The disclosure relates to handling and processing secured data.
Field-users of secure mobile devices may employ multiple digital assets in the field for digital communications and other applications. Examples may include voice applications and surveillance unmanned aerial vehicles (UAVs). Some data sources do not support any secured level classification. Some integrated systems may allow field-users to use commercial off-the-shelf (COTS) devices for secured level tactical and front-line use (e.g., common operating picture, data feeds, real-time communications, etc.). Even though the non-secured data sources may improve the effectiveness of field-users and improve the ability to complete missions, these systems may not be capable of connecting with secured devices because of the difference in security classification levels (i.e., rules governing the operation of secure devices preclude direct connection of such devices to non-secure devices or devices at a different classification level than the secured device; thus, the system may block the non-secured data from flowing into the secured domain and may control any/all data flowing into the non-secured domain).
In general, the techniques of this disclosure describe a hub device that is configured to receive data packets from both secured client devices and non-secured client devices. The hub device may send the data packets from the secured client devices to a host device. For the data packets from the non-secured client devices, the hub device may first process the data packets to ensure the integrity of the received non-secure data packets and then send the non-secure data packets to the host device once the hub device determines that the non-secure data packets meet some threshold level of integrity.
In one example, the disclosure is directed to a method including receiving, by a hub device via a first port, a first data packet from a first client device, wherein the first client device has a first security classification. The method also includes performing, by the hub device, a first guard process on the first data packet based at least in part on the first security classification and, based on results of the first guard process indicating that the first data packet is valid, sending, by the hub device and via a third port, the first data packet to a host device. The method further includes receiving, by the hub device via a second port, a second data packet from a second client device, wherein the second client device has a second security classification different than the first security classification. The method also includes performing, by the hub device, a second guard process on the second data packet based at least in part on the second security classification, wherein the second guard process is different than the first guard process and, based on results of the second guard process indicating that the second data packet is valid, sending, by the hub device via the third port, the second data packet to the host device.
In another example, the disclosure is directed to a hub device that includes a first port, a second port, a third port, and one or more processors. The one or more processors are configured to receive, via the first port, a first data packet from a first client device, wherein the first client device has a first security classification. The one or more processors are further configured to perform a first guard process on the first data packet based at least in part on the first security classification and, based on results of the first guard process indicating that the first data packet is valid, send, via a third port, the first data packet to a host device. The one or more processors are further configured to receive, via the second port, a second data packet from a second client device, wherein the second client device has a second security classification different than the first security classification. The one or more processors are also configured to perform a second guard process on the second data packet based at least in part on the second security classification, wherein the second guard process is different than the first guard process and, based on results of the second guard process indicating that the second data packet is valid, send, via the third port, the second data packet to the host device.
In another example, the disclosure is directed to a computer readable storage medium storing instructions that when executed by one or more processors cause the one or more processors to receive, via a first port, a first data packet from a first client device, wherein the first client device has a first security classification. The instructions further cause the one or more processors are to perform a first guard process on the first data packet based at least in part on the first security classification and, based on results of the first guard process indicating that the first data packet is valid, send, via a third port, the first data packet to a host device. The instructions further cause the one or more processors to receive, via a second port, a second data packet from a second client device, wherein the second client device has a second security classification different than the first security classification. The instructions further cause the one or more processors to perform a second guard process on the second data packet based at least in part on the second security classification, wherein the second guard process is different than the first guard process and, based on results of the second guard process indicating that the second data packet is valid, send, via the third port, the second data packet to the host device.
In another example, the disclosure is directed to an apparatus that includes means for receiving, via a first port, a first data packet from a first client device, wherein the first client device has a first security classification. The apparatus also includes means for performing a first guard process on the first data packet based at least in part on the first security classification and, based on results of the first guard process indicating that the first data packet is valid, means for sending, via a third port, the first data packet to a host device. The apparatus further includes means for receiving, via a second port, a second data packet from a second client device, wherein the second client device has a second security classification different than the first security classification. The apparatus also includes means for performing a second guard process on the second data packet based at least in part on the second security classification, wherein the second guard process is different than the first guard process and, based on results of the second guard process indicating that the second data packet is valid, means for sending, via the third port, the second data packet to the host device.
The details of one or more examples of the disclosure are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the disclosure will be apparent from the description and drawings, and from the claims.
In general, this disclosure describes a hub device that is configured to receive data packets from both secured client devices and non-secured client devices. In some instances, the hub device may send the data packets from the secured client devices straight to a secured host device, as secured client devices may be implicitly trusted within the overall system of devices in the information exchange. In other instances, the hub device may perform some preliminary processing of the secure data packets, such as determining a sender of the data packets or the type of contents within the data packets. For the data packets originating from the non-secured client devices, the hub device may first process the data packets to ensure the integrity of the received non-secure data packets. Generally, the hub device may process and route non-secure traffic according to some pre-defined guard process based on the particular non-secure source. For instance, the hub device may perform a virus scan and/or some other integrity check on the non-secure data packets prior to sending the non-secure data packets to the host device such that the hub device blocks unsafe data packets or infiltration attempts from outside devices being forwarded to the host device.
Other devices may simply block all non-secured data from reaching the host device entirely. However, the non-secured data may still include critical information necessary for the host device. As such, blocking the data entirely may be detrimental. Other devices, however, may analyze the non-secured data once it reaches the host device. However, due to the potential damaging nature of non-secured data, malicious or virus-laden data may damage the host device to the point of where the host device may be useless or compromised.
Rather than blocking non-secured data either entirely or not at all, the techniques described herein may provide heightened one-way filtering of incoming data packets/streams received from non-secured client devices (e.g., transmission control protocol (TCP) data flows and user datagram protocol (UDP) data flows). Further, a single hub device may interconnect multiple data sources, both secured and non-secured, across multiple ports to the secured host device. A single hub device also implies a single configuration interface. The hub device, for example, may be a computing device with a full central processing unit (CPU), one or more universal serial bus (USB) ports (e.g., 4), one or more Ethernet ports (e.g., 2), and an operating system or a micro-operating system (e.g., the evaluation assurance level (EAL) 7 secure level 4 (seL4) micro-kernel), although other examples of the hub device may include more or fewer ports, different protocols for the ports (e.g., Wi-Fi, Bluetooth, etc.), or a different CPU and/or operating system. The hub device of this disclosure may perform the techniques described herein regardless of the device type, vendor, or operating system used by the end-user host device.
