Skip to main navigation Skip to search Skip to main content

Implementation of multi-domain isolation architecture and communication mechanism in Linux

  • Yuqing Lan*
  • , Jianlun Zou
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Multiple Independent Levels of Security (MILS) is widely used in the design of high assurance operating system. By separating the system into components, and making the components run in different domains, the kernel can control and monitor information flow between components to enhance the security and availability of system. However, due to the complexity and certification cost issue associate with large monolithic kernel, MILS architecture is mainly used in microkernel system. But we still want to use the idea of MILS in monolithic kernel system to improve the security. In the Linux, although there are some access control models based on the concept of domain (like SELinux). Limited by the feature of shared kernel, the security of system is affected by the vulnerabilities in itself. Therefore, this paper proposes a scheme of constructing multiple independent isolated domains based on virtualization technology in Linux. We developed on Linux kernel and QEMU/KVM hypervisor, exploiting the isolation feature brought by virtualization to achieve data isolation. We build domain from virtual machine, so that we can separate origin system into components and run them in domains. In the host, we take control of all domains and implements a secure communication mechanism between domains. By using this secure channel, we can monitor the data transmission between domains, and control the information flow according to the security level of the domain. Finally, we evaluated the effectiveness and efficiency of our communication mechanism.

Original languageEnglish
Title of host publicationThird International Conference on Computer Science and Communication Technology, ICCSCT 2022
EditorsYingfa Lu, Changbo Cheng
PublisherSPIE
ISBN (Electronic)9781510661240
DOIs
StatePublished - 2022
Event3rd International Conference on Computer Science and Communication Technology, ICCSCT 2022 - Beijing, China
Duration: 30 Jul 202231 Jul 2022

Publication series

NameProceedings of SPIE - The International Society for Optical Engineering
Volume12506
ISSN (Print)0277-786X
ISSN (Electronic)1996-756X

Conference

Conference3rd International Conference on Computer Science and Communication Technology, ICCSCT 2022
Country/TerritoryChina
CityBeijing
Period30/07/2231/07/22

Keywords

  • Multi-domain isolation
  • communication mechanism
  • virtualization

Fingerprint

Dive into the research topics of 'Implementation of multi-domain isolation architecture and communication mechanism in Linux'. Together they form a unique fingerprint.

Cite this