Researchers Map Path to Software Data Segregation

Modern communication networks can simultaneously support multiple levels of data sensitivity without compromising security. The System of Knowledge details a transition from physically isolated network architectures, traditionally used in voice communications, to software-based methods for segregating information domains by integrating systems security with advanced networking and encryption techniques. By assessing technologies like Software-Defined Networking and Separation Kernels, it supports development of scalable, high-assurance voice communication systems suitable for diverse operational environments.

Voice communication is shifting from physically separate networks towards more adaptable software solutions. These advancements consolidate existing knowledge, providing a foundation for building the next generation of communications infrastructures used in defence, emergency services, and essential public utilities. Researchers at RMIT University and C4i Pty Ltd characterised technologies like Software-Defined Networking and Separation Kernels to enable scalable data segregation without compromising security assurances.

The work addresses growing demands for flexible yet secure real-time coordination within increasingly complex operational environments. Traditionally, voice communications relied upon physically isolated ‘Red/Black’ architectures; imagine two entirely separate telephone networks, one for unclassified information and another exclusively for top secret conversations, but these hardware solutions present challenges in scaling to meet the demands of increasingly complex operations.

The team is characterising a shift towards software-based Multi-Domain Data Segregation (MDDS), creating secure ‘rooms’ within a single network where sensitive data remains protected from other areas. It consolidates existing knowledge regarding technologies like Software Defined Networking and Separation Kernels, paving the way for more adaptable systems suitable for defence, emergency services, and critical infrastructure.

Refining secure communication literature reveals advancements in software defined multi domain data

A systematic review initially identified 2741 papers relating to secure communication systems; rigorous filtering reduced this number to eighty relevant publications, representing over ninety-seven percent reduction. This substantial refinement proved necessary given the breadth of initial search results and the need for highly focused evidence regarding software-based Multi-Domain Data Segregation (MDDS). Reliance upon physically isolated networks previously limited interoperability, but MDDS now enables seamless data exchange across multiple security domains within a single infrastructure. Technologies such as Software Defined Networking and Separation Kernels enable scalable segregation without compromising assurances formerly achievable only through hardware isolation.

Researchers carefully categorised the initial 2741 papers retrieved from databases including IEEE Xplore, Springer Link, Scopus, Web of Science and ACM Digital Library; ultimately identifying forty-eight publications within IEEE Xplore itself relevant to secure communication systems. A significant 1830 papers originated from SpringerLink demonstrating its prominence in this field while eighty formed the final dataset after applying strict inclusion criteria regarding primary research and accessibility.

These works were organised across six subsections encompassing areas like Software Defined Networking and foundational security assurance concepts; title screening alone excluded over half, specifically 515 titles, based on established exclusion rules. Despite rigorous filtering, included studies currently lack practical implementation or validation beyond conceptual frameworks, indicating a need for further work towards real-world deployment within complex operational environments.

Dynamic Network Partitioning via Programmable Interfaces

This investigation underpinned by Software-Defined Networking enabled dynamic control over network behaviour through programmable interfaces. Centralised software applications managed how network resources were allocated and secured rather than configuring each networking device individually. This approach created virtual networks, akin to secure ‘rooms’ within a computer network, allowing isolation of traffic based on sensitivity levels without relying solely on physical separation like traditional Red/Black architectures which imagined two entirely separate telephone networks for classified versus unclassified data.

Abstracting the underlying hardware allowed rapid provisioning and reconfiguration of these isolated pathways, adapting quickly to changing operational needs while supporting multiple security domains simultaneously. The team assessed Software-Defined Networking, Network Slicing, Separation Kernels, and Cross-Domain Solutions to achieve Multi-Domain Data Segregation without physical separation; this work addresses emerging threats including those posed by quantum computing through implementation of Post-Quantum Cryptography techniques alongside existing cryptographic standards.

Previously used physically separated ‘Red/Black’ networks relied upon complete hardware duplication limiting scalability and flexibility. Achieving both interoperability and strong assurance is vital for modern operations facing increasingly sophisticated cyberattacks requiring adaptable network architectures.

Virtualisation struggles to match physical separation for high assurance data segregation

Modern operations increasingly demand seamless communication between different secure environments; however, relying solely on physically isolated systems presents escalating challenges regarding scalability and interoperability as requirements evolve. Analysis reveals that software-based Multi-Domain Data Segregation offers potential flexibility through technologies like Software Defined Networking but establishing equivalent security assurances remains an open question. A lack of demonstrative implementations proving these virtualised approaches genuinely replicate the strong guarantees offered by hardware isolation in real-world deployments under stress is particularly notable.

Acknowledging this unproven durability does not diminish the importance of this work; it clarifies precisely where further research must focus. This System of Knowledge establishes a consolidated understanding of transitioning voice communication systems from physically isolated architectures towards flexible, software-based MDDS. The systematic review identified over two thousand papers and highlighted key technologies such as Separation Kernels as enablers for scalable security without complete hardware duplication. By integrating expertise in systems security, networking, and cryptography, this work clarifies how modern operations can balance interoperability with robust data protection across increasingly interconnected domains. NATO uses a five-tier classification system detailed within the paper highlighting its relevance to international standards while analysis reveals that demonstrably achieving equivalent assurance to traditional methods remains an ongoing research priority.

This System of Knowledge demonstrated potential benefits when transitioning voice communication systems from physically separated architectures to software-based Multi-Domain Data Segregation. It establishes that Software Defined Networking and technologies like Separation Kernels may enable scalability without entirely replicating existing hardware infrastructure. The review of over two thousand papers highlights challenges in proving virtualised approaches offer comparable security assurances to physical isolation under operational stress, which is identified as a key area for future work. This characterisation supports development of adaptable network architectures balancing interoperability with robust data protection across diverse domains.

👉 More information
🗞 SoK: Secure Software-Based Multi-Domain Data Segregation
✍️ Quang Cao, Peter Vinci, Nick Georghiou, Shane Phillips, Mathieu Philippe and Nalin Arachchilage
🧠 ArXiv: https://arxiv.org/abs/2609.07701

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Muhammad Rohail T.

Latest Posts by Muhammad Rohail T.: