首页> 外国专利> MULTI-LEVEL SECURITY SYSTEM FOR ENABLING SECURE FILE SHARING ACROSS MULTIPLE SECURITY LEVELS AND METHOD THEREOF

MULTI-LEVEL SECURITY SYSTEM FOR ENABLING SECURE FILE SHARING ACROSS MULTIPLE SECURITY LEVELS AND METHOD THEREOF

机译:跨多个安全级别启用安全文件共享的多级安全系统及其方法

摘要

A multi-level security system includes a storage medium partitionable into a plurality of partitions, a file system coupleable to the plurality of partitions, and a plurality of enclaves. Each enclave is assigned a security classification level. Each enclave resides in a different storage partition of the storage medium. Data stored on the storage medium is cryptographically separated at rest on a per-enclave basis. Cryptographic separation occurs at the disk block level, allowing individual blocks to be read and decrypted. The system also includes a reference monitor that enforces a system security policy that governs access to information between the enclaves. The reference monitor allows an enclave having a first classification level to securely read-down to an enclave having a second classification level lower than the first classification level and to write to another enclave having the first classification level.
机译:一种多级安全系统,包括可划分为多个分区的存储介质,可耦合至所述多个分区的文件系统以及多个区域。每个飞地都分配了一个安全分类级别。每个区域都位于存储介质的不同存储分区中。存储在存储介质中的数据在每个安全区的基础上被加密分离。加密分离发生在磁盘块级别,允许读取和解密单个块。该系统还包括一个参考监控器,该参考监控器强制执行一项系统安全策略,该策略管理对安全区之间信息的访问。参考监视器允许具有第一分类级别的安全区可靠地读取到具有低于第一分类级别的第二分类级别的安全区,并写入具有第一分类级别的另一个安全区。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号