US2007174627A1PendingUtilityA1

Secure compartmented mode knowledge management portal

Assignee: RAYTHEON COMPANY A DELAWARE COPriority: Jun 30, 2000Filed: Feb 16, 2006Published: Jul 26, 2007
Est. expiryJun 30, 2020(expired)· nominal 20-yr term from priority
H04L 63/062H04L 63/0823H04L 63/0869H04L 63/101H04L 63/0209
34
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A layered defense-in-depth knowledge-based data management comprises a reception zone for authenticating a user for access to the system and an operations zone for adjudicating on a user level access to data objects stored in the system database. In addition, the data management comprises a security zone for issuing certificates of accessibility for defined users and a screening zone to interrogate data packets during processing thereof. The first line of defense is firewall protection and packet filtering preceding the reception zone.

Claims

exact text as granted — not AI-modified
1 . A layered defense-in-depth knowledge-based management system, comprising: 
 a reception zone for authenticating a user for access to the system;    an operations zone for adjudicating on a user level access to the data objects stored in a system database; and    a security zone for issuing certificates of accessibility for defined users.    
   
   
       2 . A layered defense-in-depth knowledge-based management system as in  claim 1  further comprises revoking certificates for users no longer allowed access to the system.  
   
   
       3 . A layered defense-in-depth knowledge-based management system as in  claim 2 , wherein the security zone further comprises performing key recovery operations.  
   
   
       4 . A layered defense-in-depth knowledge-based management system as in  claim 1 , wherein the security zone further comprises filters to control and limit access to a predefined set of user workstations.  
   
   
       5 . A layered defense-in-depth knowledge-based management system as in  claim 1 , wherein the reception zone comprises a public key infrastructure for authenticating users for accessing contents of the system.  
   
   
       6 . A layered defense-in-depth knowledge-based management system, comprising: 
 a reception zone for authenticating a user for access to the system;    a screening zone to interrogate data packets during processing thereof;    an operations zone for adjudicating on the user level access to the data objects stored in a system database; and    a security zone for issuing certificates of accessibility for defined users, revoke certificates for users no longer allowed access to the system, and performing key recovering operations.    
   
   
       7 . A layered defense-in-depth knowledge-based management system as set forth in  claim 6 , wherein the reception zone comprises a public key infrastructure for authenticating users for accessing contents of the system.  
   
   
       8 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the operations zone comprises packet filtering for incoming and outgoing messages.  
   
   
       9 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the security zone comprises packet filtering of incoming and outgoing messages for access control.  
   
   
       10 . A layered defense-in-depth knowledge-based management system as in  claim 6 , wherein the operations zone comprises a document management server for establishing access to data stored in a library of the management system.  
   
   
       11 . A method of layered defense-in-depth knowledge-based management, comprising: 
 authenticating a user of the knowledge base;    determine the clearance level of a requested document by the authenticated user;    determine the clearance level of the authenticated user;    comparing the clearance level of the document with the clearance level of the authenticated user; and    displaying the secure document to the authenticated user in response to the clearance level of the user dominating the clearance level of the requested document.    
   
   
       12 . The method of layered defense-in-depth knowledge-based management as set forth in  claim 11 , further comprising determining the allowance of both a document caveat and clearance access in response to the comparison of the clearance level of a document with the clearance level of the authenticated user prior to displaying the secure document.  
   
   
       13 . The method of layered defense-in-depth knowledge-based management as in  claim 11 , further comprising encrypting and signing the authenticated user prior to determining the clearance level of a requested document.  
   
   
       14 . The method of layered defense-in-depth knowledge-based management as in  claim 11 , wherein authenticating a user comprises a certificate authority program running on a server.  
   
   
       15 . The method of accessing an electronic support library as in  claim 14 , further comprising packet filtering incoming and outgoing messages for access to authorization certificates issued by the security zone.

Join the waitlist — get patent alerts

Track US2007174627A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.