Noname manuscript No. (will be inserted by the editor)
SoK: Secure Software-Based Multi-Domain Data Segregation
arXiv:2609.07701v1 [cs.CR] 7 Sep 2026
Quang Cao1 · Peter Vinci2 · Nick Georghiou2 · Shane Phillips2 · Mathieu Philippe2 · Nalin Arachchilage1
Received: date / Accepted: date
Abstract Modern mission-critical coordination demands seamless communication across multiple domains. Traditionally, Voice Communication Systems (VCS) have relied on physically separated Red/Black architectures to ensure voice and data segregation. While these hardwarebased methods provide strong security assurances and remain foundational in high-security contexts, they can introduce significant complexity and scalability challenges as mission parameters expand into highly dynamic, multi-domain integrations. As defence, emergency response, and critical infrastructure operations increasingly require interoperable, flexible, and costefficient communication environments, there is a growing need to understand whether software-based approaches can provide comparable assurance while supporting modern operational requirements. This SoK characterises a transition to software-based Multi-Domain Data Segregation (MDDS) by integrating systems security, networking, and cryptography. Its goal is to consolidate existing research, identify shared architectural patterns, and address the security challenges facing next-generation high-assurance software-based VCS architectures. By assessing software-defined and virtualized approaches, this SoK supports the development of scalable, highassurance VCS architectures that facilitate secure realtime coordination across diverse operational domains. Specifically, this SoK examines the security implications of Software-Defined Networking, Network Slicing, # Quang Cao [email protected] Nalin Arachchilage [email protected]
1
RMIT University, Melbourne, Australia
2
C4i Pty Ltd, Melbourne, Australia
Separation Kernels, and Cross-Domain Solutions while addressing challenges posed by quantum computing through Post-Quantum Cryptography (PQC). As the first comprehensive synthesis of the shift from hardwareenforced isolation to software-based segregation, this SoK serves as an essential foundation for researchers and industry stakeholders seeking to advance secure, adaptable, and future-ready VCS infrastructures for mission-critical operations. Keywords Voice Communications Systems · Cross Domain Solution · Software-Defined Networking · Network Function Virtualization · Network Slicing · Separation Kernel · Air Gap
1 Introduction Modern operational environments increasingly require communication systems that can support multiple security domains simultaneously [59]. However, traditional air-gapped architectures were built around the assumption of strict physical separation and are typically limited to two domains. While these architectures provide strong security guarantees, their reliance on complex, hardware-only separation makes them costly, inflexible, and difficult to scale when meeting the efficiency demands of contemporary multi-domain operations [85]. As illustrated in Figure 1, hardware-enforced isolation relies on completely separate networks to prevent crossdomain leakage of voice data. This reliance on physical duplication often confines systems to just two security domains, revealing a notable limitation when navigating the complexities of modern environments that demand the integration of multiple, diverse security enclaves. The concept of multiple domains contains distinct security domains, defined as systems operating within
Quang Cao1 et al.
2
RED DOMAIN (Classified Network)
Secure IP Network
Radio
Telephony IP Voice Recorder
BLACK DOMAIN (Unclassified Network)
AIR GAP
Table 1 NATO security classification levels and their disclosure impact. NATO Classification
Description
COSMIC TOP SECRET (CTS)
Protects information whose disclosure would cause exceptionally grave damage to NATO.
NATO SECRET (NS)
Covers information whose disclosure would cause severe damage to NATO.
NATO CONFIDENTIAL (NC)
Applies to information whose disclosure would damage NATO’s interests.
NATO RESTRICTED (NR)
Used for information whose disclosure would be disadvantageous to NATO.
NATO UNCLASSIFIED (NU)
Refers to official NATO information that does not meet classification criteria and may be shared externally when it poses no risk to NATO.
Unsecure IP Network
Radio
Telephony IP Voice Recorder
Fig. 1 Red/Black architecture with strict air-gap isolation, ensuring complete separation between classified and unclassified domains.
specific administrative and security boundaries and governed by a standard security policy [5]. Within these boundaries, information assets are protected and managed in accordance with established security principles and procedures. This approach segments information environments based on varying trust and security obligations [5]. Each security domain is governed by a security policy that outlines information classification, release conditions, and handling requirements [28]. For example, NATO uses a five-tier classification system (see Table 1 for further details). These policies specify who can access domain-specific information and establish necessary security controls to maintain data confidentiality, integrity, and availability [28]. In practice, a security domain can refer to an organisation’s enterprise network operating under a specific classification or to an enclave within a larger network [5]. External networks, such as the public internet, are separate domains with undefined security controls, posing additional risks, such as malicious ingress, data egress, traffic interception and manipulation [5, 90, 42, 116]. The concept of security domains is crucial in designing multidomain environments. Classified information (RED) is separated from unclassified information (BLACK) to ensure sensitive data are managed in distinct systems, as shown in Figure 1 [16]. This segregation is essential for secure communications and data management, especially in military and governmental settings. As security challenges evolve, multi-domain architectures are increasingly essential to address complex risks. In this SoK, we examine potential pathways for transitioning from hardware-based isolation to softwarebased multi-domain data segregation in Voice Communication Systems (VCS), with particular awareness to balancing operational scalability and strong security
guarantees. Our study is guided by three research questions: RQ1: What software-based methods, frameworks, and architectures have been proposed to enable secure multi-domain data segregation? RQ2: What technical and operational limitations have been identified in existing software-based segregation mechanisms? RQ3: What research gaps remain, and how can they inform a future roadmap for secure VCS design? The remainder of this paper is structured as follows. Section 3 details the methodology employed for this systematization. Section 3.3 addresses RQ1 by categorizing the 80 reviewed papers into thematic groups and identifies the technical limitations pertinent to RQ2. In addressing RQ3, Section 4 synthesizes these findings into a layered architectural model for software-based multidomain systems, while also evaluating the system-level limitations of current mechanisms. Collectively, these sections highlight a significant research gap: the lack of a unified software solution for operator-centric Voice Communication Systems (VCS). Finally, Section 5 proposes a roadmap for integrated architectural frameworks and empirical validation to strike a balance between security and real-time performance.
SoK: Secure Software-Based Multi-Domain Data Segregation
3
This SoK makes three significant contributions. First, it offers a comprehensive cross-disciplinary synthesis of 80 papers across systems security, networking, cryptography, and critical infrastructure, effectively unifying previously fragmented research on various aspects of VCS security. Second, it presents a structured evaluation framework for approaches to multi-domain data segregation. Finally, it identifies key research gaps and outlines a forward-looking roadmap to facilitate the secure design of next-generation, scalable, software-based multi-domain data segregation for VCS.
Software-defined networking (SDN) improves upon traditional networks by separating the control plane from the data plane, allowing centralized management of network intelligence while switches handle traffic forwarding. Its architecture comprises three planes: the Data Plane (forwarding devices), the Control Plane (centralized controller using protocols such as OpenFlow), and the Application Plane (network applications). Through programmability and open standards, SDN minimizes vendor lock-in, streamlines network management, and improves scalability and flexibility [76,44,109, 36]. For detailed technical specifications and its architectural details, see Appendix A. Network slicing enhances virtualization by creating multiple end-to-end service-specific virtual networks over a shared physical infrastructure. Each slice operates as an independent logical network with tailored control, data, and management properties to meet specific performance, reliability, or security needs. Widely used in 5G and mission-critical systems, slicing supports diverse applications, such as ultra-reliable low-latency services and high-bandwidth media delivery, without requiring separate physical networks. Slices are instantiated from predefined templates and implemented with virtualized network functions on shared hardware. Slicing can be vertical (service-oriented), horizontal (resource partitioning), static (preconfigured), or dynamic (real-time adjustments), allowing for scalable and flexible network management [20,14,126,52]. For comprehensive information on various types of network slicing, refer to Appendix B. Separation kernels, first proposed by Rushby in 1981 [102], are minimal, high-assurance microkernels or bare-metal hypervisors that enforce strict isolation between software partitions on shared hardware, minimizing the Trusted Computing Base (TCB). Each partition operates as if on a separate machine, with controlled information flow. This architecture is a cornerstone of the Multiple Independent Levels of Security (MILS) architecture and is widely used in high-assurance domains such as avionics [98]. Their compact design enables formal verification and certification under standards such as Common Criteria EAL 5 and DO-178B/C, making them essential for safety and security critical systems [4, 132, 124,58,101,29,53]. For further details on separation kernels and comparisons, please refer to Table 9 and Appendix D. Internet Protocol Security (IPsec) is a networklayer security framework that provides confidentiality, integrity, and authentication for IP communications, primarily used in Virtual Private Networks (VPNs) [112]. It operates in two modes: transport mode, which encrypts only the packet payload, and tunnel mode, which en-
2 Background Voice Communication Systems (VCS) function as sophisticated digital switching platforms in high-pressure environments such as air traffic control and military operations [68]. They enable operators to communicate with pilots and ground crews by converting voice into digital data transmitted over IP-based networks. Each operator interacts through a dedicated workstation equipped with an user interface and headset, which connects to a distributed call control and routing infrastructure rather than a single central system. To safeguard sensitive information, VCS traditionally employ a Red/Black security architecture, where a strict physical air gap separates classified (Red) and unclassified (Black) domains (see Figure 1). This design effectively prevents unintended voice leakage, ensuring that communications remain confidential. Only a minimal amount of control data is permitted to traverse the Cross Domain Solution (CDS), where it undergoes rigorous filtering and controlled transfer. Although this model has traditionally depended on hardware-enforced isolation, current trends are shifting towards software-based and virtualized implementations, which introduce greater flexibility while also presenting evolving security challenges [16, 30, 49]. Cross Domain Solution (CDS) is a security mechanism that regulates information exchange between networks of different security levels [5]. By default, it blocks all data flow and only permits communication that complies with established security policies, ensuring confidentiality, integrity, availability, authenticity, and accountability across domains. CDS can be implemented as hardware, software, or both, commonly found in military and high-assurance environments. There are three main types: access solutions (view-only interactions), transfer solutions (controlled data movement), and Multi-Level Security (MLS) solutions (managing users and data across classification levels). Well-designed CDS architectures prevent unauthorized access and cross-domain threats while enabling interoperability [6,111,5]. For detailed information regarding CDS, see Appendix C.
Quang Cao1 et al.
4
crypts the entire IP packet [52,112]. To counter quantum threats to traditional cryptography, PQC algorithms such as Dilithium and Kyber can be integrated into IPsec, ensuring quantum-resilient communication while utilizing symmetric encryption [52]. Access control is a vital security mechanism that manages access to physical and digital resources through identification, authentication, authorization, and auditing. It includes physical controls such as locks and biometrics and logical controls such as passwords and MultiFactor Authentication (MFA). Organizations use various models such as Mandatory Access Control (MAC), Discretionary Access Control (DAC), Role-Based Access Control (RBAC), and Attribute-Based Access Control (ABAC), to meet their security needs. Effective access control is crucial for maintaining confidentiality, integrity, compliance, and protection against data breaches [40, 94]. Existing multi-domain data segregation solutions are predominantly hardware-based, relying on physical separation or duplicated infrastructure to enforce security boundaries. While effective, these approaches are costly, difficult to scale, inflexible to reconfiguration, and poorly suited to modern requirements such as rapid deployment, cloud integration, and AI-enabled processing. There remains a significant knowledge gap in understanding how software-based architectures can provide equivalent or higher assurance while improving scalability, maintainability, and adaptability. To address this gap, we undertake a systematic literature review (SLR) to examine existing software-based frameworks, architectures, methods, and techniques for data segregation, identifying their strengths, limitations, and assurance trade-offs. This evidence-driven understanding is essential to inform the design of a robust, high-assurance software-defined data segregation architecture that can meet the demands of contemporary multi-domain operational environments.
3 Systematic Literature Review This SLR aims to provide a comprehensive and critical examination of current state-of-the-art methods, frameworks, and architectures designed for secure, softwarebased multi-domain data segregation. The review methodology adheres to the guidelines established by Kitchenham and Charters, which provide a systematic and replicable framework for performing SLRs within the discipline of software engineering [62, 65,32]. Following these guidelines, the SLR was structured into three key phases: planning, conducting, and reporting.
3.1 Planning the Review In the planning stage, a structured protocol was developed comprising four key components: defining research questions, constructing search strings, identifying data sources, and determining study selection criteria. The primary purpose of this protocol was to minimise researcher bias by clearly outlining these elements prior to the execution of the SLR [62, 65, 32].
3.1.1 Defining Research Questions The formulation of research questions (RQs) is a key component of the planning stage, serving as the cornerstone that directs the entire SLR process [62, 65, 32]. To precisely address our objective of investigating secure multi-domain data segregation, we meticulously aligned our methodology with the established RQs as outlined below: Data Searching: We utilized the PICOC framework (Population, Intervention, Comparison, Outcome, Context), as outlined in Table 2, to systematically develop our search strategy. The keywords derived from each PICOC element (detailed in Table 3) were carefully selected to create search strings that effectively capture literature on software-based segregation methods (RQ1), their identified limitations (RQ2), and the broader gaps in VCS research (RQ3). Data Extraction: We developed a targeted data extraction form aimed at capturing evidence that directly addresses our research questions (RQs). Specifically, we extracted structural details of proposed software frameworks and architectures to answer RQ1, documented any explicitly stated technical or operational limitations to address RQ2, and recorded the authors’ identified future work and unresolved challenges to inform RQ3. Data Analysis: Our analysis procedures were designed to clarify the extracted data into clear answers for each research question (RQ). This included categorizing the diverse software-based mechanisms and architectures for RQ1, conducting a thematic analysis of the identified operational bottlenecks and limitations for RQ2, and synthesizing the remaining research gaps to propose a cohesive roadmap for the future design of secure VCS (RQ3). By employing the PICOC framework to structure our search strings and meticulously aligning our extraction and analysis protocols with Research Questions 1, 2, and 3, we establish a rigorously traceable and transparent SLR process [62, 65, 32].
SoK: Secure Software-Based Multi-Domain Data Segregation
5
Table 2 PICOC elements, definitions, and SLR applications [62, 65, 32].
Table 3 Keyword derivation for research questions and search strings (excluding the Comparison element) [62, 65, 32].
Element
Definition
SLR Application
Element
Population of interest in the SLR.
Software artifacts and systems handling multidomain environments.
Primary Phrase(s)
Derived Keyword(s)
Population
Population
Existing approaches addressing the core problem.
Software-based security mechanisms, architectures, design patterns, and cryptographic techniques.
Software artifacts, systems, multidomain
(”multi-domain” OR ”multi-enclave” OR ”multisecurity domain” OR ”cross-domain” OR ”multilevel”)
Intervention
Comparison
Alternative approaches used for comparison.
