IP Library Granted Patent US 9,489,534
Granted Patent B2
US 9,489,534 · App. 14/522,447 · Granted Nov 8, 2016

Multi-level security system for enabling secure file sharing across multiple security levels and method thereof

Inventors: Brant D. Hashii (Long Beach, CA); Mark O. Scott (Escondido, CA); Daniel R. Silverman (Hermosa Beach, CA); Lee Wixtrom (La Palma, CA); Jonathan Tester (Encinitas, CA); Steve A. Brown (Los Angeles, CA)
Assignee: Northrop Grumman Systems Corporation
G06F21/6218G06F17/30203G06F21/62G06F17/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,489,534
App. No.
14/522,447
Granted
Nov 8, 2016
Kind
B2
Abstract

A multi-level security system includes a storage medium partitionable into a plurality of partitions, a file system coupleable to the plurality of partitions, and a plurality of enclaves. Each enclave is assigned a security classification level. Each enclave resides in a different storage partition of the storage medium. Data stored on the storage medium is cryptographically separated at rest on a per-enclave basis. Cryptographic separation occurs at the disk block level, allowing individual blocks to be read and decrypted. The system also includes a reference monitor that enforces a system security policy that governs access to information between the enclaves. The reference monitor allows an enclave having a first classification level to securely read-down to an enclave having a second classification level lower than the first classification level and to write to another enclave having the first classification level.

Claims (13)

1. A multi-level security system, the system comprising: a storage medium, the storage medium partitionable into a plurality of partitions; a file system coupleable to the plurality of partitions;

a plurality of enclaves each assigned a security classification level, wherein each one of the plurality of enclaves resides in a different storage partition of the storage medium;

wherein data stored on the storage medium is cryptographically separated at rest on a per-enclave basis, and wherein cryptographic separation occurs at the disk block level thereby allowing individual blocks to be read and decrypted; wherein every disk block is encrypted using a unique key for each security classification level; and

a reference monitor that enforces a system security policy that governs access to information between the plurality of enclaves, wherein the reference monitor allows an enclave of the plurality of enclaves having a first classification level to securely read-down to another enclave of the plurality of enclaves having a second classification level lower than the first classification level and to write to another enclave of the plurality of enclaves having the first classification level.

2. A non-transitory computer-readable medium embodying program instructions for execution by a data processing apparatus, the program instructions adapting the data processing apparatus for transmitting information classified at different security classification levels while maintaining data separation of the information, the program instructions comprising:

forming a plurality of enclaves defining disparate security domains by dividing information stored on a storage medium into a plurality of non-overlapping partitions;

assigning a security classification level to each one of the plurality of enclaves;

encrypting each of the plurality of non-overlapping partitions using a unique key for each security classification level; and

enforcing a system security policy that governs the flow of information between the plurality of enclaves, the security policy allowing a first enclave having a first classification level to securely read-down to a second enclave having a second classification level lower than the first classification level and to write to a third enclave having the first classification level.

3. The multi-level security system of claim 1 , wherein the storage medium is a single physical disk.

4. The non-transitory computer-readable medium of claim 2 , wherein the step of enforcing a system security policy that governs the flow of information between the plurality of enclaves includes prohibiting write-down and write-up operations.

5. The non-transitory computer-readable medium of claim 2 , wherein the step of enforcing a system security policy that governs the flow of information between the plurality of enclaves includes prohibiting read-only clients from writing data.

6. The non-transitory computer-readable medium of claim 2 , wherein the step of forming a plurality of enclaves defining disparate security domains by dividing information stored on a storage medium into a plurality of non-overlapping partitions includes dividing information stored on a storage medium into a plurality of non-overlapping partitions on a single physical disk.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2016
From: SILVERMAN, DANIEL R.
To: NORTHROP GRUMMAN SYSTEMS CORPORATION
Reel/Frame 038908/0036 →
CORRECTIVE ASSIGNMENT TO REFLECT THE NAMES OF THE ADDITIONAL INVENTORS PREVIOUSLY RECORDED ON REEL 034023 FRAME 0743. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 20, 2016
From: SCOTT, MARK O.; WIXTROM, LEE
To: NORTHROP GRUMMAN SYSTEMS CORPORATION
Reel/Frame 037565/0968 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2014
From: BROWN, STEPHEN A; HASHII, BRANT D.; TESTER, JONATHAN
To: NORTHROP GRUMMAN SYSTEMS CORPORATION
Reel/Frame 034023/0743 →
Continuity (1)
Related Publication 20160117519A1 · Apr 28, 2016