Nova Patents
EP1632833B1

Computer system protection

Abstract

This record has no abstract on file.

EP1632833B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 24 December 2021, 4.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

33 claims: 33 independent, 0 dependent

  1. 1
    A computer system (72) for receiving incoming data (62) from an external source (60), the computer system (72) being arranged to provide a main desktop (200) and also including a sandbox application (76) for receiving data (62) and defining a sandbox desktop, and decrypting means (80) for decrypting data, characterised in that:a) the computer system (72) is arranged to distinguish harmless incoming data (65) from potentially harmful incoming data (66) and includes encrypting means (68, 208) for encrypting the potentially harmful incoming data (66) to transform it to encrypted data (70) and thereby render it harmless,b) the computer system (72) is also arranged to make incoming data (65) distinguished as harmless available in unencrypted form for processing by means of a main desktop application (78),c) the decrypting means (80) is arranged to decrypt the encrypted data (70) to transform it to decrypted data, andd) a constrained application (82) constrained by the sandbox application (76) is arranged to process the decrypted data. Computersystem (72) zum Empfangen von ankommenden Daten (62) von einer externen Quelle (60), wobei das Computersystem (72) dazu eingerichtet ist, einen Haupt-Desktop (200) bereitzustellen, der auch eine Sandbox-Anwendung (76), die Daten (62) empfängt und einen Sandbox-Desktop definiert, und eine Entschlüsselungseinrichtung (80) zum Entschlüsseln von Daten enthält, dadurch gekennzeichnet, dassa) das Computersystem (72) dazu eingerichtet ist, harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) zu unterscheiden, und eine Verschlüsselungseinrichtung (68, 208) zum Verschlüsseln der potenziell schädlichen ankommenden Daten (66) enthält, um sie in verschlüsselte Daten (70) umzuwandeln und sie dadurch harmlos zu machen,b) das Computersystem (72) außerdem dazu eingerichtet ist, ankommende Daten (65), die als harmlos unterschieden wurden, in unverschlüsselter Form für die Verarbeitung durch eine Haupt-Desktop-Anwendung (78) verfügbar zu machen,c) die Entschlüsselungseinrichtung (80) dazu eingerichtet ist, die verschlüsselten Daten (70) zu entschlüsseln, um sie in entschlüsselte Daten umzuwandeln, undd) eine eingegrenzte Anwendung (82), die durch die Sandbox-Anwendung (76) eingegrenzt ist, dazu eingerichtet ist, die entschlüsselten Daten zu verarbeiten. Système informatique (72) pour recevoir des données entrantes (62) d'une source externe (60), le système informatique (72) étant disposé pour fournir un bureau principal (200) et aussi comprendre une application de type bac à sable (76) pour recevoir des données (62) et définir un bureau de type bac à sable, et un moyen de décryptage (80) pour décrypter des données, caractérisé en ce que : a) le système informatique (72) est disposé pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) et comprend un moyen de cryptage (68, 208) pour crypter les données entrantes potentiellement dangereuses (66) pour les transformer en données cryptées (70) et ainsi les rendre sans danger,b) le système informatique (72) est aussi disposé pour élaborer des données entrantes (65) distinguées comme sans danger disponibles dans une forme non-cryptée pour le traitement au moyen d'une application de bureau principal (78),c) le moyen de décryptage (80) est disposé pour décrypter les données cryptées (70) pour les transformer en données décryptées, etd) une application forcée (82) forcée par l'application de type bac à sable (76) est disposée pour traiter les données décryptées.
  2. 2
    A computer system (72) according to Claim 1 characterised in that the computer system (72) includes a software checker (64) arranged to distinguish harmless incoming data (65) from potentially harmful incoming data (66). Computersystem (72) nach Anspruch 1, dadurch gekennzeichnet, dass das Computersystem (72) einen Software-Prüfer (64) enthält, der dazu eingerichtet ist, harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) zu unterscheiden. Système informatique (72) selon la revendication 1, caractérisé en ce que le système informatique (72) comprend un dispositif logiciel de vérification (64) disposé pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66).
