SBIR-STTR Award

The Use of Virtual LANs (VLANs) for Multiple Level Security (MLS)
Award last edited on: 4/5/2002

Sponsored Program
SBIR
Awarding Agency
DOD : Navy
Total Award Amount
$669,896
Award Phase
2
Solicitation Topic Code
N97-050
Principal Investigator
Kenneth G Alonge

Company Information

Geologics Corporation

5285 Shawnee Road Suite 210
Alexandria, VA 22312
   (703) 750-4000
   farroyo@geologics.com
   www.geologics.com
Location: Multiple
Congr. District: 08
County: Fairfax

Phase I

Contract Number: N00024-97-C-4104
Start Date: 4/29/1997    Completed: 10/29/1997
Phase I year
1997
Phase I Amount
$69,931
GeoLogics Team personnel will investigate the use of current and emerging security and VLAN standards being produced by the Institute of Electrical and Electronics Engineers (IEEE) LAN/MAN Standards Committee (LMSC) under Project 802. IEEE LMSC working group 802.10 is chartered with producing the Standard for Interoperable LAN/MAN Security (SILS) and IEEE LMSC working group 802.1 is chartered with, among other things, producing an interoperable VLAN standard. The SILS working group has produced a Data Link Layer security standard that provides the capability to cryptographically separate communities of interest (otherwise known as VLANs) that operate simultaneously on the same media at different security levels. The standard allows for tagging (explicitly or implicitly ) each protocol data unit (PDU) with a security label appropriate to the data contained in the PDU, as well as providing a method of tagging each PDU with an identifier for grouping end stations into multicast groups on the LAN. The standard is intended for implementation in end stations, bridges, and bridging routers that implement IEEE LMSC Medium Access Control (MAC) standards, for example, CSMA/CD (a.k.a. Ethernet) and Token Ring, and bridging standards. The standard also operates in conjunction with FDDI networks since the same MAC definition (ISO/IEC IS 10039) is used in the FDDI standard, as well as ATM network products that implement the same MAC interface using AAL5. The GeoLogics Team will study all aspects of these current standardization efforts and their applicability to Navy requirements, and as necessary, will recommend modifications to these proposed standards.

Phase II

Contract Number: N00024-98-C-4126
Start Date: 7/21/1998    Completed: 7/21/2000
Phase II year
1998
Phase II Amount
$599,965
GeoLogics will develop a proof-of-concept system for differential access control of Data at Rest. This system will automatically encrypt files as they are stored to electronic media and decrypt files as they are retrieved. A File System Management Application will provide the ability to encrypt data on the same media for different access control levels and user roles. This system will be designed to allow various COTS encryption/key management packages to be used. The initial proof-of-concept system will use Constructive Key Management (CKMtm) technology. GeoLogics will research the use of CKMtm technology and emerging networking standards to determine the viability of developing an MLS network architecture for security of Data in Transit. GeoLogics will study all aspects of current standardization efforts and their applicability to Navy requirements, and will recommend use of these standards as appropriate.