IP Library Granted Patent US 12,513,124
Granted Patent B2
US 12,513,124 · App. 18/612,554 · Granted Dec 30, 2025

Multi-independent level security for high performance computing and data storage systems

Inventors: Richard J. Takahashi (Layton, UT); Timothy Paul Abel (Fruit Heights, UT); Benjamin Kirk Nielson (West Haven, UT)
Assignee: SECTURION SYSTEMS, INC.
H04L63/0428H04L9/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,124
App. No.
18/612,554
Filed
Mar 21, 2024
Granted
Dec 30, 2025
Kind
B2
Art Unit
2434
USPC
713/166
Abstract

Systems, methods, and apparatus for a MILS HPC, data storage system (DSS) system architecture that incorporates a multi-crypto module (MCM) to provide end-to-end multi-independent level security (MILS) protection. Configuration of each MCM enables a high performance computing (HPC) resource to compute different security domains with the associated security level keys from a key/node manager. The HPC resource can be dynamically re-allocated to different security level domain(s) by the key/node manager. In one embodiment, the DSS stores encrypted data regardless of the domains.

Claims (29)

1 . A system comprising:

a plurality of compute nodes;

a plurality of cryptographic modules, each module configured to encrypt communications in a networked system, and each module configured to support different security levels for multiple domains; and

a data storage system configured to store encrypted data for each of the compute nodes, wherein each compute node is configured to access the data storage system via a respective one of the cryptographic modules.

2 . The system of claim 1 , wherein each domain is defined by a key manager.

3 . The system of claim 1 , wherein each compute node is configured to serve one of the multiple domains.

4 . The system of claim 1 , wherein the cryptographic modules maintain cryptographic isolation between the compute nodes.

5 . The system of claim 1 , wherein each of the compute nodes is configured to perform transport encryption for communicating with other ones of the compute nodes, and to perform data at rest encryption for storing data in the data storage system.

6 . The system of claim 5 , further comprising a key/node manager configured to manage keys for the transport encryption and the data at rest encryption.

7 . The system of claim 5 , wherein the transport encryption provides a secure link to the other ones of the compute nodes at a same security level.

8 . The system of claim 1 , further comprising a key/node manager configured to provision each of the cryptographic modules to one of the different security levels.

9 . A system comprising:

a plurality of compute nodes:

a plurality of cryptographic modules to provide multi-independent level security, wherein each cryptographic module is configured to enable computation of different security domains; and

a data storage system configured to store encrypted data for each of the compute nodes, wherein each compute node is configured to access the data storage system via a respective one of the cryptographic modules.

10 . The system of claim 9 , wherein the computation of different security domains is enabled with associated security level keys from at least one key manager.

11 . The system of claim 9 , wherein the system is configured for dynamic re-allocation to at least one different security level domain.

12 . The system of claim 9 , wherein each compute node is configured to serve one of the different security domains.

13 . The system of claim 9 , wherein the cryptographic modules maintain cryptographic isolation between the compute nodes.

14 . A system comprising:

a plurality of compute nodes, each node configured to serve one of multiple different security domains;

at least one cryptographic module configured to maintain cryptographic isolation between the compute nodes; and

a data store coupled to the compute nodes, wherein each node is configured to access the data store to retrieve data for the security domain served by the node, and the data store is accessible to the at least one cryptographic module.

15 . The system of claim 14 , wherein at least one compute node of the compute nodes is configured for reallocation to a new security domain.

16 . The system of claim 14 , wherein the at least one cryptographic module comprises a cryptographic engine configured for data processing using a systolic array.

17 . The system of claim 14 , further comprising a key manager configured to select a set of keys from multiple key sets for performing encryption by the at least one cryptographic module.

18 . The system of claim 17 , wherein each set of the multiple key sets corresponds to one of the different security domains.

19 . The system of claim 14 , wherein the at least one cryptographic module maintains cryptographic isolation between data elements stored in the data store.