  3. 3
    A computer system (72) according to Claim 2 characterised in that the software checker (64) is arranged to:a) receive incoming data (62) for distinguishing harmless incoming data (65) from potentially harmful incoming data (66),b) pass on incoming data (65) distinguished as harmless for processing with the main desktop application (78), andc) send potentially harmful incoming data (66) to the encrypting means (64, 68, 208) for encryption. Computersystem (72) nach Anspruch 2, dadurch gekennzeichnet, dass der Software-Prüfer (64) dazu eingerichtet ist, a) ankommende Daten (62) zur Unterscheidung von harmlosen ankommenden Daten (65) von potenziell schädlichen ankommenden Daten (66) zu empfangen,b) ankommende Daten (65), die als harmlos unterschieden wurden, für die Verarbeitung durch die Haupt Desktop-Anwendung (78) weiterzuleiten, undc) potenziell schädliche ankommende Daten (66) zur Verschlüsselung an die Verschlüsselungseinrichtung (64, 68, 208) zu senden. Système informatique (72) selon la revendication 2, caractérisé en ce que le dispositif logiciel de vérification (64) est disposé pour : a) recevoir des données entrantes (62) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66),b) passer des données entrantes (65) distinguées comme sans danger pour le traitement à une application de bureau principal (78), etc) envoyer des données entrantes potentiellement dangereuses (66) au moyen de cryptage (64, 68, 208) pour le cryptage.
  4. 4
    A computer system (72) according to Claim 1, 2 or 3 characterised in that the constrained application (82) does not communicate directly with any application. (78) associated with the main desktop (200). Computersystem (72) nach Anspruch 1, 2 oder 3, dadurch gekennzeichnet, dass die eingegrenzte Anwendung (82) nicht direkt mit irgendeiner Anwendung (78) kommuniziert, die zu dem Haupt-Desktop (200) gehört. Système informatique (72) selon la revendication 1, 2 ou 3, caractérisé en ce que l'application forcée (82) ne communique pas directement avec une application quelconque (78) associée au bureau principal (200).
  5. 5
    A computer system (72) according to Claim 1, 2, 3 or 4 characterised in that it is associated with means (86, 88) for enabling a user to retrieve data from the sandbox application (76) in encrypted form for relaying to expert inspection (90). Computersystem (72) nach Anspruch 1, 2, 3 oder 4, dadurch gekennzeichnet, dass es mit Einrichtungen (86, 88) verbunden ist, die einem Benutzer ermöglichen, Daten aus der Sandbox-Anwendung (76) in verschlüsselter Form abzurufen, um sie zur Untersuchung durch Experten (90) weiterzuleiten. Système informatique (72) selon la revendication 1, 2, 3 ou 4, caractérisé en ce qu'il est associé au moyen (86, 88) pour permettre à un utilisateur de récupérer des données à partir de l'application de type bac à sable (76) dans une forme cryptée pour relayer à l'inspection d'expert (90).
  6. 6
    A computer system (72) according to any one of Claims 1, to 5 characterised in that it includes means (210) for checking decrypted data released from the sandbox application (76) for potentially harmful content. Computersystem (72) nach einem der Ansprüche 1 bis 5, dadurch gekennzeichnet, dass es eine Einrichtung (210) enthält, die die entschlüsselten Daten, die von der Sandbox-Anwendung (76) als potenziell schädlicher Inhalt freigegeben wurden, auf potenziell schädlichen Inhalt hin überprüft. Système informatique (72) selon l'une quelconque des revendications 1 à 5, caractérisé en ce qu'il comprend un moyen (210) pour vérifier si les données décryptées sorties de l'application de type bac à sable (76) ont un contenu potentiellement dangereux.
  7. 7
    A computer system (72) according to any one of Claims 1 to 6 characterised in that it is linked via a firewall (110) to the external source which is a network (60). Computersystem (72) nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass es über eine Firewall (110) mit der externen Quelle verbunden ist, die ein Netzwerk (60) ist. Système informatique (72) selon l'une quelconque des revendications 1 à 6, caractérisé en ce qu'il est lié via un pare-feu (110) à la source externe qui est un réseau (60).
  8. 8
    A computer system (72) according to any one of Claims 1 to 6 characterised in that it includes a firewall (110) protecting the checking means (116) from the external source (60) to which the firewall (110) is linked. Computersystem (72) nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass es eine Firewall (110) enthält, die die Prüfungseinrichtung (116) vor der externen Quelle (60) schützt, mit der die Firewall (110) verbunden ist. Système informatique (72) selon l'une quelconque des revendications 1 à 6, caractérisé en ce qu'il comprend un pare-feu (110) protégeant le moyen de vérification (116) de la source externe (60) auquel le pare-feu (110) est lié.