The hub device of this disclosure may be configured to provide a cross-domain solution (CDS) between the secure and non-secure domains that takes advantage of a modular virtualized framework. A Virtualized CDS Software Framework (VCSF) may utilize an approved hypervisor solution and approved virtual machine components that can be installed on different hardware and then customized for different needs. Specific data flow filters can then be selected and installed to create a customized CDS product.
Furthermore, by using a modular virtualized framework, the techniques described herein enable the VCSF to be implemented on a small hub device that may be worn by the end-users, such as on a device that may be clipped onto an article of clothing or carried as a backpack. These hub devices may also be mounted onto a vehicle or incorporated to a larger server device.
Host device 4 is an end-user device (EUD) described below, for purposes of illustration only, as a tablet computer. However, in some examples, host device 4 may be a computerized watch (e.g., a smart watch), computerized eyewear, computerized headwear, other types of wearable computing devices, a smartphone, a personal digital assistant (PDA), a laptop computer, a media player, a television platform, an automobile navigation system, a digital camera, or any other type of mobile and/or non-mobile computing device that is configured to perform a media operation as described herein.
Secure client devices 6 may be any device configured to send data packets to hub 10 over a secured channel (e.g., a hard-wired connection or a closed/protected network connection) and further configured to operate in accordance with a trusted secure security classification, such as secret, top secret, classified, or protected. Examples of secure client devices 6 may include a secured radio device, a secured global positioning system device, any computing device configured to operate in accordance with an encryption protocol also used by host device 4, a computing device configured to utilize steganography to write a particular string of data within a data packet, any computing device that has been approved for secure status (e.g., an approved surveillance drone, an approved UAV, an approved video feed, an approved biometric sensor, etc.), or any other computing device configured to operate with some threshold level of security such that host device 4 may implicitly trust the data packets received from secure client devices 6.
Non-secure client devices 8 may be any device configured to send data packets to hub 10 over a non-secured channel (e.g., an open network or an unprotected network) or a channel with unknown security. Further, non-secure client device 8 may not be configured to operate in accordance with a trusted secure security classification or it may be unknown to hub 10 and host device 4 as to whether non-secure client devices 8 are configured to operate in accordance with a trusted secure security classification. Examples of non-secure client devices 8 may include a UAV, a general data producing device not configured to operate in accordance with a trusted security protocol, video and voice applications, anonymous cellular phones, landline telephones, anonymous Internet devices, any computing device that has not been approved for secure status (e.g., a non-approved surveillance drone, a non-approved video feed, a non-approved biometric sensor, etc.), biometric sensors, or any other untrusted or potentially unsafe computing device.
For the purposes of this disclosure, hub 10 may be any device capable of receiving data from and sending data to at least two computing devices (i.e., host device 4 and at least one of secure client devices 6 or non-secure client devices 8). Hub 10 may be configured to utilize one or more different communication protocols for receiving and sending the data packets, including Wi-Fi (e.g., the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard), the Bluetooth protocol, various radio frequency communication devices and waveforms, USB, the Ethernet industrial protocol, radio waves/frequencies, the Internet protocol suite, Java remote method invocation, dynamic data exchange, or any other communication protocol suitable for exchanging secure and non-secure data packets.
Hub 10 may include three or more ports 12A, 12B, and 12C (collectively, ports 12). Ports 12 may serve as an interface between hub 10 and other computers or peripheral devices (e.g., host 4, secure client devices 6, and non-secure client devices 8). In some examples, ports 12 may refer to a physical connection, and in other examples, ports 12 may refer to logical or wireless connections. Electronically, when ports 12 refer to a physical connection, several conductors where ports 12 and a physical cable contacts connect may provide a method to transfer signals between devices. In other examples, ports 12 may refer to a portion of hub 10 configured to wirelessly connect with other computing devices in order to exchange information and data packets/streams. In some examples, each port of ports 12 may be configured to only communicate with devices in a particular domain. For instance, port 12A may only communicate with client devices in the non-secure domain and over a non-secure network connection, and port 12B may only communicate with client devices in the secure domain and over a secure network connection.
Hub 10 may further include one or more processors 14. One or more processors 14, in one example, are configured to implement functionality and/or process instructions for execution within hub 10. For example, processors 14 may be capable of processing instructions stored in a storage device of hub 10. Examples of processors 14 may include, any one or more of a microprocessor, a controller, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or equivalent discrete or integrated logic circuitry.
In accordance with the techniques of this disclosure, processors 14 of hub 10 may receive, via port 12A, a first data packet from non-secure client device 8A. For instance, non-secure client device 8A may be a data producing device not configured to operate in accordance with a trusted or secure protocol. For instance, a secure protocol may include the IPsec protocol or the encapsulating security payload (ESP) protocol, among other things. Conversely, the non-secure data producing protocols may include the real-time protocol (RTP) for voice or audio, the voice over internet protocol (VoIP), or the file transfer protocol (FTP), among other things. However, non-secure client device 8A may generate information that would be beneficial to transmit to host 4. As such, non-secure client device 8A may transmit the data packets to hub 10 via port 12A.
Processors 14 of hub 10 may also receive, via port 12B, a second data packet from secure client device 6A. For instance, secure client device 6A may be a radio that transmits data packets wirelessly to hub 10 over a channel that uses a trusted or secure protocol. Host 4 may request a status update from a user of secure client device 6A, and secure client device 6A may respond by transmitting the data packets to hub 10 via port 12B.
