Nova Patents
EP1153496A2

Network arrangement for communication

Abstract

A method for secure communication between a first end terminal located in a first secure network and a second end terminal located in a second secure network, said first and second networks being separated by a relatively insecure intermediate network, wherein the method including the steps of: selectively routing a communication from the first end terminal to the second end terminal over said relatively insecure intermediate network by means of one or more network elements triggerable to selectively route said communication; and encrypting said selectively routed communication by means of an encryption engine before it traverses said intermediate network, wherein said one or more network elements and said encryption engine are located substantially within said firs secure network.

Term

Term ended

Projected expiry passed 18 February 2020, 6.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

59 claims: 29 independent, 30 dependent

  1. 1
    Claims of equivalent WO 0049755 A2 CLAIMS :1. A method for secure communication between a first end terminal located in a first secure network and a second end terminal located in a second secure network, said first and second networks being separated by a relatively insecure intermediate network, the method including the steps of: selectively routing a communication from the first end terminal to the second end terminal over said relatively insecure intermediate network by means of one or more network elements triggerable to selectively route said communication;and encrypting said selectively routed communication by means of an encryption engine before it traverses said intermediate network, wherein said one or more network elements and said encryption engine are located substantially within said first secure network.
  2. 6
    A method as in any of claims 3 to 5 , wherein said switch means is operable to selectively route a predetermined communication according to routing information held in the storage means .
  3. 7
    A method as in any of claims 4 to 6, wherein said encryption engine is operable to encrypt said predetermined communication according to security information held in said storage means .
  4. 11
    A method as in any of claims 4 to 10, wherein said storage means is operable to store security information, said security information being distributed from a first node to one or more target nodes responsive to a predetermined trigger .
  5. 12
    A method as in any of claims 3 to 11, wherein the stored routing information includes subscriber routing preferences.
  6. 13
    A method as in any of claims 4 to 12, wherein the security information includes subscriber security preferences.
  7. 14
    A method as in any of claims 4 to 13 , wherein the security information includes encryption/decryption information defining a preferred algorithm or key for use with predetermined types of communication.
  8. 15
    A method as in any of claims 2 to 14, wherein information stored in the storage means is arranged to identify one or more groups of users whose communications are to be routed and encrypted according to common preferences.
  9. 16
    A method as in any of claims 2 to 15, wherein a service management access point is provided for accessing and changing information held in the storage means.
  10. 17
    A method as in any of claims 11 to 16, wherein said security information comprises decryption information, the distribution of said decryption information being triggered according to a predetermined schedule.
  11. 18
    A method as in any of claims 11 to 17, wherein said security information is distributed to a node within one or more of the first and second secure networks.
  12. 19
    A method as in any of claims 11 to 18, wherein said security information is distributed to the end terminal for the communication in question.
  13. 20
    A method as in any of claims 11 to 19, wherein the one or more network elements distributes security information from a location substantially within the first secure network.
  14. 21
    A method as in any of claims 11 to 20, wherein one or more network elements distributes security information from a location substantially within the second secure network.
  15. 25
    A method for the distribution of security information between a first node and one or more second nodes, including the step of providing one or more network elements operable to store security information and triggerable to distribute the security information from said first node to one or more target nodes .
  16. 26
    A method for the distribution of security information between a first node in a first secure network and one or more nodes in a second secure network, said first and second networks being separated by a relatively insecure network, wherein communications from said first node to one or more of said second nodes via said relatively insecure network are encrypted, including the step of providing one or more network elements operable to store security information and triggerable to distribute security information in a secure manner from said first node to one or more target nodes in said second secure network.
  17. 27
    A secure network arrangement for communication between a first end terminal located in a first secure network and a second end terminal located in a second secure network, said first and second networks being ■ separated by a relatively insecure intermediate network, the secure network arrangement including :one or more network elements triggerable to selectively route a communication from the first end terminal to the second end terminal over said relatively insecure intermediate network;and an encryption engine for encrypting said selectively routed communication before it traverses said intermediate network, wherein said one or more network elements and said encryption engine are located substantially within said first secure network.
  18. 37
    A secure network arrangement for communication between a first end terminal located in a first secure network and a second end terminal located in a second secure network, said first and second networks being separated by one or more intermediate networks at least one communication route through which constitutes a relatively insecure communication route from the first end terminal to the second end terminal, the secure network arrangement including one or more network elements triggerable to selectively route a communication from the first end terminal to the second end terminal over said relatively insecure intermediate network;and an encryption engine for encrypting said selectively routed communication before it traverses said interemediate network, wherein said one or more network elements and said encryption engine are located substantially within said first secure network .
  19. 41
    A method for the distribution of security information between a first node in a first secure network and one or more nodes in a second secure network, said first and second networks being separated by a relatively insecure network, wherein communications from said first node to one or more of said second nodes via said relatively insecure network are encrypted, the method comprising providing one or more network elements operable to store security information and being triggerable to distribute said security information in a secure manner from said first node to one or more target nodes in said second secure network.
  20. 42
    A network arrangement for the distribution of security information between a first node in a first. secure network and one or more nodes in a second secure network, said first and second networks being separated by a relatively insecure network, wherein communications from said first node to one or more of said second nodes via said relatively insecure network are encrypted, the network arrangement comprising one or more network elements operable to store security information and triggerable to distribute said security information in a secure manner from said first node' to one or more target nodes in said second secure network.
  21. 48
    A network arrangement according to any of claims 42 to 47, comprising a service management access point.
  22. 49
    A network arrangement according to any of claims 42 to 48, wherein the security information is distributed to a node within one or more of the first secure network and second secure network, rather than the destination end terminal for the communication in question.
  23. 50
    A network arrangement according to any of claims 42 to 49, wherein the security information is distributed to the end terminal for the communication in question.
  24. 51
    A network arrangement according to any of claims 42 to 50, wherein the one or more network elements distributes security information from a location substantially within the first secure network.
  25. 52
    A network arrangement according to any of claims 42 to 51, wherein the one or more network elements distributes the security information from a location substantially within one of the first or second networks.
  26. 55
    A network arrangement for the distribution of security information between a first node and one or more second nodes, including one or more network elements operable to store security information and triggerable to_ distribute the security information from said first node to one or more of said second nodes .
  27. 56
    A network arrangement for the distribution of security information between a node in a first secure network and one or more nodes in a second secure network, said first and second networks being separated by a relatively insecure intermediate network, including:• in at least one of said first and second secure networks one or more network elements operable to store security information and triggerable to distribute security information to one or more target nodes in said second secure network;and an encryption engine for encrypting a communication before it traverses said intermediate network.
  28. 57
    A method for the distribution of security information between a first node and one or more second nodes, including the step of providing one or more network elements operable to store security information and triggerable to distribute the security information from said first node to one or more target nodes.
  29. 58
    A method for the distribution of security information between a first node in a first secure network and one or more nodes in a second secure network, said first and second networks being separated by a relatively insecure network, wherein communications from said first node to one or more of said second nodes via said relatively insecure network are encrypted, including the step of providing one or more network elements operable to store security information and triggerable to distribute security information in a secure manner from said first node to one or more target nodes in said second secure network.
Independent claims29