communication channels.
- first may be used herein to describe various elements, components, regions, and/or sections, these elements, components, regions, and/or sections should not be limited by these terms. These terms are only used to distinguish one element, component, region, or section from another element, component, region, or section. Thus, a first element, component, region, or section discussed herein could be termed a second element, component, region, or section, without departing from the spirit and scope of the inventive concept.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
- Logic Circuits (AREA)
- Microcomputers (AREA)
Abstract
Description
Claims
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CA2972078A CA2972078C (en) | 2015-01-22 | 2015-11-18 | Multi-level security domain separation using soft-core processor embedded in an fpga |
| NZ733305A NZ733305B2 (en) | 2015-01-22 | 2015-11-18 | Multi-level security domain separation using soft-core processor embedded in an fpga |
| AU2015378597A AU2015378597C1 (en) | 2015-01-22 | 2015-11-18 | Multi-level security domain separation using soft-core processor embedded in an FPGA |
| GB1712280.5A GB2549908B (en) | 2015-01-22 | 2015-11-18 | Multi-level security domain separation using soft-core processor embedded in an FPGA |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/603,215 | 2015-01-22 | ||
| US14/603,215 US9971910B2 (en) | 2015-01-22 | 2015-01-22 | Multi-level security domain separation using soft-core processor embedded in an FPGA |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016118224A1 true WO2016118224A1 (en) | 2016-07-28 |
Family
ID=54979913
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2015/061415 Ceased WO2016118224A1 (en) | 2015-01-22 | 2015-11-18 | Multi-level security domain separation using soft-core processor embedded in an fpga |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US9971910B2 (en) |
| AU (1) | AU2015378597C1 (en) |
| CA (1) | CA2972078C (en) |
| GB (1) | GB2549908B (en) |
| WO (1) | WO2016118224A1 (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB2552966A (en) * | 2016-08-15 | 2018-02-21 | Arm Ip Ltd | Methods and apparatus for protecting domains of a device from unauthorised accesses |
| WO2019125574A1 (en) * | 2017-12-18 | 2019-06-27 | Xilinx, Inc. | Security for programmable devices in data center |
| WO2026003463A1 (en) * | 2024-06-26 | 2026-01-02 | Safran Electronics & Defense | Method for controlling communication between a high-security critical component and a low-security non-critical component of a computer and controller for implementing such a method |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10176249B2 (en) * | 2014-09-30 | 2019-01-08 | Raytheon Company | System for image intelligence exploitation and creation |
| US10402566B2 (en) * | 2016-08-01 | 2019-09-03 | The Aerospace Corporation | High assurance configuration security processor (HACSP) for computing devices |
| KR102021008B1 (en) * | 2017-08-23 | 2019-09-11 | 서울대학교산학협력단 | System and method for intra-level privilege seperation for system software on arm |
| EP3764235B1 (en) * | 2019-07-12 | 2022-10-26 | Ratier-Figeac SAS | Field programmable gate array (fpga) having dissimilar cores |
| US11349872B2 (en) | 2019-11-26 | 2022-05-31 | General Electric Company | Provably secure application-specific cross-domain solutions |
| DE102020204148A1 (en) * | 2020-03-31 | 2021-09-30 | Airbus Operations Gmbh | Information processing architecture for implementation in a vehicle |
| US11665174B2 (en) | 2021-01-29 | 2023-05-30 | Raytheon Company | Method and system for multi-tiered, multi-compartmented DevOps |
| PL4307151T3 (en) * | 2022-07-13 | 2025-03-17 | Helsing Gmbh | Method and device for enabling data access to a federated storage |
| US12506709B2 (en) | 2022-11-30 | 2025-12-23 | Lockheed Martin Corporation | Method and system for managing traffic packets |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100077472A1 (en) * | 2008-09-23 | 2010-03-25 | Atmel Corporation | Secure Communication Interface for Secure Multi-Processor System |
Family Cites Families (22)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6298370B1 (en) * | 1997-04-04 | 2001-10-02 | Texas Instruments Incorporated | Computer operating process allocating tasks between first and second processors at run time based upon current processor load |
