IP Library Granted Patent US 6,931,411
Granted Patent B1
US 6,931,411 · App. 10/157,231 · Granted Aug 16, 2005

Virtual data labeling system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,931,411
App. No.
10/157,231
Granted
Aug 16, 2005
Kind
B1
Abstract

A mandatory access control system and method that employs virtual data labeling (VDL) on the communications channel to allow aspects about the data to determine by whom and where such data can be accessed. When combined with a secure network system, the VDL system is able to base delivery decisions not only on destination address but also on the type of data that is to be delivered.

Claims (48)

1. A virtual data labeling system for dynamically labeling data received over an Internet communications network in response to a database call, said network including a database external to a database management system, comprising:

means for listening to Internet Protocol (IP) communications traffic;

means for mapping labeling rules to a search request to the database from a requestor;

means for retrieving data from the database in accordance with the labeling rules and the search request;

means for labeling the retrieved data; and

means for forwarding the labeled retrieved data to the requestor over the Internet communications channel.

2. The virtual data labeling system as set forth in claim 1 , further comprising means for discriminating said labeled retrieved data such that said requestor is able to access only that portion of said labeled retrieved data having a label corresponding to an access privilege of said requestor.

3. The virtual data labeling system as set forth in claim 2 , wherein said labeling means labels said retrieved data with a FIPS 188 label and said means for discriminating is a FIPS 188 label processor.

4. The virtual data labeling system as set forth in claim 1 , wherein said mapping means comprises:

a front-end subsystem for receiving the search request from the requestor; and

a policy manager subsystem coupled to said front-end subsystem for storing policy rules and providing said policy rules to said front-end subsystem, said front-end subsystem receiving the policy rules from the policy manager subsystem and generating a modified search request.

5. The virtual data labeling system as set forth in claim 4 , wherein said retrieving means comprises:

a back-end subsystem interposed between the front end subsystem and the database for reformatting the modified search request to generate an enhanced search request, said back-end subsystem forwarding the enhanced search request to the database and receiving the requested data as retrieved data, said back-end subsystem forwarding said retrieved data to said front-end subsystem.

6. The virtual data labeling system as set forth in claim 4 , wherein said labeling means labels a communication header of said retrieved data, and said forwarding means is embodied as said front-end subsystem.

7. A label server system including a plurality of subsystems on an Internet communications channel between a client server and a data repository, said label server system cooperating with a label processor for discriminating communications channel traffic, said label server system comprising:

a front-end subsystem for receiving a search request from a requestor at the client server;

a policy manager subsystem coupled to said front-end subsystem for storing policy rules and providing said policy rules to said front-end subsystem, said front-end subsystem receiving the policy rules from the policy manager subsystem and generating a modified search request;

a back-end subsystem interposed between the front end subsystem and the data repository for reformatting the modified search request to generate an enhanced search request, said back-end subsystem receiving the requested data from said data repository as retrieved data, said back-end subsystem forwarding said retrieved data to said front-end subsystem; and

a labeling engine subsystem, coupled to said front-end subsystem, for labeling a communication header of said retrieved data;

said front-end subsystem transferring the labeled retrieved data through said label processor to the requestor.

8. The label server system as set forth in claim 7 , said label processor including a FIPS 188 label processor for discriminating traffic on said Internet communications channel using said labeled communication header.

9. The label server system as set forth in claim 7 , said policy manager subsystem comprising:

a configuration editor allowing entry, verification and reporting of data categories which define configuration data;

a policy manager database for storing said configuration data and a plurality of rules;

a policy editor, coupled to said configuration editor, for determining which of said plurality of rules are to be applied to the data categories; and

a metadata manager, coupled to said configuration editor and to said policy editor, for mapping content data to said rules determined by said policy editor.

10. A method for dynamically labeling a communication channel comprising the steps of:

listening to Internet Protocol (IP) communications traffic;

receiving a query request from a database caller;

mapping labeling rules to said query request to generate an enhanced query request;

retrieving data from a database in accordance with said enhanced query request;

labeling the retrieved data in accordance with said labeling rules;

forwarding the labeled retrieved data to the database caller.

11. The method as set forth in claim 10 , further comprising before the step of listening the step of inputting a plurality of metadata defining data categories and rules into a policy manager, said step of mapping including determining by said policy manager which of said plurality of metadata to apply to said query request.

12. The method as set forth in claim 10 , further comprising the step of discriminating said labeled retrieved data such that said database caller is able to access only that portion of said labeled retrieved data having a label corresponding to an access privilege of said requestor.