  9. 9
    A computer system (72) according to any preceding claim including software (208) for encrypting potentially harmful data which a user may wish to process using the main desktop application (78) instead of the sandbox application (76). Computersystem (72) nach einem der vorangehenden Ansprüche, das Software (208) zum Verschlüsseln potenziell schädlicher Daten enthält, die ein Benutzer möglicherweise mit der Haupt-Desktop-Anwendung (78) statt mit der Sandbox-Anwendung (76) verarbeiten möchte. Système informatique (72) selon l'une quelconque des revendications précédentes, comprenant un logiciel (208) pour crypter des données potentiellement dangereuses qu'un utilisateur peut désirer traiter en utilisant l'application de bureau principal (78) au lieu de l'application de type bac à sable (76).
  10. 10
    A computer system (72) according to any preceding claim characterised in that it includes software for enabling a user to retrieve data from the sandbox application (76) in encrypted form for relaying to expert inspection (90). Computersystem (72) nach einem der vorangehenden Ansprüche, dadurch gekennzeichnet, dass es Software enthält, die es einem Benutzer ermöglicht, Daten von der Sandbox-Anwendung (76) in verschlüsselter Form abzurufen, um sie zur Untersuchung durch Experten (90) weiterzuleiten. Système informatique (72) selon l'une quelconque des revendications précédentes, caractérisé en ce qu'il comprend un logiciel pour permettre à un utilisateur de récupérer des données à partir de l'application de type bac à sable (76) dans une forme cryptée pour relayer à l'inspection d'expert (90).
  11. 11
    A computer system (72) according to any one of Claims 7 to 10 characterised in that it includes software (210) for checking decrypted data released from the sandbox application (76) for potentially harmful content and suitability for processing by the main desktop application (78). Computersystem (72) nach einem der Ansprüche 7 bis 10, dadurch gekennzeichnet, dass es Software (210) zum Prüfen der entschlüsselten Daten, die aus der Sandbox-Anwendung (76) abrufen wurden, auf potenziell schädlichen Inhalt und Eignung für die Verarbeitung durch die Haupt-Desktop-Anwendung (78) hin enthält. Système informatique (72) selon l'une quelconque des revendications 7 à 10, caractérisé en ce qu'il comprend un logiciel (210) pour vérifier si des données décryptées sorties de l'application de type bac à sable (76) ont un contenu potentiellement dangereux et la capacité pour le traitement par l'application de bureau principal (78).
  12. 12
    A computer system (72) according to any preceding claim characterised in that it is arranged to distinguish harmless incoming data (65) from potentially harmful incoming data (66) by decomposing incoming data into individual data parts such as for example a message body and attachment, and selecting successive data parts for checking (146). Computersystem (72) nach einem der vorangehenden Ansprüche, dadurch gekennzeichnet, dass es dazu eingerichtet ist, harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) zu unterscheiden, indem es ankommende Daten in einzelne Datenteile zerlegt, wie etwa beispielsweise einen Body der Nachricht und Anhänge, und aufeinander folgende Datenteile zur Überprüfung (146) auswählt. Système informatique (72) selon l'une quelconque des revendications précédentes, caractérisé en ce qu'il est disposé pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) en décomposant des données entrantes en parties de données individuelles telles que par exemple un corps de message et une pièce jointe, et sélection des parties de données successives pour la vérification (146).
  13. 13
    A computer system (72) according to Claim 12 characterised in that it is arranged to encrypt (158) a data part which has not been verified to be harmless (154) and replace that data part by the encrypted data part. Computersystem (72) nach Anspruch 12, dadurch gekennzeichnet, dass es dazu eingerichtet ist, einen Datenteil, für den nicht verifiziert wurde, dass er harmlos ist (154), zu verschlüsseln (158), und diesen Datenteil durch den verschlüsselten Datenteil zu ersetzen. Système informatique (72) selon la revendication 12, caractérisé en ce qu'il est disposé pour crypter (158) une partie de données qui n'a pas été vérifiée être sans danger (154) et remplacer cette partie de données par la partie de données cryptées.
