Visible to the public The Cross Domain Desktop Compositor: Using Hardware-based Video Compositing for a Multi-level Secure User Interface

TitleThe Cross Domain Desktop Compositor: Using Hardware-based Video Compositing for a Multi-level Secure User Interface
Publication TypeConference Paper
Year of Publication2016
AuthorsBeaumont, Mark, McCarthy, Jim, Murray, Toby
Conference NameProceedings of the 32Nd Annual Conference on Computer Security Applications
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4771-6
KeywordsCollaboration, composability, Human Behavior, information assurance, Metrics, pubcrawl, Resiliency, Scalability
Abstract

We have developed the Cross Domain Desktop Compositor, a hardware-based multi-level secure user interface, suitable for deployment in high-assurance environments. Through composition of digital display data from multiple physically-isolated single-level secure domains, and judicious switching of keyboard and mouse input, we provide an integrated multi-domain desktop solution. The system developed enforces a strict information flow policy and requires no trusted software. To fulfil high-assurance requirements and achieve a low cost of accreditation, the architecture favours simplicity, using mainly commercial-off-the-shelf components complemented by small trustworthy hardware elements. The resulting user interface is intuitive and responsive and we show how it can be further leveraged to create integrated multi-level applications and support managed information flows for secure cross domain solutions. This is a new approach to the construction of multi-level secure user interfaces and multi-level applications which minimises the required trusted computing base, whilst maintaining much of the desired functionality.

URLhttp://doi.acm.org/10.1145/2991079.2991087
DOI10.1145/2991079.2991087
Citation Keybeaumont_cross_2016