IP Library › Granted Patent US 8,584,250
Granted Patent B2
US 8,584,250 · App. 12/565,413 · Granted Nov 12, 2013

Methods and apparatus for information assurance in a multiple level security (MLS) combat system

Inventors: Rother V. Hodges (Wakefield, RI); Patrick A. Luvara (East Greenwich, RI)
Assignee: Rite-Solutions, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,584,250
App. No.
12/565,413
Granted
Nov 12, 2013
Kind
B2
Abstract

Methods and apparatus are provided for information assurance in a multiple level security (MLS) combat system. A plurality of tasks are executed, where at least one of the tasks requiring a transition from a first security level to a second security level. At least one of the tasks are executed on a cloud computing system; and a kernel is employed to prevent a leakage of data between at least two of the tasks. The cloud computing system comprises a virtualization layer and provides one or more operating systems, as well as interface access control to data. The kernel provides a mechanism for the transition from the first security level to the second security level. The kernel optionally tags one or more data records with a security classification to allow one or more classification levels to be segregated for role-based data access.

Claims (24)

1. A method for executing a plurality of tasks, said method comprising the steps of:

executing at least one of said tasks on a cloud computing system; and

employing a kernel to prevent a leakage of data between at least two of said tasks, wherein a task security level of at least one of said tasks switches from a first security level to a second security level on the cloud computing system, wherein at least one of said executing and employing steps are performed by at least one hardware device.

2. The method of claim 1 , wherein said cloud computing system provides one or more operating systems.

3. The method of claim 1 , wherein said cloud computing system provides interface access control to data.

4. The method of claim 1 , wherein said kernel provides a mechanism for said transition from said first security level to said second security level.

5. The method of claim 1 , wherein said cloud computing system comprises a virtualization layer.

6. The method of claim 1 , wherein said kernel tags one or more data records with a security classification.

7. The method of claim 6 , wherein said security classification tag employs one or more features to prevent tampering.

8. The method of claim 6 , wherein said security classification tag is employed to control access to said corresponding data record.

9. The method of claim 6 , wherein said security classification tag allows one or more classification levels to be segregated for role-based data access.

10. A system for executing a plurality of tasks, said system comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to:

execute at least one of said tasks on a cloud computing system; and

employ a kernel to prevent a leakage of data between at least two of said tasks, wherein a task security level of at least one of said tasks switches from a first security level to a second security level on the cloud computing system.

11. The system of claim 10 , wherein said cloud computing system provides one or more operating systems.

12. The system of claim 10 , wherein said cloud computing system provides interface access control to data.

13. The system of claim 10 , wherein said kernel provides a mechanism for said transition from said first security level to said second security level.

14. The system of claim 10 , wherein said cloud computing system comprises a virtualization layer.

15. The system of claim 10 , wherein said kernel tags one or more data records with a security classification.

16. The system of claim 15 , wherein said security classification tag employs one or more features to prevent tampering.

17. The system of claim 15 , wherein said security classification tag is employed to control access to said corresponding data record.

18. The system of claim 15 , wherein said security classification tag allows one or more classification levels to be segregated for role-based data access.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2009
From: HODGES, ROTHER V.; LUVARA, PATRICK A.
To: RITE-SOLUTIONS, INC.
Reel/Frame 023666/0097 →
Continuity (2)
Provisional Application 61099236 · Sep 23, 2008
Related Publication 20130276133A1 · Oct 17, 2013