  14. 14
    A computer system (72) according to Claim 13 characterised in that it is arranged to:a) abandon (152) processing of an item of incoming data if it contains a data part which is found (148) to contain dangerous code, andb) provide (156) a partially encrypted and partially non-encrypted item of incoming data if a last data part in the item of incoming data has been processed, processing not having been abandoned (152) prior to that. Computersystem (72) nach Anspruch 13, dadurch gekennzeichnet, dass es dazu eingerichtet ist: a) die Verarbeitung eines Abschnitts ankommender Daten abzubrechen (152), wenn er einen Datenteil enthält, für den festgestellt wird (148), dass er gefährlichen Code enthält, undb) einen teilweise verschlüsselten und teilweise nicht verschlüsselten Abschnitt von ankommenden Daten bereitzustellen (156), wenn ein letzter Datenteil in dem Abschnitt von ankommenden Daten verarbeitet worden ist, wobei die Verarbeitung davor nicht abgebrochen worden ist (152). Système informatique (72) selon la revendication 13, caractérisé en ce qu'il est disposé pour : a) abandonner (152) le traitement d'un élément de données entrantes s'il contient une partie de données qui est trouvée (148) contenir un code dangereux, etb) fournir (156) un élément partiellement crypté et partiellement non-crypté de données entrantes si une dernière partie de données dans l'élément des données entrantes a été traitée, le traitement n'ayant pas été abandonné (152) avant cela.
  15. 15
    A method of protecting a computer system (72) against potentially harmful incoming data (62) from an external source (60), the computer system (72) being arranged to provide a main desktop (200) and also including a sandbox application (76) for receiving data and defining a sandbox desktop, and means for decrypting data, characterised in that the method incorporates the steps of:- a) distinguishing harmless incoming data (65) from potentially harmful incoming data (66) and encrypting the potentially harmful incoming data (66) to transform it into harmless encrypted data (70),b) making incoming data (65) distinguished as harmless available in unencrypted form for processing by means of a main desktop application (78),c) decrypting the encrypted data (70) to transform it into decrypted data, andd) processing the decrypted data by means of a constrained application (82) constrained by the sandbox application (76). Procédé de traitement de système informatique (72) par rapport à des données entrantes potentiellement dangereuses (62) à partir d'une source externe (60), le système informatique (72) étant disposé pour fournir un bureau principal (200) et comprenant aussi une application de type bac à sable (76) pour recevoir des données et définir un bureau de type bac à sable, et un moyen pour décrypter des données, caractérisé en ce que le procédé incorpore les étapes de : a) distinction des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) et cryptage des données entrantes potentiellement dangereuses (66) pour les transformer en données cryptées sans danger (70),b) établissement de données entrantes (65) distinguées comme sans danger disponibles dans la forme non-cryptée pour le traitement au moyen d'une application de bureau principal (78),c) décryptage des données cryptées (70) pour les transformer en données décryptées, etd) traitement des données décryptées au moyen d'une application forcée (82) forcée par l'application de type bac à sable (76). Verfahren zum Schützen eines Computersystems (72) gegen potenziell schädliche ankommende Daten (62) aus einer externen Quelle (60), bei dem das Computersystem (72) dazu eingerichtet ist, einen Haupt-Desktop (200) bereitzustellen, der auch eine Sandbox-Anwendung (76), die Daten empfängt und einen Sandbox-Desktop definiert, und eine Einrichtung zum Entschlüsseln von Daten enthält, dadurch gekennzeichnet, dass das Verfahren die folgenden Schritte enthält: a) harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) unterscheiden und potenziell schädliche ankommende Daten (66) verschlüsseln, um sie in harmlose verschlüsselte Daten (70) umzuwandeln,b) ankommende Daten (65), die als harmlos unterschieden wurden, in unverschlüsselter Form für die Verarbeitung durch eine Haupt-Desktop-Anwendung (78) verfügbar machen,c) verschlüsselte Daten (70) entschlüsseln, um sie in entschlüsselte Daten umzuwandeln, undd) entschlüsselte Daten mittels einer eingegrenzten Anwendung (82) verarbeiten, die durch die Sandbox-Anwendung (76) eingegrenzt ist.
  16. 16
    A method according to Claim 15 characterised in that the step of distinguishing harmless incoming data (65) from potentially harmful incoming data (66) and encrypting the potentially harmful incoming data (66) comprises using a software checker to check incoming data (62). Procédé selon la revendication 15, caractérisé en ce que l'étape de distinction de données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) et de cryptage de données entrantes potentiellement dangereuses (66) comprend l'utilisation d'un dispositif logiciel de vérification pour vérifier des données entrantes (62). Verfahren nach Anspruch 15, dadurch gekennzeichnet, dass der Schritt des Unterscheidens harmloser ankommender Daten (65) von potenziell schädlichen ankommenden Daten (66) und des Verschlüsselns der potenziell schädlichen ankommenden Daten (66) die Verwendung eines Software-Prüfers umfasst, der ankommende Daten (62) überprüft.