In some examples, based on the sender of the respective data packet, processor 14 may perform separate guard processes on the respective data packets. For instance, processors 14 may perform a first guard process on the first data packet based on the security classification of non-secure client device 8A (i.e., non-secure or untrusted) and perform a second guard process on the second data packet based on the security classification of secure client device 6A (e.g., a secure security classification, such as secret, top secret, classified, or protected). For the second guard process, in some instances, processors 14 may simply forward the second data packet to host 4 via port 12C. In other instances, for the second guard process, processors 14 may analyze contents of the second data packet to determine an identity of the sender of the second data packet or the type of contents in the second data packet prior to forwarding the second data packet to host 4 via port 12C. As the second data packet may come from a secure and trusted client device, processors 14 may refrain from determining an integrity of the received data and performing a virus scan operation on the second data packet, or only determine that the sender of the second data packet is a verified secure client device. As described in greater detail below with respect to
Processors 14 of hub 10 may send, via port 12C, the first data packet from non-secure client device 8A and the second data packet from secure client device 6A to host 4. Port 12C may forward the respective data packets to host 4 either upon receipt of the respective data packets or after the respective data packets have been processed. In other words, port 12C may not necessarily forward the first data packet and the second data packet simultaneously, but instead forward the first data packet and the second data packet after processors 14 determines the respective data packet to be safe to forward to host 4 in the respective data packet's own respective processing loop. The timing with which processors 14 forward the first data packet is independent of the timing with which processors 14 forward the second data packet.
In some examples, processors 14 may simply forward the first data packet and the second data packet to host 4 upon receiving the respective data packets. In other examples, as described above, processors 14 may implement some form of guard process to evaluate the first data packet received from non-secure client device 8A. Upon determining that the first data packet meets a threshold level of integrity, processors 14 may forward the first data packet to host 4 via port 12C. In still other instances, processors 14 may process information certain information regarding the second data packet (i.e., sender information or content information) prior to forwarding the second data packet to host 4.
In some examples, processors 14 of hub 10 may receive an outgoing message to be sent to non-secure client devices 8 or secure client devices 6. For instance, if the outgoing message is intended for one of secure client devices 6, processors 14 of hub 10 may forward the outgoing message to the one of secure client devices 6 without restriction or with restrictions based on the respective trust level of the one of secure client devices 6. For instance, host 4 may attempt to send an ACK message, or an acknowledgement message that verifies the receipt of the incoming data packets, to non-secure client device 8A. However, in response to determining that the outgoing message contains secure information, processors 14 of hub 10 may refrain from sending the outgoing message to non-secure client device 8A so as to protect the integrity of the secured system. In other instances, however, processors 14 of hub 10 may scan the outgoing message to determine whether the outgoing message contains secure information that would be improper for a non-secure client device to receive. In response to determining that the outgoing message does not contain secure information, processors 14 of hub 10 may send the outgoing message to non-secure client device 8A via port 12A. Processors 14 may only send the outgoing messages to the non-secure client devices 8A and/or 8B when a security policy has been set up with approvals to send the such messages to the respective non-secure client devices.
In some other examples, rather than expecting host 4 to produce and send ACK messages, processors 14 may utilize a proxy module to produce an ACK message. If processors 14 still receive the ACK message from host 4, processors 14 may block the received ACK message and utilize a proxy module to produce an ACK instead. For instance, if the first data packet was part of a TCP conversation, processors 14 may utilize the proxy module to create an ACK message and send the ACK message to non-secure client device 8A. In creating a separate ACK message at processors 14, hub 10 may maintain a one-way communication between host 4 and the non-secure client device, as the non-secure client device will not receive any data created by host 4.
In other examples, processors 14 of hub 10 may prevent all outgoing traffic from reaching non-secure client device 8A. In such examples, processors 14 of hub 10 may receive an outgoing message to be sent to non-secure client device 8A. Upon determining that the intended recipient of the outgoing message is a non-secure client device (i.e., non-secure client device 8A), processors 14 of hub 10 may refrain from sending the outgoing message to non-secure client device 8A so as to protect the operation and safety of the secured system.
While the techniques described with respect to
For example, hub 10 may include a battery to provide power to the components of hub 10, or hub 10 may include more ports than three (e.g., four or more ports). Similarly, the components of hub 10 shown in
One or more storage devices 30 of hub 10 include virtual machines 18A and 18B and secure data module 32. One or more storage devices 30 may be configured to store information within hub 10 during operation. Storage device 30, in some examples, is described as a computer-readable storage medium. In some examples, storage device 30 is a temporary memory, meaning that a primary purpose of storage device 30 is not long-term storage. Storage device 30, in some examples, are described as volatile memories, meaning that storage device 30 does not maintain stored contents when the computing device is turned off. Examples of volatile memories include random access memories (RAM), dynamic random access memories (DRAM), static random access memories (SRAM), and other forms of volatile memories known in the art. In some examples, storage device 30 is used to store program instructions for execution by processors 14.
Storage devices 30, in some examples, also include one or more computer-readable storage media. Storage devices 30 may be configured to store larger amounts of information than volatile memory. Storage devices 30 may further be configured for long-term storage of information. In some examples, storage devices 30 include non-volatile storage elements. Examples of such non-volatile storage elements include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories.
Disk 31 represents computer readable storage media that includes volatile and/or non-volatile, removable and/or non-removable media implemented in any method or technology for storage of information such as processor-readable instructions, data structures, program modules, or other data. Computer readable storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), EEPROM, flash memory, CD-ROM, digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by processor 14.
Communication channels 40, represented by the solid lines in
Virtual data paths 41A-41C, represented by the dotted lines of various patterns, represent virtual connections within hub 10. For instance, data packets may be received by one of ports 12A-12C and be processed by one of virtual machines 18A-18B or secure data module 32. After being processed, the data packets may be output to a different device via another one of ports 12A-12C. Although each of virtual data paths 41A-41C is shown as being received by one of ports 12A or 12B and being output by port 12C, each of the data paths may be reversed. In other words, port 12C may receive data from the host device to be output to non-secure client devices or secure client devices via ports 12A or 12B.