Baseline security mechanisms (e.g., air-gap networks).
Outcome(s)
Effects of the interventions on the population.
Security, efficiency, and flexibility of data segregation in multi-domain environments.
Security mechanisms, architectures, design patterns, cryptographic techniques
Context
Research setting or operational environment.
Networked, heterogeneous, mission-critical multidomain systems supporting real-time voice communication over redundant IP networks.
(security OR secure OR cryptograph* OR guard OR virtualization OR middleware OR TEMPEST OR emanations OR logical) AND (mechanism OR architecture OR system OR technique OR method OR approach OR software OR platform OR network OR solution OR segregat* OR separ* OR segmentation OR isolation)
Outcome(s)
Security, efficiency, flexibility, data segregation
(confidenti* OR integrity OR efficien* OR flexib* OR ”information assurance” OR agility OR reconfigurability OR classification OR ”zero trust”)
Context
Networked, heterogeneous, missioncritical, voice communication
(”command and control” OR ”military network” OR ”tactical network” OR ”battlefield network” OR ”coalition network” OR ”voice communication” OR ”heterogeneous network” OR ”voice guard”)
Intervention
3.1.2 Constructing Search Strings
The search strings used to identify relevant literature were developed based on the PICOC elements presented in Table 3. First, Primary Phrase(s) were formulated for each element according to its specific SLR focus (e.g., security mechanisms, architectures, design patterns for the intervention element). Second, these primary phrases were systematically expanded into a comprehensive list method OR approach OR software OR platform OR netof derived keywords by incorporating synonyms, related work OR solution OR segregat* OR separ* OR segmenterms, and common variations (e.g., expanding segrega- tation OR isolation) AND (confidenti* OR integrity OR tion to separation or partition). Finally, the derived key- efficien* OR flexib* OR ”information assurance” OR words were refined for database searching through the agility OR reconfigurability OR classification OR ”zero application of Boolean logic (AND / OR) and the use of trust”) AND (”command and control” OR ”military netthe asterisk (*) for stemming (e.g., segregat* to capture work” OR ”tactical network” OR ”battlefield network” different word forms). The complete set of search terms OR ”coalition network” OR ”voice communication” OR and operators is presented under the column Derived ”heterogeneous network” OR ”voice guard”) Keyword(s) in Table 3. To ensure accuracy, duplicate keywords within each 3.1.3 Identifying Data Sources element’s set were removed. The final search query was then formulated using the logical operators AND and The search was conducted up to November 20, 2025, OR, as shown below: with no specific starting date, allowing for the incluSearch string: (”multi-domain” OR ”multi-enclave” sion of all relevant studies that contained the specified OR ”multi-security domain” OR ”cross-domain” OR search terms, regardless of their publication year. The re”multi-level”) AND (security OR secure OR cryptoview covered academic databases including IEEE Xplore, graph* OR guard OR virtualization OR middleware OR SpringerLink, Web of Science, Scopus and the ACM DigTEMPEST OR emanations OR logical) AND (mechital Library. Additionally, Google was used to identify anism OR architecture OR system OR technique OR white papers and other publicly available documents
Quang Cao1 et al.
6
relevant to this field. In this SLR, we adopted a structured search strategy, as outlined in Table 4, to detail the steps undertaken in the study [62, 65, 32].
Table 4 Search Strategy. Category
Details
Academic Databases
IEEE Xplore Springer Link Scopus ACM Digital Library Web of Science
General Databases
Target Items
Journal Papers Survey Papers Conference Papers Book Chapters White Papers
Table 6 Overview of Inclusion and Exclusion Criteria Applied During SLR Study Selection [62, 65, 32].
Language
English
Publication Period
Start date not set End date: November 20, 2025
Type
3.1.4 Determining Study Selection Criteria The search execution phase involved applying the constructed search string across the selected databases to retrieve relevant literature. The resulting papers were then categorised by database, as shown in Table 5.
Table 5 SLR Search Results Categorized by Database [62, 65, 32].
(”multi-domain” OR ”multi-enclave” OR ”multi-security domain” OR ”cross-domain” OR ”multi-level”) AND (security OR secure OR cryptograph* OR guard OR virtualization OR middleware OR TEMPEST OR emanations OR logical) AND (mechanism OR architecture OR system OR technique OR method OR approach OR software OR platform OR network OR solution OR segregat* OR separ* OR segmentation OR isolation) AND (confidenti* OR integrity OR efficien* OR flexib* OR ”information assurance” OR agility OR reconfigurability OR classification OR ”zero trust”) AND (”command and control” OR ”military network” OR ”tactical network” OR ”battlefield network” OR ”coalition network” OR ”voice communication” OR ”heterogeneous network” OR ”voice guard”)
IEEE Xplore Springer Link Scopus ACM Digital Library Web of Science Total
ID
Statement
I1 I2 I3 Inclusion I4 I5 I6
Journal papers Conference papers Book chapters Survey papers Papers in computer science Papers in engineering
E1 E2 Exclusion E3 E4
Papers not written in English Duplicate papers within the search results Papers that are not primary research Papers that are not accessible
3.2 Conducting the Review 3.2.1 Literature Review Execution
Search String
Database
During this phase, several key observations were made. First, the number of retrieved studies was considerably large, mainly due to the comprehensive and detailed nature of the search string. Second, because each database search was conducted independently, duplicate records were present among the results. Finally, some papers identified through the search originated from different but potentially relevant contexts, indicating the breadth of coverage achieved by the search strategy. To ensure the relevance and quality of the selected studies, it was therefore necessary to establish and apply strict inclusion and exclusion criteria to refine and narrow down the final set of papers used for analysis, as shown in Table 6.
Date
20-11-2025
Papers 48 1830 59 771 33 2741
In November 2025, we conducted a systematic search across all digital libraries, including IEEE Xplore, SpringerLink, Web of Science, Scopus, and the ACM Digital Library, as listed in Section 3.1.3. These libraries were queried using the search terms defined in Section 3.1.2. A total of 2741 papers were screened using these criteria. Following recommendations from prior studies [13, 81], the criteria were applied iteratively across different reading stages to improve efficiency. The full screening workflow, including the number of papers included and excluded at each phase, is summarised in Table 7. After removing papers not written in English (E1), those that already met the inclusion criteria (I1–I6), and duplicates (E2), the exclusion criteria (E1–E4) were applied to titles (1399 papers), abstracts (884 papers), and the introduction and conclusion sections (316 papers). Full-text screening was then conducted on 247 papers, applying both inclusion and exclusion criteria (I1–I6 and E1–E4)
SoK: Secure Software-Based Multi-Domain Data Segregation
7
to determine the type of evidence. Ultimately, all 80 papers met the selection criteria and were included in the final dataset. In order to rigorously assess their contributions to secure, software-based multi-domain data segregation, the selected works are systematically organized and elaborated upon across six distinct subsections in Appendix E: Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Network Slicing (Section E.1); Cross-Domain, Multi-Domain, and Heterogeneous environments (Section E.2); Command, Control, and Military Systems (Section E.3); Cybersecurity, Threat Detection, and Policy (Section E.4); Secure IoT Architecture and Policy Control (Section E.5); and Foundational Security and Assurance (Section E.6).
that software-defined approaches are crucial for moving beyond rigid, traditional air-gapped architectures toward a multi-domain operational environment.
Table 7 Study selection results after applying inclusion and exclusion criteria [62, 65, 32]. Step
Criteria
Total
Incl.
Excl.
Database search
Search string
2741
–
–
Non-English removed
E1
2741
2721
20
Apply inclusion criteria
I1–I6
2721
1486
1235
Duplicates moved
E2
1486
1399
87
Title screening
E1–E4
1399
884
515
Abstract screening
E1–E4
884
316
568
Introductionconclusion screening
E1–E4
316
247
69
Full-text screening
I1–I6, E1–E4
re-
247
80
167
3.3 Reporting the Review To ensure full coverage of all 80 reviewed papers, Table 8 maps each paper to its corresponding thematic group and summarises the key gaps identified in the literature, which are further analysed in the following subsections. 3.3.1 Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Network Slicing The list of papers in the Section E.1 primarily focuses on the enabling technologies of Software Defined Networking (SDN), Network Virtualization, and Network Slicing as foundational concepts for modern and flexible network management. These papers collectively suggest
Theme 1: Foundational SDN Architectures and Principles. A significant number of studies delineate the architectural and operational foundations of SoftwareDefined Networking (SDN), emphasizing centralized control, programmability, and abstraction as essential enablers of contemporary networks. Foundational surveys and architectural analyses [44, 109,9,122, 61] elaborate on SDN layers, controller designs, and application ecosystems. Complementary research investigates controller frameworks, programmability, and optimization strategies [26, 96, 113,71, 35], illustrating how SDN facilitates scalable and multi-domain control. Earlier studies on programmable routing and network security [17] further underscore the evolution towards software-controlled infrastructures. Security-focused surveys [76,24] assess threats, attack surfaces, and mitigation strategies within SDN, while studies oriented towards Quality of Service (QoS) and performance [63] demonstrate how SDN can uphold service guarantees in dynamic environments. Collectively, these works establish SDN as a mature paradigm capable of implementing complex policies across multiple domains. Key Takeaways: SDN introduces centralized programmability, fine-grained control, and dynamic policy enforcement, serving as the fundamental enabler for transitioning from rigid, hardware-based isolation to software-defined multi-domain architectures. Theme 2: NFV, Virtualization, and Service Function Realization. Network Function Virtualization (NFV) and virtualization enhance Software-Defined Networking (SDN) by decoupling network functions from hardware. This enables flexible deployment and orchestration of services. Comprehensive reviews [12, 2] and studies focused on specific Virtual Network Functions (VNFs) [128] illustrate how these virtualized functions can be integrated, chained, and managed across distributed infrastructures. These findings emphasize the pivotal role of virtualization in promoting scalability, resource efficiency, and multi-domain isolation. Additionally, experimental and system-level studies [115,134] further confirm the viability of merging SDN and NFV within heterogeneous optical and packet networks, reinforcing their practicality in real-world applications. Key Takeaways: NFV and virtualization facilitate flexible service deployment and logical isolation, serving as foundational elements for multi-domain systems that operate over shared physical infrastructure.
Quang Cao1 et al.
8 Table 8 Summary of Reviewed Literature Theme
Covered Papers
Identified Gap
Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Network Slicing
[3, 51, 15, 127, 76, 63, 115, 134, 12, 122, 35, 9, 96, 26, 17, 113, 92, 44, 109, 71, 2, 126, 128, 117, 21, 131, 19, 22, 123, 120, 84, 36, 67, 24, 10, 61, 66, 14, 75, 43]
Lack of support for real-time, operator-centric voice communication; no mechanisms for multidomain voice mixing, per-domain transmit control, or strict non-interference guarantees.
Cross-Domain, Multi-Domain, and Heterogeneous
[129, 121, 110, 64, 78, 23, 70, 72, 25, 31, 86]
Focus on authentication, routing, and policy enforcement; lack of real-time multi-domain communication, operator interaction, and scalable bidirectional secure voice channels.
Command, Control, and Military Systems (C2/C4ISR)
[83, 73, 119, 1, 34, 80, 104, 114, 91, 108, 95, 103, 125, 75, 100, 60]
Voice communication treated as infrastructure, not operator interface; no support for simultaneous multi-domain voice interaction or secure audio isolation.
Cybersecurity, Threat Detection, and Policy
[69, 45, 82, 135, 39]
Strong foundations in identity, MLS, and cryptography, but limited to single-domain or application-level systems; no support for multidomain voice workflows or audio-level separation.
Secure IoT Architecture and Policy Control
[99, 36, 77, 57, 33]
Focus on device- and data-centric security; no support for operator-centric communication, realtime voice mixing, or domain-level audio control.
Foundational Security and Assurance
[38, 54, 107, 130]
Provide policy, isolation, and validation principles, but lack application to real-time communication systems, especially multi-domain voice and non-interference guarantees.
Theme 3: Network Slicing and 5G/6G Infrastructures. Network slicing has emerged as a vital mechanism for establishing logically isolated domains tailored to specific service requirements. Foundational and survey works [126,123,66] articulate slicing architectures, guarantees of isolation, and security considerations. Application-driven studies [21,14,15] showcase the implementation of slicing in mission-critical and healthcare scenarios, highlighting its ability to satisfy constraints related to latency, reliability, and security. Experimental validation [117] substantiates the feasibility of resource allocation within slicing environments. Furthermore, broader 5G/6G vision papers [3,127, 51] identify slicing as a fundamental capability of nextgeneration networks. Key Takeaways: Network slicing enables the creation of multiple logically isolated networks using shared infrastructure, effectively establishing virtual air gaps that support a range of applications while ensuring high performance and scalability. Theme 4: Security, Policy, and Trust Management. Numerous studies concentrate on policy enforcement, trust, and secure management within software-defined environments. Policy-based architectures [10, 120] offer mechanisms for defining and enforcing access and control rules. Security frameworks and trust-based systems [131, 19, 84, 67] illustrate how Software-Defined Networking (SDN) can incorporate security policies, Quality
of Experience (QoE), and automated management in dynamic settings. Fine-grained access control mechanisms, such as Hash Flow [22], exemplify how SDN can implement domain-specific permissions, while IoT-focused security management [36] underscores the applicability of SDN in diverse and distributed environments. Key Takeaways: Policy-driven control and security frameworks facilitate programmable enforcement of access, trust, and communication constraints, which are crucial for effectively managing interactions across multiple domains. Theme 5: Related Networking Concepts. Recent research expands the concepts of software-defined networking (SDN) and slicing to encompass wide-area and multi-domain environments. Surveys on SD-WAN [92] and multi-domain control architectures [113,71] focus on the management of geographically distributed networks. Studies centered on tactical and military applications [75,43] illustrate how SDN and slicing can facilitate mission-critical, multi-domain communication systems, emphasizing essential requirements such as resilience, interoperability, and secure coordination. Key Takeaways: The application of software-defined networking is increasingly relevant in large-scale, distributed, and mission-critical settings, showcasing its effectiveness for multi-domain operations.
SoK: Secure Software-Based Multi-Domain Data Segregation
9
Gap Analysis: A consistent conclusion emerges from the reviewed studies. Software-Defined Networking (SDN) Network Functions Virtualization (NFV) and network slicing collectively provide a solid technical foundation for logical multi-domain separation. This enables programmable control, flexible service deployment, and scalable isolation over shared infrastructure. However, the majority of these analyses primarily focus on networklevel abstractions, data flows, and service orchestration. Importantly, none of the studies address the specific requirements for secure real-time operator-centric Voice Communication Systems (VCS). Key capabilities such as simultaneous monitoring across multiple domains, per-domain transmission control, secure voice mixing, and stringent non-interference guarantees have not been considered. Additionally, while slicing and virtualization can approximate logical isolation, they do not deliver the assurance levels necessary to replace traditional air-gapped systems in high-security environments. This highlights a fundamental gap. Despite the potential of software-defined technologies to support multi-domain networking, their application in the realm of secure realtime voice communication remains largely uncharted.