| US7389413B2 (en) * | 1998-07-23 | 2008-06-17 | Tumbleweed Communications Corp. | Method and system for filtering communication |
| US6326758B1 (en) * | 1999-12-15 | 2001-12-04 | Reliance Electric Technologies, Llc | Integrated diagnostics and control systems |
| US7103914B2 (en) * | 2002-06-17 | 2006-09-05 | Bae Systems Information Technology Llc | Trusted computer system |
| US7222114B1 (en) * | 2003-08-20 | 2007-05-22 | Xilinx, Inc. | Method and apparatus for rule-based operations |
| JP4191170B2 (en) * | 2004-07-23 | 2008-12-03 | Necエレクトロニクス株式会社 | Programmable gate array copy protection method and system |
| US8078707B1 (en) * | 2004-11-12 | 2011-12-13 | Juniper Networks, Inc. | Network management using hierarchical domains |
| US20060282886A1 (en) * | 2005-06-09 | 2006-12-14 | Lockheed Martin Corporation | Service oriented security device management network |
| US7509434B1 (en) * | 2006-01-26 | 2009-03-24 | Rockwell Collins, Inc. | Embedded MILS network |
| US7739289B2 (en) * | 2006-05-15 | 2010-06-15 | Microsoft Corporation | Reviewing user-created content before website presentation |
| US8627079B2 (en) * | 2007-11-01 | 2014-01-07 | Infineon Technologies Ag | Method and system for controlling a device |
| US8739270B1 (en) | 2009-01-28 | 2014-05-27 | The Boeing Company | Trusted, cross domain information sharing between multiple legacy and IP based devices |
| US8745385B2 (en) | 2009-06-24 | 2014-06-03 | Raytheon Company | System and method for protecting data with multiple independent levels of security |
| US8434044B1 (en) * | 2010-01-28 | 2013-04-30 | Altera Corporation | Specifying placement and routing constraints for security and redundancy |
| US20110219424A1 (en) * | 2010-03-05 | 2011-09-08 | Microsoft Corporation | Information protection using zones |
| US8694659B1 (en) * | 2010-04-06 | 2014-04-08 | Symantec Corporation | Systems and methods for enhancing domain-name-server responses |
| US8478997B2 (en) * | 2010-09-10 | 2013-07-02 | Raytheon Company | Multi-level security software architecture |
| US8584211B1 (en) * | 2011-05-18 | 2013-11-12 | Bluespace Software Corporation | Server-based architecture for securely providing multi-domain applications |
| US20140059692A1 (en) * | 2012-08-22 | 2014-02-27 | Michael Dapp | System and method for cross domain flight data import and export |
| US9596212B2 (en) * | 2013-11-11 | 2017-03-14 | The Boeing Company | Apparatus, method, and system for hardware-based filtering in a cross-domain infrastructure |
| US9294097B1 (en) * | 2013-11-15 | 2016-03-22 | Scientific Concepts International Corporation | Device array topology configuration and source code partitioning for device arrays |
| US10277511B2 (en) * | 2015-12-16 | 2019-04-30 | Nxp Usa, Inc. | Hash-based packet classification with multiple algorithms at a network processor |
-
2015
- 2015-01-22 US US14/603,215 patent/US9971910B2/en active Active
- 2015-11-18 GB GB1712280.5A patent/GB2549908B/en active Active
- 2015-11-18 WO PCT/US2015/061415 patent/WO2016118224A1/en not_active Ceased
- 2015-11-18 AU AU2015378597A patent/AU2015378597C1/en active Active
- 2015-11-18 CA CA2972078A patent/CA2972078C/en active Active
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100077472A1 (en) * | 2008-09-23 | 2010-03-25 | Atmel Corporation | Secure Communication Interface for Secure Multi-Processor System |
Cited By (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB2552966A (en) * | 2016-08-15 | 2018-02-21 | Arm Ip Ltd | Methods and apparatus for protecting domains of a device from unauthorised accesses |
| KR20180019057A (en) * | 2016-08-15 | 2018-02-23 | 에이알엠 아이피 리미티드 | Methods and apparatus for protecting domains of a device from unauthorised accesses |
| CN107766706A (en) * | 2016-08-15 | 2018-03-06 | 阿姆Ip有限公司 | For protection equipment domain from unwarranted access method and apparatus |
| GB2552966B (en) * | 2016-08-15 | 2019-12-11 | Arm Ip Ltd | Methods and apparatus for protecting domains of a device from unauthorised accesses |
| US10757100B2 (en) | 2016-08-15 | 2020-08-25 | Arm Ip Limited | Methods and apparatus for protecting domains of a device from unauthorized accesses |
| KR102352505B1 (en) * | 2016-08-15 | 2022-01-19 | 에이알엠 아이피 리미티드 | Methods and apparatus for protecting domains of a device from unauthorised accesses |
