EP1094682B1

Mobile phone incorporating security firmware

Abstract

This record has no abstract on file.

EP1094682B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 22 October 2019, 6.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

38 claims: 38 independent, 0 dependent

  1. 1
    A method for communication of data packets in a communication system comprising a remote host (1010), an independent access unit (1030) authenticating access to a communications network and encrypting information, a receiving computer (1050) acting as a security gateway to an intranet, and forwarding received data packets to an intranet host (400), characterized by the steps:- establishing a first communications path between the remote host (1010) and the independent access unit (1030);- determining, by use of security firmware and secret key information at the independent access unit (1030), a security association;- establishing a second communications path according to a security protocol layer between the independent access unit (1030) and the receiving computer (1050) over the communications network and in dependence of the security association.- establishing a communications path between the remote host (1010) and the intranet host comprising the first and the second communications paths whereby the independent access unit (1030) serves as a gateway between the first and the second communications paths and whereby the receiving computer (1050) serves as a gateway between the second communications path and an intranet path to the intranet host. Ein Verfahren zur Übertragung von Datenpaketen in einem Kommunikationssystem mit einem Fern-Host(1010), einer unabhängigen Zugangseinheit (1030) zum Authentifizieren eines Zugangs zu einem Kommunikationsnetzwerk und Verschlüsseln von Information, einem Empfangscomputer (1050), der als ein Sicherheits-Gateway zu einem Intranet tätig ist und empfangene Datenpakete zu einem Intranet-Host (400) weiterleitet, gekennzeichnet durch die folgenden Schritte: - Aufbauen eines ersten Übertragungspfades zwischen dem Fern-Host (1010) und der unabhängigen Zugangseinheit (1030);- Bestimmen, durch Gebrauch von Sicherheitsfirmware und Geheimschlüsselinformation bei der unabhängigen Zugangseinheit (1030), eines Sicherheitsverbands;- Aufbauen eines zweiten Übertragungspfades gemäß einer Sicherheitsprotokollschicht zwischen der unabhängigen Zugangseinheit (1030) und dem Empfangscomputer (1050) über das Kommunikationsnetzwerk und in Abhängigkeit von dem Sicherheitsverband.- Aufbauen eines Übertragungspfades zwischen dem Fern-Host (1010) und dem Intranet-Host mit dem ersten und dem zweiten Übertragungspfad, wobei die unabhängige Zugangseinheit (1030) als ein Gateway zwischen dem ersten und dem zweiten Übertragungspfad dient, und wobei der Empfangscomputer (1050) als ein Gateway zwischen dem zweiten Übertragungspfad und einem Intranetpfad zu dem Intranet-Host dient. Procédé de communication de paquets de données dans un système de communication comprenant un ordinateur hôte distant (1010), une unité indépendante d'accès (1030) authentifiant l'accès à un réseau de communication et chiffrant les informations, un ordinateur récepteur (1050) jouant le rôle de passerelle de sécurité vers un réseau intranet et transmettant des paquets de données reçues à un ordinateur hôte sur l'intranet (400), caractérisé par les étapes consistant à : - établir un premier trajet de communication entre l'ordinateur hôte distant (1010) et l'unité indépendante d'accès (1030) ;- déterminer, en utilisant un micrologiciel de sécurité et des informations de clef secrète au niveau de l'unité indépendante d'accès (1030), une association de sécurité ;- établir un second trajet de communication, selon une couche de protocole de sécurité, entre l'unité indépendante d'accès (1030) et l'ordinateur récepteur (1050) sur le réseau de communication et en fonction de l'association de sécurité ;- établir un trajet de communication entre l'ordinateur hôte distant (1010) et l'ordinateur hôte sur l'intranet, comprenant les premier et second trajets de communication, grâce à quoi l'unité indépendante d'accès (1030) sert de passerelle entre le premier et le second trajet de communication, et l'ordinateur récepteur (1050) sert de passerelle entre le second trajet de communication et un trajet intranet menant à l'ordinateur hôte sur l'intranet.
