EP0465016A2

Distributed multilevel computer security system and method.

Abstract

A computer network has a number of computers coupled thereto at distinct nodes. A trust realm table defines which computers are members of predefined trust realms. All the members of each predefined trust realm enforce a common set of security protocols for protecting the confidentiality of data. Each computer that is a member of a trust realm enforces a predefined security policy, and also defines a security level for each set of data stored in the computer. Thus, each message has an associated label denoting how to enforce the computer's security policy with respect to the message. A trust realm service program prepares a specified message for transmission to a specified other computer system. To do this it uses the trust realm table to verify that both the computer system and the specified computer system are members of at least one common trust realm, and then selects one of those common trust realms. The message is transmitted as a protocol data unit, which includes a sealed version of the message, authenticated identifiers for the sending system and user, the message's label, and an identifier for the selected trust realm. Received protocol data units are processed by validating each of the components of the received protocol data unit before accepting the sealed message in the protocol data unit as authentic. Further, the label in the received protocol data unit is used by the receiving computer to determine what predefined security policy is to be enforced with respect to the message.

EP0465016A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 11 June 2011, 15.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

6 claims: 2 independent, 4 dependent

  1. 1
    In a computer network having a multiplicity of computers coupled thereto, message transmission apparatus comprising:trust realm defining means for storing information denoting which ones of said computers are members of predefined trust realms;wherein all the members of each predefined trust realm enforce a common set of security protocols for protecting confidentiality of data;and    security apparatus in each of a plurality of said computers, comprising:    a trusted computing base which enforces a predefined security policy in said computer and which defines a security level for each set of data stored therein;authentication means for authenticating and validating messages sent to another computer via said network;each said message comprising data having an associated label denoting how said trusted computing base is to enforce security policy with respect to said message;trust realm service means, coupled to said trusted computing base, authentication means and trust realm defining means, for preparing a specified message for transmission to a specified other computer system, including means for    obtaining trust realm information stored by said trust realm defining means, verifying that both said computer system and said specified computer system are members of at least one common trust realm, and selecting a trust realm from among said at least one common trust realm,    authenticating an identifier for said computer, and sealing said message, said label associated with said message, and an identifier for said selected trust realm, and    transmitting to said specified other computer a protocol data unit including said authenticated identifier for said computer, said sealed message, said label associated with said message, and said identifier for said selected trust realm;said trust realm service means further including means for receiving protocol data units transmitted by other ones of said computers via said network, and means for validating messages received by said computer, including means for validating each of said components of a received protocol data unit before accepting said sealed message in said protocol data unit as authentic.
  2. 2
    The message transmission apparatus set forth in Claim 1, said trust realm service means including means for aborting transmission of a message when, according to said information stored in said trust realm defining means, said computer and said specified other computer are not members of a common trust realm.
  3. 3
    The message transmission apparatus set forth in Claim 1, said trust realm service means including means for conveying said label in said received protocol data unit to said trusted computing base so that said trusted computing base will enforce a predefined security policy with respect to said message in said received protocol data unit in accordance with said label.
  4. 4
    In a computer network having a multiplicity of computers coupled thereto, a method of enforcing security protocols when transmitting messages between computers via said network, the steps of the method comprising:storing information denoting computers which are members of predefined trust realms;wherein all the members of each predefined trust realm enforce a common set of security protocols for protecting confidentiality of data;authenticating and validating a specified message that an application running in a computer is attempting to send to a specified other computer via said network, each said message comprising data having an associated label denoting how a predefined security policy is to be enforced with respect to said message;said authenticating and validating steps including the steps of:    accessing said stored trust realm information, verifying that both said computer system and said specified computer system are members of at least one common trust realm, and selecting a trust realm from among said at least one common trust realm;sealing said message, authenticating said label associated with said message, authenticating an identifier for said selected trust realm, and authenticating an identifier for said computer;transmitting to said specified other computer a protocol data unit including said sealed message, said authenticated label, said authenticated identifier for said computer, and said authenticated identifier for said selected trust realm;receiving said protocol data unit at said specified other computer;and    validating each component of said received protocol data unit before accepting said sealed message in said protocol data unit as authentic.
  5. 5
    The method of enforcing security protocols when transmitting messages between computers as set forth in Claim 4, including the step of aborting transmission of a message when, according to said stored trust realm information, said computer and said specified other computer are not members of a common trust realm.
  6. 6
    The method of enforcing security protocols when transmitting messages between computers set forth in Claim 4, including the step of enforcing a predefined security policy with respect to said message in said received protocol data unit in accordance with said label in said received protocol data unit.