Patent · US Active

Multi-level secure (MLS) information network

US7676673B2 · kind B2 · utility

152Cited by
9References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 28, 2006
Grant dateMar 9, 2010
Priority date
Expiry dateJan 7, 2029

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2113
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method of enforcing a network security policy including mandatory access control (MAC), discretionary access control (DAC) and integrity control for a secure information network, includes operating a transport guard within a memory partition logically between a protected application running in the partition and a networking stack, and defining ports for the transport guard including (i) an application port for forwarding data to and receiving data from the application, (ii) a data port for receiving data addressed to the application from the networking stack, and for sending data originating from the application to the stack, and (iii) a control port for supplying configuration data to the transport guard. The configuration data corresponds to MAC, DAC and integrity control policies specified by the network for the protected application. The transport guard limits data flow between its protected application and the data ports accordingly.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.