Method and device for gaining access to computer resources through fire wall
Abstract
protective means such as fire walls isolating computer and network resources residing behind fire walls from networks, computers, and application programs beyond the latter. SUBSTANCE: internal resources are usually private data bases and local computer networks; peripheral objects are users and computer application programs operating in public communication networks such as Internet. Fire wall usually enables internal users and objects to establish communication with peripheral objects or networks but makes it impossible to do so in reverse direction, that is, from outside. Novelty is introduction of tunneling system enabling communication either side of fire wall from outside upon request for said communication from authorized persons, users, objects, or computer application programs residing beyond fire wall. Provision is made for minimizing number of resources engaged in establishing such tunnel connections (that is, communications through fire wall upon request of peripherals) and for minimizing risk of unauthorized intervention through fire wall. Method and device use application programs executed by means of interface servers mounted behind and beyond fire wall; they also use special table of authorized sockets whose generation and operation is conducted by internal application program for tunneling. Items of said table of authorized sockets determine objects residing behind fire wall and identify special internal port, data transmission protocol used for each port, and host object coupled with each port. EFFECT: provision for establishing communications either side of fire wall on request of authorized objects or users. 6 cl, 6 dwg
Term
Term ended
Expired 2 October 2017, 9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
6 claims: 6 independent, 0 dependent
- 1A system for tunneling data network having a firewall (1), which separates the inner and outer zone and forms a protective barrier to retrieve the object from the outer zone of direct access to the objects in the inner zone and simultaneously allows the object of the inner zone directly to request and obtain access to the objects in the outer zone, and having an external interface computer (3) located in the outer zone and providing interaction between the firewall (1) and objects in the outer zone, inside interface computer (2) located in the inner zone and providing interaction between the firewall (1) and objects in the inner zone, means provided on the external and the internal interface computer and enables identification of trusted objects in the inner zone, which allow access from the outer zone, means provided on the external interface computer and operates in response to request sent by an object from the outer zone, as well as interacting with these means of ensuring the identification, for checking, addressed whether the said request to one of the trusted sites and, in the case of a positive test result, to forward the query back-end computer, and means provided on the external and the internal interface computer and operates in response to the request, addressed to one of the trusted entity to establish a connection for data transmission between the proxy object and an external object, send the appropriate request, and those portions of the data connection which are located in the inner zone and pass through the firewall are formed under the exclusive control of the internal interface of the computer and the portion of said data connection, which extends from the outside interface computer to the object that sent the request is formed under control of the external interface of the computer with on the domestic front-end computer means are provided to establish and maintain their own control connection to an external computer interface, which is used for transmitting a request from the external interface to the internal computer interface computer. 1. Система туннелирования для сети передачи данных, имеющая брандмауэр (1), который разделяет внешнюю и внутреннюю зоны и образует защитный барьер, препятствующий получению объектами из внешней зоны прямого доступа к объектам во внутренней зоне и одновременно позволяющий объектам из внутренней зоны напрямую запрашивать и получать доступ к объектам во внешней зоне, и имеющая внешний интерфейсный компьютер (3), расположенный во внешней зоне и обеспечивающий взаимодействие между брандмауэром (1) и объектами во внешней зоне, внутренний интерфейсный компьютер (2), расположенный во внутренней зоне и обеспечивающий взаимодействие между брандмауэром (1) и объектами во внутренней зоне, средства, предусмотренные и на внешнем, и на внутреннем интерфейсных компьютерах и обеспечивающие идентификацию доверенных объектов во внутренней зоне, к которым разрешен доступ из внешней зоны, средства, предусмотренные на внешнем интерфейсном компьютере и срабатывающие в ответ на запрос, посланный от объекта из внешней зоны, а также взаимодействующие с указанными средствами, обеспечивающими идентификацию, для проверки, адресован ли указанный запрос к одному из доверенных объектов и, в случае положительного результата проверки, для пересылки этого запроса внутреннему интерфейсному компьютеру, и средства, предусмотренные и на внешнем, и на внутреннем интерфейсных компьютерах и срабатывающие в ответ на указанный запрос, адресованный одному из доверенных объектов, для установления соединения для передачи данных между этим доверенным объектом и внешним объектом, пославшим соответствующий запрос, причем те участки этого соединения для передачи данных, которые расположены во внутренней зоне и проходят через брандмауэр, формируются исключительно под управлением внутреннего интерфейсного компьютера, а тот участок указанного соединения для передачи данных, который проходит от внешнего интерфейсного компьютера к объекту, пославшему запрос, формируется под управлением этого внешнего интерфейсного компьютера, при этом на внутреннем интерфейсном компьютере предусмотрены средства для установления и поддержания собственного управляющего соединения с внешним интерфейсным компьютером, которое используется для передачи запроса от внешнего интерфейсного компьютера к внутреннему интерфейсному компьютеру.