  17. 17
    A method according to Claim 16 characterised in that the software checker (64) is arranged to implement the steps of:a) receiving incoming data (62) for distinguishing harmless incoming data (65) from potentially harmful incoming data (66),b) passing on incoming data (65) distinguished as harmless for processing with the main desktop application (78), andc) sending potentially harmful incoming data (66) for encryption. Procédé selon la revendication 16, caractérisé en ce que le dispositif logiciel de vérification (76) est disposé pour implémenter les étapes de : a) réception de données entrantes (62) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66),b) passage des données entrantes (65) distinguées comme sans danger pour le traitement à l'application de bureau principal (78), etc) envoi des données entrantes potentiellement dangereuses (66) pour le cryptage. Verfahren nach Anspruch 16, dadurch gekennzeichnet, dass der Software-Prüfer (64) dazu eingerichtet ist, folgende Schritte zu implementieren: a) Empfangen ankommender Daten (62), um harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) zu unterscheiden,b) Weiterleiten von ankommenden Daten (65), die als harmlos unterschieden wurden, zur Verarbeitung durch die Haupt-Desktop-Anwendung (78), undc) Senden von potenziell schädlichen ankommenden Daten (66) zur Verschlüsselung.
  18. 18
    A method of protecting a computer system (72) according to Claim 17 characterised in that the software checker (116) protected by a firewall (110) from the external source (60). Procédé de protection d'un système informatique (72) selon la revendication 17, caractérisé en ce que le dispositif logiciel de vérification (116) est protégé par un pare-feu (110) de la source externe (60). Verfahren zum Schützen eines Computersystems (72) nach Anspruch 17, dadurch gekennzeichnet, dass der Software-Prüfer (116) durch eine Firewall (110) von der externen Quelle (60) geschützt ist.
  19. 19
    A method of protecting a computer system (72) according to Claim 16, 17 or 18 characterised in that the constrained application (82) does not communicate with any application (78) associated with the main desktop (200). Procédé de protection d'un système informatique (72) selon la revendication 16, 17 ou 18, caractérisé en ce que l'application forcée (82) ne communique pas avec une application quelconque (78) associée au bureau principal (200). Verfahren zum Schützen eines Computersystems (72) nach Anspruch 16, 17 oder 18, dadurch gekennzeichnet, dass die eingegrenzte Anwendung (82) nicht mit irgendeiner Anwendung (78) kommuniziert, die zu dem Haupt-Desktop (200) gehört.
  20. 20
    A method of protecting a computer system (72) according to Claim 16,17,18 or 19 characterised in that it includes the step of retrieving data from the sandbox application (76) in encrypted form for relaying to expert inspection (90). Procédé de protection d'un système informatique (72) selon la revendication 16, 17, 18 ou 19, caractérisé en ce qu'il comprend les étapes de récupération de données à partir de l'application de type bac à sable (76) dans la forme cryptée pour relayer à l'inspection d'expert (90). Verfahren zum Schützen eines Computersystems (72) nach Anspruch 16, 17, 18 oder 19, dadurch gekennzeichnet, dass es den Schritt des Abrufens von Daten in verschlüsselter Form aus der Sandbox-Anwendung (76) zur Weiterleitung zur Untersuchung durch Experten (90) enthält.
  21. 21
    A method of protecting a computer system (72) according to any one of Claims 16 to 20 characterised in that it includes checking decrypted data released from the sandbox desktop (76) for potentially harmful content. Procédé de protection d'un système informatique (72) selon l'une quelconque des revendications 16 à 20, caractérisé en ce qu'il comprend la vérification si des données décryptées sorties par le bureau de type bac à sable (76) ont un contenu potentiellement dangereux. Verfahren zum Schützen eines Computersystems (72) nach einem der Ansprüche 16 bis 20, dadurch gekennzeichnet, dass es das Überprüfen entschlüsselter Daten, die aus dem Sandbox-Desktop (76) abgerufen wurden, auf potenziell schädlichen Inhalt hin enthält.
  22. 22
    A method of protecting a computer system (72) according to Claim 16 characterised in that the computer system (72) is linked via a firewall (110) to the external source which is a network (60). Procédé de protection d'un système informatique (72) selon la revendication 16, caractérisé en ce que le système informatique (72) est lié via un pare-feu (110) à la source externe qui est un réseau (60). Verfahren zum Schützen eines Computersystems (72) nach Anspruch 16, dadurch gekennzeichnet, dass das Computersystem (72) über eine Firewall (110) mit der externen Quelle verbunden ist, die ein Netzwerk (60) ist.