One or more communication units 16 of hub 10 may communicate with external devices, such as a server device, a host device, secure client devices, and/or non-secure client devices, via one or more wired and/or wireless networks by transmitting and/or receiving network signals on the one or more networks. Communication units 16 may include a network interface card, such as an Ethernet card, an optical transceiver, a radio frequency transceiver, or any other type of device that can send and receive information. Examples of such network interfaces may include Bluetooth, infrared signaling, 3G, LTE, and Wi-Fi radios as well as Universal Serial Bus (USB) and Ethernet. In some examples, hub 10 utilizes communication units 16 to wirelessly communicate with another computing device that is operably coupled to hub 10, such as host device 4, secure client devices 6, and/or non-secure client devices 8 of
In some examples, communication units 16 may include a sufficient number of communication units such that each of ports 12A-12C connects to components in hub 10 through a respective communication unit. In other words, port 12A may utilize a first one of communication units 16 to receive data packets from an outside computing device and to send the received data packets to the correct units for processing. In other examples, the respective ports 12A-12C may be configured to automatically send the received packets to the correct units on its own. In other words, communications channels for different sets of components can be isolated.
One or more processors 14, in one example, are configured to implement functionality and/or process instructions for execution within hub 10. For example, processors 14 may be capable of processing instructions stored in storage device 30. Examples of processors 14 may include, any one or more of a microprocessor, a controller, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or equivalent discrete or integrated logic circuitry.
Hub 10 executes a hypervisor 33 to manage virtual machines 18. Example hypervisors include Kernel-based Virtual Machine (KVM) for the Linux kernel, Xen, ESXi available from VMware, Windows Hyper-V available from Microsoft, and other open-source and proprietary hypervisors. Hypervisor 33 may represent a virtual machine manager (VMM). Hypervisor 33 includes a physical driver 35 to use the physical function provided by a network interface card.
The VCSF framework of the techniques described herein may be built upon hypervisor 33, with either additional modules to those shown in
In order to simplify
Each of virtual machines 18 may include a virtual driver presented directly into the virtual machine guest operating system, effectively bypassing hypervisor 33 to offer direct communication between communication units 16 and the virtual machine. This may reduce hypervisor 33 overhead involved with software-based, vSwitch implementations.
Hub 10 may include virtual machines 18A and 18B (collectively, virtual machines 18), and secure data module 32. Each of virtual machines 18A and 18B may include a respective non-secure data module 28A and 28B. Modules 28A, 28B, and 32 may perform operations described using software, hardware, firmware, or a mixture of hardware, software, and firmware residing in and/or executing at hub 10. Hub 10 may execute modules 28A, 28B, and 32 with one or more processors. Hub 10 may execute modules 28A, 28B, and 32 as a virtual machine executing on underlying hardware. Modules 28A, 28B, and 32 may execute as a service or component of an operating system or computing platform. Modules 28A, 28B, and 32 may execute as one or more executable programs at an application layer of a computing platform. Modules 28A, 28B, and 32 may be otherwise arranged remotely to and remotely accessible to hub 10, for instance, as one or more network services operating at a network in a network cloud. In other words, modules 28A, 28B, and 32 may not be executing at hub 10. Instead, modules 28A, 28B, and 32 may be executing at a remote computing system (e.g., a server).
Virtual machines 18 and secure data module 32 may be stored in long-term storage, such as storage 30. However, when virtual machines 18 or secure data module 32 are executed by processor 14, processor 14 may read virtual machines 18 or secure data module 32 into volatile memory, such as disk 31. Virtual machines 18 or secure data module 32 may be stored in disk 31 throughout processor 14's execution of virtual machines 18 or secure data module 32.
Virtual machines 18 may be an emulation of a computer system. Virtual machines 18 may be based on computer architectures and provide functionality of a physical computer. Virtual machines 18 may be implemented in hub 10 using specialized hardware, software, or a combination thereof. Virtual machines 18 may be process virtual machines designed to execute the techniques described herein in a platform-independent environment. Specifically, each of virtual machines 18 may be designed to execute the guard and filtering techniques for data packets received from a non-secure client device. Although shown as virtual machines, virtual machines 18A and/or 18B may instead be containers. In such instances, a kernel of hypervisor 33 may allow for multiple, distinct virtualization engines that may enable the performance of the techniques described herein. Each of virtual machines 18A and 18B may include various hardware or software components to perform the techniques of this disclosure. These components are described in greater detail below.
In accordance with the techniques of this disclosure, processors 14 of hub 10 may receive, via port 12A, a first data packet from a non-secure client device. For example, the non-secure client device may be a UAV attempting to send data (e.g., a full motion video TCP stream) to the host device. The UAV may not be configured to operate in accordance with a trusted or secure protocol. However, the UAV may still generate information that would be beneficial to transmit to host 4. As such, the UAV may transmit the data packets associated with the TCP stream to hub 10 via port 12A. In examples where hub 10 includes virtual machine 18A, the first data packet may generally follow path 41A, i.e., the first data packet may be received by port 12A, analyzed using virtual machine 18A, and output via port 12C. In other examples where hub 10 includes virtual machine 18B, the first data packet may generally follow path 41B, i.e., the first data packet may be received by port 12A, analyzed using virtual machine 18B, and output via port 12C.
Processors 14 of hub 10 may also receive, via port 12B, a second data packet from a secure client device. For instance, the secure client device may be a global positioning system (GPS) device that transmits data packets that include various locations to hub 10 over a secure channel. Host 4 may request a status update from a user of the GPS with regards to the location of the GPS, and the GPS may respond by transmitting the data packets to hub 10 via port 12B. The second data packet, upon being received at port 12B, may generally follow path 41C within hub 10, i.e., the second data packet may be received by port 12B, analyzed using secure data module 32, and output via port 12C.