  2. 2
    A method according to claim 1, characterized in that the end-to-end protocol layer is TCP/IP and the security protocol layer is IPsec for which support is provided by said firmware. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass die End-zu-End-Protokollschicht TCP/IP ist und die Sicherheitsprotokollschicht IPsec ist, für die Unterstützung durch die Firmware bereitgestellt wird. Procédé selon la revendication 1, caractérisé en ce que la couche de protocole de bout en bout est le TCP/IP et la couche de protocole de sécurité est IPsec, dont le support est fourni par ledit micrologiciel.
  3. 3
    A method according to claim 1, characterized in that the firmware is provided in the form of software. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass die Firmware in der Form von Software bereitgestellt ist. Procédé selon la revendication 1, caractérisé en ce que le micrologiciel est fourni sous la forme de logiciel.
  4. 4
    A method according to claim 1-3, characterized in that said remote host is a laptop or a stand-alone computer. Ein Verfahren gemäß Anspruch 1 bis 3, dadurch gekennzeichnet, dass der Fern-Host ein Laptop oder ein eigenständiger Computer ist. Procédé selon les revendications 1 à 3, caractérisé en ce que ledit ordinateur hôte distant est un ordinateur portable ou un ordinateur autonome.
  5. 5
    A method according to claim 1-3, characterized in that said remote host is a personal digital assistant. Ein Verfahren gemäß Anspruch 1 bis 3, dadurch gekennzeichnet, dass der Fern-Host ein Persönlicher-Digital-Assistent (PDA) ist. Procédé selon les revendications 1 à 3, caractérisé en ce que ledit ordinateur hôte distant est un assistant numérique personnel.
  6. 6
    A method according to claim 1, characterized in that the first communication between the independent access unit (1030) and the remote host (1010) is performed by means of a wireless connection. Ein Verfahren gemäß Anspruch 1,dadurch gekennzeichnet, dass die erste Übertragung zwischen der unabhängigen Zugangseinheit (1030) und dem Fern-Host (1010) mittels einer Funkverbindung durchgeführt wird. Procédé selon la revendication 1, caractérisé en ce que la première communication entre l'unité indépendante d'accès (1030) et l'ordinateur hôte distant (1010) est réalisée au moyen d'une connexion sans fil.
  7. 7
    A method according to claim 1, characterized in that the first communication between the independent access unit (1030) and the remote host (1010) is performed by means of short-range radio. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass die erste Übertragung zwischen der unabhängigen Zugangseinheit (1030) und dem Fern-Host (1010) mittels Kurzwellenfunk durchgeführt wird. Procédé selon la revendication 1, caractérisé en ce que la première communication entre l'unité indépendante d'accès (1030) et l'ordinateur hôte distant (1010) est réalisée au moyen d'une communication radio à faible portée.
  8. 8
    A method according to claim 7, characterized in that said short-range radio communication is adapted to the Bluetooth standard. Ein Verfahren gemäß Anspruch 7, dadurch gekennzeichnet, dass die Kurzwellenfunkübertragung an den Bluetooth-Standard angepasst ist. Procédé selon la revendication 7, caractérisé en ce que ladite communication radio à faible portée est adaptée à la norme Bluetooth.
  9. 9
    A method according to claim 6, characterized in that the first communication between the independent access and the remote host is performed by means of infrared light. Ein Verfahren gemäß Anspruch 6, dadurch gekennzeichnet, dass die erste Übertragung zwischen dem unabhängigen Zugang und dem Fern-Host mittels Infrarotlicht durchgeführt wird. Procédé selon la revendication 6, caractérisé en ce que la première communication entre l'unité indépendante d'accès et l'ordinateur hôte distant est réalisée au moyen de lumière infrarouge.