| WO2019125574A1 (en) * | 2017-12-18 | 2019-06-27 | Xilinx, Inc. | Security for programmable devices in data center |
| US10657292B2 (en) | 2017-12-18 | 2020-05-19 | Xilinx, Inc. | Security for programmable devices in a data center |
| KR20200099571A (en) * | 2017-12-18 | 2020-08-24 | 자일링크스 인코포레이티드 | Security for programmable devices in the data center |
| KR102547547B1 (en) | 2017-12-18 | 2023-06-23 | 자일링크스 인코포레이티드 | Security for Programmable Devices in the Data Center |
| WO2026003463A1 (en) * | 2024-06-26 | 2026-01-02 | Safran Electronics & Defense | Method for controlling communication between a high-security critical component and a low-security non-critical component of a computer and controller for implementing such a method |
| FR3164084A1 (en) * | 2024-06-26 | 2026-01-02 | Safran Electronics & Defense | Method for controlling communication between a high-security critical part and a low-security non-critical part of a computer and controller for the implementation of such a method |
Also Published As
| Publication number | Publication date |
|---|---|
| GB2549908A (en) | 2017-11-01 |
| GB201712280D0 (en) | 2017-09-13 |
| CA2972078C (en) | 2023-04-04 |
| AU2015378597C1 (en) | 2021-03-11 |
| US9971910B2 (en) | 2018-05-15 |
| CA2972078A1 (en) | 2016-07-28 |
| US20160335459A1 (en) | 2016-11-17 |
| GB2549908B (en) | 2021-07-28 |
| NZ733305A (en) | 2021-08-27 |
| AU2015378597B2 (en) | 2020-11-26 |
| AU2015378597A1 (en) | 2017-08-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9971910B2 (en) | Multi-level security domain separation using soft-core processor embedded in an FPGA | |
| US10885186B2 (en) | System and method for operating a protected endpoint device | |
| US8635686B2 (en) | Integrated privilege separation and network interception | |
| KR100997802B1 (en) | Device and method for managing security of information terminal | |
| US10083129B2 (en) | Code loading hardening by hypervisor page table switching | |
| US9479538B2 (en) | Combining network endpoint policy results | |
| US9183391B2 (en) | Managing device driver cross ring accesses | |
| CN113728319B (en) | Method for monitoring a hardware application and configurable hardware module | |
| CN107622211A (en) | A big data cluster access control method and device | |
| US8635664B2 (en) | Method and system for securing application program interfaces in unified extensible firmware interface | |
| US10242174B2 (en) | Secure information flow | |
| US20080256599A1 (en) | Apparatus and method for protecting system in virtualized environment | |
| CN101290646B (en) | Apparatus and method for protecting system in virtualized environment | |
| NZ733305B2 (en) | Multi-level security domain separation using soft-core processor embedded in an fpga | |
| US20080104695A1 (en) | Device and Method for Controlling Access, Core with Components Comprising Same and Use Thereof | |
| EP4733973A1 (en) | Data access control method and apparatus | |
| US20190042473A1 (en) | Technologies for enabling slow speed controllers to use hw crypto engine for i/o protection | |
| US11520941B2 (en) | Dual level management | |
| CN118520482B (en) | Mailbox implementation method and device supporting information and function security | |
| US11882057B2 (en) | Pluggable cloud security system | |
| CN115987540B (en) | Network gateway and method for transferring data from a first network to a second network | |
| Rivera et al. | A separation and protection scheme for on-chip memory blocks in FPGAs | |
| Sun et al. | Multilateral security architecture for virtualization platform in multi-tenancy cloud environment | |
| CN121389125A (en) | Secure boot method, computing device and computer program product | |
| WO2022199807A1 (en) | Device and method for managing resource access |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15813947 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2972078 Country of ref document: CA |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 201712280 Country of ref document: GB Kind code of ref document: A Free format text: PCT FILING DATE = 20151118 |
|
| ENP | Entry into the national phase |
Ref document number: 2015378597 Country of ref document: AU Date of ref document: 20151118 Kind code of ref document: A |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15813947 Country of ref document: EP Kind code of ref document: A1 |