Theme 2: Cross-Domain Communication and Coordination. The exploration of cross-domain interaction is further enhanced through routing and coordination frameworks [129,31]. These studies illustrate how trustaware routing, crowdsourced decision-making, and the integration of satellite and terrestrial networks can facilitate communication across diverse and geographically distributed domains. They underscore the critical importance of scalability, adaptability, and trust management in effectively coordinating resources across multiple domains. Key Takeaways: These methods promote efficient data exchange and coordination across domains, primarily focusing on network-layer optimization and resource management. However, they fall short of offering mechanisms for secure and simultaneous interaction across multiple domains in real-time communication systems. Theme 3: Cross-Domain Policy Enforcement and Guard Architectures. Traditional cross-domain solutions depend on guard-based architectures and stringent policy enforcement mechanisms [110]. These systems facilitate controlled information flow between domains through isolation, inspection, and filtering mechanisms, often bolstered by separation kernels and secure communication protocols such as IPsec. Key Takeaways: The guard model is unidirectional (classified to unclassified) and designed for constrained management messaging, not for high-throughput, realtime, or bidirectional communication. It assumes static message schemas and predictable traffic, limiting adaptability to dynamic, multi-domain systems. Scalability for simultaneous domains or high-rate streaming applications, such as real-time voice communication, is not considered. Theme 4: Multi-Domain Security, Defense, and Resilience. Numerous studies focus on broader strategies for resilience and defense in multi-domain systems [23, 70,86]. These include game-theoretic models for resilient command and control, zero-trust architectures aimed at preventing lateral movement, and conceptual analyses of the evolution of the cyber domain. Collectively, these works underscore the growing complexity and strategic significance of multi-domain operations. Key Takeaways: These studies offer valuable insights into resilience, threat modeling, and defense strategies across various domains. However, they tend to be primarily conceptual or network-centric and do not thoroughly address operator-level interactions or the requirements for real-time communication. Theme 5: Multi-Domain Access Control and PolicyBased Management. The topic of access control and policy enforcement across domains is explored through programmable and agent-based frameworks [78]. These
3.3.2 Cross Domain, Multi-domain, and Heterogeneous Cross domain research investigates techniques and architectures that facilitate controlled interactions between different security domains. This includes mechanisms for authentication, guard-based enforcement, and trust establishment [121, 64,72, 129]. Collectively, these studies illustrate how secure communication and coordination can be achieved across domain boundaries. Theme 1: Cross-Domain Authentication and Trust Establishment. A significant body of research focuses on authentication protocols and trust mechanisms within cross-domain environments [121,64,72]. These studies propose lightweight, privacy-preserving authentication schemes that leverage a combination of cryptographic primitives (e.g., AES, RSA), zero-knowledge proofs, blockchain integration, and distributed storage solutions. They demonstrate that secure and efficient authentication across domains is achievable, even in highly dynamic environments such as 5G heterogeneous networks and Industrial Internet of Things (IIoT) systems. Key Takeaways: These works lay a robust foundation for secure, efficient, and privacy-preserving crossdomain authentication. However, it is important to note that they are primarily designed for user or device authentication and do not adequately address real-time, operator-centric communication or stringent domain isolation requirements.
10
approaches illustrate how to systematically manage permissions and interactions across multiple administrative domains. Key Takeaways: Policy-based management facilitates structured and programmable control of cross-domain interactions. Nevertheless, these mechanisms are not specifically designed for real-time communication control or for ensuring strict isolation between concurrent domain interactions. Theme 6: Heterogeneous and Multi-Layer Network Integration. Heterogeneous environments add complexity due to the integration of diverse technologies, protocols, and operational contexts [72,25,31]. Research in this field includes privacy-preserving authentication within heterogeneous networks, adaptive key management for quantum multi-domain systems, and integrated space-air-ground networking. These studies emphasize the need for flexible routing, adaptive cryptographic mechanisms, and coordinated control across multiple layers. Key Takeaways: Heterogeneous networks require robust authentication, flexible routing, and adaptive security policies across diverse technologies. Cryptography, blockchain, and federated monitoring provide essential tools to enable secure cross-domain operations. Gap Analysis: While significant advances have been made in cross-domain authentication, trust, routing, and policy enforcement, no existing research addresses secure, real-time multi-domain voice communication. Current work focuses primarily on data exchange, traffic management, resource orchestration, and policy control. None provide mechanisms for operators to simultaneously monitor multiple security domains, nor do they support software-defined domain separation capable of replacing traditional two-domain, air-gapped architectures. Features such as secure voice mixing, per-domain transmit control, and strong non-interference guarantees for multi-domain audio flows remain unaddressed. Even cross-domain guard architectures are limited to lowbandwidth, two-domain environments and cannot meet the latency, throughput, or covert-channel requirements of modern Voice Communication Systems. 3.3.3 Command, Control, and Military Systems (C2/C4ISR) Research on Command and Control (C2) and C4ISR systems establishes the architectural, operational, and security foundations essential for modern military and mission-critical environments. The studies in this category collectively focus on the design of systems-ofsystems, interoperability, secure communications, and the advancement of tactical networks through software-
Quang Cao1 et al.
defined, cloud-enabled, and multi-domain paradigms [83, 73, 119, 1, 34, 80, 104, 114, 91, 108, 95, 103, 125, 75, 100, 60]. Theme 1: Command and Control (C2). Foundational research delineates methodologies, architectural frameworks, and interoperability mechanisms for large-scale C2 systems [83,73, 119]. These studies underscore the importance of mission-oriented analysis, layered system design from hardware to user interface and the integration of diverse components through interoperability adapters and distributed communication models. They frame C2 systems as complex, evolving systemsof-systems that necessitate scalability, modularity, and cross-domain coordination. Key Takeaways: These works describe how C2 systems can be architected, integrated, and validated as complex, distributed systems-of-systems. They emphasize interoperability, standard data models, and robust networking for collaborative operations. However, communication services, including voice, are treated as underlying infrastructure, without guidance on secure, multi-domain operator voice interfaces. Theme 2: Security of C3I/C4ISR and Tactical Networks. A substantial body of research examines the security challenges and defensive measures within military communication systems [1,104,125,60]. These studies analyze vulnerabilities, attack vectors, and countermeasures in C3I/C4ISR environments, advocating for multilayered and data-centric security strategies. Concepts such as distributed MILS and fine-grained information protection emphasize the significance of strong isolation and controlled information flow across varying classification levels. Key Takeaways: These studies illustrate that contemporary military systems necessitate robust, multi-layered security and strong isolation assurances. However, they predominantly focus on system-level and data-centric security, often overlooking the real-time communication requirements at the operator level. Theme 3: Multi-Domain Security and Information Sharing. Numerous studies have explored secure information exchange and management across various domains [34,114, 95]. These works propose architectures and frameworks designed to enforce release policies, manage multi-domain services, and facilitate controlled information sharing in federated and coalition environments. Key Takeaways: These approaches illustrate that secure interactions across multiple domains are achievable through effective policy enforcement and managementplane integration. However, the focus remains primarily on data exchange and service coordination, rather than enabling simultaneous, real-time operator interaction across domains.
SoK: Secure Software-Based Multi-Domain Data Segregation
Theme 4: SDN, 5G, and Next-Generation Military Networking. Emerging research delves into the integration of Software-Defined Networking (SDN), 5G, and cloud/edge technologies within military networks [80, 108,75,103, 91, 100]. These studies illustrate how softwaredefined control, network programmability, and distributed computing can enhance flexibility, scalability, and resilience in tactical environments. They demonstrate that modern communication infrastructures are capable of supporting dynamic mission requirements and multidomain operations through virtualization and orchestration.
11
3.3.4 Cybersecurity, Threat Detection, and Policy
This section synthesizes literature on essential cybersecurity mechanisms, including identity federation, access control, multilevel security architectures, secure communication protocols, and formal assurance frameworks [69,45,82,135,39]. Collectively, these studies establish foundational principles necessary for enforcing security policies and safeguarding sensitive communications in complex, high-assurance environments. Theme 1: Identity Federation and Access Control. The management of identity and authentication across distributed systems is effectively addressed through multi-protocol federation frameworks [69]. These frameKey Takeaways: These technologies establish a roworks facilitate interoperability among various identity bust foundation for modernizing military communicastandards (e.g., SAML, OpenID) and support unified tion systems and facilitating flexible, multi-domain operauthentication mechanisms across services, such as Sinations. However, the focus remains primarily on network gle Sign-On (SSO). They illustrate how consistency in services, resource orchestration, and infrastructure-level authentication and secure identity propagation can be optimization rather than on communication mechanisms upheld across heterogeneous environments. that are operator-facing. Key Takeaways: Identity federation offers scalable and interoperable authentication across systems, repreGap Analysis: Current research in C2/C4ISR arsenting a critical component within secure multi-domain chitectures and military communications focuses on environments. Nevertheless, these mechanisms primarily system-of-systems design, interoperability, distributed emphasize user authentication and session establishment networking, and modernized tactical networks using and fall short in addressing real-time communication SDN, 5G, and cloud/edge technologies [83,73,119,1, 34, control or domain-level interactions. 80,104,114,91,108,95,103,125,75]. While these works Theme 2: Multilevel Security and Policy Enforceaddress interoperability, policy enforcement, multi-domain ment. The exploration of multilevel security (MLS) and information sharing, and network-level security, they policy-based control is facilitated through middlewaregenerally treat voice communication as an underlying driven architectures and management frameworks [135]. infrastructure rather than as a critical operator interface. These studies elucidate how centralized control and layNo existing studies provide mechanisms for secure, realered security policies can effectively enforce separation time multi-domain voice communication that allow operacross various classification levels within a unified sysators to monitor and transmit across multiple classified tem. domains simultaneously. Furthermore, current architecKey Takeaways: MLS and policy enforcement mechtures and security frameworks do not address softwareanisms provide structured control over information flow defined domain separation, per-domain transmit control, and access across different security levels. However, their voice mixing, or strong non-interference guarantees, all operation is primarily at the system and data levels, of which are essential for modern operator-centric C2 without adequately addressing real-time communication environments. Additionally, research on cloud-native flows or operator-centric interactions across multiple and edge computing infrastructures demonstrates how domains. distributed computing resources, services, and policies Theme 3: Secure Communication. Secure commucan be orchestrated to achieve resilience, high perfornication in mission-critical environments is reinforced mance, and assurance in mission-critical or military by precedence-based communication models and speenvironments [100]. This study shows that virtualizacialized cryptographic techniques [45,39]. These studies tion and the cloud–edge continuum can enable scalable demonstrate how communication priority can be mainand flexible multi-domain operations. However, these tained in secure IP networks and how voice data can be investigations primarily focus on data flows, resource safeguarded through advanced encryption methods that management, and general service orchestration, neglectintegrate time- and frequency-domain transformations. ing the specific challenges of operator-facing, real-time multi-domain voice communication, including secure Key Takeaways: These approaches ensure confidenvoice mixing, per-domain transmit control, and lowtiality and the prioritization of critical communications, latency, high-assurance audio delivery. which are vital for mission-critical systems. However,
12
they primarily focus on securing individual communication channels and do not address the management of multiple simultaneous communications across domains. Theme 4: Formal Assurance and Certification. Formal assurance processes are analyzed through methodologies for constructing rigorous security arguments [82]. These frameworks facilitate the certification and validation of high-assurance systems by providing structured reasoning about the security properties of systems. Key Takeaways: Formal assurance techniques are crucial for validating security-critical systems and achieving certification in high-assurance environments. Yet, they remain largely abstract and do not directly confront the implementation challenges faced in multi-domain communication systems. Gap Analysis: A consistent limitation emerges across the reviewed literature [69,45,82, 135,39]. Existing studies offer robust foundations for identity management, multilevel security, policy enforcement, secure communication, and system assurance. These mechanisms are effective in enforcing security policies and protecting data within single-domain or application-level contexts. However, none of these studies address the requirements for secure, real-time multi-domain voice communication. Specifically, capabilities such as simultaneous monitoring of multiple domains, per-domain transmission control, secure voice mixing, and strict non-interference guarantees remain unexamined. While identity federation, MLS, and cryptographic techniques provide essential building blocks, they do not encompass operator-centric communication workflows within multi-domain environments. This underscores a fundamental gap between established cybersecurity mechanisms and the requirements for secure, real-time, multi-domain voice communication systems. 3.3.5 Secure IoT Architecture and Policy Control This section synthesizes a body of research focused on security, trust, and policy enforcement within Internet of Things (IoT), Industrial IoT (IIoT), and the Internet of Battlefield Things (IoBT) environments [99,36,77, 57,33]. Collectively, these studies investigate softwaredefined networking (SDN)-enabled architectures, edge and fog computing frameworks, trust evaluation mechanisms, and distributed policy enforcement mechanisms across expansive, heterogeneous systems. Theme 1: Trust Management. The issue of trustworthiness in distributed IoT and IoBT landscapes is addressed through SDN-integrated trust evaluation frameworks [99]. These methodologies assess the behavior of devices, enabling the enforcement of trust-aware decisions through centralized control planes. Such ap-
Quang Cao1 et al.
proaches facilitate the secure participation of devices in mission-critical scenarios. Key Takeaways: The trust evaluation mechanisms examined provide a solid foundation for securing device interactions within large-scale distributed systems. However, the focus is predominantly on device-level assurance and neglects aspects related to operator-level communication or interactions that span multiple domains. Theme 2: SDN-Based Security Management and Policy Enforcement. A number of studies have elucidated how SDN facilitates centralized security management and policy enforcement across distributed IoT environments [36,77]. These architectures effectively decouple control and data planes while integrating access control mechanisms, such as role-based access control (RBAC) and token-based authentication. Policies are enforced through distributed enforcement points, including gateways and edge nodes. Key Takeaways: SDN-based control frameworks afford flexible and programmable enforcement of security policies across heterogeneous systems. While these approaches prove effective for access control and overall system management, they fail to address real-time communication flows or multi-domain interactions at the operator level. Theme 3: Edge/Fog Computing. The exploration of edge and fog computing paradigms aims to enhance scalability, reduce latency, and bolster resilience in IoT systems [57,33]. The findings demonstrate that computation and security functions can be situated nearer to devices while maintaining centralized coordination through SDN. Key aspects such as monitoring, scalability, and reliability are underscored in the context of wide-area IoT deployments. Key Takeaways: Edge and fog architectures promote scalable and responsive control within geographically distributed environments. Nevertheless, the emphasis remains on data processing and system efficiency, thereby neglecting secure, real-time communication between human operators across domains. Gap Analysis: Existing research in IoT, IIoT, and IoBT security provides strong foundations for trust management, policy enforcement, and distributed control through SDN-based architectures, edge/fog computing, and context-aware security policies [99,77,57,33, 36]. These studies demonstrate how to secure heterogeneous, geographically distributed systems and manage resources and policies across multiple nodes. However, they primarily focus on device- and data-centric security and do not address operator-facing multi-domain voice communication, including secure real-time voice mixing, per-domain transmit paths, and software-enforced
SoK: Secure Software-Based Multi-Domain Data Segregation
13
domain separation. The concepts of trust evaluation, SDN control, and edge/fog placement have not been applied to the challenges of securing operator-centric multi-domain voice channels.
