EP0787397B1

System and method for providing secure internetwork services

Abstract

This record has no abstract on file.

EP0787397B1, drawing sheet 1
Sheet 1 of 31

Term

Term ended

Expired 12 October 2015, 11 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

22 claims: 5 independent, 17 dependent

  1. 1
    A secure wide-area access system, having a first secure computer (48), comprising a first internal network interface (64) and a public network interface (72), a first internal network (64), and a first computing system (63) connected across the first internal network to the first secure computer; wherein the first secure computer further comprises a public network program code module (70) used to communicate through the public network interface to a public network (74), a private network program code module (66) used to communicate through the first internal network interface to the first computing system and a security policy program code module (68) for enforcing a Type Enforcement security mechanism to restrict access of a process to data; and wherein the security policy program code module comprises assured pipeline program code for establishing an assured pipeline for the transfer of data and programs between the first internal network and the public network through the secure computer, wherein the assured pipeline program code comprises:i) program code which places processes within domains, including assigning processes received from the public network to an external domain;ii) program code which assigns types to files;and iii) program code which restricts access by processes within the external domain to certain file types.
  2. 14
    A method of protecting a computer system (40) connected to an unsecured external network (74), wherein the computer system includes a plurality of workstations (63) connected to a private network, the method comprising the steps of:providing a secure computer (48), wherein the secure computer comprises security policy program code for enforcing a Type Enforcement security mechanism to restrict access of a process to data;connecting the Type Enforcement based secure computer to the private network;and establishing an assured pipeline for the transfer of data and programs between the private network and the external network through the secure computer, wherein the step of establishing an assured pipeline includes the steps of: i) placing processes within domains, wherein the step of placing processes within domains includes the step of assigning processes received from the external network to an external domain;ii) assigning types to files;and iii) restricting access by processes within the external domain to certain file types.
  3. 16
    A secure server for use in controlling access to data stored within an internal network, comprising:administrative and operational kernels, wherein the operational kernel includes security policy program code for enforcing a Type Enforcement security mechanism to restrict access of a process received from the external network to data stored on the internal network;wherein the security policy program code includes assured pipeline program code for establishing an assured pipeline for the transfer of data and programs between the internal network and an external network through the secure server, wherein the assured pipeline program code includes: i) program code which places processes within domains, including assigning processes received from the external network to an external domain;ii) program code which assigns types to files;and iii) program code which restricts access by processes within the external domain to certain file types;and wherein the administrative kernel is restricted to execution only while isolated from the internal network.
  4. 17
    A secure server, having a processor (80), an internal network interface (90), connected to the processor, for communicating on an internal network, and an external network interface (96), connected to the processor, for communicating on an external network (74); wherein the processor includes server program code (92) for transferring data between the internal and external network interfaces and a security policy program code module for enforcing a Type Enforcement security mechanism to restrict access of a process received from the external network to data stored on the internal network; and wherein the security policy program code module comprises assured pipeline program code for establishing an assured pipeline for the transfer of data and programs between the internal network and a public network through the secure computer, wherein the assured pipeline program code comprises:i) program code which places processes within domains, including assigning processes received from the external network to an external domain;ii) program code which assigns types to files;and iii) program code which restricts access by processes within the external domain to certain file types.
  5. 22
    A method of transferring data between a first and a second network (42) connected by an external network (43), wherein the first network comprises a first workstation (63) connected to a first secure computer server (48) and wherein the second network comprises a second workstation (63) connected to a second secure computer server (48), wherein each secure computer server comprises a trusted subsystem first encryption means (66) for encrypting and decrypting data transferred between the secure computer server and its respective workstation and second encryption means (70) for encrypting and decrypting data transferred between the secure computer server and the external network, the method comprising the steps of:establishing an authenticated and protected interaction between the first workstation and the first secure computer server;sending data from the first workstation to the first secure computer server;enforcing a Type Enforcement security mechanism on the first secure computer server to restrict access of a process to data, comprising:    establishing an assured pipeline for the transfer of data and programs between the private network and the external network through the secure computer, wherein the step of establishing an assured pipeline includes the steps of: i) placing processes within domains, wherein the step of placing processes within domains includes the step of assigning processes received from the external network to an external domain;ii) assigning types to files;and iii) restricting access by processes within the external domain to certain file types;selecting an authentication and protection mechanism for interaction on the external network;encrypting, via the second encryption means of the first secure computer server, the data received from the first workstation;and sending the encrypted data over the external network to the second secure computer server.