In some examples, based on the sender of the respective data packet, processor 14 may perform separate guard processes on the respective data packet. For instance, non-secure data modules 28A and/or 28B may receive the non-secure data packet from port 12A and perform a first guard process on the first data packet based on the security classification of the UAV (i.e., non-secure or untrusted) and secure data module 32 may perform a second guard process on the second data packet based on the security classification of the GPS (e.g., a secure security classification, such as secret, top secret, classified, or protected). For the second guard process, in some instances, secure data module 32 may simply forward the second data packet to the host device via port 12C. In other instances, for the second guard process, secure data module 32 may analyze contents of the second data packet to determine an identity of the sender of the second data packet or the type of contents in the second data packet prior to forwarding the second data packet to the host device via port 12C. As the second data packet may come from a verified secure and trusted client device, secure data module 32 may refrain from determining an integrity of the received data and performing a virus scan operation on the second data packet.
For the first guard process, non-secure data module 28A or 28B may execute the respective guard process 22A or 22B to perform an integrity check on the first data packet based at least in part on a type of connection between hub 10 and the non-secure client device and a data type of the first data packet. In other words, the data packet may have a different structure depending on the type of data stored within the data packet and the protocol used to transmit the data packet to hub 10. As such, the specific method for determining the integrity of the first data packet may vary based on the expected structure of the first data packet. Non-secure data module 28A or 28B may determine an expected structure of the first data packet based at least in part on type of connection between hub 10 and the non-secure client device and the data type of the first data packet. Non-secure data module 28A or 28B may also determine an actual structure of the first data packet and compare the actual structure with the expected structure. If non-secure data module 28A or 28B determines that the actual structure of the first data packet matches the expected structure of the first data packet, non-secure data module 28A or 28B may determine that the first data packet passes the integrity check and send the first data packet to the host device via port 12C. Conversely, if non-secure data module 28A or 28B determines that the actual structure of the first data packet does not match the expected structure of the first data packet, non-secure data module 28A or 28B may determine that the first data packet fails the integrity check and block the first data packet from reaching the host device.
Part of the integrity check may include non-secure data modules 28A and 28B determining that the actual structure of the first data packet matches an expected structure based on the type of data stored within the data packet and the protocol used to transmit the data packet to hub 10. For instance, if the UAV sends the TCP stream using Wi-Fi, non-secure data modules 28A and 28B may expect the first data packet to have a particular structure with particular bitfields filled out in particular ways. Non-secure data modules 28A and 28B may determine that the first data packet passes the integrity check if the bitfields match the expected structure.
Another part of the integrity check may include non-secure data modules 28A and 28B performing a virus scan operation on the first data packet. The virus scan operation may include comparing certain values within the data packet to known virus or malware structures. If non-secure data modules 28A and 28B determine that the first data packet contains a virus or malware, then non-secure data modules 28A and 28B may block the first data packet from reaching the host device. Conversely, if non-secure data modules 28A and 28B determines that the virus scan operation shows no harmful data in the first data packet, non-secure data modules 28A and 28B may forward the first data packet to the host device via port 12C.
Secure data module 32 and non-secure data modules 28A and 28B of hub 10 may send, via port 12C, the first data packet and the second data packet to the host device. The respective data modules may forward the respective data packets to host device 4 either upon receipt of the respective data packets or after the respective data packets have been processed. In other words, the respective data modules may not necessarily forward the first data packet and the second data packet simultaneously, but instead forward the first data packet and the second data packet after the respective data modules determines the respective data packet to be safe to forward to the host device in the respective data packet's own respective processing loop. The timing with which non-secure data modules 28A and/or 28B forward the first data packet is independent of the timing with which secure data module 32 forwards the second data packet.
In some examples, modules 28A, 28B, and 32 may simply forward the first data packet and the second data packet to the host device upon receiving the respective data packets. In other examples, as described above, modules 28A and 28B may implement some form of guard process to evaluate the first data packet received from the non-secure client device. Upon determining that the first data packet meets a threshold level of integrity, non-secure data modules 28A and 28B may forward the first data packet to the host device via port 12C. In still other instances, secure data module 32 may process certain information regarding the second data packet (e.g., sender information or content information) prior to forwarding the second data packet to the host device.
In some examples, non-secure data module 28A or 28B of hub 10 may receive an outgoing message to be sent to the non-secure client device. For instance, the host device may attempt to send an ACK message to the UAV. In some instances, non-secure data modules 28A and 28B of hub 10 may prevent all outgoing traffic from reaching non-secure client device 8A. In such examples, non-secure data module 28A or 28B of hub 10 may receive an outgoing message to be sent to the non-secure client device. Upon determining that the intended recipient of the outgoing message is a non-secure client device (e.g., the UAV), non-secure data module 28A or 28B of hub 10 may refrain from sending the outgoing message to the non-secure client device so as to protect the integrity of the secured system.
In other examples, hub 10 may forward the ACK message to the non-secure client device. Prior to forwarding the ACK message, non-secure data module 28A or 28B of hub 10 may scan the outgoing message to determine whether the outgoing message contains secure information that would be improper for a non-secure client device to receive based on various security protocols that hub 10 must operate within. In response to determining that the outgoing message does not contain secure information, non-secure data module 28A or 28B of hub 10 may send the outgoing message to the non-secure client device via port 12A. However, in response to determining that the outgoing message contains secure information, non-secure data module 28A or 28B of hub 10 may refrain from sending the outgoing message to the non-secure client device so as to protect the integrity of the secured system.
In some other examples, rather than waiting for the host device to produce and send ACK messages, virtual machine 18A may utilize proxy modules 20 and 24 to produce an ACK message. If non-secure data module 28A or 28B still receives the ACK message from the host device, guards 22A or 22B may block the received ACK message and utilize a proxy module to produce an ACK instead. For instance, if the first data packet was part of a TCP message, non-secure data module 28A may utilize the proxy modules 20 and 24, as described below, to create an ACK message and send the ACK message to the non-secure client device. By enabling hub 10 to create the ACK messages, outgoing communication from the host device to the non-secure client device is further limited or prevented. In creating a separate ACK message at ProxyL 20, hub 10 may maintain a one-way communication between the host device and the non-secure client device, as the non-secure client device will not receive any data created by the host device.