  23. 23
    A method of protecting a computer system (72) according to any one of Claims 15 to 22 characterised in that the step of distinguishing harmless incoming data (65) from potentially harmful incoming data (66) is implemented by decomposing incoming data into individual data parts such as for example a message body and attachment, and selecting successive data parts for checking (146). Procédé de protection d'un système informatique (72) selon l'une quelconque des revendications 15 à 22, caractérisé en ce que l'étape de distinction de données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) est implémentée en décomposant les données entrantes en parties de données individuelles telles que par exemple un corps de message et une pièce jointe, et sélection de parties de données successives pour la vérification (146). Verfahren zum Schützen eines Computersystems (72) nach einem der Ansprüche 15 bis 22, dadurch gekennzeichnet, dass der Schritt des Unterscheidens harmloser ankommender Daten (65) von potenziell schädlichen ankommenden Daten (66) implementiert ist, indem ankommende Daten in einzelne Datenteile zerlegt werden, wie etwa einen Body und einen Anhang einer Nachricht, und aufeinander folgende Datenteile zur Überprüfung (146) ausgewählt werden.
  24. 24
    A method of protecting a computer system (72) according to Claim 23 characterised in that the step of distinguishing harmless incoming data (65) from potentially harmful incoming data (66) includes encrypting (158) a data part which has not been verified to be harmless (154) and replacing that data part by the encrypted data part. Procédé de protection d'un système informatique (72) selon la revendication 23, caractérisé en ce que l'étape de distinction de données entrantes sans danger (55) de données entrantes potentiellement dangereuses (66) comprend le cryptage (158) d'une partie de données qui n'a pas été vérifiée être sans danger (154) et remplacer cette partie de données par la partie de données cryptées. Verfahren zum Schützen eines Computersystems (72) nach Anspruch 23, dadurch gekennzeichnet, dass der Schritt des Unterscheidens harmloser ankommender Daten (65) von potenziell schädlichen ankommenden Daten (66) das Verschlüsseln (158) eines Datenteils, der nicht als harmlos (154) verifiziert worden ist, und das Ersetzen dieses Datenteils durch den verschlüsselten Datenteil enthält.
  25. 25
    A method of protecting a computer system (72) according to Claim 24 characterised in that the step of distinguishing harmless incoming data (65) from potentially harmful incoming data (66) includes:a) abandoning (152) processing of an item of incoming data if it contains a data part which is found (148) to contain dangerous code, andb) providing (156) a partially encrypted and partially non-encrypted item of incoming data if a last data part in the item of incoming data has been processed, processing not having been abandoned (152) prior to that. Procédé de protection d'un système informatique (72) selon la revendication 24, caractérisé en ce que l'étape de distinction de données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) comprend : a) l'abandon (152) du traitement d'un élément de données entrantes s'il contient une partie de données qui est trouvée (148) contenir un code dangereux, etb) la fourniture (156) d'un élément partiellement crypté et partiellement non-crypté de données entrantes si une dernière partie de données dans l'élément de données entrantes a été traitée, le traitement n'ayant pas été abandonné (152) avant cela. Verfahren zum Schützen eines Computersystems (72) nach Anspruch 24, dadurch gekennzeichnet, dass der Schritt des Unterscheidens harmloser ankommender Daten (65) von potenziell schädlichen ankommenden Daten (66) folgendes enthält: a) Abbrechen (152) der Verarbeitung eines Abschnitts ankommender Daten, wenn er einen Datenteil enthält, für den festgestellt wird (148), dass er gefährlichen Code enthält, undb) Bereitstellen (156) eines teilweise verschlüsselten und teilweise nicht verschlüsselten Abschnitts von ankommenden Daten, wenn ein letzter Datenteil in dem Abschnitt von ankommenden Daten verarbeitet worden ist, wobei die Verarbeitung davor nicht abgebrochen worden ist (152).