  10. 10
    A method according to claim 1, characterized in that client private information required per client authentication are stored in a personal tamperproof storage and used in combination with the independent access unit as a security gateway upon establishment of a IPsec tunnel enabling a user to borrow any remote host in order to access the intranet by means of a mobile communication network or a fixed network. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass pro Client-Authentifizierung erforderliche Client-Privat-Information in einem persönlichen, gegen Eingriffe gesicherten Speicher gespeichert und in Kombination mit der unabhängigen Zugangseinheit verwendet wird als ein Sicherheits-Gateway bei Einrichtung eines IPsec-Tunnels, der einem Benutzer das Ausborgen irgendeines Fern-Hosts ermöglicht, um auf das Intranet mittels eines Mobilkommunikationsnetzwerkes oder eines festen Netzwerkes zuzugreifen. Procédé selon la revendication 1, caractérisé en ce que les informations privées du client exigées pour l'authentification du client sont stockées dans une mémoire personnelle protégée contre les manipulations et sont utilisées en combinaison avec l'unité indépendante d'accès jouant le rôle de passerelle de sécurité après établissement d'un tunnel IPsec permettant à un utilisateur d'emprunter n'importe quel ordinateur hôte distant pour accéder à l'intranet au moyen d'un réseau de communication mobile ou d'un réseau fixe.
  11. 11
    A method according to claim 10, characterized in that said tamperproof storage is provided in the form of a SIM-card/smart card. Ein Verfahren gemäß Anspruch 10, dadurch gekennzeichnet, dass der gegen Eingriffe gesicherte Speicher in der Form einer SIM-Karte/Smart-Card bereitgestellt wird. Procédé selon la revendication 10, caractérisé en ce que ladite mémoire protégée contre les manipulations est fournie sous la forme d'une carte SIM/carte à puce.
  12. 12
    A method according to claim 1, characterized in that the security gateway 300 terminates the IPsec secure link and forwards the IP packets from the remote host to the intranet host. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass der Sicherheits-Gateway 300 die IPsec gesicherte Verbindung abbricht und die IP-Pakete von dem Fern-Host zu dem Intranet-Host weiterleitet. Procédé selon la revendication 1, caractérisé en ce que la passerelle de sécurité 300 constitue la terminaison de la liaison Ipsec sécurisée et transfère les paquets IP entre l'ordinateur hôte distant et l'ordinateur hôte sur l'intranet.
  13. 13
    A method according to claim 1, characterized in that the configuration of the independent access unit Security Association SA is performed statically in a pre-configuration phase. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass die Konfiguration des Sicherheitsverbands SA der unabhängigen Zugangseinheit statisch in einer Vorkonfigurationsphase durchgeführt wird. Procédé selon la revendication 1, caractérisé en ce que la configuration de l'association de sécurité SA (pour « Security Association ») de l'unité indépendante d'accès est réalisée statiquement au cours d'une phase de préconfiguration.
  14. 14
    A method according to claim 1, characterized in that the configuration of the independent access unit Security Association SA is performed dynamically. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass die Konfiguration des Sicherheitsverbands SA der unabhängigen Zugangseinheit dynamisch durchgeführt wird. Procédé selon la revendication 1, caractérisé en ce que la configuration de l'association de sécurité SA de l'unité indépendante d'accès est réalisée dynamiquement.
  15. 15
    A method according to claim 14, characterized in that the dynamic configuration is provided by means of Internet Key Exchange (IKE) in order to establish an initial security association between the independent access unit and the security gateway, thereat said secure link is used to negotiate a remote host SA. Ein Verfahren gemäß Anspruch 14, dadurch gekennzeichnet, dass die dynamische Konfiguration mittels eines Internetschlüsselaustauschs (IKE) bereitgestellt wird, um einen Anfangssicherheitsverband zwischen der unabhängigen Zugangseinheit und dem Sicherheits-Gateway aufzubauen, wobei die sichere Verbindung zum Aushandeln eines Fern-Host-SA verwendet wird. Procédé selon la revendication 14, caractérisé en ce que la configuration dynamique est fournie au moyen d'un échange de clefs sur internet (IKE, pour « Internet Key Exchange »), afin d'établir une association de sécurité initiale entre l'unité indépendante d'accès et la passerelle de sécurité, après quoi ladite liaison sécurisée est utilisée pour négocier une association de sécurité pour l'ordinateur hôte distant.