Depending on the final needs and requirements of the solution, both virtual machines 18A and 18B may be used as configurable options in addition to more or different types of flow controls. In the example of
Virtual machine 18B shows a simpler filtering technique that only includes guard 22B and does not mimic the TCP ACKs. In this example, traffic may flow both from the non-secure client device to the host device and from the host device to the non-secure client device. As such, the host device may generate the TCP ACK messages, which hub 10 may forward to the non-secure client device. Guard 22B may implement the same or more virus detection, deep packet inspection and other safeguards guard 22A.
In some examples, the cross-domain system in
One method of achieving this redundancy and security is to include filter plug-in 300 into, for example, virtual machine 18A (or any virtual machine of a set of virtual machines that handle traffic flows from non-secure client devices to the secure end-user device). Filter plug-in 300 may be a software module that may be included in hub device 10 and executed by virtual machine 18A to perform the various filter operations described above.
Each of extensive markup language (XML) filter set 302, video filter set 304, and joint variable message format (JVMF) filter set 306 may include a plurality of filters that each execute the filter for the data type the filter is designed for. For instance, XML filter set 302 may include two or more filters that each perform the same filtering operations for all XML data traffic flowing from a non-secure client device to a secure end-user client device, providing redundant and unavoidable security for the XML traffic. Similarly, video filter set 304 and JVMF filter set 306 may perform the same filtering operations for all video data traffic and all JVMF data traffic, respectively, flowing from a non-secure client device to a secure end-user client device, providing redundant and unavoidable security for the video and JVMF traffic.
In other examples, the redundancy and security may be replicated by instead incorporating multiple virtual machines into the data path, with each virtual machine containing similar components and performing similar functions. For instance, in the example of
The various filters may be responsible for deep content inspection and sanitization. The inspection may be based on a full understanding of the syntactic structure and the semantic meaning of the various file formats. The filters may also verify that the submitted files are of the correct type and ensure that the data conforms with various format specifications. Based on defined policies, the filters may verify that the files do not contain any suspect, hidden, or malicious content. In the sanitization process, the filters may, based on defined policies, sanitize (e.g., clear or modify) the file's content of any suspect, hidden, or malicious content using a new file or template.
The filters may also randomize files of internal structure. For instance, based on known file structures, the filters may obfuscate and mix up/reorder data in the files. In doing so, the filters do not rely on signatures or knowledge of previous attacks. Further, the resulting file is typically close to the original file with only minimal damage or changes. This process is a reliable mechanism for valid text extraction for word searching and is difficult to trick.
The filters may also perform format conversion, transforming files and data using defined policies. The filters may also transliterate files and data using defined policies (e.g., convert from one character set encoding to another). The filters may further convert a file to a related format, then convert the file back to the original file format (e.g., PDF to postscript and then back to PDF). In doing so, the filters can disrupt malware by altering the file, remove unwanted or risky feature in the conversion process, and remove hidden data when layers are removed.
The filters may also perform a canonicalization process, which converts content from a specialized form to a standardized (e.g., canonical) or raw form. In doing so, there is no loss of fidelity in the data during the canonicalization process, and the filters can remove malware, malware C2 communications, and data exfiltration through some types of covert channels. The filters may also use the canonicalization process as a protocol break that works very well for imagery, video, and audio.
The filters may further perform a flattening process, or converting to another file/protocol which is less complex. This is effective in removing data attacks and can reduce data hiding attacks (by removing layers). If the filters use recursion and decomposition in the flattening process, complex documents (e.g. PDF documents) and container file formats (e.g. ZIP files) that are made of various files each may be handled individually. The decomposition process extracts files (e.g. images/objects) or content (e.g. text), and the filter sends decomposed objects recursively through the filter pipeline for additional deep content inspection and sanitization. Filters may set limits on the amount of recursion to prevent resource exhaustion attacks.
One option for controlling the outgoing traffic to non-secured client devices 54 and 56 is for guard 22C (similar to guards 22A and 22B of
Contrast this with the “bump-in-the-wire” approach. In this option, guard 22C would be implemented as a respective intermediary on each of the connections between non-secured client devices 54 and 56 and hub 10 to allow traffic to flow in only one direction (i.e., from the non-secure client devices 54 and 56 to hub device 10). Each of the guards would need to be configured independently, as there may not be a common interface for network devices 58A and 58B. Further, a separate guard would be needed for each and every potential connection with a non-secure client device, further increasing the complexity and variability of the overall system.
Another contrasting example to the example of
In the example of
Hub sleeve 62 may generally include any mechanism for attaching a hub device, such as hub 10, to the body, clothing, or uniform of a user, or to host 4 itself. Hub sleeve 62 may also include an external CPU that may connect to host 4 rather than hub 10, which is a separate device. However, hub sleeve 62 may still perform the same functions of hub 10, including connecting to multiple devices, both secured and non-secured, and perform particular guard processes on the received non-secured data packets, in accordance with the techniques described throughout this disclosure.
In the example of
In another example, the guard functionalities may be implemented in an advanced CPU within hub sleeve 62 operably connected to host device 4. In such an example, hub sleeve 62 may add more ports to host device 4 and may enable host device 4 to have a fully capable dual stack. As such, the functionality of hub device 10 may be split between hub device 10 and hub sleeve 62. Hub device 10 may process all data packets coming from devices 50 and 52 in the secure domain, and hub sleeve 62 may process all data packets coming from devices 54 and 56 in the non-secure domain.
The example of
In the example of
By using a non-secure end-user device directly connected to the hub device, hub devices 902A-902C may utilize non-secure radios to transmit the data rather than only using secure radios to transmit the data across the secure networks 904A-904B. Another benefit of the having non-secure end-user client devices 910A-910B directly connected to the hub devices is the ability to create a High-assurance Tunnel to “tunnel” low-side data over the high-side communications network. Hub devices 902A-902B would work at the frontlines, with hub device 902C in the rear-echelon to provide two end-points to a VPN-like tunnel. As packets enter this tunnel, from either end of the non-secure network, hub devices 902A-902C tag the data packets with a cryptographically signed message hash (i.e., message authentication code) such that message integrity and authenticity can be verified by the receiving end-user device. Before entering secure networks 904A-904B, the data packets may also pass through the cross-domain filters.