  26. 26
    Computer software for protecting a computer system (72) against potentially harmful incoming data (62) received from an external source (60), the computer software being arranged to provide a main desktop (200) and including decrypting software for decrypting data and a sandbox application (76) for receiving data and defining a sandbox desktop, characterised in that the computer software is arranged to control the computer system (72) to:- a) distinguish harmless incoming data (65) from potentially harmful incoming data (66) and encrypt the potentially harmful incoming data (66) to transform it into harmless encrypted data (70),b) make incoming data (65) distinguished as harmless available in unencrypted form for processing by means of a main desktop application (78),c) decrypt the encrypted data (70) to transform it into decrypted data, andd) process the decrypted data by means of a constrained application (82) constrained by the sandbox application (76). Computersoftware zum Schützen eines Computersystems (72) gegen potenziell schädliche ankommende Daten (62), die von einer externen Quelle (60) empfangen werden, wobei die Computersoftware dazu eingerichtet ist, einen Haupt-Desktop (200) bereitzustellen, der eine Entschlüsselungssoftware zum Entschlüsseln von Daten und eine Sandbox-Anwendung (76) enthält, die Daten empfängt und einen Sandbox-Desktop definiert, dadurch gekennzeichnet, dass die Computersoftware dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es: a) harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) unterscheidet und die potenziell schädlichen ankommenden Daten (66) verschlüsselt, um sie in harmlose verschlüsselte Daten (70) umzuwandeln,b) ankommende Daten (65), die als harmlos unterschieden wurden, in unverschlüsselter Form für die Verarbeitung durch eine Haupt-Desktop-Anwendung (78) verfügbar macht,c) die verschlüsselten Daten (70) entschlüsselt, um sie in entschlüsselte Daten umzuwandeln, undd) die entschlüsselten Daten durch eine eingegrenzte Anwendung (82) verarbeitet, die durch die Sandbox-Anwendung (76) eingegrenzt ist. Logiciel informatique pour protéger un système informatique (72) contre des données entrantes potentiellement dangereuses (62) reçues d'une source externe (60), le logiciel informatique étant disposé pour fournir un bureau principal (200) et comprenant un logiciel de décryptage pour décrypter des données et une application de type bac à sable (76) pour recevoir des données et définir un bureau de type bac à sable, caractérisé en ce que le logiciel informatique est disposé pour commander le système informatique (72) pour : a) distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) et crypter les données entrantes potentiellement dangereuses (66) pour les transformer en données cryptées sans danger (70),b) rendre les données entrantes (65) distinguées comme dangereuses disponibles dans une forme non-cryptée pour le traitement au moyen d'une application de bureau principal (78),c) décrypter les données cryptées (70) pour les transformer en données décryptées, etd) traiter les données décryptées au moyen d'une application forcée (82) forcée par l'application de type bac à sable (76).
  27. 27
    Computer software according to Claim 26 characterised in that it is arranged to control the computer system (72) to distinguish harmless incoming data (65) from potentially harmful incoming data (66) and encrypt the potentially harmful incoming data (66) by:a) checking incoming data (62) to distinguish harmless incoming data (65) from potentially harmful incoming data (66),b) passing on incoming data (65) distinguished to be harmless for processing with the main desktop application (78), andc) encrypting incoming data (66) distinguished to be potentially harmful. Computersoftware nach Anspruch 26, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) unterscheidet und potenziell schädliche ankommende Daten (66) verschlüsselt, indem es: a) ankommende Daten (62) überprüft, um harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) zu unterscheiden,b) ankommende Daten (65), die als harmlos für die Verarbeitung durch die Haupt-Desktop-Anwendung (78) unterschieden wurden, weiterleitet, undc) ankommende Daten (66), die als potenziell schädlich unterschieden wurden, verschlüsselt.2 Logiciel informatique selon la revendication 26, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) et crypter les données entrantes potentiellement dangereuses (66) par : a) la vérification de données entrantes (62) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66),b) le passage sur les données entrantes (65) distinguées être sans danger pour le traitement avec l'application de bureau principal (78), etc) le cryptage des données entrantes (66) distinguées être potentiellement dangereuses.
  28. 28
    Computer software according to Claim 26 or 27 characterised in that the constrained application (82) is arranged not to communicate directly with any application (78) associated with a main desktop (200) of the computer system (72). Computersoftware nach Anspruch 26 oder 27, dadurch gekennzeichnet, dass die eingegrenzte Anwendung (82) dazu eingerichtet ist, nicht direkt mit irgendeiner Anwendung (78) zu kommunizieren, die zu einem Haupt-Desktop (200) des Computersystem (72) gehört. Logiciel informatique selon la revendication 26 ou 27, caractérisé en ce que l'application forcée (82) est disposée pour ne pas communiquer directement avec une application quelconque (78) associée à un bureau principal (200) du système informatique (72).