  16. 16
    A method according to claim 13, characterized in that the pre-configuration of the security only allows access to certain gateways. Ein Verfahren gemäß Anspruch 13, dadurch gekennzeichnet, dass die Vorkonfiguration der Sicherheit nur Zugang zu gewissen Gateways erlaubt. Procédé selon la revendication 13, caractérisé en ce que la préconfiguration de la sécurité ne permet l'accès qu'à certaines passerelles.
  17. 17
    A method according to claim 13, characterized in that the pre-configuration is under user control. Ein Verfahren gemäß Anspruch 13, dadurch gekennzeichnet, dass die Vorkonfiguration unter Benutzersteuerung erfolgt. Procédé selon la revendication 13, caractérisé en ce que la préconfiguration est commandée par l'utilisateur.
  18. 18
    A method according to claim 15, characterized in that the PKI based key management is used. Ein Verfahren gemäß Anspruch 15, dadurch gekennzeichnet, dass die PKI-basierte Schlüsselverwaltung verwendet wird. Procédé selon la revendication 15, caractérisé en ce que l'on utilise la gestion de clefs basée sur la PKI.
  19. 19
    A method according to claim 1, characterized in that in that said method is used in a communication system transmitting speech over an IP-channel. Ein Verfahren gemäß Anspruch 1, dadurch gekennzeichnet, dass in diesem das Verfahren in einem über einen IP-Kanal Sprache übertragenden Kommunikationssystem verwendet wird. Procédé selon la revendication 1, caractérisé en ce que ledit procédé est utilisé dans un système de communication transmettant de la parole sur un canal IP.
  20. 20
    A computer program product directly loadable into the internal memory of an independent access unit, characterized by comprising software portions for performing the method according to any of claims 1-19, when the independent access unit is activated by a computer. Ein direkt in den internen Speicher einer unabhängigen Zugangseinheit ladbares Computerprogrammprodukt, gekennzeichnet durch Umfassen von Softwareteilen zum Durchführen des Verfahrens gemäß irgendeinen der Ansprüche 1 bis 19, wenn die unabhängige Zugangseinheit durch einen Computer aktiviert wird. Produit logiciel d'ordinateur pouvant être directement chargé dans la mémoire interne d'une unité indépendante d'accès, caractérisé en ce qu'il comprend des portions de logiciel pour exécuter le procédé selon l'une quelconque des revendications 1 à 19 lorsque l'unité indépendante d'accès est activée par un ordinateur.
  21. 21
    Agencement pour la communication de paquets de données dans un système de communication comprenant un ordinateur hôte distant (1010), une unité indépendante d'accès (1030) à un réseau de communication, un ordinateur récepteur (1050), jouant le rôle de passerelle de sécurité entre le réseau de communication au moins partiellement public et un réseau intranet, et un ordinateur hôte sur l'intranet, caractérisé par :- un moyen pour établir un premier trajet de communication entre l'ordinateur hôte distant (1010) et l'unité indépendante d'accès (1030) ;- un moyen pour déterminer, en utilisant un micrologiciel de sécurité et des informations de clef secrète sur l'unité indépendante d'accès (1030), une association de sécurité entre l'unité indépendante d'accès (1030) et l'ordinateur récepteur (1050) ;- un moyen pour établir un second trajet de communication, selon une couche de protocole de sécurité, entre l'unité indépendante d'accès (1030) et l'ordinateur récepteur (1050) sur le réseau de communication et en fonction de l'association de sécurité ;- un moyen pour établir un trajet de communication selon une couche de protocole de bout en bout, entre l'ordinateur hôte distant (1010) et l'ordinateur hôte sur l'intranet, comprenant les premier et second trajets de communication, grâce à quoi l'unité indépendante d'accès (1030) sert de passerelle entre le premier et le second trajet de communication, et l'ordinateur récepteur (1050) sert de passerelle entre le second trajet de communication et un trajet intranet