- 2The system of claim. 1, characterized in that said means provided on the internal and external interfaces computers and provides identification of the trusted object, have the means to create and maintain a table with a list of these trusted sites, means for transferring a copy of this table through the firewall ( 1) an external interface computer (3), and means provided on the external interface computer for storing a copy of the table and the facing. 2. Система по п. 1, отличающаяся тем, что указанные средства, предусмотренные на внутреннем и внешнем интерфейсных компьютерах и обеспечивающие идентификацию доверенного объекта, имеют средства для создания и ведения таблицы со списком указанных доверенных объектов, средства для передачи копии этой таблицы через брандмауэр (1) на внешний интерфейсный компьютер (3) и средства, предусмотренные на внешнем интерфейсном компьютере для хранения копии этой таблицы и обращения к ней.
- 3The system of claim. 2, characterized in that each element (30) in said table of trusted objects list consists of a first group unit data identifying an object in the inner area of the second elementary group data identifying a data port corresponding highlighted object, and a third unit of data groups defining the communication protocol to be used for transmitting data through said port. 3. Система по п. 2, отличающаяся тем, что каждый элемент (30) в указанной таблице со списком доверенных объектов состоит из первой элементарной группы данных, идентифицирующих объект во внутренней зоне, из второй элементарной группы данных, идентифицирующих порт передачи данных, выделенный соответствующему объекту, и из третьей элементарной группы данных, определяющей протокол передачи данных, который должен использоваться для передачи данных через указанный порт.
- 4The system of claim. 1, characterized in that the external and internal areas are respectively external and internal data network, and the internal and external interface computers are servers installed respectively between the firewall and nodes of internal and external networks. 4. Система по п. 1, отличающаяся тем, что во внешних и внутренних зонах имеются соответственно внешняя и внутренняя сети передачи данных, а внутренний и внешний интерфейсные компьютеры представляют собой серверы, установленные соответственно между брандмауэром и узлами этих внутренней и внешней сетей.
- 5tunneling device serving to provide the data objects that are outside the firewall capabilities establish a data connection with the data objects that are inside the firewall, and comprising inner and outer components designed to run on computers located respectively inside and outside the firewall and are used for communication between the firewall and the specified objects located respectively inside and outside the firewall, and the inner component includes controls internal computer to create and maintain a table of internal trusted sites and tools to manage internal computer and a firewall to provide copies of the Table external component, and also includes means for establishing and maintaining its own control connection with an external component, which is used for transmission from the external component, an internal component of a request sent from an object located in the external component. 5. Устройство туннелирования, служащее для предоставления объектам обработки данных, которые находятся вне брандмауэра, возможности устанавливать соединения для передачи данных с теми объектами обработки данных, которые находятся внутри брандмауэра, и содержащее внутренние и внешние компоненты, предназначенные для выполнения на компьютерах, которые расположены соответственно внутри и вне брандмауэра и служат для взаимодействия между брандмауэром и указанными объектами, находящимися соответственно внутри и вне брандмауэра, при этом внутренний компонент включает средства управления внутренним компьютером по созданию и ведению таблицы внутренних доверенных объектов и средства для управления внутренним компьютером и брандмауэром по предоставлению копии этой таблицы внешнему компоненту, а также включает средства для установления и поддержания собственного управляющего соединения с внешним компонентом, которое используется для передачи от внешнего компонента внутреннему компоненту запроса, посланного от объекта, находящегося в этом внешнем компоненте.
