Communication outside the intended path
A covert channel is an unintended mechanism that cooperating subjects use to transfer information in violation of policy. A sender deliberately modulates shared state or timing. A receiver observes the changes and decodes the message.
A storage channel changes a shared object, allocation, name, error, or resource state. A timing channel changes when work, contention, or events occur. The intended interface can deny direct communication while the shared mechanism still carries bits.
Difference from a side channel
A side channel often leaks information because a victim's behavior correlates with a secret. A covert channel usually has a cooperating sender that intentionally encodes information. One mechanism can support both. Cache contention can leak an uncooperative victim's access pattern or carry a deliberate signal between isolated workloads.
Find and measure channels
Inventory shared caches, CPUs, memory, files, names, locks, quotas, network queues, logs, status codes, resource exhaustion, scheduler state, and administrative workflows. Determine sender and receiver access, symbol choices, error rate, bandwidth, noise, detectability, and operational value.
Prioritize channels by credible data rate and attacker conditions. A low-bandwidth channel can still leak a key, approval bit, identity, or presence signal.
Failure and residual risk
Removing one shared resource can move the channel to another. Random delay can reduce bandwidth and rarely proves elimination. Strong tenant isolation can still share hardware, management, network, power, or observability. Monitoring can miss low-rate or adaptive signaling and can itself create a shared channel.
Complete channel elimination is difficult in general-purpose shared systems. The design can reduce sharing, constrain sender and receiver, limit secret lifetime, add noise, monitor patterns, and accept a bounded residual capacity.
Pomerium boundary
Pomerium controls documented request paths. It does not prevent cooperating upstream workloads from signaling through shared hosts, caches, quotas, response timing, logs, or external systems. Operators must choose isolation and resource-sharing boundaries that match the tenant and data threat model.
Evaluation checklist
- Which sender and receiver can share storage, timing, load, quota, cache, error, name, or administrative state?
- What symbols can the sender modulate, and what bandwidth and error rate can the receiver achieve?
- Is the channel accidental leakage, deliberate cooperation, or usable as both?
- Which isolation, scheduling, partitioning, rate, secret-lifetime, and monitoring control reduces the exact channel?
- Is the remaining capacity enough to leak a key, identity, presence signal, or policy result?