menant à l'ordinateur hôte sur l'intranet. An arrangement for communication of data packets in a communication system including a remote host (1010), an independent access unit (1030) to a communications network, a receiving computer (1050) acting as a security Gateway between the at least partly public communications network and an intranet, and an intranet host characterized by: - means for establishing a first communications path between the remote host (1010) and the independent access unit (1030);- means for determining, by use of security firmware and secret key information at the independent access unit (1030), a security association between the independent access unit (1030) and the receiving computer (1050);- means for establishing a second communications path according to a security protocol layer between the independent access unit (1030) and the receiving computer (1050) over the communications network and in dependence of the security association.- means for establishing a communications path according to a end-to-end protocol layer between the remote host (1010) and the intranet host comprising the first and the second communications paths whereby the independent access unit (1030) serves as a gateway between the first and the second communications paths and whereby the receiving computer (1050) serves as a gateway between the second communications path and an intranet path to the intranet host. Eine Vorrichtung zur Übertragung von Datenpaketen in einem Kommunikationssystem mit einem Fern-Host (1010), einer unabhängigen Zugangseinheit (1030) zu einem Kommunikationsnetzwerk, einem Empfangscomputer (1050), der als ein Sicherheits-Gateway zwischen dem mindestens teilweise öffentlichen Kommunikationsnetzwerk und einem Intranet tätig ist, und einem Intranet-Host, gekennzeichnet durch: - Mittel zum Aufbauen eines ersten Übertragungspfades zwischen dem Fern-Host (1010) und der unabhängigen Zugangseinheit (1030);- Mittel zum Bestimmen, durch Gebrauch von Sicherheitsfirmware und Geheimschlüsselinformation bei der unabhängigen Zugangseinheit (1030), eines Sicherheitsverbands zwischen der unabhängigen Zugangseinheit (1030) und dem Empfangscomputer (1050);- Mittel zum Aufbauen eines zweiten Übertragungspfades gemäß einer Sicherheitsprotokollschicht zwischen der unabhängigen Zugangseinheit (1030) und dem Empfangscomputer (1050) über das Kommunikationsnetzwerk und in Abhängigkeit des Sicherheitsverbands;- Mittel zum Aufbauen eines Kommunikationspfades gemäß einer End-zu-End-Protokollschicht zwischen dem Fern-Host (1010) und dem Intranet-Host, die den ersten und den zweiten Übertragungspfad umfassen, wobei die unabhängige Zugangseinheit (1030) als ein Gateway zwischen dem ersten und dem zweiten Übertragungspfad dient, und wobei der Empfangscomputer (1050) als ein Gateway zwischen dem zweiten Übertragungspfad und einem Intranetpfad zu dem Intranet-Host dient.
  22. 22
    Agencement selon la revendication 21, caractérisé en ce que le micrologiciel est fourni sous la forme d'IPsec. An arrangement according to claim 21, characterized in that the firmware is provided in the form of IPsec. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass die Firmware in der Form von IPsec bereitgestellt ist.
  23. 23
    Agencement selon la revendication 21, caractérisé en ce que le micrologiciel est fourni sous la forme de logiciel. An arrangement according to claim 21, characterized in that the firmware is provided in the form of software. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass die Firmware in der Form von Software bereitgestellt ist.
  24. 24
    Agencement selon les revendications 21 à 23, caractérisé en ce que ledit ordinateur hôte distant est un ordinateur portable ou un ordinateur autonome. An arrangement according to claim 21-23, characterized in that said remote host is a laptop or a stand-alone computer. Eine Vorrichtung gemäß Anspruch 21 bis 23, dadurch gekennzeichnet, dass der Fern-Host ein Laptop oder ein eigenständiger Computer ist.