Key Takeaways: Rigorous testing and validation procedures are indispensable for ensuring system reliability and certification in high-assurance environments. Nonetheless, existing methodologies predominantly focus on functional correctness and interoperability, rather than verifying real-time behavior or enforcing non interference within multi-domain communication systems. Gap Analysis: Research in policy-based control, system isolation, and verification/validation provides foundational methods for enforcing access, resource, and security policies in complex, multi-domain, and militaryoriented systems [38, 54, 107,130]. These works demonstrate how high-assurance separation, lightweight capability domains, and rigorous verification and validation methods can support secure, distributed operations. However, they are generic and focus on data or systemlevel interactions rather than operator-facing voice communication. Specifically, there is no research addressing per-domain audio isolation, one-hot transmit mechanisms, secure voice mixing, or verifiable non-interference for multi-domain voice systems.
3.3.6 Foundational Security and Assurance
This cluster addresses high-level mechanisms for policy enforcement, system isolation, and verification/validation in complex networked and operational environments [38, 54,107,130]. Collectively, these works provide foundational guidance for enforcing resource and access policies, achieving strong isolation, and ensuring system correctness in distributed and multi-domain systems. Theme 1: Policy-Based Control. Policy-driven methodologies for resource allocation and admission control are analyzed within the context of evolving and nextgeneration networks [38]. These investigations elucidate how access, quality of service (QoS), and system behavior can be governed through dynamic policy frameworks, thereby facilitating adaptable and context-aware control across distributed environments. Key Takeaways: The implementation of policy-based 4 Discussion control offers a flexible mechanism for enforcing access and resource constraints across varied domains. NevA review of recent literature reveals a significant gap ertheless, these approaches predominantly operate at in the application of advanced networking and security the network and service levels and do not sufficiently technologies to real-time voice communication systems. address application-specific requirements, such as realIn particular, there is currently no comprehensive, setime voice control or domain-specific communication cure, software-based solution that enables robust multiconstraints. domain data segregation for Voice Communication SysTheme 2: System Isolation and Trusted Computing tems (VCS). Existing approaches largely rely on tradiFoundations. The concept of strong isolation is examined tional air-gapped architectures to achieve high assurance through operating system–level mechanisms, including separation. However, the technologies examined in this lightweight capability domains [54]. These strategies SoK each provide partial building blocks toward this aim to minimize the trusted computing base (TCB) transition. Collectively, they contribute foundational while enforcing fine-grained separation among system mechanisms that can support the gradual evolution from components, thus providing a solid foundation for highrigid, isolated infrastructures (air-gapped) to flexible, assurance systems. software-based, yet still high-assurance, multi-domain Key Takeaways: Fine-grained isolation mechanisms voice communication architectures in different layers of facilitate robust separation within complex systems, supsecurity. porting secure multi-domain operations. However, these mechanisms primarily concern process and memory isolation, leaving communication-level separation, especially for real-time data streams, such as voice insufficiently 4.1 Network Isolation Layer addressed. Theme 3: Interoperability and System Validation. Network separation technologies play a critical role in The verification of system correctness and interoperabilVoice Communication Systems (VCS), particularly in ity is thoroughly investigated through comprehensive high-assurance environments where each communicatesting frameworks and validation methodologies [107, tion flow must be strictly segregated from the operator 130]. These studies illustrate how complex systems, inposition to its designated destination domain. In such cluding those conforming to military standards, can be contexts, logical and virtualized isolation mechanisms validated for compliance, correctness, and operational must provide strong guarantees that traffic from one reliability. security domain cannot interfere with or leak into an-
Quang Cao1 et al.
14
other, while still maintaining real-time performance and operational flexibility [36]. Software Defined Networking (SDN) represents a mature and programmable approach to network separation. Large-scale deployments such as Google’s B4 WAN architecture [50,55] demonstrate that SDN can operate at hyperscale with high reliability and performance. By decoupling the control and data planes, SDN enables centralized policy enforcement, dynamic Access Control List (ACL) updates, and fine-grained microsegmentation, which are particularly valuable in multidomain VCS environments. Although centralized control introduces a potential single point of compromise, it also allows rapid security patching and coordinated traffic engineering. From a cost perspective, SDN leverages commodity switching hardware and open-source controllers, making it economically attractive, while its flow-level programmability supports high throughput and responsive traffic management across domains [44, 109]. Network Virtualization (NV) further enhances separation by abstracting logical networks over shared physical infrastructure. Widely adopted in cloud platforms such as Amazon Web Services and Microsoft Azure, NV uses overlay encapsulation mechanisms (e.g., VXLAN [74], GRE [41], Geneve [47]) to provide multitenant isolation. In VCS deployments, this enables the creation of logically independent communication planes for different operational or security domains while sharing the same hardware. Security in NV depends largely on hypervisor correctness and virtual switch enforcement; although not equivalent to physical air gaps, it has been extensively validated in commercial environments. NV offers high feasibility and scalability with moderate cost, making it a practical solution for segregating traffic in distributed, software-defined architectures [2]. Network Slicing (NS), standardized within the 3rd Generation Partnership Project (3GPP) 5G framework, extends virtualization concepts by enabling multiple service-specific logical networks to coexist on a common infrastructure [93,46]. Each slice can be tailored to distinct performance and reliability requirements, such as ultra-low latency, high bandwidth, or missioncritical reliability, characteristics highly relevant to VCS in multi-domain operations. While slicing enforces logical isolation through virtualization layers, it still relies on shared physical resources, raising assurance considerations in high-security deployments. Nevertheless, it offers efficient resource utilization, strong configurability, and high performance, positioning it as a promising approach for future multi-domain VCS architectures where strict separation and service differentiation must coexist [21, 14, 126].
IPsec serves as a key mechanism for protecting segregated voice traffic in multi-domain networks by providing network-layer confidentiality, integrity, authentication, and anti-replay protection. Standardized in RFC 4301, IPsec faces long-term security challenges due to quantum computing advancements, particularly from Shor’s algorithm, which threatens widely used asymmetric cryptographic schemes such as RSA and ECDSA [7,8]. In response, the development of PQCIPsec integrates quantum-resistant algorithms into Internet Key Exchange (IKE) processes, driven by the National Institute of Standards and Technology’s (NIST) post-quantum standardization efforts [89]. This includes new Federal Information Processing Standards (FIPS) such as FIPS 203 (ML-KEM) [88] for general encryption and FIPS 204 (ML-DSA) [87] for digital signatures. While PQC-IPsec significantly enhances security for high-assurance voice communication systems, it introduces moderate performance overhead and still requires improvements in implementation and interoperability compared to classical IPsec [52]. Nonetheless, it marks a crucial step in securing network architectures in the post-quantum era [112].
4.2 Platform Isolation Layer Separation kernels provide a high-assurance isolation platform that can replaces traditional air-gapped infrastructures by minimizing the Trusted Computing Base (TCB) and enforcing strict partitioning of system components. Introduced by John Rushby in 1981, this concept underpins the Multiple Independent Levels of Security (MILS) framework and operates as a minimal hypervisor that creates logically isolated partitions on shared hardware [102]. Each partition functions autonomously while the kernel controls inter-partition communication, ensuring properties such as data separation, information flow control, temporal separation, and fault isolation, all encapsulated in the NEAT principles (Non-bypassable, Evaluatable, Always-invoked, Tamperproof). Widely adopted in avionics and achieving high assurance through certifications such as Common Criteria (CC) and DO-178C [101,58], separation kernels (e.g., INTEGRITY-178B and LynxSecure, etc., in Table 9) demonstrate their effectiveness in meeting stringent safety and security requirements [132]. Unlike traditional air gaps requiring separate hardware, separation kernels allow multiple secure domains to coexist on the same processor while maintaining strict logical isolation, thus significantly reducing hardware overhead. Their compact size makes them amenable to rigorous mathematical verification, positioning separation kernels as scalable and
SoK: Secure Software-Based Multi-Domain Data Segregation
15
credible alternatives for secure, multi-domain, real-time communication without sacrificing assurance.
Mandatory Access Control (MAC) is effective, while Role-Based Access Control (RBAC) simplifies privilege management by assigning permissions based on roles, and Attribute-Based Access Control (ABAC) refines access decisions by considering user attributes and environmental conditions. Ultimately, effective VCS access control integrates MAC, RBAC, and ABAC approaches to ensure both security and operational reliability [40, 94].
Table 9 Comparison of Separation Kernel Implementations (Sec.: Security, Saf.: Safety, RT: Realtime) [132] # Name
Sec. Saf. RT
Certification/ Compliance
Formal Methods
Industrial Implementations 1
PikeOS
✓
✓
2
VxWorks 653
×
✓
3
VxWorks MILS
✓
×
4
INTEGRITY-178B
✓
✓
5 6
INTEGRITY Mult. LynxSecure
✓ ✓
× ✓
7
LynxOS-178
✓
×
8
DDC-I Deos
×
✓
9 AAMP7a 10 ED 11 ARLX Hyper.
✓ ✓ ✓
✓ ✓ ×
DO-178B Level B, IEC 61508 SIL 3, EN 50128 SIL 4, ARINC 653 ✓ DO-178B/C Level A, ARINC 653 × SKPP, CC, DO178C Level A ✓ DO-178B Level A, CC EAL 6+/SKPP, ARINC 653 × Unknown ✓ CC EAL 7, DO178B Level A ✓ DO-178B Level A, ARINC 653 ✓ DO-178B Level A, ARINC 653 N/A CC EAL 7 × CC ✓ DO-178B Level A, MILS EAL, IEC 61508 ✓
✓
?
? ✓
? ? ? ? ✓ ✓ ?
Academic Implementations 12 seL4 13 OKL4 Micro. 14 XtratuM 15 PROSPER 16 Xenon 17 Quest-V 18 Muen 19 POK 20 AIR/AIR II
✓ ✓ × ✓ ✓ ✓ ✓ ✓ ✓
× ✓ ✓ ✓ × × ✓ × ✓
× × ✓ ✓ ✓ ✓ × ✓ ✓
None None ARINC 653 None None None None ARINC 653 ARINC 653
✓ ✓ ✓ × ✓ × ✓ × ×
4.3 Security Service Layer Access Control is essential in multi-domain VCS, regulating access to operator consoles, signaling services, and classified voice channels to ensure that only authenticated and authorized personnel, services, or devices can engage in communication across different security domains. It encompasses two dimensions: physical access control, which secures facilities using measures such as biometric authentication, and logical access control, which manages digital resources through techniques such as MFA and access control lists (ACLs). A robust access control framework includes identification to establish unique identities, authentication to verify them, preferably using MFA, authorization to dictate permissible actions based on security policies, and auditing to log activities for traceability. For high-assurance environments,
Cross Domain Solutions (CDS) form the foundation for securely connecting networks at different classification levels in multi-domain Voice Communication Systems (VCS). They manage risks associated with information transfer by blocking all inter-domain information flow by default and allowing only explicitly authorized data to pass through security enforcement points, preventing leakage of classified voice streams and information. A secure CDS architecture relies on layered enforcement mechanisms across physical, network, and application layers, guided by key security objectives: confidentiality, integrity, availability, authenticity, and accountability. CDS can bridge Unclassified, Secret, and Top Secret networks for monitoring voice traffic, transferring approved recordings, or consolidating audit data. Without proper CDS controls, interconnections risk exposing sensitive voice data to lower classification levels, increasing unauthorized access potential. CDS technologies include access solutions, transfer solutions, and Multi-Level Security (MLS) systems, supporting secure VCS interoperability. In a software-defined multidomain VCS architecture, CDS act as a trusted bridge between isolated security domains, enabling operational interoperability while preserving the confidentiality, integrity, and availability of sensitive communications [111, 6]. Cross Domain Guard is essential for enforcing data traffic policies to prevent unauthorized disclosure of classified information by blocking accidental and intentional transmissions with specific indicators [110]. In a VCS environment, where operational commands and session metadata may contain classification markings, the guard serves as a critical checkpoint for inter-domain exchanges. It scans for dirty words such as secret and classification tags within signaling data. When XML formats are used for session control or configuration, the guard validates messages against an approved XML schema, rejecting any that deviate from the specified structure. This schema enforcement is vital for maintaining signaling integrity and operational security in VCS environments [110]. Auditability is also crucial. Error messages and rejected transmissions are sent to a dedicated audit component via unidirectional links, ensuring no data flows back into the protected domain.
16
Access to audit records is limited to authorized administrators, maintaining accountability and domain isolation [110]. Additionally, to address potential buffer overflow in the guard, an external buffer can be implemented upstream to regulate traffic flow and notify senders of capacity limits, ensuring continuity of operations without compromising the guard’s integrity [110]. Overall, the Cross Domain Guard facilitates secure interoperability in multi-domain VCS architectures, balancing operational effectiveness with the protection of classified information.
5 Conclusion This SoK paper synthesizes the security implications of transitioning Voice Communication Systems (VCS) from hardware-enforced isolation to a software-based segregation model. It highlights that evolving from traditional air-gapped architectures to software-defined, multi-domain VCS can be achieved through the integration of network separation mechanisms such as Software-Defined Networking (SDN), slicing, network virtualization, as well as separation kernels and crossdomain solutions. By combining PQC with IPsec, the paper underscores the importance of long-term confidentiality, while MILS-compliant kernels provide robust isolation guarantees. Together, these technologies create a high-assurance foundation for secure data segregation, enabling scalable and flexible architectures without compromising mission-critical security or real-time performance. Furthermore, this SoK identifies significant research gaps, notably the scarcity of unified architectural frameworks that systematically integrate these technologies and the limited empirical validation in realistic multi-domain VCS environments. Addressing these gaps will represent the next phase of this research, focusing on designing an integrated framework and developing a prototype to assess security, performance, and deployment trade-offs, thereby bridging the divide between conceptual feasibility and practical implementation. Acknowledgements The initiative partnered C4i Pty Ltd with RMIT University, Melbourne, Australia.
