Nova Patents
EP1153496B1

Network arrangement for communication

Abstract

A method for secure communication between a first end terminal located in a first secure network and a second end terminal located in a second secure network, said first and second networks being separated by a relatively insecure intermediate network, wherein the method including the steps of: selectively routing a communication from the first end terminal to the second end terminal over said relatively insecure intermediate network by means of one or more network elements triggerable to selectively route said communication; and encrypting said selectively routed communication by means of an encryption engine before it traverses said intermediate network, wherein said one or more network elements and said encryption engine are located substantially within said firs secure network.

EP1153496B1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 18 February 2020, 6.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

38 claims: 17 independent, 21 dependent

  1. 1
    A method for secure communication between a first end terminal (10) located in a first secure network and a second end terminal (12) located in a second secure network, said first and second networks being separated by a relatively insecure intermediate network (22) and a relatively secure intermediate network (16), the method characterized by :selectively routing a predetermined type of communication identified by a trigger from the first end terminal (10) to the second end terminal (12) over one of the relatively insecure intermediate network (22) and the relatively secure intermediate network (16) by means of one or more network elements (30) triggerable by the trigger to refer to information held in a storage means to selectively route said communication according to said information held in said storage means;and encrypting said selectively routed communication by means of an encryption engine (40) before it traverses the relatively insecure intermediate network (22), wherein said one or more network elements (30) and said encryption engine (40) are located within the first secure network.
  2. 6
    A method as in any of claims 3 to 5, wherein said switch means (32) is operable to selectively route a predetermined communication according to routing information held in the storage means (36).
  3. 7
    A method as in any of claims 4 to 6, wherein said encryption engine (40) is operable to encrypt said predetermined communication according to security information held in said storage means (36).
  4. 11
    A method as in any of claims 4 to 10, wherein said storage means (36) is operable to store security information, said security information being distributed from a first node (30) to one or more target nodes (18) responsive to the predetermined trigger.
  5. 12
    A method as in any of claims 3 to 11, wherein the stored routing information includes subscriber routing preferences.
  6. 13
    A method as in any of claims 4 to 12, wherein the security information includes subscriber security preferences.
  7. 14
    A method as in any of claims 4 to 13, wherein the security information includes encryption/decryption information defining a preferred algorithm or key for use with predetermined types of communication.
  8. 15
    A method as in any of claims 2 to 14, wherein information stored in the storage means (36) is arranged to identify one or more groups of users whose communications are to be routed and encrypted according to common preferences.
  9. 16
    A method as in any of claims 2 to 15, wherein a service management access point (100) is provided for accessing and changing information held in the storage means (36).
  10. 17
    A method as in any of claims 11 to 16, wherein said security information comprises decryption information, the distribution of said decryption information being triggered according to a predetermined schedule.
  11. 18
    A method as in any of claims 11 to 17, wherein said security information is distributed to a node within one or more of the first and second secure networks.
  12. 19
    A method as in any of claims 11 to 18, wherein said security information is distributed to the end terminal (12) for the communication in question.
  13. 20
    A method as in any of claims 11 to 19, wherein the one or more network elements (30) distributes security information from a location within the first secure network.
  14. 21
    A method as in any of claims 11 to 20, wherein one or more network elements (30) distributes security information from a location within the second secure network.
  15. 25
    A secure network arrangement for communication between a first end terminal (10)located in a first secure network and a second end terminal (12) located in a second secure network, said first and second networks being separated by a relatively insecure intermediate network (22) and a relatively secure intermediate network (16), the secure network arrangement characterized by :one or more network elements (30) triggerable by a trigger to refer to information held in a storage means to selectively route a predetermined communication identified by the trigger according to said information held in said storage means from the first end terminal (10) to the second end terminal (12) over one of the relatively insecure intermediate network (22) and the relatively secure intermediate network (16);and an encryption engine (40) for encrypting selectively routed communication before it traverses the relatively insecure intermediate networks (22), wherein said one or more network elements (30) and said encryption engine (40) are located within said first secure network.
  16. 34
    A secure network arrangement according to claims 25 to 33, comprising a service management access point (100) for accessing and changing information held in the storage means (36).
  17. 35
    A secure network arrangement according to claims 25 to 34, including decryption means (42) located within the second secure network.