发明名称 Search mechanism for content based information security repositories
摘要 A secure search mechanism (or search engine) for use with content based information security repositories. The present invention may be embodied in an information security system or method. In accordance with the present invention, a search occurs in a protected device that contains classified metadata and addresses of encrypted headers relating to classified data or information objects. A search request comes in from a user in a particular access level and the search engine returns a set of addresses that are at appropriate access levels and satisfy the search criteria. These addresses are passed or transferred to another device that stores the encrypted headers, and the encrypted headers are sent to the user.
申请公布号 US8898792(B1) 申请公布日期 2014.11.25
申请号 US200511156354 申请日期 2005.06.17
申请人 Lockheed Martin Corporation 发明人 Fall Thomas C.
分类号 G06F21/10;H04N21/4405 主分类号 G06F21/10
代理机构 Oblon, Spivak, McClelland, Maier & Neustadt, L.L.P. 代理人 Oblon, Spivak, McClelland, Maier & Neustadt, L.L.P.
主权项 1. An information security system comprising: a network; a secure storage device that stores encrypted data and encrypted headers relating to the encrypted data; a protected device comprising a storage device that stores classified unencrypted metadata relating to the encrypted data and addresses of the encrypted headers relating to the encrypted data, the protected storage device being physically separate from the secure storage device; a user computer that securely communicates at a particular access level over the network with the protected device and generates a search request relating to the encrypted data; a search engine disposed on the protected device that interfaces with the user computer to process the search request to return a set of addresses corresponding to headers associated with desired data that are at the particular access level and satisfy the search request, transfers the set of addresses to the secure storage device that stores the encrypted headers, and transfers the encrypted headers without the encrypted data to the user computer that generated the search request, wherein the storage device of the protected device does not store the encrypted data, wherein there is no instance of the encrypted data in the protected device, and wherein the protected device is accessible only by a user having the particular access level, the particular access level being one of a plurality of access levels.
地址 Bethesda MD US