In accordance with the techniques of this disclosure, processors 14 of hub 10 may receive, via port 12A, a first data packet from non-secure client device 8A (100). Processors 14 of hub 10 may then perform a first guard process on the first data packet (110). Based on results of the first guard process indicating that the first data packet is valid, processors 14 may send the first data packet to host 4 via port 12C (120).
In some examples, based on the sender of the respective data packet, processor 14 may perform separate guard processes on the respective data packet. For instance, processors 14 may execute a separate virtual machine in hub 10, with the virtual machine performing a first guard process on the first data packet based on the security classification of non-secure client device 8A (i.e., non-secure or untrusted) and a second virtual machine performing a second guard process on the second data packet based on the security classification of secure client device 6A (e.g., a secure security classification, such as secret, top secret, classified, or protected).
For the first guard process, processors 14 of hub 10 may utilize the separate virtual machine to determine an integrity of the first data packet based at least in part on a type of connection between hub 10 and non-secure client device 8A and a data type of the first data packet. In other words, the data packet may have a different structure depending on the type of data stored within the data packet and the protocol used to transmit the data packet to hub 10. As such, the specific method for determining the integrity of the first data packet may vary based on the expected structure of the first data packet. If the virtual machine determines that the integrity of the first data packet is above a threshold integrity level, processors 14 may send the first data packet to host 4 via port 12C.
Part of the integrity check may include processors 14 utilizing the separate virtual machine to determine that the actual structure of the first data packet matches an expected structure based on the type of data stored within the data packet and the protocol used to transmit the data packet to hub 10. For instance, if non-secure client device 8A sends an image file over a USB connection, hub 10 may expect the first data packet to have a particular structure with particular bitfields filled out in particular ways. The virtual machine may determine that the first data packet passes the integrity check if the bitfields match the expected structure.
Another part of the integrity check may include processors 14 utilizing the separate virtual machine to perform a virus scan operation on the first data packet. The virus scan operation may include comparing certain values within the data packet to known virus or malware structures. If the virtual machine determines that the first data packet contains a virus or malware, then processors 14 may block the first data packet from reaching host 4. Conversely, if processors 14 determines that the virus scan operation shows no harmful data in the first data packet, processors 14 may forward the first data packet to host 4 via port 12C.
Processors 14 of hub 10 may receive, via port 12B, a second data packet from secure client device 6A (130). Processors 14 of hub 10 may then perform a second guard process on the second data packet (140). Based on results of the second guard process indicating that the second data packet is valid, processors 14 of hub 10 may send, via port 12C, the second data packet to host 4 (150).
For the second guard process, in some instances, processors 14 may simply forward the second data packet to host 4 via port 12C. In other instances, for the second guard process, processors 14 may analyze contents of the second data packet to determine an identity of the sender of the second data packet or the type of contents in the second data packet prior to forwarding the second data packet to host 4 via port 12C. As the second data packet may come from a secure and trusted client device, processors 14 may refrain from determining an integrity of the received data and performing a virus scan operation on the second data packet, instead only verifying that the second client device is a verified secure client device.
Port 12C may forward the respective data packets to host 4 either upon receipt of the respective data packets or after the respective data packets have been processed. In other words, port 12C may not necessarily forward the first data packet and the second data packet simultaneously, but instead forward the first data packet and the second data packet after processors 14 determines the respective data packet to be safe to forward to host 4 in the respective data packet's own respective processing loop. The timing with which processors 14 forward the first data packet is independent of the timing with which processors 14 forward the second data packet.
In some examples, processors 14 may simply forward the first data packet and the second data packet to host 4 upon receiving the respective data packets. In other examples, as described above, processors 14 may implement some form of guard process to evaluate the first data packet received from non-secure client device 8A. Upon determining that the first data packet meets a threshold level of integrity, processors 14 may forward the first data packet to host 4 via port 12C. In still other instances, processors 14 may process certain information regarding the second data packet (i.e., sender information or content information) prior to forwarding the second data packet to host 4.
In some examples, processors 14 of hub 10 may receive an outgoing message to be sent to non-secure client device 8A. For instance, host 4 may attempt to send an ACK message to non-secure client device 8A. Prior to forwarding the ACK message, processors 14 of hub 10 may scan the outgoing message to determine whether the outgoing message contains secure information that would be improper for a non-secure client device to receive. In response to determining that the outgoing message does not contain secure information, processors 14 of hub 10 may send the outgoing message to non-secure client device 8A via port 12A. However, in response to determining that the outgoing message contains secure information, processors 14 of hub 10 may refrain from sending the outgoing message to non-secure client device 8A so as to protect the integrity of the secured system.
In some other examples, rather than expecting host 4 to produce and send ACK messages, processors 14 may utilize a proxy module to produce an ACK message. For instance, if the first data packet was part of a TCP message, processors 14 may utilize the proxy module to create an ACK message and send the ACK message to non-secure client device 8A.
In other examples, processors 14 of hub 10 may prevent all outgoing traffic from reaching non-secure client device 8A. In such examples, processors 14 of hub 10 may receive an outgoing message to be sent to non-secure client device 8A. Upon determining that the intended recipient of the outgoing message is a non-secure client device (i.e., non-secure client device 8A), processors 14 of hub 10 may refrain from sending the outgoing message to non-secure client device 8A so as to protect the integrity of the secured system.
By way of example, and not limitation, such computer-readable storage media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage, or other magnetic storage devices, flash memory, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. It should be understood, however, that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but are instead directed to non-transient, tangible storage media. Disk and disc, as used, includes compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.
Instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Accordingly, the term “processor,” as used may refer to any of the foregoing structure or any other structure suitable for implementation of the techniques described. In addition, in some aspects, the functionality described may be provided within dedicated hardware and/or software modules. Also, the techniques could be fully implemented in one or more circuits or logic elements.
