EP2035948B1

Unidirectional secure links from and to a security engine

Abstract

This record has no abstract on file.

EP2035948B1, drawing sheet 1
Sheet 1 of 3

Term

0.3 yearsleft in the term

Expires 28 December 2026.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 2 independent, 13 dependent

  1. 1
    A method for secure communications between a transmitting computer (24) and a receiving computer (22), the method comprising:transmitting data from the transmitting computer (24) over a first link (28) to a data security engine (26);receiving and validating the data within the data security engine (26);and after validating the data, transmitting the data from the data security engine (24) to the receiving computer (22) over a second link (30), the method characterized in that : both the transmission from the transmitting computer (24) to the security engine (26) via the first link (28) and from the security engine (26) to the receiving computer (22) via the second link (30) are performed over one way links of a unidirectional transmission medium, which have no reverse path.
  2. 8
    The method of any of claims 1-7, wherein validating the data comprises determining that the data comprises invalid content and rejecting the invalid content.
  3. 10
    The method of any of claims 1-7, wherein validating the data comprises testing the data for malicious software.
  4. 11
    The method of any of claims 1-7, wherein the one-way links (28,30) comprise wire or optical links.
  5. 12
    The method of any of claims 1-7, wherein validating the data comprises authenticating a source of the data.
  6. 13
    System (20) for secure communications between a transmitting computer (24) and a receiving computer (22), the system comprising:a data security engine (26) having a transmit port (56) and a receive port (54) and operative to receive data at the receive port, to validate the data, and to output the data after being validated at the transmit port;a first link (28) operative to transmit the data from the transmitting computer (24) to the receive port of the data security engine (26);and a second link (30) operative to transmit the data from the transmit port of the data security engine (26) to the receiving computer (22), characterized in that : the first and second links (28,30) are one way links of a unidirectional transmission medium, which have no reverse path.