References 1. Ahmad, H., Dharmadasa, I., Ullah, F., Babar, M.A.: A review on c3i systems’ security: Vulnerabilities, attacks, and countermeasures. arXiv preprint arXiv:2104.11906 (2021). URL https://arxiv.org/ abs/2104.11906 2. Alam, I., Sharif, K., Li, F., Latif, Z., Karim, M.M., Biswas, S., Nour, B., Wang, Y.: A survey of network
Quang Cao1 et al. virtualization techniques for internet of things using sdn and nfv. ACM Computing Surveys (CSUR) 53(2), 1–40 (2020) 3. Alfaqawi, M., Gateau, M., Huard, P., Reungoat, P., Le Mercier, M.C., Davai, S., Ben Mabrouk, M.: A comprehensive study on 5g: Ran architecture, enabling technologies, challenges, and deployment. In: M.A. Matin (ed.) A Glimpse Beyond 5G in Wireless Networks, Signals and Communication Technology, pp. 1–57. Springer International Publishing, Cham, Switzerland (2023). DOI 10.1007/978-3-031-13786-0 1 4. Alves-Foss, J., Oman, P.W., Taylor, C., Harrison, W.S.: The mils architecture for high-assurance embedded systems. International journal of embedded systems 2(3-4), 239–247 (2006) 5. ASD: Fundamentals of Cross Domain Solutions (2021). URL https://www.cyber.gov.au/sites/ default/files/2025-03/Fundamentals%20of%20Cross% 20Domain%20Solutions%20%28October%202021%29.pdf 6. ASD: Introduction to Cross Domain Solutions (2021). URL https://www.cyber.gov.au/sites/ default/files/2025-03/Introduction%20to%20Cross% 20Domain%20Solutions%20%28October%202021%29.pdf URL 7. ASD: Guidelines for cryptography (2025). https://www.cyber.gov.au/business-government/ asds-cyber-security-frameworks/ ism/cybersecurity-guidelines/ guidelines-for-cryptography URL 8. ASD: Information security manual (2025). https://www.cyber.gov.au/sites/default/files/ 2025-09/Information%20security%20manual%20% 28September%202025%29.pdf 9. Bastin, N., McGeer, R.: Programmable, Controllable Networks. In: R. McGeer, M. Berman, C. Elliott, R. Ricci (eds.) The GENI Book, pp. 149–178. Springer International Publishing, Cham (2016). DOI 10.1007/ 978-3-319-33769-2 8. URL https://doi.org/10.1007/ 978-3-319-33769-2_8 10. Bertó-Monleón, R., Casini, E., van Engelshoven, R., Goode, R., Tuchs, K.D., Halmai, T.: Specification of a policy based network management architecture. In: 2011-MILCOM 2011 Military Communications Conference, pp. 1393–1398. IEEE (2011) 11. Bholebawa, I.Z., Dalal, U.D.: Performance analysis of sdn/openflow controllers: Pox versus floodlight. Wireless Personal Communications 98(2), 1679–1699 (2018) 12. Bonfim, M.S., Dias, K.L., Fernandes, S.F.: Integrated nfv/sdn architectures: A systematic literature review. ACM Computing Surveys (CSUR) 51(6), 1–39 (2019) 13. Booth, A., Martyn-St James, M., Clowes, M., Sutton, A.: Systematic Approaches to a Successful Literature Review, 3rd edn. SAGE Publications Ltd, London (2021) 14. Borsatti, D., Grasselli, C., Contoli, C., Micciullo, L., Spinacci, L., Settembre, M., Cerroni, W., Callegati, F.: Mission critical communications support with 5g and network slicing. IEEE Transactions on Network and Service Management 20(1), 595–607 (2022) 15. Borsatti, D., et al.: Mission critical communications support with 5g and network slicing. In: IEEE (or related conference/workshop) / peer-reviewed manuscript (postprint available) (2023). Postprint available (IRIS / institutional repository) 16. C4i: Solutions for secure communications (2026). URL https://www.c4i.com/en/about-us 17. Cafini, R., Cerroni, W., Raffaelli, C., Savi, M.: Security issues in programmable routers for future internet. In: Trustworthy Internet, pp. 17–30. Springer (2011)
SoK: Secure Software-Based Multi-Domain Data Segregation
17
18. Cai, Z.: Maestro: Achieving scalability and coordination in centralizaed network control plane. Rice University (2012) 19. de la Calera Molina, E.G., Garcı́a, S.C., Murcia, J.M.B., Zarca, A.M., Gómez, A.F.S.: Cerberus: Towards secure and automated multi-operator management in b5g through a dynamic policy-based zsm framework. Journal of Network and Systems Management 34(1), 18 (2026) 20. Celdrán, A.H., Pérez, M.G., Clemente, F.J.G., Ippoliti, F., Pérez, G.M.: Dynamic network slicing management of multimedia scenarios for future remote healthcare. Multimedia Tools and Applications 78(17), 24707–24737 (2019) 21. Celdrán, A.H., Pérez, M.G., Clemente, F.J.G., Ippoliti, F., Pérez, G.M.: Dynamic network slicing management of multimedia scenarios for future remote healthcare. Multimedia Tools and Applications 78(17), 24707–24737 (2019) 22. Chang, S.H., Pei, Y., Chung, P.T.: Hash flow: An access control mechanism for software defined network. In: Workshops of the International Conference on Advanced Information Networking and Applications, pp. 554–565. Springer (2020) 23. Chen, J., Zhu, Q.: A games-in-games approach to mosaic command and control design of dynamic network-ofnetworks for secure and resilient multi-domain operations. In: Sensors and Systems for Space Applications XII, vol. 11017, pp. 189–195. SPIE (2019) 24. Chen, M., Qian, Y., Mao, S., Tang, W., Yang, X.: Software-defined mobile networks security. Mobile Networks and Applications 21(5), 729–743 (2016) 25. Chen, X., Cao, Y., Chen, Y., Yang, S., Liu, Y., Wang, Y., Guo, M., Yu, X., Zhao, Y., Wang, Q.: Secret key rate-adaptive inter-domain key service provisioning in heterogeneous protocol-based multi-domain quantum networks. Journal of Optical Communications and Networking 17(10), 950–966 (2025) 26. Chowdhary, A., Huang, D., Ahn, G.J., Kang, M., Kim, A., Velazquez, A.: Sdnsoc: Object oriented sdn framework. In: Proceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization, pp. 7–12 (2019) 27. Controller, O.: Snac (simple network access control) (2011) U.M.: NATO SECURITY BRIEF28. Corps, ING FOREWORD (2005). URL https: //www.information.marines.mil/Portals/224/Docs/ Newcomers/NATO-Security-Briefing.pdf 29. Criteria, C.: Common Criteria for Information Technology Security Evaluation - Part 3: Security assurance components (2017). URL https://www.commoncriteriaportal.org/files/ ccfiles/CCPART3V3.1R5.pdf 30. Daigle, J., Langford, J.: Models for analysis of packet voice communications systems. IEEE Journal on selected areas in communications 4(6), 847–855 (2003) 31. Davoli, F.: Satellite networking in the context of green, flexible and programmable networks. In: International Conference on Personal Satellite Services, pp. 1–11. Springer (2016) 32. Del Amo, I.F., Erkoyuncu, J.A., Roy, R., Palmarini, R., Onoufriou, D.: A systematic review of augmented reality content-related techniques for knowledge transfer in maintenance applications. Computers in Industry 103, 47–71 (2018) 33. Delkhosh, M., Javidan, R.: Toward a robust wan-scale iot-fog networks: A distributed sdn security architecture
encompassing monitoring, scalability, reliability, and security. Iranian Journal of Science and Technology, Transactions of Electrical Engineering pp. 1–18 (2025) 34. Domingo, A., Wietgrefe, H.: An applied model for secure information release between federated military and nonmilitary networks. In: Proceedings of the IEEE Military Communications Conference (MILCOM), pp. 465–470 (2015). DOI 10.1109/MILCOM.2015.7357486. URL https://doi.org/10.1109/MILCOM.2015.7357486 35. Duan, Q., Zeng, M., Huang, J., Xing, C.c.: Performance analysis for a service delivery platform in software defined network. In: Proceedings of the 30th Annual ACM Symposium on Applied Computing, pp. 2257–2262 (2015) 36. El Jaouhari, S., Bouabdallah, A., Corici, A.A.: Sdn-based security management of multiple wot smart spaces. Journal of Ambient Intelligence and Humanized Computing 12(10), 9081–9096 (2021) 37. Erickson, D.: The beacon openflow controller. In: Proceedings of the second ACM SIGCOMM workshop on Hot topics in software defined networking, pp. 13–18 (2013) 38. Esteve Rothenberg, C., Roos, A.: A review of policybased resource and admission control functions in evolving access and next generation networks. Journal of Network and Systems Management 16(1), 14–45 (2008) 39. Faragallah, O.S., Farouk, M., El-sayed, H.S., El-bendary, M.A.: Speech cryptography algorithms: utilizing frequency and time domain techniques merging. Journal of Ambient Intelligence and Humanized Computing 15(10), 3617–3649 (2024) 40. Farhadighalati, N., Estrada-Jimenez, L.A., NikghadamHojjati, S., Barata, J.: A systematic review of access control models: Background, existing research, and challenges. IEEE Access (2025) 41. Farinacci, D., Li, T., Hanks, S., Meyer, D., Traina, P.: Generic Routing Encapsulation (GRE). RFC 2784, Internet Engineering Task Force (IETF) (2000). URL https://datatracker.ietf.org/doc/html/rfc2784 42. Ferguson, P., Senie, D.: Network ingress filtering: Defeating denial of service attacks which employ ip source address spoofing. RFC 2827, Internet Engineering Task Force (IETF) (1998) 43. Gomes, J.E.C., Ehlert, R.R., Boesche, R.M., Santosde Lima, V., Stocchero, J.M., Barone, D.A., Wickboldt, J., de Freitas, E.P., dos Anjos, J.C., de Araujo Fernandes, R.Q.: Surveying emerging network approaches for military command and control systems. ACM Computing Surveys 56(6), 1–38 (2024) 44. Gong, Y., Huang, W., Wang, W., Lei, Y.: A survey on software defined networking and its applications. Frontiers of Computer Science 9(6), 827–845 (2015) 45. Goode, R., Ulsh, C., Tarr, J., DeSimone, T., McKenica, R.: Attaining precedence-based communications in secure ip networks. In: MILCOM 2007-IEEE Military Communications Conference, pp. 1–7. IEEE (2007) 46. Grings, F.H., Bruno, G.Z., Prade, L.R., Both, C.B., Brito, J.M.C.: Nasp: Network slice as a service platform for 5g networks. arXiv preprint arXiv:2505.24051 (2025) 47. Gross, J., Ganga, I., Sridhar, T., et al.: Geneve: Generic network virtualization encapsulation. IETF draft (2020). URL https://datatracker.ietf.org/doc/rfc8926/ 48. Gude, N., Koponen, T., Pettit, J., Pfaff, B., Casado, M., McKeown, N., Shenker, S.: Nox: towards an operating system for networks. ACM SIGCOMM computer communication review 38(3), 105–110 (2008) 49. Guri, M., Kedma, G., Kachlon, A., Elovici, Y.: Airhopper: Bridging the air-gap between isolated networks and
18 mobile phones using radio frequencies. In: 2014 9th International Conference on Malicious and Unwanted Software: The Americas (MALWARE), pp. 58–67. IEEE (2014) 50. Hong, C.Y., Mandal, S., Al-Fares, M., Zhu, M., Alimi, R., B, K.N., Bhagat, C., Jain, S., Kaimal, J., Liang, S., et al.: B4 and after: managing hierarchy, partitioning, and asymmetry for availability and scale in google’s software-defined wan. In: Proceedings of the 2018 Conference of the ACM Special Interest Group on Data Communication, pp. 74–87 (2018) 51. Husen, A., Chaudary, M.H., Ahmad, F.: A survey on requirements of future intelligent networks: Solutions and future research directions. ACM Computing Surveys 55(4), 73:1–73:61 (2023) 52. Iliadis-Apostolidis, D., Lawo, D.C., Kosta, S., Monroy, I.T., Olmos, J.J.V.: Qrons: Quantum resilience over ipsec tunnels for network slicing. Electronics 14(21), 4234 (2025) 53. ISO/IEC: Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 1: Introduction and general model (2022). URL https://www.iso.org/obp/ui/en/#iso: std:iso-iec:15408:-1:dis:ed-5:v1:en 54. Jacobsen, C., Khole, M., Spall, S., Bauer, S., Burtsev, A.: Lightweight capability domains: towards decomposing the linux kernel. In: Proceedings of the 8th Workshop on Programming Languages and Operating Systems, pp. 8–14 (2015) 55. Jain, S., Kumar, A., Mandal, S., Ong, J., Poutievski, L., Singh, A., Venkata, S., Wanderer, J., Zhou, J., Zhu, M., et al.: B4: Experience with a globally-deployed software defined wan. ACM SIGCOMM Computer Communication Review 43(4), 3–14 (2013) 56. Jayawardena, C., Chen, J., Bhalla, A., Bu, L.: Comparative analysis of pox and ryu sdn controllers in scalable networks. arXiv preprint arXiv:2504.12770 (2025) 57. Jazaeri, S.S., Jabbehdari, S., Asghari, P., Haj Seyyed Javadi, H.: Edge computing in sdn-iot networks: a systematic review of issues, challenges and solutions. Cluster Computing 24(4), 3187–3228 (2021) 58. Johnson, L.A., et al.: Do-178b: Software considerations in airborne systems and equipment certification. Crosstalk, October 199, 11–20 (1998) 59. Jorquera Valero, J.M., Sanchez Sanchez, P.M., Lekidis, A., Fernandez Hidalgo, J., Gil Perez, M., Siddiqui, M.S., Huertas Celdran, A., Martinez Perez, G.: Design of a security and trust framework for 5g multi-domain scenarios. Journal of Network and Systems Management 30(1), 7 (2022) 60. Kampichler, W., Steiner, W., Eier, D.: Distributed mils: A novel approach to advanced atm communication services. In: 2013 Integrated Communications, Navigation and Surveillance Conference (ICNS), pp. 1–8. IEEE (2013) 61. Kazmi, S.H.A., Qamar, F., Hassan, R., Nisar, K., Chowdhry, B.S.: Survey on joint paradigm of 5g and sdn emerging mobile technologies: Architecture, security, challenges and research directions. Wireless Personal Communications 130(4), 2753–2800 (2023) 62. Keele, S., et al.: Guidelines for performing systematic literature reviews in software engineering. Tech. rep., Technical report, ver. 2.3 ebse technical report. ebse (2007) 63. Keshari, S.K., Kansal, V., Kumar, S.: A systematic review of quality of services (qos) in software defined networking (sdn). Wireless Personal Commu-
Quang Cao1 et al. nications 116(3), 2593–2614 (2021). DOI 10.1007/ s11277-020-07812-2. URL https://doi.org/10.1007/ s11277-020-07812-2 64. Khalid, H., Hashim, S.J., Ahmad, S.M.S., Hashim, F., Chaudhary, M.A.: A lightweight and secure online/offline cross-domain authentication scheme for vanet systems in industrial iot. PeerJ Computer Science 7, e714 (2021) 65. Kitchenham, B., Charters, S.: Guidelines for Performing Systematic Literature Reviews in Software Engineering. Tech. Rep. EBSE-2007-01, Keele University and University of Durham, Keele, UK (2007). URL https://www.elsevier.com/__data/ promis_misc/525444systematicreviewsguide.pdf 66. Kotulski, Z., Nowak, T.W., Sepczuk, M., Tunia, M., Artych, R., Bocianiak, K., Osko, T., Wary, J.P.: Towards constructive approach to end-to-end slice isolation in 5g networks. EURASIP Journal on Information Security 2018(1), 2 (2018) 67. Krishnan, P., Jain, K., Jose, P.G., Achuthan, K., Buyya, R.: Sdn enabled qoe and security framework for multimedia applications in 5g networks. ACM Transactions on Multimedia Computing, Communications, and Applications (TOMM) 17(2), 1–29 (2021) 68. Levin, E., Zaynal, S.: Voice communication system for air traffic control-development and evaluation of a prototype. Master’s thesis, Chalmers University of Technology (2011) 69. Li, M., Chi, C.H., Ding, C., Wong, R., She, Z.: A multiprotocol authentication shibboleth framework and implementation for identity federation. In: International Conference on Security and Privacy in Communication Systems, pp. 81–101. Springer (2018) 70. Li, T., Pan, Y., Zhu, Q.: Decision-dominant strategic defense against lateral movement for 5g zero-trust multidomain networks. In: Network Security Empowered by Artificial Intelligence, pp. 25–76. Springer (2024) 71. Li, W., Zhao, J., Fan, H., Zhu, S., Liang, W., Yu, H., Lin, P.: Design of general sdn controller system framework for multi-domain heterogeneous networks. In: International Conference on Computational & Experimental Engineering and Sciences, pp. 1195–1209. Springer (2023) 72. Liu, G., Li, H., Wang, N., Chen, B., Le, J., Liu, Y., Xiang, T.: Pecha: Privacy-preserving and efficient crossdomain handover authentication for heterogeneous networks. IEEE Transactions on Dependable and Secure Computing (2024) 73. Lundberg, J., Andersson, K.: Surveying emerging network approaches for military command and control systems. Tech. Rep. FOI-R–5157–SE, FOI (2021) 74. Mahalingam, M., Dutt, D., Duda, K., Agarwal, P., Kreeger, L., Sridhar, T., Bursell, M., Wright, C.: Virtual Extensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks. RFC 7348, Internet Engineering Task Force (IETF) (2014). URL https://datatracker.ietf.org/ doc/html/rfc7348 75. Mahmud, R., Toosi, A.N., Rodriguez, M.A., Madanapalli, S.C., Sivaraman, V., Sciacca, L., Sioutis, C., Buyya, R.: Software-defined multi-domain tactical networks: Foundations and future directions. In: Mobile Edge Computing, pp. 183–227. Springer (2021) 76. Maleh, Y., Qasmaoui, Y., El Gholami, K., Sadqi, Y., Mounir, S.: A comprehensive survey on sdn security: threats, mitigations, and future directions. Journal of Reliable Intelligent Environments 9(2), 201–239 (2023) 77. Mao, M., Yi, P., Hou, L., Zhao, W.: A controller-based roadside unit plane architecture for software-defined in-
