Software methods improve secure communication across multiple domains
SoK: Secure Software-Based Multi-Domain Data Segregation
Cryptography and Security
Summary
Keeping communication safe between different groups is very important, especially for things like emergency services and defense. Traditionally, this safety came from using separate physical devices and networks, which are secure but hard to manage and scale. The authors studied software-based ways to keep data separated securely, which could be more flexible and easier to use across different communication needs. They looked at various software security tools and how new challenges like quantum computers might affect these systems. This work helps guide future development of secure, adaptable communication systems that work well in complex, real-time environments.
voice communication systemsdata segregationsoftware-defined networkingnetwork slicingseparation kernelscross-domain solutionspost-quantum cryptographymulti-domain integrationhardware isolationsoftware segregation
Authors
Quang Cao, Peter Vinci, Nick Georghiou, Shane Phillips, Mathieu Philippe, Nalin Arachchilage
Abstract
Modern mission-critical coordination demands seamless communication across multiple domains. Traditionally, Voice Communication Systems (VCS) have relied on physically separated Red/Black architectures to ensure voice and data segregation. While these hardware-based methods provide strong security assurances and remain foundational in high-security contexts, they can introduce significant complexity and scalability challenges as mission parameters expand into highly dynamic, multi-domain integrations. As defence, emergency response, and critical infrastructure operations increasingly require interoperable, flexible, and cost-efficient communication environments, there is a growing need to understand whether software-based approaches can provide comparable assurance while supporting modern operational requirements. This SoK characterises a transition to software-based Multi-Domain Data Segregation (MDDS) by integrating systems security, networking, and cryptography. Its goal is to consolidate existing research, identify shared architectural patterns, and address the security challenges facing next-generation high-assurance software-based VCS architectures. By assessing software-defined and virtualized approaches, this SoK supports the development of scalable, high-assurance VCS architectures that facilitate secure real-time coordination across diverse operational domains. Specifically, this SoK examines the security implications of Software-Defined Networking, Network Slicing, Separation Kernels, and Cross-Domain Solutions while addressing challenges posed by quantum computing through Post-Quantum Cryptography (PQC). This SoK provides a comprehensive analysis of the shift from hardware isolation to software segregation, serving as a crucial foundation for researchers and industry stakeholders aiming to enhance secure and adaptable VCS infrastructures for mission-critical operations.