Security

Safe Connections Across Different Security Levels…From the Basics of CDS to Its Applications

IT DAILY ·

Professor Lee Deok-gyu of Seowon University speaks on the topic of “CDS Concepts and Detailed Operations” at the “CDS Workshop 2026” held on the 10th at the Korea Science and Technology Convention Center in Gangnam-gu, Seoul. [Photo: Kim Ho-joon, reporter]

✦ AI Summary

When domains with different security levels exchange information, both blocking confidential leaks and preventing malicious data from flowing in are necessary, and Cross Domain Solution (CDS) is proposed as the technology for this purpose.

CDS has been newly added to the official guidelines of the National Network Security System (N2SF), and its value is expanding as the focus of security shifts from networks to data.

The CDS research group of the Korea Information Security Association held the "CDS Workshop 2026" at the Science and Technology Convention Center in Gangnam District, Seoul, on the 10th to introduce the concept and direction of CDS technology.

To exchange information between domains with different security levels, it is necessary to simultaneously block confidential leaks and prevent malicious data from flowing in as an information-sharing challenge, and differentiated control standards are required between domains with different security levels. In addition, to protect data and systems, it is necessary to verify and control the scope of information that can be accepted and disclosed, and Cross Domain Solution (CDS) has been proposed as a technology that meets these needs. CDS has been newly added to the official guidelines of the National Network Security System (N2SF), and its value is expanding as the focus of security shifts from networks to data.

However, since CDS is still an unfamiliar concept to many, the CDS research group of the Korea Information Security Association will hold the "CDS Workshop 2026" at the Science and Technology Convention Center in Gangnam District, Seoul, on the 10th. The event aims to introduce the concept and direction of CDS technology.

On the 10th, Lee Deok-gyu, a professor at Seowon University, gave a presentation titled "CDS Concepts and Detailed Operations" at the "CDS Workshop 2026" held at the Science and Technology Convention Center in Gangnam District, Seoul.

CDS is a mechanism for controlling information access and transfer between domains with different security and trust levels. CDS has criteria for classifying types, and by usage it is divided into "Access" and "Transfer." "Access" allows only viewing, while "Transfer" moves data objects. By communication direction, it is classified into "one-way" and "two-way."

The professor explained that CDS plays a role in protecting the process of sending and receiving data in environments where external connections are not freely allowed. He also said CDS is distinct from simple policy controls or data filtering.

Professor Lee Deok-gyu of the Department of AI Software at Seowon University explained that "outbound transfer," which refers to data leaving an organization, and "inbound transfer," which refers to data entering it, have different security requirements. He then said CDS is needed as a means of responding to those differences in security requirements.

The professor said that because the internal space is already under access and usage control, the key in outbound transfer is determining the permissible scope of disclosure, and confidentiality is critical. In contrast, inbound transfer involves untrusted external data entering the system, so safety and integrity verification procedures are necessary. He added, however, that outbound and inbound transfer cannot be fully separated.

For that reason, the professor said outbound transfer requires minimizing the scope of disclosure, and that new execution paths and leak paths can arise even after information has been reprocessed. He explained that a structure is needed to recheck each time such a path appears. On the inbound side, he added, data must be used for limited purposes even after verification is complete, and the purpose is to reduce internal impact.

He explained that the nature of bidirectional internal-external data communication lies in the intersection of confidentiality and integrity. Accordingly, policy control based on a single path is insufficient, and CDS is necessary, he emphasized. He also said CDS is difficult for the general public to understand, but it becomes a little easier to grasp if one sees it as an entity that enforces permitted information flows to the end.

The professor emphasized careful internal control within CDS. He explained that even the same message can allow secrets to be inferred depending on transmission time, message size, and order. He suggested checking observable information flows from outside along with content inspection. He also noted that management paths, such as policies and updates, need to be protected together with data paths.

On the 10th, Park Jung-soo, a professor in the School of Computer Engineering at Kangnam University, gave a presentation titled "CDS Technology in a Mobile Environment" at the "CDS Workshop 2026" held at the Science and Technology Convention Center in Gangnam District, Seoul. Professor Park Jung-soo of Kangnam University introduced ways to apply CDS in mobile environments.

Professor Park explained that CDS is needed for data communication between different security domains. He pointed out that most CDS equipment is a fixed structure designed to prioritize security. The CDS equipment he examined was the size of a server rack. He also said CDS equipment has constraints in installation and operation environments.

The subtitle was the expansion of the application scope from large equipment to mobile devices. The person in the photo is Professor Park Jung-soo of Kangnam University. The photo credit reads Reporter Kim Ho-jun.

Overseas, research continues toward making CDS smaller to suit mobile device environments. That is because it is difficult to use existing centralized CDS equipment in mobile devices such as tactical vehicles and drones. In the past, there were cases in which a communication structure using VPN was built to use CDS on smartphones. However, in that structure, data concentration can occur, which in turn may lead to inspection load and bottlenecks.

The issue of data communication between domains with different security and trust levels is not limited to military environments. Professor Park cited the case of a parking management worker to emphasize the need for mobile CDS technology. He explained that photos taken for parking management are stored in the Work area of an Android Enterprise device, and that processing those photos requires connecting the device to a computer via USB and performing separate work. He also said that even on the same device, photos in the Work area cannot be moved to the Personal area.

Professor Park's lab is studying a structure that places a Guard between the Work and Personal areas of an Android device. The research separates the Work and Personal areas on Android devices and checks data moving between the two areas with a Guard. The Work area is configured with a high security level, and the Personal area with a lower security level.

Data transferred between the two areas is verified using a Guard inspection method. In this process, file content inspection is handled by the Guard, while policy integrity verification, which checks whether the Guard usage policy has been tampered with, is handled by the hardware-based Trusted Execution Environment (TEE). This design is intended to reduce the processing burden of sending the entire file to the TEE for inspection.

In lab experiments, Professor Park said it took about 1.9 seconds for a process including inspection and policy verification on a file of about 8 megabytes (MB). The research team implemented a function that allows delivery of normal PDFs and also implemented a function that blocks PDFs containing execution elements such as scripts. It is currently expanding the inspection items.

Professor Park explained that the current research focus is on the Android operating system (OS) environment. He added that the team plans to continue CDS-based data protection research with the goal of expanding the scope of application to small devices such as smartphones and laptops, and of implementing data protection through CDS across various devices.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241534

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.