SoK: Secure Software-Based Multi-Domain Data Segregation
19
ternet of vehicles. Cluster Computing 27(2), 1235–1249 (2024) 78. Martı́nez-Garcı́a, C., Navarro-Arribas, G., Borrell, J., Martı́n-Campillo, A.: An access control scheme for multiagent systems over multi-domain environments. In: 7th International Conference on Practical Applications of Agents and Multi-Agent Systems (PAAMS 2009), pp. 401–410. Springer (2009) 79. Medved, J., Varga, R., Tkacik, A., Gray, K.: Opendaylight: Towards a model-driven sdn controller architecture. In: Proceeding of IEEE international symposium on a world of wireless, mobile and multimedia networks 2014, pp. 1–6. IEEE (2014) 80. Mishra, V.K., Verma, D.C., Williams, C.: Improving security in coalition tactical environments using an sdn approach. In: Guide to Security in SDN and NFV: Challenges, Opportunities and Applications, pp. 273–298. Springer (2017). DOI 10.1007/978-3-319-64653-4\ 11. URL https://doi.org/10.1007/978-3-319-64653-4_ 11 81. Moher, D., Liberati, A., Tetzlaff, J., Altman, D.G.: Preferred reporting items for systematic reviews and metaanalyses: the prisma statement. Bmj 339 (2009) 82. Moore, A.P., Klinker, J.E., Mihelcic, D.M.: How to construct formal arguments that persuade certifiers. In: Industrial-Strength Formal Methods in Practice, pp. 285– 314. Springer (1999) 83. Morin, M.: Methodology for collecting and analyzing user requirements: Mission-oriented analysis. In: Proceedings of the 24th International Command and Control Research and Technology Symposium (ICCRTS) (2019) 84. Muzafar, S., Jhanjhi, N., Talib, M.N.: Sdn based network management and security in 6g networks. In: 2025 International Conference on Metaverse and Current Trends in Computing (ICMCTC), pp. 1–6. IEEE (2025) 85. Na, M.R., Sundharakumar, K.: A study on air-gap networks. In: 2024 5th International Conference on Innovative Trends in Information Technology (ICITIIT), pp. 1–6. IEEE (2024) 86. Nichols, R.A.: Cyber progression of the domains of warfare. In: International Conference on Computational Science and Computational Intelligence, pp. 64–76. Springer (2024) 87. NIST: Module-Lattice-Based Digital Signature Standard (2024). URL https://nvlpubs.nist.gov/nistpubs/ fips/nist.fips.204.pdf 88. NIST: Module-Lattice-Based Key-Encapsulation Mechanism Standard (2024). URL https://nvlpubs.nist. gov/nistpubs/fips/nist.fips.203.pdf 89. NIST: Post-Quantum Cryptography (2025). URL https: //www.nist.gov/pqcrypto 90. Oppliger, R.: Internet security: firewalls and beyond. Communications of the ACM 40(5), 92–102 (1997) 91. Ou, X., Liao, J., Chen, K., Hu, Z.: Research on the middle platform service system of battlefield data governance information based on 5g technology. In: 2021 3rd International Conference on Artificial Intelligence and Advanced Manufacture, pp. 512–517 (2021) 92. Ouamri, M.A., Alharbi, T., Singh, D., Sylia, Z.: A comprehensive survey on software-defined wide area network (sd-wan): principles, opportunities and future challenges. The Journal of Supercomputing 81(1), 291 (2025) 93. Park, K., Sung, S., Kim, H., Jung, J.i.: Technology trends and challenges in sdn and service assurance for end-toend network slicing. Computer Networks 234, 109908 (2023)
94. PCI: PCI DSS Quick Reference Guide (2018). URL https://listings.pcisecuritystandards.org/ documents/PCI_DSS-QRG-v3_2_1.pdf 95. Poltronieri, F., Campioni, L., Lenzi, R., Morelli, A., Suri, N., Tortonesi, M.: Secure multi-domain information sharing in tactical networks. In: MILCOM 2018-2018 IEEE Military Communications Conference (MILCOM), pp. 1–6. IEEE (2018) 96. Poularakis, K., Tassiulas, L., Lakshman, T.: SDN Data Plane Optimization, pp. 73–127. Springer International Publishing, Cham (2021). DOI 10.1007/ 978-3-031-02382-8 3. URL https://doi.org/10.1007/ 978-3-031-02382-8_3 97. Prete, L.R., Shinoda, A.A., Schweitzer, C.M., De Oliveira, R.L.S.: Simulation in an sdn network scenario using the pox controller. In: 2014 IEEE Colombian Conference on Communications and Computing (COLCOM), pp. 1–6. Ieee (2014) 98. Prisaznuk, P.J.: Integrated modular avionics. In: Proceedings of the IEEE 1992 National Aerospace and Electronics Conference@ m NAECON 1992, pp. 39–45. IEEE (1992) 99. Rivera, A.O.G., White, E.M., Acosta, J.C., Tosh, D.: Enabling device trustworthiness for sdn-enabled internetof-battlefield things. In: 2022 IEEE Conference on Dependable and Secure Computing (DSC), pp. 1–7. IEEE (2022) 100. Rojas, E., Lopez-Pajares, D., Alvarez-Horcajo, J., Llopis Sánchez, S.: The cloud continuum for military deployable networks: Challenges and opportunities. In: European Symposium on Research in Computer Security, pp. 500–519. Springer (2022) 101. RTCA Special Committee 167: DO-178B: Software Considerations in Airborne Systems and Equipment Certification. Standard, Radio Technical Commission for Aeronautics (RTCA), Washington, D.C., USA (2011). Revised version of the original 1992 standard 102. Rushby, J.M.: Design and verification of secure systems. ACM SIGOPS Operating Systems Review 15(5), 12–21 (1981) 103. Saha, S., Low, W., Di Martino, B.: Sustainment of military operations by 5g and cloud/edge technologies. In: International Conference on Advanced Information Networking and Applications, pp. 70–79. Springer (2023) 104. Sahu, K., Kumar, R., Srivastava, R.K., Singh, A.K.: Military computing security: Insights and implications. Journal of The Institution of Engineers (India): Series B pp. 1091–1115 (2024). DOI 10.1007/s40031-024-01136-6. URL https://doi.org/10.1007/s40031-024-01136-6 105. Sasaki, T., Pappas, C., Lee, T., Hoefler, T., Perrig, A.: Sdnsec: Forwarding accountability for the sdn data plane. In: 2016 25th International Conference on Computer Communication and Networks (ICCCN), pp. 1–10. IEEE (2016) 106. Sasaki, T., Perrig, A., Asoni, D.E.: Control-plane isolation and recovery for a secure sdn architecture. In: 2016 IEEE NetSoft Conference and Workshops (NetSoft), pp. 459–464. IEEE (2016) 107. Schöbel, A., Klotz, P., Zaschke, C., Essendorfer, B.: How to test interoperability of different implementations of a complex military standard. In: Advances in Software Engineering, Education, and e-Learning: Proceedings from FECS’20, FCS’20, SERP’20, and EEE’20, pp. 545– 555. Springer (2021) 108. Rodrigues da Silva, C.A., de Souza Silva, L., Santos dos Anjos, J.C., Matiuzzi Stocchero, J., Wickboldt, J., Pignaton de Freitas, E.: Sdn supported network state aware
20 command and control application framework. In: International Conference on Advanced Information Networking and Applications, pp. 448–459. Springer (2024) 109. Singh, S., Jha, R.K.: A survey on software defined networking: Architecture for next generation network. Journal of Network and Systems Management 25(2), 321–374 (2017) 110. Steinmetz, P.: Use of cross domain guards for consis network management. In: 2012 Military Communications and Information Systems Conference (MCC), pp. 1–5. IEEE (2012) 111. Sundaravarathan, V., Alqalaf, H., Siddiqui, A., Kim, K., Lee, S., Reisslein, M., Thyagaturu, A.S., Ross, N., Howard, J., Tayal, S.: Cross-domain solutions (cds): A comprehensive survey. Ieee Access 12, 163551–163620 (2024) 112. Tariq, Z., e Zainab, B., Hussain, M.Z.: Evaluating the effectiveness and resilience of ssl/tls, https, ipsec, ssh, and wpa/wpa2 in safeguarding data transmission. UCP Journal of Engineering & Information Technology 1(2), 01–07 (2023) 113. Thottan, M., Di Martino, C., Kim, Y.J., Atkinson, G., Choi, N., Mohanasamy, N., Jagadeesan, L., Mendiratta, V., Simsarian, J.E., Kozicki, B.: The network os: Carriergrade sdn control of multi-domain, multi-layer networks. Bell Labs Technical Journal 24, 1–26 (2019) 114. Tuchs, K.D., Halmai, T., van Selm, M.: Multi-security domain management integration architecture for endto-end service management in military networks. In: Proceedings of the IEEE Military Communications Conference (MILCOM), pp. 1375–1380 (2011). DOI 10.1109/MILCOM.2011.6127835. URL https://dblp. org/rec/conf/milcom/TuchsHS11.html 115. Tzanakaki, A., Anastasopoulos, M., Rofoee, B., Peng, S., Zervas, G., Nejabati, R., Simeonidou, D., Landi, G., Bernini, G., Monno, R., et al.: Converged wireless access/optical metro networks in support of cloud and mobile cloud services deploying sdn principles. In: FiberWireless Convergence in Next-Generation Communication Networks: Systems, Architectures, and Management, pp. 359–388. Springer (2017) 116. Ullah, F., Edwards, M., Ramdhany, R., Chitchyan, R., Babar, M.A., Rashid, A.: Data exfiltration: A review of external attack vectors and countermeasures. Journal of Network and Computer Applications 101, 18–54 (2018) 117. Vilalta, R., Muñoz, R., Casellas, R., Martı́nez, R., Li, F., Tang, P.: Experimental validation of resource allocation in transport network slicing using the adrenaline testbed. Photonic Network Communications 40(2), 82–93 (2020) 118. Voellmy, A., Wang, J.: Scalable software defined network controllers. In: Proceedings of the ACM SIGCOMM 2012 conference on Applications, technologies, architectures, and protocols for computer communication, pp. 289–290 (2012) 119. van der Wal, R., Veldhuis, R., van den Berg, J., Scholten, G., de Jong, A.: Unified camelot interoperability adapters for existing unmanned command and control systems. Tech. Rep. TNO 2019 R11680, TNO (2019) 120. Waller, A., Johnson, J.: Policy based network management in high assurance environments. In: IEEE Global Telecommunications Conference, 2004. GLOBECOM’04., vol. 4, pp. 2151–2157. IEEE (2004) 121. Wang, M., Zhao, D., Yan, Z., Wang, H., Li, T.: Xauth: Secure and privacy-preserving cross-domain handover authentication for 5g hetnets. IEEE Internet of Things Journal 10(7), 5962–5976 (2022)
Quang Cao1 et al. 122. Wang, S., Wu, J., Yang, W., Guo, L.h.: Novel architectures and security solutions of programmable softwaredefined networking: a comprehensive survey. Frontiers of Information Technology & Electronic Engineering 19(12), 1500–1521 (2018) 123. Wichary, T., Mongay Batalla, J., Mavromoustakis, C.X., Żurek, J., Mastorakis, G.: Network slicing security controls and assurance for verticals. Electronics 11(2), 222 (2022) 124. Woodcock, J., Larsen, P.G., Bicarregui, J., Fitzgerald, J.: Formal methods: Practice and experience. ACM computing surveys (CSUR) 41(4), 1–36 (2009) 125. Wrona, K.: Towards data-centric security for nato operations. In: International Conference on Digital Transformation, Cyber Security and Resilience, pp. 75–92. Springer (2020) 126. Yamany, S., Contreras, L.M., Toy, M.: Network slicing and management. In: Future Networks, Services and Management, pp. 261–287. Springer International Publishing AG, Switzerland (2021) 127. You, X., Wang, C.X., Huang, J., Gao, X., et al.: Towards 6g wireless communication networks: vision, enabling technologies, and new paradigm shifts. Science China Information Sciences 64(1), 1–74 (2021). DOI 10.1007/ s11432-020-2955-6 128. Zhang, B., Fan, Q., Zhang, X., Fu, Z., Wang, S., Li, J., Xiong, Q.: A survey of vnf forwarding graph embedding in b5g/6g networks. Wireless Networks 30(5), 3735–3758 (2024) 129. Zhang, J., Yan, Z., Dong, H., Zhang, P.: Crowdrouting: trustworthy and customized cross-domain routing based on crowdsourcing. Digital Communications and Networks 11(3), 734–756 (2025) 130. Zhang, M., Zhang, R., Yang, M.: Research on verification and validation of operational software program models. In: Proceedings of the 2024 2nd International Conference on Artificial Intelligence, Systems and Network Security, pp. 143–147 (2024) 131. Zhang, Y., Gong, B., Wu, Y., Zheng, G., Diao, Z.: A trusted remote data trading scheme in hybrid sdn for intelligent internet of things. Wireless Communications and Mobile Computing 2023(1), 7463722 (2023) 132. Zhao, Y., Sanán, D., Zhang, F., Liu, Y.: High-assurance separation kernels: a survey on formal methods. arXiv preprint arXiv:1701.01535 (2017) 133. Zhao, Y., Yang, Z., Ma, D.: A survey on formal specification and verification of separation kernels. Frontiers of Computer Science 11(4), 585–607 (2017) 134. Zhou, Y., Yin, S., Guo, B., Huang, H., Li, W., Zhang, M., Huang, S.: Experimental demonstration of softwaredefined optical network for heterogeneous packet and optical networks. Photonic Network Communications 32(2), 329–335 (2016) 135. Zou, Y.: Implementation of multi-level network security management system based middleware strategy. International Journal of Security and Its Applications 10(10), 77–88 (2016)
A Software Defined Networking (SDN) Software Defined Networking (SDN) emerged as a necessary response to the longstanding limitations of traditional networks. These legacy systems suffered from the rigidity of vertically integrated devices, where control logic (the decision-making process for directing traffic) and the data forwarding plane (the
SoK: Secure Software-Based Multi-Domain Data Segregation
21
