IP Library Granted Patent US 11,595,411
Granted Patent B2
US 11,595,411 · App. 16/832,192 · Granted Feb 28, 2023

Adaptive, multi-layer enterprise data protection and resiliency platform

Inventor: Torsten Staab (Bristow, VA)
Assignee: Raytheon Company
H04L63/1416H04L9/0637H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,411
App. No.
16/832,192
Granted
Feb 28, 2023
Kind
B2
Abstract

A system for data protection includes a first computing device comprising a security module; and a storage device coupled to the first computing device via a network interface. The security module comprises at least one of Software Root of Trust (SRoT) and Hardware Root of Trust (HRoT). The security module is further configured to: establish a trust channel between the first computing device and the storage device or storage service; monitor the first computing device and the storage device; create and enforce multi-dimensional data access control by tightly binding data access and permissions to authorized computing devices, users, applications, system services, networks, locations, and access time windows; and take over control of the storage device or storage service in response to a security risk to the system.

Claims (39)

1. A system for data protection, the system comprising::

a first computing device comprising a security module; and

a storage device coupled to the first computing device,

wherein the security module comprises a Software-based Root of Trust (SRoT) and a Hardware Root of Trust (HRoT), the SRoT and the HRoT perform independent software-level and hardware-level monitoring tasks in parallel,

wherein the security module is configured to:

establish a trust channel between the first computing device and the storage device, the trust channel based on a permissioned blockchain defining allowable actions by the first computing device;

establish data access policies which define multi-dimensional data access;

adjust the data access policies based on real-time risk scores;

monitor communication of the first computing device and the storage device; and

take over control of the storage device in response to detection of a security risk to the system.

2. The system of claim 1 , wherein the first computing device further comprises a third-party agent configured to communicate to one or more third-party applications, which include an insider threat detection application, a data loss prevention application, a system and/or network intrusion detection application, and/or a user behavior analysis application.

3. The system of claim 1 , the security module autonomously takes over control of the storage device in response to detection of a security risk to the system.

4. The system of claim 1 , wherein the security module prevents access to application, storage, network, and system resources on associated computing devices in response to detection of the security risk to the system.

5. The system of claim 1 , wherein the HRoT and SRoT work together to monitor user, system, application, storage media, and network access behaviors and activities of the system.

6. The system of claim 1 , wherein the SRoT monitors the HRoT and the HRoT monitors the SRoT.

7. The system of claim 1 , wherein the permissioned Blockchain being used to log transactions, securely share secrets, establish consensus, confirm system critical operations, and extend trust in the system.

8. The system of claim 1 , wherein the storage device comprises one of a local data storage, external data storage, or a cloud-based storage service.

9. The system of claim 1 , wherein the security risk comprises a suspicious or unauthorized data access from a remote device or from inside of the first computing device.

10. A method of data protection, comprising:

employing a first computing device comprising a security module; and

employing a storage device coupled to the first computing device, wherein the security module comprises a Software-based Root of Trust (SRoT) and a Hardware Root of Trust (HRoT), the SRoT and the HRoT perform independent software-level and hardware-level monitoring tasks in parallel, wherein the security module performs the steps of:

establishing a trust channel between the first computing device and the storage device, the trust channel based on a permissioned blockchain defining allowable actions by the first computing device;

establishing data access policies which define multi-dimensional data access permissions;

adjusting the data access policies based on real-time risk scores;

monitoring communication of the first computing device and the storage device; and

taking over control of the storage device in response to detection of a security risk to the system.

11. The method of claim 10 , wherein the first computing device further comprises a third-party agent configured to communicate to one or more third-party applications, which include an insider threat detection application, a data loss prevention application, a system and/or network intrusion detection application, and/or a user behavior analysis application.

12. The method of claim 10 , wherein the security module autonomously takes over control of the storage device in response to detection of a security risk to the system.

13. The method of claim 10 , wherein the security module prevents access to application, storage, network, and system resources on associated computing devices in response to detection of the security risk to the system.

14. A system for data protection, the system comprising:

a first computing means comprising a security module; and

a storage means coupled to the first computing means,

wherein the security module comprises Software-based Root of Trust (SRoT) and a Hardware Root of Trust (HRoT, the SRoT and the HRoT perform independent software-level and hardware-level monitoring tasks in parallel,

wherein the security module is configured to:

establish a trust channel between the first computing means and the storage means, the trust channel based on a permissioned blockchain defining allowable actions by the first computing device;

establish data access policies which define multi-dimensional data access perm issions;

adjusting the data access policies based on real-time risk scores;

monitor communication of the first computing means and the storage means; and

take over control of the storage means in response to detection of a security risk to the system.

Assignments (4)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2020
From: STAAB, TORSTEN
To: RAYTHEON COMPANY
Reel/Frame 052259/0046 →