US2002053020A1PendingUtilityA1

Secure compartmented mode knowledge management portal

Assignee: RAYTHEON COPriority: Jun 30, 2000Filed: Jun 26, 2001Published: May 2, 2002
Est. expiryJun 30, 2020(expired)· nominal 20-yr term from priority
H04L 63/062H04L 63/0209H04L 63/0869H04L 63/0823H04L 63/101
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A layered defense-in-depth knowledge-based data management comprises a reception zone for authenticating a user for access to the system and an operations zone for adjudicating on a user level access to data objects stored in the system database. In addition, the data management comprises a security zone for issuing certificates of accessibility for defined users and a screening zone to interrogate data packets during processing thereof. The first line of defense is firewall protection and packet filtering preceding the reception zone.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A layered defense-in-depth knowledge-based management system, comprising: 
 a reception zone for authenticating a user for access to the system;    an operations zone for adjudicating on a user level access to the data objects stored in a system database; and    a security zone for issuing certificates of accessibility for defined users.    
     
     
         2 . A layered defense-in-depth knowledge-based management system as in  claim 1  further comprises revoking certificates for users no longer allowed access to the system.  
     
     
         3 . A layered defense-in-depth knowledge-based management system as in  claim 2 , wherein the security zone further comprises performing key recovery operations.  
     
     
         4 . A layered defense-in-depth knowledge-based management system as in  claim 1 , wherein the security zone further comprises filters to control and limit access to a predefined set of user workstations.  
     
     
         5 . A layered defense-in-depth knowledge-based management system as in  claim 1 , wherein the reception zone comprises a public key infrastructure for authenticating users for accessing contents of the system.  
     
     
         6 . A layered defense-in-depth knowledge-based management system, comprising: 
 a reception zone for authenticating a user for access to the system;    a screening zone to interrogate data packets during processing thereof;    an operations zone for adjudicating on the user level access to the data objects stored in a system database; and    a security zone for issuing certificates of accessibility for defined users, revoke certificates for users no longer allowed access to the system, and performing key recovering operations.    
     
     
         7 . A layered defense-in-depth knowledge-based management system as set forth in  claim 6 , wherein the reception zone comprises a public key infrastructure for authenticating users for accessing contents of the system.  
     
     
         8 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the operations zone comprises packet filtering for incoming and outgoing messages.  
     
     
         9 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the security zone comprises packet filtering of incoming and outgoing messages for access control.  
     
     
         10 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the operations zone comprises a document management server for establishing access to data stored in a library of the management system.  
     
     
         11 . A method of layered defense-in-depth knowledge-based management, comprising: 
 authenticating a user of the knowledge base;    determine the clearance level of a requested document by the authenticated user;    determine the clearance level of the authenticated user;    comparing the clearance level of the document with the clearance level of the authenticated user; and    displaying the secure document to the authenticated user in response to the clearance level of the user dominating the clearance level of the requested document.    
     
     
         12 . The method of layered defense-in-depth knowledge-based management as set forth in  claim 11 , further comprising determining the allowance of both a document caveat and clearance access in response to the comparison of the clearance level of a document with the clearance level of the authenticated user prior to displaying the secure document.  
     
     
         13 . The method of layered defense-in-depth knowledge-based management as in  claim 11 , further comprising encrypting and signing the authenticated user prior to determining the clearance level of a requested document.  
     
     
         14 . The method of layered defense-in-depth knowledge-based management as in  claim 11 , wherein authenticating a user comprises a certificate authority program running on a server.  
     
     
         15 . A method of layered defense-in-depth knowledge-based management, comprising: 
 authenticating a user of the knowledge base;    determine the clearance level of a requested secure document;    determine the clearance level of the authenticated user;    comparing the clearance level of the requested document with the clearance level of the authenticated user;    obtain a document caveat;    obtain an authenticated user caveat;    comparing the authenticated user caveat with the document caveat to allow access to the obtained document caveat;    determining the access allowability of the obtained document caveat;    determine the allowance of both the document caveat and the clearance access to identify clearance of the authorized user to the requested secure document; and    displaying the secure document to the authenticated user.    
     
     
         16 . The method of layered defense-in-depth knowledge-based management as in  claim 15 , further comprising multiple authentication of a user prior to comparing the clearance level of the requested document with the clearance level of the authenticated user.  
     
     
         17 . A method of accessing an electronic support library for layered defense-in-depth knowledge-based management, comprising: 
 authenticating in a reception zone a user in response to a request for data;    document manipulation and administration in an operations zone of a request by an authenticated user; and    issuing authorization certificates in a security zone for users to allow access to data managed in the operations zone.    
     
     
         18 . The method of accessing an electronic support library as in  claim 17 , wherein authenticating a user in the reception zone comprises authenticating the user to a public key infrastructure.  
     
     
         19 . The method of accessing an electronic support library as in  claim 17 , further comprising accessing data stored in the electronic support library by a document management server.  
     
     
         20 . The method of accessing an electronic support library as in  claim 17 , further comprising packet filtering incoming and outgoing messages in and through the operations zone.  
     
     
         21 . The method of accessing an electronic support library as in claim  20 , further comprising packet filtering incoming and outgoing messages for access to authorization certificates issued by the security zone.

Join the waitlist — get patent alerts

Track US2002053020A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.