发明名称 MULTI-LEVEL SECURITY DOMAIN SEPARATION USING SOFT-CORE PROCESSOR EMBEDDED IN AN FPGA
摘要 A system and method for operating multiple security domains on one circuit card assembly, using a field-programmable gate array (FPGA) with an embedded security domain separation gate providing the MAC between multiple soft-core CPUs also embedded in the FPGA. In one embodiment, the FPGA is segregated into two or more security domains with no data paths between soft-core CPUs in each security domain except through the security domain separation gate. The security domain separation gate applies rules to any information to be transmitted between the security domains to avoid transmission of malicious content and to avoid transmission of information of a certain classification level or type to a security domain at a lower classification level or type.
申请公布号 US2016335459(A1) 申请公布日期 2016.11.17
申请号 US201514603215 申请日期 2015.01.22
申请人 RAYTHEON COMPANY 发明人 Kling Matthew T.;Hockenbury Clark B.;Bonn Jerrold L.;Bataller Susan F.;Veneziano Mark
分类号 G06F21/76;G06F21/60 主分类号 G06F21/76
代理机构 代理人
主权项 1. A system for performing operations on data in two different security domains, the system comprising a field-programmable gate array (FPGA), the FPGA comprising: a first security domain having a first classification level, the first security domain comprising: first processing circuitry anda first soft-core processor, and a second security domain having a second classification level, the second security domain comprising: second processing circuitry anda second soft-core processor, and one or more security domain separation gates connected to the first security domain and to the second security domain, the one or more security domain separation gates configured: to receive first data from the first security domain and transmit the first data to the second security domain when the first data complies with a first set of rules, andto receive second data from the second security domain and transmit the second data to the first security domain when the second data complies with a second set of rules, the only data paths between the first security domain and the second security domain being through the one or more security domain separation gates.
地址 Waltham MA US