physical transmission of traffic) were tightly coupled within each router and switch. This inflexibility created challenges, making networks difficult and slow to evolve. Every device required manual configuration, policies were enforced inconsistently, and introducing new protocols often necessitated costly hardware upgrades throughout the entire infrastructure [76, 44, 109, 36]. SDN addresses this rigid, device-centric approach by separating the network’s control plane from its data plane. Instead of each router making independent routing decisions, SDN consolidates all control logic into a single, logically centralized controller. This change allows network switches to focus solely on forwarding packets according to the rules provided by the controller, which is done instantly and automatically. The result is a programmable network that is easier to manage and much more adaptable to modern demands [76, 44, 109, 36]. By centralizing control, SDN eliminates the tedious and error-prone task of manually configuring each device. Network policies are set at the controller, which automatically and consistently distributes rules across all switches. This approach removes the need for unique, proprietary management protocols, resulting in a flexible and automated operational model that reduces human error, speeds up deployment, and simplifies configuration and troubleshooting. The SDN controller provides a global network view, allowing it to coordinate essential functions such as access control, flow scheduling, load balancing, and security policies. Achieving this level of consistency is often difficult in traditional distributed networks. Additionally, the abstraction layers of SDN enable applications to view the network as a unified system, enhancing applicationdriven performance. Advococacy for open standards such as OpenFlow addresses vendor lock-in, allowing easy integration of equipment from multiple vendors. This openness enables researchers and enterprises to test new protocols without hardware modifications, fostering the development of innovative network applications. Such vendor independence has driven significant adoption within modern data centers and cloud networks [76, 44, 109, 36].
the physical network equipment, such as switches and routers, and the internal components and APIs that handle packet processing. The core functionality of a network device in this plane is to receive packets at its ports and execute specific network functions based on rules provided by the Control Plane. This includes actions such as forwarding the packet to an egress port, dropping the packet, or modifying its header [76, 44, 109, 36]. Control plane: The control layer of Software-Defined Networking (SDN) is built around the SDN controller, which centralizes network intelligence and operates similarly to a network operating system. The controller manages flow tables on switches and routers through the Southbound API, with OpenFlow being the most widely used protocol. Through a secure channel, the controller installs, updates, and removes forwarding rules on OpenFlow-enabled devices [76, 44, 109, 36]. A variety of SDN controllers exist, differing in language, threading models, OpenFlow support, and performance characteristics. Key examples include [76, 44, 109, 36]: – NOX [48]: The first public SDN controller, implemented in C. – POX [97]: A Python-based controller derived from NOX, aimed at improving usability and performance. – Maestro [18]: A multi-threaded controller that distributes tasks efficiently to support parallel processing. – Beacon [37]: A Java-based, multi-threaded, modular controller developed at Stanford, designed for cross-platform use. – SNAC [27]: A controller with a web-based interface for configuring rules and managing events. – Floodlight [11]: A lightweight, high-performance version of Beacon, supported by major vendors such as Intel, Cisco, HP, and IBM. – McNettle [118]: Built with Nettle (a DSL in Haskell), designed for low-latency, high-performance operation on multi-core servers. – Ryu [56]: A Python controller supporting OpenFlow 1.5 and enabling domain separation without VLANs. – OpenDaylight [79]: A Java-based, open-source, crossplatform controller using OSGi and REST APIs, supported by industry partners such as IBM, NEC, Cisco, and Ericsson. Application plane: The Application Plane is the highest level in the SDN architecture, representing the set of software programs and utilities that configure, control, and monitor the network’s behavior. This layer enables the implementation of crucial network management rules and services through various applications, such as Intrusion Detection Systems (IDS), firewalls, and load balancing. Crucially, it promotes automation by interacting with the centralized SDN Controller via northbound APIs, typically using protocols such as REST (Representational State Transfer), allowing service providers to dictate network policy and abstracting the underlying network complexities. Sitting above the Control Plane, the Application Plane uses these APIs to access and interpret network status information provided by the controller, enabling applications to manipulate physical network elements indirectly for sophisticated services such as security monitoring and traffic engineering [76, 44, 109, 36].
A.1 SDN Architecture The Open Networking Foundation outlines three core ideas that define Software-Defined Networking (SDN) [105, 106]: 1. Decoupled Control and Forwarding: SDN separates the logic that determines how traffic should be handled from the hardware that actually forwards packets. Even with this separation, the control logic continues to interact with and influence the forwarding devices. 2. Logically Centralized Control: Rather than relying on distributed decision-making across individual devices, SDN employs a central controller that maintains a global view of the network. This unified perspective enables consistent policy enforcement and reduces delays caused by local configuration. 3. Programmable Network Abstractions: SDN exposes abstracted representations of network resources and state, enabling external applications to program the network without dealing with device-specific details. These principles are reflected in the SDN architectural design, which is typically organized into three planes: Data plane: The Data plane (or Infrastructure layer) is responsible for the high-speed forwarding of network traffic. It comprises
B Network Slicing Network slicing builds on virtualization by creating end-to-end, service-specific virtual networks tailored to different perfor-
Quang Cao1 et al.
22 mance or security requirements. Each slice functions as an independent logical network with its own control, data, and management characteristics, even while sharing the same physical infrastructure. This approach is essential in modern systems such as 5G, mission-critical communications, and multidomain environments. Network slicing enables fine-grained customization and efficient resource allocation, allowing providers to support diverse use cases without deploying separate physical networks [21, 14, 126].
B.1 Vertical Slicing Vertical slicing is a key principle in 5G architecture, allowing for the creation of customized end-to-end logical networks tailored to specific industry needs. Each slice covers multiple network layers, such as access, transport, and core domains, designed for particular use cases such as automotive systems and industrial automation. These slices maintain distinct service-level attributes, including latency, throughput, reliability, and security, ensuring isolation to prevent performance degradation. This isolation is vital for delivering specialized services over shared infrastructure, supporting the Network-as-a-Service (NaaS) paradigm for flexible, ServiceLevel Agreement (SLA)-driven offerings [52].
B.2 Horizontal Slicing Horizontal slicing involves resource partitioning within a single network layer, such as the radio access network (RAN) or transport network. It enables multiple virtualized functions to operate simultaneously, focusing on resource sharing and management rather than end-to-end service delivery. This approach supports scenarios requiring infrastructure sharing and dynamic scaling, key to Software-Defined Networking (SDN) and Network Functions Virtualization (NFV). For instance, vertical baseband units in the RAN can share hardware while maintaining distinct performance profiles, enhancing network flexibility and cost-effectiveness [52].
B.3 Static Slicing Static slicing configures network slices during the design phase, keeping them fixed throughout operation. Each slice has a predetermined set of resources and performance metrics optimized for specific services. While it simplifies administration, static slicing is less adaptable to demand fluctuations, risking inefficient utilization and making it difficult to accommodate new services without manual reconfiguration. Although important in early network slicing, its limitations are more evident in today’s dynamic 5G environments, prompting a shift towards more adaptive solutions [52].
B.4 Dynamic Slicing Dynamic slicing allows networks to create, modify, and remove slices in real-time based on user demand and network conditions. Unlike static slicing, it employs automation and AI-driven management for efficient resource provisioning with minimal human input. This flexibility is crucial for modern applications such as connected vehicles and IoT deployments,
enhancing resource efficiency and reducing operational costs. Dynamic slicing requires real-time monitoring and orchestration, representing a significant advancement in network slicing, especially for future 6G networks accommodating variable services and stringent SLAs [52].
C Cross Domain Solution (CDS) Cross Domain Solution (CDS) is a system that includes security mechanisms specifically designed to manage the risks associated with accessing or transferring information between different security domains. A CDS is designed to block the flow of information between different security domains by default, permitting only specific data to pass through security enforcement points when it fully complies with the defined security policy. The security-enforcing functions within a CDS can be implemented using separate hardware or software components, and the system’s architecture must ensure that these components cannot be bypassed [6]. A secure CDS implementation ensures that the security policies of all connected domains are consistently enforced across every physical and logical layer of the connection. Therefore, it is essential that the information security objectives are clearly understood before the design or implementation of a CDS begins. These objectives include [5]: – Confidentiality: Ensuring that information is disclosed only to authorized entities. – Integrity: Ensuring that information and systems cannot be modified without proper authorization. – Availability: Ensuring that systems remain accessible and usable by authorized entities whenever required. – Authenticity: Ensuring that the identity of a user, process, or device is verified before granting access to system resources. – Accountability: Ensuring that the origin and integrity of data can be verified, and that any authenticated actions cannot be repudiated (also known as non-repudiation). The secure design and operation of a CDS can only be achieved if every stage of the system lifecycle produces outputs that are traceable to the security requirements derived from these objectives. Typical CDS applications include importing publicly available data from an official network into a SECRET-level analysis system, combining multiple classified desktop environments into a single interface, or gathering inputs from various classified systems into a single central auditing platform [6]. When CDS controls are not properly enforced, connections between different security domains can be exploited by malicious actors. This can result in unauthorised access, theft or alteration of sensitive information, and the compromise of system or data integrity. Weak enforcement may also enable attackers to bypass critical security functions, disrupt essential systems or services, and use less-protected networks as pathways to reach more sensitive environments [6]. The National Cross Domain Strategy and Management Office (NCDSMO) delineates three categories of Cross Domain Solutions (CDS): access, transfer, and Multi-Level Security (MLS) solutions. These classifications are based on the varying types of interactions that CDS devices have with data, which can be categorized according to different security levels or classifications [111].
SoK: Secure Software-Based Multi-Domain Data Segregation
C.1 Access Access refers to a type of Cross-Domain Solution (CDS) used when a client in an untrusted or low-side domain needs to view information from a trusted high-side domain, or vice versa. These solutions allow users to see data without allowing any actual data transfer between the domains, thereby helping to prevent information leaks. For example, an employee at the Arizona State University (ASU) Tempe campus (low side) who needs to view specific data stored at the ASU Research Enterprise (ASURE), which works on defence and space systems (high side), could use an access CDS to securely view that information across domains [111]. Before Cross-Domain Solutions (CDS), secure data sharing across domains relied on a manual Swivel Chair Setup. Staff used separate desktops for each domain and retyped information between systems. CDS were created to automate and streamline these labour-intensive processes for domains with different trust levels (e.g., top secret, secret, unclassified), though their design and accreditation are complex and mostly used in military and commercial settings [111]. A CDS can be hardware, software, or both, providing isolation between domains while enabling controlled information flow. An access CDS lets a user in one domain view data in another without transferring it. A transfer CDS securely moves or copies data between domains. An MLS solution labels and manages both users and data across multiple classification or trust levels [111]. In everyday language, accessing often means both viewing and downloading data, but CDS terminology separates these clearly. With an access CDS, only encrypted keyboard/mouse input goes to the remote desktop and encrypted display data returns; files never leave the remote environment. Thus, in CDS terms, accessing can mean either viewing only (access CDS) or requesting/downloading data between domains (transfer CDS), and the distinction is critical for security [111].
C.2 Transfer Transfer Cross-Domain Solutions (CDS) support secure data exchange between domains by allowing information to be moved or copied across environments with different trust levels. They are generally classified as either unidirectional or bidirectional [111]. In a unidirectional solution, data flows in only one direction. A common example is a data diode, which ensures information can travel from machine A to machine B, but never in reverse [111]. Bidirectional solutions, on the other hand, allow information to flow both ways, making real-time interaction possible. Guards are an example of this type; they control the exchange of data between machine A and machine B based on predefined rules, enabling interactive communication (such as a Zoom call) while filtering which information is permitted and which is blocked [111].