The techniques of this disclosure may be implemented in a wide variety of devices or apparatuses, including a wireless handset, an integrated circuit (IC) or a set of ICs (e.g., a chip set). Various components, modules, or units are described in this disclosure to emphasize functional aspects of devices configured to perform the disclosed techniques, but do not necessarily require realization by different hardware units. Rather, as described above, various units may be combined in a hardware unit or provided by a collection of interoperative hardware units, including one or more processors as described above, in conjunction with suitable software and/or firmware.
It is to be recognized that depending on the embodiment, certain acts or events of any of the methods described herein can be performed in a different sequence, may be added, merged, or left out altogether (e.g., not all described acts or events are necessary for the practice of the method). Moreover, in certain embodiments, acts or events may be performed concurrently, e.g., through multi-threaded processing, interrupt processing, or multiple processors, rather than sequentially.
In some examples, a computer-readable storage medium may include a non-transitory medium. The term “non-transitory” indicates that the storage medium is not embodied in a carrier wave or a propagated signal. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in RAM or cache).
Various examples of the disclosure have been described. Any combination of the described systems, operations, or functions is contemplated. These and other examples are within the scope of the following claims.
This application claims the benefit of U.S. Provisional Application No. 62/489,320, filed Apr. 24, 2017, the entire content of which is incorporated herein by reference.
This invention was made with Government support under Contract W91CRB-17-C-0026 awarded by the United States Army. The Government may have certain rights in this invention.
Number | Name | Date | Kind |
---|---|---|---|
7669235 | Hunt et al. | Feb 2010 | B2 |
8561142 | Sobel | Oct 2013 | B1 |
8970348 | Evans et al. | Mar 2015 | B1 |
9419799 | Chung | Aug 2016 | B1 |
9524399 | Takahashi | Dec 2016 | B1 |
9858441 | Brown et al. | Jan 2018 | B2 |
10091230 | Machani et al. | Oct 2018 | B1 |
10164974 | Spencer et al. | Dec 2018 | B2 |
20020069369 | Tremain | Jun 2002 | A1 |
20040003284 | Campbell | Jan 2004 | A1 |
20040044902 | Luthi | Mar 2004 | A1 |
20050198412 | Pedersen | Sep 2005 | A1 |
20070192585 | Briancon | Aug 2007 | A1 |
20080289027 | Yariv | Nov 2008 | A1 |
20090064309 | Boodaei | Mar 2009 | A1 |
20090077375 | Anspach | Mar 2009 | A1 |
20140119727 | Ousley | May 2014 | A1 |
20140157381 | Disraeli | Jun 2014 | A1 |
20140304773 | Woods et al. | Oct 2014 | A1 |
20150161370 | North et al. | Jun 2015 | A1 |
20150281225 | Schoen et al. | Oct 2015 | A1 |
20150363582 | Sheller et al. | Dec 2015 | A1 |
20160233946 | Wengrovitz et al. | Aug 2016 | A1 |
20160241523 | Ahn et al. | Aug 2016 | A1 |
20170193211 | Blake et al. | Jul 2017 | A1 |
20170242995 | Bassenye-Mukasa et al. | Aug 2017 | A1 |
20180041475 | Rai | Feb 2018 | A1 |
20180054312 | Kamal | Feb 2018 | A1 |
20180095900 | Sarangdhar et al. | Apr 2018 | A1 |
Entry |
---|
“A Heart to my Key,” economist.com., economist.com, May 9, 2013, 4 pp. |
“Joint Tactical Radio System,” Wikipedia, retrieved from https://en.wikipedia.org/wiki/Joint_Tactical_Radio_System, Jan. 18, 2018, 9 pp. |
“Multi-Factor Authentication,” Wikipedia, retrieved from https://en.wikipedia.org/wiki/Multi-factor_authentication, on Jan. 18, 2018, 8 pp. |
“NYMI Band: Product Overview,” NYMI, retrieved from https://nymi.com/product_overview, on Jan. 18, 2018, 2 pp. |
“Technavio Says Global EEG and ECG Biometrics Market Will Reach $42.14 Million by 2020,” Techanvio.com, Apr. 7, 2016, 2 pp. |
Keller, “ATCorp to build SWaP-Optimized Airborne Networking Router Prototypes for Carrier-Based Aircraft,” Military and Aerospace Electronics, Jan. 19, 2017, 4 pp. |
Lugovaya, “Biometric Human Identification Based on ECG,” physionet.org, 2005 (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2005, is sufficiently earlier than the effective U.S. filing date, 2018, so that the particular month of publication is not in issue.) 9 pp. |
“Using Phase III,” Equipping the Warfighter with Small Business Ingenuity, Phase III Desk Reference, vol. 1.0, 2016 (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2016, is sufficiently earlier than the effective U.S. filing date, 2017, so that the particular month of publication is not in issue.) p. 16. |
“Military Communications Market Worth USD 40.82 Billion by 2020,” MarketWatch, Sep. 11, 2015, 2 pp. |
“Military Tablet Wars: Windows Gaining on Apple,” Kiosk Industry, Feb. 27, 2016, 1 pp. |
“Harris Still in Neutral Zone,” Zacks Equity Research, Feb. 13, 2012, 2 pp. |
De Renesse, “Virtual Digital Assistants to Overtake World Population by 2021,” informa.com, May 17, 2017, 3 pp. |
“Gartner Says Worldwide Information Security Spending will Grow 7 Percent to Reach $86.4 Billion in 2017,” gartner.com, Aug. 16, 2017, 4 pp. |
U.S. Appl. No. 15/866,046, filed Jan. 9, 2018, by Charan et al. |
U.S. Appl. No. 15/866,097, filed Jan. 9, 2018, by Bonney et al. |
U.S. Appl. No. 15/870,492, filed Jan. 12, 2018, by Burnett et al. |
Number | Date | Country | |
---|---|---|---|
62489320 | Apr 2017 | US |