  29. 29
    Computer software according to Claim 26, 27 or 28 characterised in that it is arranged to control the computer system (72) to retrieve data from the sandbox application (76) in encrypted form for relaying to expert inspection (90). Computersoftware nach Anspruch 26, 27 oder 28, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es Daten aus der Sandbox-Anwendung (76) in verschlüsselter Form abruft, um sie zur Untersuchung durch Experten (90) weiterzuleiten. Logiciel informatique selon la revendication 26, 27 ou 28, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour récupérer les données à partir de l'application de type bac à sable (76) dans une forme cryptée pour relayer à l'inspection d'expert (90).
  30. 30
    Computer software according to any one of Claims 26 to 29 characterised in that it is arranged to control the computer system (72) to check decrypted data released from the sandbox desktop (76) for potentially harmful content. Computersoftware nach einem der Ansprüche 26 bis 29, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es entschlüsselte Daten, die aus dem Sandbox-Desktop (76) abgerufen wurden, auf potenziell schädlichen Inhalt hin überprüft. Logiciel informatique selon l'une quelconque des revendications 26 à 29, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour vérifier les données décryptées délivrées du bureau de type bac à sable (76) pour un contenu potentiellement dangereux.
  31. 31
    Computer software according to any one of Claims 26 to 30 characterised in that it is arranged to control the computer system (72) to distinguish harmless incoming data (65) from potentially harmful incoming data (66) by decomposing incoming data into individual data parts such as for example a message body and attachment, and selecting successive data parts for checking (146). Computersoftware nach einem der Ansprüche 26 bis 30, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) unterscheidet, indem es ankommenden Daten in einzelne Datenteile zerlegt, wie etwa zum Beispiel einen Body und einen Anhang einer Nachricht, und aufeinanderfolgende Datenteile zur Überprüfung (146) auswählt. Logiciel informatique selon l'une quelconque des revendications 26 à 30, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) en décomposant des données entrantes en parties de données individuelles telles que par exemple un corps de message et une pièce jointe, et en sélectionnant des parties de données successives pour la vérification (146).
  32. 32
    Computer software according to Claim 31 characterised in that it is arranged to control the computer system (72) to distinguish harmless incoming data (65) from potentially harmful incoming data (66) by a process which includes encrypting (158) a data part which has not been verified to be harmless (154) and replacing that data part by the encrypted data part. Computersoftware nach Anspruch 31, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) durch einen Prozess unterscheidet, der die Verschlüsselung (158) eines Datenteils, der nicht als harmlos (154) verifiziert worden ist, und das Ersetzen dieses Datenteils durch den verschlüsselten Datenteil enthält. Logiciel informatique selon la revendication 31, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) par un traitement qui comprend le cryptage (158) d'une partie de données qui n'a pas été vérifiée être sans danger (154) et remplacer cette partie de données par la partie de données cryptées.
  33. 33
    Computer software according to Claim 32 characterised in that it is arranged to control the computer system (72) to distinguish harmless incoming data (65) from potentially harmful incoming data (66) by a process which includes:a) abandoning (152) processing of an item of incoming data if it contains a data part which is found (148) to contain dangerous code, andb) providing (156) a partially encrypted and partially non-encrypted item of incoming data if a last data part in the item of incoming data has been processed, processing not having been abandoned (152) prior to that. Computersoftware nach Anspruch 32, dadurch gekennzeichnet, dass sie dazu eingerichtet ist, das Computersystem (72) derart zu steuern, dass es harmlose ankommende Daten (65) von potenziell schädlichen ankommenden Daten (66) durch einen Prozess unterscheidet, der folgendes enthält: a) Abbrechen (152) der Verarbeitung eines Abschnitts von ankommenden Daten, wenn er einen Datenteil enthält, für den festgestellt wird (148), dass er gefährlichen Code enthält, undb) Bereitstellen (156) eines teilweise verschlüsselten und teilweise nicht verschlüsselten Abschnitts von ankommenden Daten, wenn ein letzter Datenteil in dem Abschnitt von ankommenden Daten verarbeitet worden ist, wobei die Verarbeitung davor nicht abgebrochen worden ist (152). Logiciel informatique selon la revendication 32, caractérisé en ce qu'il est disposé pour commander le système informatique (72) pour distinguer des données entrantes sans danger (65) de données entrantes potentiellement dangereuses (66) par un traitement qui comprend : a) l'abandon (152) du traitement d'un élément de données entrantes s'il contient une partie de données qui est trouvée (148) contenir un code dangereux, etb) la fourniture (156) d'un élément partiellement crypté et partiellement non-crypté de données entrantes si une dernière partie de données dans l'élément de données entrantes a été traitée, le traitement n'ayant pas été abandonné (152) avant cela.
Independent claims33