Patent · US Active

Multi-level security system for enabling secure file sharing across multiple security levels and method thereof

US9489534B2 · kind B2 · utility

6Cited by
13References
6Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 23, 2014
Grant dateNov 8, 2016
Priority date
Expiry dateOct 28, 2034

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2113
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A multi-level security system includes a storage medium partitionable into a plurality of partitions, a file system coupleable to the plurality of partitions, and a plurality of enclaves. Each enclave is assigned a security classification level. Each enclave resides in a different storage partition of the storage medium. Data stored on the storage medium is cryptographically separated at rest on a per-enclave basis. Cryptographic separation occurs at the disk block level, allowing individual blocks to be read and decrypted. The system also includes a reference monitor that enforces a system security policy that governs access to information between the enclaves. The reference monitor allows an enclave having a first classification level to securely read-down to an enclave having a second classification level lower than the first classification level and to write to another enclave having the first classification level.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.