首页> 外国专利> APPARATUS AND METHOD FOR PROVIDING TRUSTED CHANNEL IN SECURE OPERATING SYSTEMS WHICH ARE BY USING MANDATORY ACCESS CONTROL POLICY

APPARATUS AND METHOD FOR PROVIDING TRUSTED CHANNEL IN SECURE OPERATING SYSTEMS WHICH ARE BY USING MANDATORY ACCESS CONTROL POLICY

机译:通过使用强制访问控制策略在安全操作系统中提供可信通道的设备和方法

摘要

PURPOSE: An apparatus and a method for providing a reliable channel in a security OS(Operating System) to which MAC(Mandatory Access Control) is applied is provided to offer a new header for independently encoding a packet used in communication by a security level of the MAC and minimize network performance degradation using the security level of the MAC. CONSTITUTION: If data according to a communication request provided from a transmission-side user(S1) are for a packet transmission request, a reliable channel subsystem(12) judges whether a reliable channel is applied. If the reliable channel is applied, the reliable channel subsystem(12) composes a reliable channel header, encodes a specific portion of a packet, stores authentication information in the reliable channel header, and transmits the packet through a network(A). A MAC module(20) provides MAC information for indicating whether the reliable channel is applied. A kernel memory(30) provides an encryption key and an authentication key necessary for encoding a reliable channel application host address and the packet and generating authentication data. A reliable channel subsystem(12-1) retrieves the authentication data of the reliable channel header before decoding the packet received through the network(A). If the authentication data are valid, the reliable channel subsystem(12-1) decodes the encoded packet. If process for the reliable channel is ended, the reliable channel subsystem(12-1) transmits the packet to an upper level to transmit the packet to a reception-side user(S2). A kernel memory provides an authentication key and an encryption key necessary for checking authentication with respect to the packet encoded by the reliable channel subsystem(12) and decoding the packet.
机译:目的:提供一种装置和方法,用于在应用了MAC(强制访问控制)的安全OS(操作系统)中提供可靠的信道,以提供新的报头,用于以安全等级为1来独立编码用于通信的数据包。使用MAC的安全级别来降低MAC并最大程度地降低网络性能。构成:如果根据传输方用户(S1)提供的通信请求的数据是针对分组传输请求的,则可靠信道子系统(12)判断是否应用了可靠信道。如果应用了可靠信道,则可靠信道子系统(12)组成可靠信道报头,对分组的特定部分进行编码,将认证信息存储在可靠信道报头中,并通过网络(A)发送该分组。 MAC模块(20)提供用于指示是否应用了可靠信道的MAC信息。内核存储器(30)提供加密密钥和认证密钥,该加密密钥和认证密钥是对可靠的信道应用主机地址和分组进行编码并生成认证数据所必需的。可靠通道子系统(12-1)在解码通过网络(A)接收到的数据包之前检索可靠通道头的身份验证数据。如果认证数据有效,则可靠信道子系统(12-1)对编码的分组进行解码。如果可靠信道的处理结束,则可靠信道子系统(12-1)将分组发送到上级,以将分组发送给接收侧用户(S2)。内核存储器提供认证密钥和加密密钥,该认证密钥和加密密钥对于检查由可靠信道子系统(12)编码的分组的认证并对该分组进行解码是必要的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号