Computer architecture for an electronic device providing SLS access to MLS file system with trusted loading and protection of program execution memory
System for providing a secure file service includes an MLS file service module comprised of a cryptographic processor. The MLS file service module also includes an MLS file system hosted by the cryptographic processor. A secure user processor includes programming and communications hardware for requ...
Gespeichert in:
Hauptverfasser: | , , , |
---|---|
Format: | Patent |
Sprache: | eng |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | System for providing a secure file service includes an MLS file service module comprised of a cryptographic processor. The MLS file service module also includes an MLS file system hosted by the cryptographic processor. A secure user processor includes programming and communications hardware for requesting at least one classified file from the MLS file service module. The cryptographic processor includes cryptographic hardware and software to decrypt the classified file. The cryptographic processor is also performs an integrity check on the classified file. Once the file is decrypted and its integrity checked by the cryptographic processor, the MLS file service module serves the classified file to the secure user processor in decrypted form. If the classified file is an executable file, the method also includes selectively enabling a write function for program memory of the secure user processor. This write function is disabled immediately after the classified executable file has been loaded into the program memory to guard against self modifying programs. |
---|