ATE285151T1

Outside access to computer resources through a firewall

Abstract

A firewall isolates computer and network resources inside the firewall from networks, computers and computer applications outside the firewall. Typically, the inside resources could be privately owned databases and local area networks (LAN's), and outside objects could include individuals and computer applications operating through public communication networks such as the Internet. Usually, a firewall allows for an inside user or object to originate connection to an outside object or network, but does not allow for connections to be generated in the reverse direction; i.e. from outside in. The disclosed invention provides a special "tunneling" mechanism, operating on both sides of a firewall, for establishing such "outside in" connections when they are requested by certain "trusted" individuals or objects or applications outside the firewall. The intent here is to minimize the resources required for establishing "tunneled" connections (connections through the firewall that are effectively requested from outside), while also minimizing the security risk involved in permitting such connections to be made at all. The mechanism includes special tunneling applications, running on interface servers inside and outside the firewall, and a special table of "trusted sockets" created and maintained by the inside tunneling application. Entries in the trusted sockets table define objects inside the firewall consisting of special inside ports, a telecommunication protocol to be used at each port, and a host object associated with each port. Each entry is "trusted" in the sense that it is supposedly known only by individuals authorized to have "tunneling" access through the firewall from outside.

Term

Term ended

Projected expiry passed 2 October 2017, 9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

27 members in 17 offices

This recordMember, by publication datePriority claim7 more offices are in the list below

Priority claims2

Priority claims
DocumentOfficeKindDate
73180096United States of AmericaA
9702712United KingdomW

Members27

Family members, oldest first
DocumentOfficeKind
CA2269544A1CanadaA1
WO9818248A1World Intellectual Property Organization (WIPO)A1
CN1180871AChinaA
TW362177BTaiwan Province of ChinaB
BR9705094ABrazilA
EP0932965A1European Patent Office (EPO)A1
CZ138799A3CzechiaA3
US5944823AUnited States of AmericaA
PL332828A1PolandA1
BR9712635ABrazilA
JP2000505270AJapanA
US6061797AUnited States of AmericaA
HUP0000336A2HungaryA2
KR20000048930ARepublic of KoreaA
HUP0000336A3HungaryA3
RU2178583C2Russian FederationC2
KR100330619B1Republic of KoreaB1
JP3285882B2JapanB2
CN1107400CChinaC
EP0932965B1European Patent Office (EPO)B1
CA2269544CCanadaC
ATE285151T1This recordAustriaT1
DE69731965D1GermanyD1
ES2231895T3SpainT3
CZ295858B6CzechiaB6
DE69731965T2GermanyT2
MY127656AMalaysiaA