Information Associations for Multi-Domain Applications
John Shield, Samuel Chenoweth, Patrick Prendergast, Mark Beaumont, Chris North, Bradley Hopkins · Proceedings of the Australasian Computer Science Week Multiconference · 2019
Multiple Independent Levels of Security (MILS) architectures provide strong information security through separation and isolation of security domains. This architecture is useful in environments where sensitive information needs to be tightly controlled at varying levels of security, e.g., in miltary environments that support multiple classifications for data. A drawback of MILS architectures is impaired functionality caused by information partitioning resulting in an inability to easily share and aggregate information. Cross domain solutions facilitate data transfer between security domains to overcome these limitations, often at the expense of security and resulting in duplication and/or reclassification of data. We describe an alternate approach to improving functionality in MILS architectures based on Information Associations, these are design patterns that allow information on different security domains to be linked together, without having to transfer data and instead rely on coordination between the separate domains. A military case study is described that uses these design patterns to limit cross domain transfers, whilst increasing overall functionality, and ultimately creating a more secure MILS architecture.