发表机构
C4i Pty Ltd; RMIT University(C4i有限公司; 皇家墨尔本理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本SoK系统梳理从硬件隔离到软件隔离的转变,整合系统安全、网络与密码学,评估SDN、网络切片、分离内核及跨域方案,并提出后量子密码应对量子威胁,为高保证VCS架构提供基础。
AI 中文摘要
现代关键任务协调要求跨多个域的无缝通信。传统上,语音通信系统(VCS)依赖物理分离的红/黑架构来确保语音和数据隔离。虽然这些基于硬件的方法提供了强大的安全保证,并在高安全环境中仍然具有基础性地位,但随着任务参数扩展到高度动态的多域集成,它们可能引入显著的复杂性和可扩展性挑战。随着国防、应急响应和关键基础设施运营日益需要可互操作、灵活且成本高效的通信环境,人们越来越需要了解基于软件的方法能否在支持现代运营需求的同时提供同等的保证。本SoK通过整合系统安全、网络和密码学,刻画了向基于软件的多域数据隔离(MDDS)的转变。其目标是整合现有研究、识别共享架构模式,并解决下一代高保证基于软件的VCS架构面临的安全挑战。通过评估软件定义和虚拟化方法,本SoK支持开发可扩展、高保证的VCS架构,以促进跨不同运营域的安全实时协调。具体而言,本SoK考察了软件定义网络、网络切片、分离内核和跨域解决方案的安全影响,同时通过后量子密码学(PQC)应对量子计算带来的挑战。本SoK对从硬件隔离到软件隔离的转变进行了全面分析,为旨在增强关键任务运营的安全且适应性强的VCS基础设施的研究人员和行业利益相关者提供了关键基础。
英文摘要
Modern mission-critical coordination demands seamless communication across multiple domains. Traditionally, Voice Communication Systems (VCS) have relied on physically separated Red/Black architectures to ensure voice and data segregation. While these hardware-based methods provide strong security assurances and remain foundational in high-security contexts, they can introduce significant complexity and scalability challenges as mission parameters expand into highly dynamic, multi-domain integrations. As defence, emergency response, and critical infrastructure operations increasingly require interoperable, flexible, and cost-efficient communication environments, there is a growing need to understand whether software-based approaches can provide comparable assurance while supporting modern operational requirements. This SoK characterises a transition to software-based Multi-Domain Data Segregation (MDDS) by integrating systems security, networking, and cryptography. Its goal is to consolidate existing research, identify shared architectural patterns, and address the security challenges facing next-generation high-assurance software-based VCS architectures. By assessing software-defined and virtualized approaches, this SoK supports the development of scalable, high-assurance VCS architectures that facilitate secure real-time coordination across diverse operational domains. Specifically, this SoK examines the security implications of Software-Defined Networking, Network Slicing, Separation Kernels, and Cross-Domain Solutions while addressing challenges posed by quantum computing through Post-Quantum Cryptography (PQC). This SoK provides a comprehensive analysis of the shift from hardware isolation to software segregation, serving as a crucial foundation for researchers and industry stakeholders aiming to enhance secure and adaptable VCS infrastructures for mission-critical operations.