C.3 Multi-Level Security (MLS) Multi-Level Security (MLS) refers to systems that tag both users (subjects) and data (objects) with security labels and apply mandatory security rules, such as those from the Biba Data Integrity model. Using Mandatory Access Control (MAC) and labelling, MLS systems ensure that only appropriately
23 cleared users can access certain information. For example, in an environment with top-secret, secret, and unclassified levels, a user with secret clearance may view secret and unclassified data but cannot access top-secret material, while someone with top-secret clearance can access information at all three levels [111].
C.4 Comparison with Other Security Tools Unlike conventional firewalls that filter traffic based on IP addresses, ports, or basic protocol rules, CDS perform deep, content-level inspection of all data transfers. While nextgeneration firewalls add features such as application awareness and limited content analysis, CDS go much further by examining data at the bit level, validating file structures, detecting hidden content, and enforcing granular rules based on data classification and content type [6]. Although data diodes are sometimes compared to CDS, their functionality is limited to one-way data transmission, ensuring information only moves in a single direction to prevent leakage. In contrast, CDS enable secure, bidirectional communication through advanced controls, allowing two-way workflows without compromising strict security boundaries, a key advantage in complex operational environments [6]. Virtual Private Networks (VPNs) provide encrypted channels for secure data transit but do not validate content or enforce security policies tied to data sensitivity. Consequently, while VPNs protect data integrity during transmission, they are inadequate for connecting domains with differing security classifications or preventing unauthorized data sharing [6]. Another defining feature of CDS is their adherence to formal certification, assessment, and accreditation requirements, which vary across national security frameworks. In the United States, CDS products are subject to requirements established by the National Cross Domain Strategy and Management Office (NCDSMO), including the evolving Raise the Bar (RTB) initiative, which promotes stronger security measures such as hardware-enforced security and advanced content filtering. These requirements are intended to increase the level of assurance provided by CDS when protecting classified and missioncritical systems. Other nations apply their own standards and regulatory frameworks. For example, in Australia, the Australian Signals Directorate (ASD) provides cross-domain security guidance through the Information Security Manual (ISM), which emphasises appropriate security-enforcing mechanisms, secure architecture and design, and high-assurance components for CDS implementations. [6]
D Separation Kernels The separation kernel concept, introduced by Rushby in 1981 [102], serves to separate kernel verification from the validation of trusted code across distinct components. Its primary goal is to enforce the segmentation of software components while minimizing the Trusted Computing Base (TCB). Security is achieved through both the physical separation of system components and trusted functionalities within these components. This concept laid the foundation for the Multiple Independent Levels of Security/Safety (MILS), as described by Jim et al. in 2006 [4], which emphasizes separation and controlled information flow. A separation kernel is a small, highly secure, and verifiable type of bare-metal hypervisor or microkernel designed
Quang Cao1 et al.
24 to enforce strict isolation between different software components (partitions) running on the same physical hardware. Its primary function is to create an environment that acts as if each partition is a separate, physically isolated machine, with strictly controlled information flow between them [132]. Initially applied in the avionics sector with Integrated Modular Avionics (IMA) in the 1990s [98], separation kernels function as partitioning kernels, focusing primarily on safety concerns. Their limited size allows for formal verification, facilitating thorough correctness assessments. The success of formal methods in both academic research and industrial applications is increasingly evident, as noted by Woodcock et al. in 2009 [124]. Certified security is typically achieved through Common Criteria (CC) evaluation, mandated by the National Security Agency, which involves formal methods for high-assurance levels, comprehensive security analysis, and formal proofs of model correspondence. The Separation Kernel Protection Profile (SKPP), established by the National Security Agency in 2007, specifically addresses the certification of separation kernels, while safety regulations are governed by RTCA DO-178B [58] and its 2011 successor, DO-178C [101], which includes a formal methods supplement.
– Evaluatable: Security functions should be sufficiently small and simple to allow for rigorous correctness proofs through mathematical verification. This requires components to be modular, well-designed, well-specified, wellimplemented, small, and of low complexity. – Always-invoked: Security functions must always be operational. This means each access or message is subjected to scrutiny by relevant security monitors, ensuring that checks are conducted not only at the initial access but also for all subsequent interactions. – Tamper-proof : The system must control modification rights pertaining to the security monitor’s code, configuration, and data. This protection prevents unauthorized alterations, whether arising from subversive actions or poorly written code. While these concepts may seem intuitive, formalizing and proving them can be challenging. Separation kernels are typically verified by demonstrating properties related to data separation, temporal separation, information flow security, and fault isolation.
E Selected Papers D.1 Multiple Independent Levels of Security (MILS) The separation kernel serves as the foundational layer of a Multiple Independent Levels of Security (MILS) architecture. Its role is to provide a trusted execution environment with minimal, formally verifiable code that enforces strict security policies [133]. The security requirements for MILS encompass four foundational properties: – Data Separation: Each partition functions as a distinct resource. Applications within one partition are unable to modify the applications or private data of other partitions, nor can they command the private devices or actuators associated with those partitions. This property is also referred to as “Data Isolation.” – Information Flow Security: Information exchanged between partitions must originate from an authenticated source and be directed to authenticated recipients. The source must be verifiable to the recipients. This is known as “Control of Information Flow.” – Temporal Separation: This property enables different components to utilize the same physical resource at different time intervals. A resource is allocated to one component for a designated period, thoroughly cleared, and then reallocated to another component. The services accessed from shared resources by applications in one partition cannot be impacted by those in other partitions. This concept is also known as “Periods Processing.” – Fault Isolation: This property limits damage by ensuring that a failure in one partition does not propagate to other partitions. NEAT refers to the well-known properties associated with separation kernels. The acronym NEAT stands for Nonbypassable, Evaluatable, Always-invoked, and Tamper-proof: – Non-bypassable: Security functions must be inviolable, meaning that components cannot utilize alternative communication paths, including lower-level mechanisms, to circumvent the security monitor.
E.1 Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Network Slicing This section consolidates research on programmable network architectures, including SDN controllers, NFV frameworks, virtual network function (VNF) embedding, network slicing, slice security, and emerging 5G/6G infrastructures for missioncritical and next-generation communication systems. 1. A Comprehensive Study on 5G: RAN Architecture, Enabling Technologies, Challenges, and Deployment [3] 2. A Survey on Requirements of Future Intelligent Networks: Solutions and Future Research Directions [51] 3. Mission Critical Communications Support With 5G and Network Slicing [15] 4. Towards 6G wireless communication networks: vision, enabling technologies, and new paradigm shifts [127] 5. A comprehensive survey on SDN security: threats, mitigations, and future directions [76] 6. A Systematic Review of Quality of Services (QoS) in Software Defined Networking (SDN) [63] 7. Converged Wireless Access/Optical Metro Networks in Support of Cloud and Mobile Cloud Services Deploying SDN Principles [115] 8. Experimental demonstration of software-defined optical network for heterogeneous packet and optical networks [134] 9. Integrated NFV/SDN Architectures: A Systematic Literature Review [12] 10. Novel architectures and security solutions of programmable software-defined networking: a comprehensive survey [122] 11. Performance analysis for a service delivery platform in software defined network [35] 12. Programmable, Controllable Networks [9] 13. SDN Data Plane Optimization [96] 14. SDNSOC: Object Oriented SDN Framework [26] 15. Security Issues in Programmable Routers for Future Internet [17] 16. The network OS: Carrier-grade SDN control of multidomain, multi-layer networks [113]
SoK: Secure Software-Based Multi-Domain Data Segregation
25
17. A comprehensive survey on software-defined wide area 3. Use of cross domain guards for CoNSIS network managenetwork (SD-WAN): principles, opportunities and future ment [110] 4. A lightweight and secure online cross-domain authenticachallenges [92] tion scheme for VANET systems in Industrial IoT [64] 18. A survey on software defined networking and its applica5. An Access Control Scheme for Multi-agent Systems over tions [44] Multi-Domain Environments [78] 19. A Survey on Software Defined Networking: Architecture 6. A games-in-games approach to mosaic command and confor Next Generation Network [109] trol design of dynamic network-of-networks for secure and 20. Design of General SDN Controller System Framework for resilient multi-domain operations [23] Multi-domain Heterogeneous Networks [71] 7. Decision-Dominant Strategic Defense Against Lateral Move21. A Survey of Network Virtualization Techniques for Interment for 5G Zero-Trust Multi-Domain Networks [70] net of Things Using SDN and NFV [2] 8. PECHA: Privacy-Preserving and Efficient Cross-Domain 22. Network Slicing and Management [126] Handover Authentication for Heterogeneous Networks [72] 23. A survey of VNF forwarding graph embedding in B5G/6G 9. Secret key rate-adaptive inter-domain key service pronetworks [128] visioning in heterogeneous protocol-based multi-domain 24. Experimental validation of resource allocation in transport quantum networks [25] network slicing using the ADRENALINE testbed [117] 10. Satellite Networking in the Context of Green, Flexible and 25. Dynamic network slicing management of multimedia sceProgrammable Networks [31] narios for future remote healthcare [21] 11. Cyber Progression of the Domains of Warfare [86] 26. A Trusted Remote Data Trading Scheme in Hybrid SDN for Intelligent Internet of Things [131] 27. CERBERUS: Towards Secure and Automated Multi-operator Management in B5G Through a Dynamic Policy-Based E.3 Command, Control, and Military Systems ZSM Framework [19] 28. Hash Flow: An Access Control Mechanism for Software This section consolidates research on Command and ConDefined Network [22] trol (C2) and Command, Control, Communications, Comput29. Network Slicing Security Controls and Assurance for Verers, Intelligence, Surveillance, and Reconnaissance (C4ISR) ticals [123] systems, focusing on architectures, interoperability, secure 30. Policy based network management in high assurance envicommunications, cyber defense, and modernized military netronments [120] work infrastructures. These works collectively address system31. SDN Based Network Management and Security in 6G of-systems design, tactical networking, multi-domain secuNetworks [84] rity, and cloud/edge-enabled military operations that support 32. SDN-based security management of multiple WoT Smart mission-critical decision-making and coordinated defense acSpaces [36] tivities. 33. SDN Enabled QoE and Security Framework for Multime1. Methodology for Collecting and Analyzing User Requiredia Applications in 5G Networks [67] ments: Mission-Oriented Analysis [83] 34. Software-Defined Mobile Networks Security [24] 2. Surveying Emerging Network Approaches for Military 35. Specification of a Policy Based Network Management arCommand and Control Systems [73] chitecture [10] 3. Unified CAMELOT Interoperability Adapters for Existing 36. Survey on Joint Paradigm of 5G and SDN Emerging Unmanned Command and Control Systems [119] Mobile Technologies: Architecture, Security, Challenges 4. A Review on C3I Systems’ Security: Vulnerabilities, Atand Research Directions [61] tacks, and Countermeasures [1] 37. Towards constructive approach to end-to-end slice isolation 5. An applied model for secure information release between in 5G networks [66] federated military and non-military networks [34] 38. Mission critical communications support with 5G and 6. Improving Security in Coalition Tactical Environments network slicing [14] Using an SDN Approach [80] 39. Software-Defined Multi-domain Tactical Networks: Foun7. Military Computing Security: Insights and Implications dations and Future Directions [75] [104] 40. Surveying emerging network approaches for military com8. Multi-security domain management integration architecmand and control systems [43] ture for end-to-end service management in military networks [114] 9. Research on the Middle Platform Service System of Battlefield Data Governance Information based on 5G TechE.2 Cross-Domain, Multi-Domain, and Heterogeneous nology [91] 10. SDN Supported Network State Aware Command and This section consolidates research addressing interoperability Control Application Framework [108] and coordination across separate administrative and security 11. Secure Multi-Domain Information Sharing in Tactical Netdomains (cross-domain), joint operations spanning multiple works [95] operational or network domains (multi-domain), and integra12. Sustainment of Military Operations by 5G and Cloud / tion across diverse technologies and platforms (heterogeneous Edge Technologies [103] environments). These works collectively explore routing, auTowards Data-Centric Security for NATO Operations [125] 13. thentication, access control, resilience, guard mechanisms, and 14. Software-Defined Multi-domain Tactical Networks: Founinter-domain key management in complex distributed systems. dations and Future Directions [75] 1. CrowdRouting: Trustworthy and customized cross-domain 15. The Cloud Continuum for Military Deployable Networks: routing based on crowdsourcing [129] Challenges and Opportunities [100] 2. XAuth: Secure and Privacy-Preserving Cross-Domain Han16. Distributed MILS: A novel approach to advanced ATM dover Authentication for 5G HetNets [121] communication services [60]
26
E.4 Cybersecurity, Threat Detection, and Policy This section examines foundational and advanced topics in cybersecurity, highlighting mechanisms for secure communication, identity and access management, multilevel security architectures, and the formal assurance processes required to certify high-assurance systems. It also includes specialised cryptographic techniques and frameworks that support robust security policy enforcement across diverse operational environments. 1. A Multi-protocol Authentication Shibboleth Framework and Implementation for Identity Federation [69] 2. Attaining Precedence-Based Communications in Secure IP Networks [45] 3. How to Construct Formal Arguments that Persuade Certifiers [82] 4. Implementation of Multi-level Network Security Management System based Middleware Strategy [135] 5. Speech cryptography algorithms: utilizing frequency and time domain techniques merging [39]
E.5 Secure IoT Architecture and Policy Control This section brings together research that advances secure communication architectures, robust identity and access management frameworks, and practical methods for enforcing and validating security policies. The selected works explore federated authentication protocols, precedence-based communication in protected IP networks, formal assurance techniques for certifiers, multi-level network security management, secure speech processing, and high-assurance communication models. Collectively, these papers highlight emerging strategies for strengthening trust, control, and resilience across modern distributed systems. 1. Enabling Device Trustworthiness for SDN-Enabled Internetof-Battlefield Things [99] 2. SDN-based security management of multiple WoT Smart Spaces [36] 3. A controller-based roadside unit plane architecture for software-defined internet of vehicles [77] 4. Edge computing in SDN-IoT networks: a systematic review of issues, challenges and solutions [57] 5. Toward a Robust WAN-Scale IoT-Fog Networks: A Distributed SDN Security Architecture Encompassing Monitoring, Scalability, Reliability, and Security [33]
E.6 Foundational Security and Assurance This section covers general frameworks, security models, and system assurance methods applicable across networks, software, and operational domains. 1. A Review of Policy-Based Resource and Admission Control Functions in Evolving Access and Next Generation Networks [38] 2. Lightweight Capability Domains: Towards Decomposing the Linux Kernel [54] 3. How to Test Interoperability of Different Implementations of a Complex Military Standard [107] 4. Research on Verification and Validation of Operational Software Program Models [130]
Quang Cao1 et al.