发明名称 Multi-level secure (MLS) information network
摘要 A method of enforcing a network security policy including mandatory access control (MAC), discretionary access control (DAC) and integrity control for a secure information network, includes operating a transport guard within a memory partition logically between a protected application running in the partition and a networking stack, and defining ports for the transport guard including (i) an application port for forwarding data to and receiving data from the application, (ii) a data port for receiving data addressed to the application from the networking stack, and for sending data originating from the application to the stack, and (iii) a control port for supplying configuration data to the transport guard. The configuration data corresponds to MAC, DAC and integrity control policies specified by the network for the protected application. The transport guard limits data flow between its protected application and the data ports accordingly.
申请公布号 US7676673(B2) 申请公布日期 2010.03.09
申请号 US20060414105 申请日期 2006.04.28
申请人 BAE SYSTEMS INFORMATION AND ELECTRONIC SYSTEMS INTEGRATION INC. 发明人 WELLER MICHAEL K.;MANGRA TARACHRAND A.;LITZINGER JOSEPH A.;SHAH SANKET J.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利