IP Library Granted Patent US 7,765,595
Granted Patent B2
US 7,765,595 · App. 11/512,180 · Granted Jul 27, 2010

Access control differentiation in trusted computer system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,765,595
App. No.
11/512,180
Granted
Jul 27, 2010
Kind
B2
Abstract

A trusted computer system that offers Linux® compatibility and supports contemporary hardware speeds. It is designed to require no porting of common applications which run on Linux, to be easy to develop for, and to allow the use of a wide variety of modern development tools. The system is further designed to meet or exceed the Common Criteria EAL-5 or higher rating through incorporation of required security features, as well as a very high level of assurance for handling data at a wide range of sensitivity (e.g., classification) levels in a wide range of operational environments. This is achieved through the implementation of a well-layered operating system which has been designed from the ground up to enforce security, but which also supports Linux operating system functions and methods.

Claims (14)

1. A trusted computer system, configured to concurrently run a plurality of processes, the trusted computer system comprising:

at least one processor;

a plurality of processor domains, each processor domain limited to a corresponding set of processor privileges associated therewith; and

a trusted operating system configured to run on the trusted computer system, the trusted operating system comprising a plurality of security policies and a plurality of security domains, the security domains to host the plurality of processes, each process having a security level associated therewith, and the trusted operating system causing the trusted computer system to enforce the security policies in the trusted computer system to prevent a first process from accessing a second process having a different security level,

wherein the processes hosted in each security domain are mapped into a processor domain, and the at least one processor enforces the resource privileges of each processor domain to prevent processes mapped into a first processor domain from modifying processes mapped into a second less privileged processor domain, and

wherein the security policies comprise a subtype policy, and the subtype policy allows access control differentiation beyond mandatory and discretionary access.

2. The trusted computer system of claim 1 , wherein the subtype policy allows a first process to access a process object, a file system object, or a device object only if the subtype of the object is on a list of subtypes authorized to be accessed by the first process.

3. The trusted computer system of claim 1 , wherein the subtype policy allows a first process to access data only if the subtype of the data is on a list of subtypes authorized to be accessed by the first process.

4. The trusted computer system of claim 1 , wherein the subtype policy comprises providing subtype information for a file system object and the security kernel prevents a process from accessing the file system object according to the subtype information.

5. A computer program product stored on tangible computer readable media, the computer program product, when executed by a computer, providing

a trusted operating system comprising a plurality of security policies and a plurality of security domains, the security domains to host a plurality of processes, each process having a security level associated therewith, and the trusted operating system causing the computer to enforce the security policies in the computer to prevent a first process from accessing a second process having a different security level,

wherein the computer comprises at least one processor;

a plurality of processor domains, each processor domain limited to a corresponding set of processor privileges associated therewith, and the processes hosted in each security domain are mapped into a processor domain, and the at least one processor enforces the resource privileges of each processor domain to prevent processes mapped into a first processor domain from modifying processes mapped into a second less privileged processor domain, and

wherein the security policies comprise a subtype policy, and the subtype policy allows access control differentiation beyond mandatory and discretionary access.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2015
From: BAE SYSTEMS INFORMATION SOLUTIONS INC.
To: BAE SYSTEMS INFORMATION AND ELECTRONIC SYSTEMS INTEGRATION INC.
Reel/Frame 036612/0960 →
CHANGE OF NAME Recorded Jun 9, 2010
From: BAE SYSTEMS INFORMATION TECHNOLOGY INC.
To: BAE SYSTEMS INFORMATION SOLUTIONS INC.
Reel/Frame 024505/0296 →
CHANGE OF NAME Recorded Apr 14, 2010
From: BAE SYSTEMS INFORMATION TECHNOLOGY INC.
To: BAE SYSTEMS INFORMATION SOLUTIONS INC.
Reel/Frame 024225/0875 →
CHANGE OF NAME Recorded Mar 23, 2007
From: BAE SYSTEMS ENTERPRISE SYSTEMS INCORPORATED
To: BAE SYSTEMS INFORMATION TECHNOLOGY INC.
Reel/Frame 019055/0149 →
MERGER Recorded Mar 15, 2007
From: BAE SYSTEMS INFORMATION TECHNOLOGY LLC
To: BAE SYSTEMS ENTERPRISE SYSTEMS INCORPORATED
Reel/Frame 019009/0886 →