发明名称 Multi-level security systems
摘要 Techniques are disclosed for improving multi-level security ("MLS") in computing systems. Communication between MLS systems in the prior art requires explicitly tagging each packet with its security classification. The packet tags comprise variable-length bit patterns inserted into packet headers. This results in a number of drawbacks, including increased path length and code complexity, as well as reduced interoperability. An MLS system according to the present invention simulates a cluster or collection of single-level security systems, and thereby avoids packet tagging. For each security classification used by an MLS system, a distinct source address is defined. This source address is used for outbound packets having that security classification, such that the packet's source address implicitly identifies the packet's security classification.
申请公布号 US7356695(B2) 申请公布日期 2008.04.08
申请号 US20020210267 申请日期 2002.08.01
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 LIVECCHI PATRICK MICHAEL
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址