Invention Grant
- Patent Title: Multi-level secure (MLS) information network
- Patent Title (中): 多级安全(MLS)信息网络
-
Application No.: US11414105Application Date: 2006-04-28
-
Publication No.: US07676673B2Publication Date: 2010-03-09
- Inventor: Michael K. Weller , Tarachrand A. Mangra , Joseph A. Litzinger , Sanket J. Shah
- Applicant: Michael K. Weller , Tarachrand A. Mangra , Joseph A. Litzinger , Sanket J. Shah
- Applicant Address: US NH Nashua
- Assignee: BAE Systems Information and Electronic Systems Integration Inc.
- Current Assignee: BAE Systems Information and Electronic Systems Integration Inc.
- Current Assignee Address: US NH Nashua
- Agent Leo Zucker
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method of enforcing a network security policy including mandatory access control (MAC), discretionary access control (DAC) and integrity control for a secure information network, includes operating a transport guard within a memory partition logically between a protected application running in the partition and a networking stack, and defining ports for the transport guard including (i) an application port for forwarding data to and receiving data from the application, (ii) a data port for receiving data addressed to the application from the networking stack, and for sending data originating from the application to the stack, and (iii) a control port for supplying configuration data to the transport guard. The configuration data corresponds to MAC, DAC and integrity control policies specified by the network for the protected application. The transport guard limits data flow between its protected application and the data ports accordingly.
Public/Granted literature
- US20070255942A1 Multi-level secure (MLS) information network Public/Granted day:2007-11-01
Information query