20 . The system of claim 14 , wherein the data store is configured to store data for at least two of the different security domains.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2024
From: TAKAHASHI, RICHARD J.; ABEL, TIMOTHY PAUL; NIELSON, BENJAMIN KIRK
To: SECTURION SYSTEMS, INC.
Reel/Frame 066868/0619 →
Continuity (3)
Continuation 17506926 · Oct 21, 2021
Provisional Application 63104795 · Oct 23, 2020
Related Publication 20240380738A1 · Nov 14, 2024
References Cited (57)
US 6304973B1 · Williams · 2001 [cited by applicant]
US 6598161B1 · Kluttz et al. · 2003 [cited by applicant]
US 7069437B2 · Williams · 2006 [cited by applicant]
US 7191341B2 · Paaske · 2007 [cited by applicant]
US 7362868B2 · Madoukh · 2008 [cited by examiner]
US 7836490B2 · Smith · 2010 [cited by applicant]
US 7954138B2 · LiVecchi · 2011 [cited by examiner]
US 7958351B2 · Luthl · 2011 [cited by applicant]
US 7979895B2 · Farrell · 2011 [cited by examiner]
US 8219799B1 · Lucchesi · 2012 [cited by applicant]
US 8230207B2 · Iyer et al. · 2012 [cited by applicant]
US 8479304B1 · Clifford · 2013 [cited by applicant]
US 8539571B2 · Smith · 2013 [cited by applicant]
US 8712044B2 · MacMillan · 2014 [cited by examiner]
US 8806204B2 · Chambers · 2014 [cited by examiner]
US 9317718B1 · Takahashi · 2016 [cited by applicant]
US 9524399B1 · Takahashi · 2016 [cited by applicant]
US 9559842B2 · Baldwin · 2017 [cited by examiner]
US 9628274B1 · Jenks · 2017 [cited by applicant]
US 9660970B1 · Rubin · 2017 [cited by applicant]
US 9847878B2 · Stella · 2017 [cited by applicant]
US 9866375B2 · Reilly · 2018 [cited by examiner]
US 10114766B2 · Takahashi · 2018 [cited by applicant]
US 10193690B1 · Self · 2019 [cited by applicant]
US 10467437B2 · Couillard · 2019 [cited by examiner]
US 10708236B2 · Takahashi · 2020 [cited by applicant]
US 11087028B2 · Jain · 2021 [cited by examiner]
US 11356271B2 · Madden · 2022 [cited by examiner]
US 11468178B1 · O'Dell · 2022 [cited by applicant]
US 11968187B2 · Takahashi et al. · 2024 [cited by applicant]
US 20030005331A1 · Williams · 2003 [cited by applicant]
US 20030225896A1 · Jain · 2003 [cited by applicant]
US 20050097357A1 · Smith · 2005 [cited by applicant]
US 20050154921A1 · Medvinsky · 2005 [cited by examiner]
US 20050169463A1 · Ahn · 2005 [cited by applicant]
US 20080181406A1 · Iyer et al. · 2008 [cited by applicant]
US 20080288782A1 · Iyer · 2008 [cited by applicant]
US 20090034734A1 · Owens et al. · 2009 [cited by applicant]
US 20090046858A1 · Iyer et al. · 2009 [cited by applicant]
US 20110087889A1 · Iyer et al. · 2011 [cited by applicant]
US 20110283339A1 · Smith · 2011 [cited by applicant]
US 20120066509A1 · Lapp et al. · 2012 [cited by applicant]
US 20150074409A1 · Reid et al. · 2015 [cited by applicant]
US 20150222604A1 · Ylonen · 2015 [cited by applicant]
US 20160205110A1 · Roth · 2016 [cited by examiner]
US 20170063811A1 · Hitchcock · 2017 [cited by applicant]
US 20170075821A1 · Takahashi · 2017 [cited by applicant]
US 20170118180A1 · Takahashi · 2017 [cited by applicant]
US 20170272247A1 · Johansson · 2017 [cited by applicant]
US 20170359317A1 · Anderson et al. · 2017 [cited by applicant]
US 20180191691A1 · Smith · 2018 [cited by applicant]
US 20190050348A1 · Takahashi et al. · 2019 [cited by applicant]
US 20210160285A1 · Smith · 2021 [cited by examiner]
US 20220286439A1 · Takahashi · 2022 [cited by applicant]
WO 2017074887 · 2017 [cited by applicant]
Korean Intellectual Property Office; PCT International Search Report, issued in connection to application No. PCT/US2021/055956; Feb. 7, 2022; 5 pages; Korea. [cited by applicant]
Korean Intellectual Property Office; PCT Written Opinion of the International Searching Authority, issued in connection to application No. PCT/US2021/055956; Feb. 7, 2022; 5 pages; Korea. [cited by applicant]