  25. 25
    Agencement selon les revendications 21 à 23, caractérisé en ce que ledit ordinateur hôte distant est un assistant numérique personnel. An arrangement according to claim 21-23, characterized in that said remote host is a personal digital assistant. Eine Vorrichtung gemäß Anspruch 21 bis 23, dadurch gekennzeichnet, dass der Fern-Host ein Persönlicher-Digital-Assistent (PDA) ist.
  26. 26
    Agencement selon la revendication 21, caractérisé en ce que le trajet de communication entre l'unité indépendante d'accès (1030) et l'ordinateur hôte distant (1010) est réalisé au moyen d'une connexion sans fil. An arrangement according to claim 21, characterized in that the communication path between the independent access unit (1030) and the remote host (1010) is established by means of a wireless connection. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass der Übertragungspfad zwischen der unabhängigen Zugangseinheit (1030) und dem Fern-Host (1010) mittels einer Funkverbindung aufgebaut ist.
  27. 27
    Agencement selon la revendication 21, caractérisé en ce que le trajet de communication entre l'unité indépendante d'accès (1030) et l'ordinateur hôte distant (1010) est réalisé au moyen d'une communication radio à faible portée. An arrangement according to claim 21, characterized in that the communication path between the independent access unit (1030) and the remote host (1010) is established by means of short range radio. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass der Übertragungspfad zwischen der unabhängigen Zugangseinheit (1030) und dem Fern-Host (1010) mittels Kurzwellenfunk aufgebaut ist.
  28. 28
    Agencement selon la revendication 27, caractérisé en ce que ladite communication radio à faible portée est adaptée à la norme Bluetooth. An arrangement according to claim 27, characterized in that said short-range radio communication is adapted to the Bluetooth standard. Eine Vorrichtung gemäß Anspruch 27, dadurch gekennzeichnet, dass die Kurzwellenfunkverbindung angepasst ist an den Bluetooth-Standard.
  29. 29
    Agencement selon la revendication 26, caractérisé en ce que le trajet de communication entre l'unité indépendante d'accès (1030) et l'ordinateur hôte distant (1010) est réalisé au moyen de lumière infrarouge. An arrangement according to claim 26, characterized in that the communication path between the independent access unit (1030) and the remote host (1010) is performed by means of infrared light. Eine Vorrichtung gemäß Anspruch 26, dadurch gekennzeichnet, dass der Übertragungspfad zwischen der unabhängigen Zugangseinheit (1030) und dem Fern-Host (1010) mittels Infrarotlicht durchgeführt ist.
  30. 30
    Agencement selon la revendication 21, caractérisé en ce que les informations privées du client exigées pour l'authentification du client sont stockées dans une mémoire personnelle protégée contre les manipulations et sont utilisées en combinaison avec l'unité indépendante d'accès jouant le rôle de passerelle de sécurité après établissement d'un tunnel IPsec permettant à un utilisateur d'emprunter n'importe quel ordinateur hôte distant pour accéder à l'intranet au moyen d'un réseau de communication mobile ou d'un réseau fixe. An arrangement according to claim 21, characterized in that client private information required per client authentication are stored in the personal tamperproof storage and used in combination with the independent access unit as a security gateway upon establishment of a IPsec tunnel enabling a user to borrow any remote host in order to access the intranet by means of a mobile communication network or a fixed network. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass pro Client-Authentifizierung erforderliche Client-Privat-Information in dem persönlichen, gegen Eingriffe gesicherten Speicher gespeichert und in Kombination mit der unabhängigen Zugangseinheit verwendet wird als ein Sicherheits-Gateway bei Einrichtung eines IPsec-Tunnels, der einem Benutzer das Ausborgen irgendeines Fern-Hosts ermöglicht, um auf das Intranet mittels eines Mobilkommunikationsnetzwerks oder eines festen Netzwerkes zuzugreifen.
  31. 31
    Agencement selon la revendication 30, caractérisé en ce que ladite mémoire protégée contre les manipulations est fournie sous la forme d'une carte SIM/carte à puce. An arrangement according to claim 30, characterized in that said tamperproof storage is provided in the form of a SIM-card/smart card. Eine Vorrichtung gemäß Anspruch 30, dadurch gekennzeichnet, dass der gegen Eingriffe gesicherte Speicher in der Form einer SIM-Karte/Smart-Card bereitgestellt ist.