13. A method of enforcing data access privileges on data received from a remote data repository over a communications channel using a label server and a policy manager, comprising the steps of:

filtering, using a front-end subsystem of said label server, a database request from a requestor for retrieval of data from the data repository;

receiving, by said front-end subsystem, a policy rules transfer document from said policy manager;

modifying, by the front-end subsystem, the database request to include attributes set forth in the policy rules transfer document;

forwarding said database request to a back-end subsystem of said label server;

reformatting, by said back-end subsystem, said database request with said attributes to generate an enhanced search request;

retrieving, by said back-end subsystem, a search response document from said data repository in accordance with said enhanced search request;

forwarding said search response document to said front-end subsystem;

labeling, by a labeling engine coupled to said front-end subsystem, a communication header of said search response document with a label; and

forwarding the labeled search response document to the requestor.

14. The method as set forth in claim 13 , further comprising the step of discriminating a plurality of labeled search response documents such that said requestor is able to access only those labeled search response documents having a label corresponding to an access privilege of said requestor.

15. The method as set forth in claim 13 , further comprising the step of:

adding a security wrapper to said search response document by said front-end subsystem.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Apr 22, 2016
From: GUGGENHEIM CORPORATE FUNDING, LLC, AS AGENT
To: API DEFENSE, INC.; NATIONAL HYBRID, INC.; API CRYPTEK INC.; SPECTRUM CONTROL, INC.; SPECTRUM MICROWAVE, INC.; API NANOFABRICATION AND RESEARCH CORPORATION
Reel/Frame 038502/0459 →
RELEASE OF SECURITY INTEREST Recorded Mar 21, 2014
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
To: API DEFENSE, INC.; NATIONAL HYBRID, INC.; API CRYPTEK INC.; SPECTRUM CONTROL, INC.; SPECTRUM MICROWAVE, INC.; API NANOFABRICATION AND RESEARCH CORPORATION
Reel/Frame 032501/0458 →
SECURITY AGREEMENT Recorded Feb 12, 2013
From: API DEFENSE. INC.; NATIONAL HYBRID. INC.,; API CRYPTEK INC.; SPECTRUM CONTROL, INC.; SPECTRUM MICROWAVE, INC.; API NANOFABRICATLON AND RESEARCH CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION (AS AGENT)
Reel/Frame 029800/0494 →
PATENT SECURITY AGREEMENT Recorded Feb 7, 2013
From: SPECTRUM MICROWAVE, INC.; API CRYPTEK INC.; API DEFENSE, INC.; SPECTRUM CONTROL, INC.; NATIONAL HYBRID, INC.; API NANOFABRICATION AND RESEARCH CORPORATION
To: GUGGENHEIM CORPORATE FUNDING, LLC
Reel/Frame 029777/0130 →
RELEASE OF SECURITY INTEREST Recorded Feb 6, 2013
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: API CRYPTEK, INC.
Reel/Frame 029767/0651 →
SECURITY INTEREST Recorded Jun 9, 2011
From: API CRYPTEK, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 026417/0670 →
RELEASE OF SECURITY INTEREST Recorded Jun 1, 2011
From: RBC BANK (USA)
To: API CRYPTEK INC.
Reel/Frame 026373/0573 →
SECURITY AGREEMENT Recorded May 2, 2011
From: API CRYPTEK INC
To: RBC BANK (USA)
Reel/Frame 026305/0163 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RE-RECORDING THE EXECUTION DATE PREVIOUSLY RECORDED ON REEL 024794 FRAME 0142. ASSIGNOR(S) HEREBY CONFIRMS THE FORECLOSURE-BILL OF SALE. Recorded Nov 23, 2010
From: API CRYPTEK INC.
To: API CRYPTEK INC.
Reel/Frame 025422/0620 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2010
From: COMERICA BANK
To: CRYPTEK, INC., A DELAWARE CORPORATION
Reel/Frame 025227/0337 →
LOAN PURCHASE AGREEMENT Recorded Aug 6, 2010
From: WACHOVIA BANK, NATIONAL ASSOCIATION; WACHOVIA CAPITAL FINANCE CORPORATION
To: API CRYPTEK INC.
Reel/Frame 024927/0475 →
FORECLOSURE/BILL OF SALE Recorded Aug 5, 2010
From: API CRYPTEK INC.
To: API CRYPTEK INC.
Reel/Frame 024794/0142 →
SECURITY AGREEMENT Recorded Aug 5, 2010
From: CRYPTEK, INC.
To: WACHOVIA BANK, NATIONAL ASSOCIATION; WACHOVIA CAPITAL FINANCE CORPORATION
Reel/Frame 024927/0349 →
SECURITY AGREEMENT Recorded May 16, 2006
From: CRYPTEK, INC.
To: COMERICA BANK
Reel/Frame 017619/0554 →
SECURITY AGREEMENT Recorded Feb 25, 2005
From: CRYPTEK, INC.
To: COMERICA BANK
Reel/Frame 015708/0166 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2002
From: BABISKIN, ROBERT; WILLIAMS, TIMOTHY C.
To: CRYPTEK, INC.
Reel/Frame 012949/0549 →