Nova Patents
EP1632833A2

Computer system protection

Abstract

Computer system protection to protect against harmful data from an external computer network 60 (e.g. the Internet) involves supplying incoming data 62 to a software checker 64 as the data enters a computer system (not shown). The checker 64 routes any suspect data 66 to an encryptor 68 which encrypts it to render it unusable and harmless. Encrypted data passes to a computer 72 in an internal network 74 and having a desktop quarantine area or sandbox 76 for suspect data. The computer 72 runs main desktop applications 78 receiving encrypted data 70 for storage and transfer, but not for use in any meaningful way because it is encrypted. Equally well applications 78 cannot be interfered with by encrypted data 70 because encryption makes this impossible. On entry into the sandbox 76, the encrypted data 70 is decrypted to usable form: it then becomes accessible by software 204 suitable for use in the sandbox 76 subject to sandbox constraints.

EP1632833A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 24 December 2021, 4.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

25 claims: 7 independent, 18 dependent

  1. 1
    A computer system (72) for receiving incoming data (62) from an external source (60), the computer system (72) including a sandbox application (76) for receiving data (62) and defining a sandbox desktop, and decrypting means (80) for decrypting data, characterised in that:a) the computer system (72) includes encrypting means (64, 68, 208) for encrypting potentially harmful incoming data (62) to transform it to encrypted data (70) and thereby render it harmless,b) the decrypting means (80) is arranged to decrypt the encrypted data (70) to transform it to decrypted data, andc) a constrained application (82) constrained by the sandbox application (76) is arranged to process the decrypted data.
  2. 3
    A computer system (72) for receiving potentially harmful incoming data (62) from an external source (60), the computer system (72) including a sandbox application (76) for receiving data (62) and defining a sandbox desktop, and decrypting means (80) for decrypting data, characterised in that:a) the computer system (72) includes checking means (64) for: i) receiving incoming data (62),ii) passing on data (65) it deems harmless for processing with an application (78) associated with a main desktop (200) of the computer system (72), andiii) sending suspect data (66) for encryption,b) the computer system (72) also includes encrypting means (68) for receiving suspect data (66) from the checking means (64) and encrypting the suspect data (66) to transform it to encrypted data and thereby render it harmless,c) the decrypting means (80) is arranged to decrypt the encrypted data to transform it to decrypted data, andd) a constrained application (82) constrained by the sandbox application (76) is arranged to process the decrypted data.
  3. 7
    A computer system (72) according to any one of Claims to 6 characterised in that it is linked via a firewall (110) to the external source which is a network (60).
  4. 12
    A method of protecting a computer system (72) against potentially harmful incoming data (62) from an external source (60), the computer system (72) including a sandbox application (76) for receiving data and defining a sandbox desktop, and means for decrypting data, characterised in that the method incorporates the steps of:- a) encrypting potentially harmful incoming data (62) to transform it into harmless encrypted data (70),b) decrypting the encrypted data (70) to transform it into decrypted data, andc) processing the decrypted data by means of a constrained application (82) constrained by the sandbox application (76).
  5. 14
    A method of protecting a computer system (72) against potentially harmful incoming data (62) from an external source (60), the computer system (72) including a sandbox application (76) for receiving data (62) and defining a sandbox desktop, and decrypting means (80) for decrypting data, characterised in that the method incorporates the steps of:a) checking incoming data (62),b) passing on data (65) deemed harmless for processing with an application (78) associated with a main desktop (200) of the computer system (72),c) encrypting the suspect data (66) to transform it to encrypted data (70) and thereby render it harmless,d) decrypting the encrypted data (70) to transform it to decrypted data for receipt by the sandbox application (76), ande) processing the decrypted data with a constrained application (82) constrained by the sandbox application (76).
  6. 20
    Computer software for protecting a computer system (72) against potentially harmful incoming data (62) received from an external source (60), the computer software including decrypting software for decrypting data and a sandbox application (76) for receiving data and defining a sandbox desktop, characterised in that the computer software is arranged to control the computer system (72) to:- a) encrypt potentially harmful incoming data (62) to transform it to encrypted data (70) and thereby render it harmless,b) decrypt the encrypted data (70) to transform it to decrypted data, andc) process the decrypted data using a constrained application (82) constrained by the sandbox application (76).
  7. 22
    Computer software for protecting a computer system (72) against potentially harmful incoming data (62) received from an external source (60), the computer software including decrypting software for decrypting data and a sandbox application (76) for receiving data and defining a sandbox desktop, characterised in that the computer software is arranged to control the computer system (72) to:- a) check incoming data (62),b) pass on data (65) deemed harmless for processing with an application (78) associated with a main desktop (200) of the computer system (72),c) encrypt the suspect data (66) to transform it to encrypted data (70) and thereby render it harmless,d) decrypt the encrypted data (70) to transform it to decrypted data for receipt by the sandbox application (76), ande) process the decrypted data with a constrained application (82) constrained by the sandbox application (76).