  32. 32
    Agencement selon la revendication 21, caractérisé en ce que la passerelle de sécurité 300 constitue la terminaison de la liaison IPsec sécurisée et transfère les paquets IP entre l'ordinateur hôte distant et l'ordinateur hôte sur l'intranet. An arrangement according to claim 21, characterized in that the security gateway 300 terminates the IPsec secure link and forwards the IP packets from the remote host to the intranet host. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass der Sicherheits-Gateway 300 die Ipsec gesicherte Verbindung abbricht und die IP-Pakete von dem Fern-Host zu dem Intranet-Host weiterleitet.
  33. 33
    Agencement selon la revendication 21, caractérisé en ce que la commande de l'association de sécurité SA de l'unité indépendante d'accès est réalisée statiquement au cours d'une phase de préconfiguration. An arrangement according to claim 21, characterized in that the control of the independent access unit Security Association SA is performed statically in a pre-configuration phase. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass die Steuerung des Sicherheitsverbands SA der unabhängigen Zugangseinheit statisch in einer Vorkonfigurationsphase durchgeführt ist.
  34. 34
    Agencement selon la revendication 21, caractérisé en ce que la commande de l'association de sécurité SA de l'unité indépendante d'accès est réalisée dynamiquement. An arrangement according to claim 21, characterized in that the control of the independent access unit Security Association SA is performed dynamically. Eine Vorrichtung gemäß Anspruch 21, dadurch gekennzeichnet, dass die Steuerung des Sicherheitsverbands SA der unabhängigen Zugangseinheit dynamisch durchgeführt ist.
  35. 35
    Agencement selon la revendication 34, caractérisé en ce que la configuration dynamique est fournie au moyen d'un échange de clefs sur internet (IKE), afin d'établir une association de sécurité initiale entre l'unité indépendante d'accès et la passerelle de sécurité, après quoi ladite liaison sécurisée est utilisée pour négocier une association de sécurité pour l'ordinateur hôte distant. An arrangement according to claim 34, characterized in that the dynamic configuration is provided by means of Internet Key Exchange (IKE) in order to establish an initial security association between the independent access unit and the security gateway, thereat said secure link is used to negotiate a remote host SA. Eine Vorrichtung gemäß Anspruch 34, dadurch gekennzeichnet, dass die dynamische Konfiguration mittels eines Internetschlüsselaustauschs (IKE) bereitgestellt ist, um einen Anfangssicherheitsverband zwischen der unabhängigen Zugangseinheit und dem Sicherheits-Gateway aufzubauen, wobei die sichere Verbindung zum Aushandeln eines Fern-Host-SA verwendet wird.
  36. 36
    Agencement selon la revendication 33, caractérisé en ce que la préconfiguration de la sécurité ne permet l'accès qu'à certaines passerelles. An arrangement to claim 33, characterized in that the pre-configuration of the security only allows access to certain gateways. Eine Vorrichtung gemäß Anspruch 33, dadurch gekennzeichnet, dass die Vor konfiguration der Sicherheit nur den Zugriff auf gewisse Gateways erlaubt.
  37. 37
    Agencement selon la revendication 33, caractérisé en ce que la préconfiguration est commandée par l'utilisateur. An arrangement according to claim 33, characterized in that the pre-configuration is under user control. Eine Vorrichtung gemäß Anspruch 33, dadurch gekennzeichnet, dass die Vorkonfiguration unter Benutzersteuerung erfolgt.
  38. 38
    Agencement selon la revendication 35, caractérisé en ce que l'on utilise la gestion de clefs basée sur la PKI. An arrangement according to claim 35, characterized in that the PKI based key management is used. Eine Vorrichtung gemäß Anspruch 35, dadurch gekennzeichnet, dass die PKI-basierte Schlüsselverwaltung verwendet wird.
Independent claims38