- 6The method of objects that are outside the firewall (1) protecting the computer system against unauthorized access, the ability to install intended for data connections to selected objects, located inside the firewall, which consists in the fact that they create and maintain a table of selected objects inside the firewall (1), each element (30) which is composed of data items that identify the corresponding selected object identifying data port, dedicated to this project, and determine the data transfer protocol to be used to transmit data via this port in the area, located outside the firewall, transmit a copy of the specified table, external objects having a specific access to protected information, provide access to data items constituting element of said table corresponding to external objects are granted the right to send requests to access the elements identifying the selected object that identifies the transmission port data and determines the type of data transfer protocol and formed data items allocated to these external objects, and the use of computer systems within and outside the firewall, set designed for a data connection between a specific internal object specified in the request, and an external object, who sent this request, and those portions of the data connections that are inside the firewall and pass therethrough, are formed exclusively under the control of a computer system inside the firewall, while using a computer system inside the firewall establishes and maintains its own control connection to located outside the firewall computer system which is used to transfer requests from the computer system, located outside the firewall, to the computer system inside the firewall. 6. Способ предоставления объектам, которые находятся вне брандмауэра (1), защищающего компьютерную систему от несанкционированного доступа, возможности устанавливать предназначенные для передачи данных соединения с выбранными объектами, находящимися внутри этого брандмауэра, заключающийся в том, что создают и ведут таблицу выбранных объектов внутри брандмауэра (1), каждый элемент (30) которой состоит из элементарных групп данных, идентифицирующих соответствующий выбранный объект, идентифицирующих порт передачи данных, выделенный этому объекту, и определяющих протокол передачи данных, который должен использоваться для передачи данных через этот порт, в зону, находящуюся вне брандмауэра, передают копию указанной таблицы, внешним объектам, имеющим определенный допуск к защищенной информации, предоставляют доступ к элементарным группам данных, образующим элемент указанной таблицы, соответствующим внешним объектам предоставляют право посылать запросы для получения доступа к элементу, идентифицирующему выбранный объект, идентифицирующему порт передачи данных и определяющему тип протокола передачи данных и образованному элементарными группами данных, выделенными этим внешним объектам, и с использованием компьютерных систем, находящихся внутри и вне брандмауэра, устанавливают предназначенное для передачи данных соединение между конкретным внутренним объектом, указанным в запросе, и внешним объектом, пославшим этот запрос, причем те участки этого соединения для передачи данных, которые находятся внутри брандмауэра и проходят через него, формируют исключительно под управлением компьютерной системы, находящейся внутри брандмауэра, при этом с помощью компьютерной системы, находящейся внутри брандмауэра, устанавливают и поддерживают собственное управляющее соединение с находящейся вне брандмауэра компьютерной системой, которое используют для передачи запросов от компьютерной системы, находящейся вне брандмауэра, к компьютерной системе, находящейся внутри брандмауэра.
Independent claims6
32 paragraphs, as filed
The invention relates to gain access to the resources of a computer system, or computer (computer) network, which is protected by a firewall, in response to requests from objects located outside the firewall.
The computer hardware is called a firewall protection system (implemented in software and / or hardware), which separates the inner area from the outer area to isolate the resources of a computer system or computer network from unauthorized access by objects that are outside the firewall. Thus, isolated resources are resources inside the firewall (m. E. In the inner zone), and external equipment is considered as being outside the firewall (m. E. The outer zone). Typically, the firewall serves as a protective "fence" or "barrier" preventing access to private local area networks (LANs), which combines a number of computers and interact with peripherals.
The basic principle of the firewall is that it allows internal objects requests a connection and communicate with external objects (eg, internal applications to access external gateway communication centers and so on. F.), But does not allow external objects produce similar operations for connection internal objects.
Often, however, are outside the firewall objects need to access internal resources behind the firewall, and obtaining such access should not lead to a complete shutdown of protective firewall features. For example, the company owner behind firewalls resources may find it useful to allow access to these resources through external public network (eg, via telephone communication network or via the telephone network in conjunction with the access points to the Internet, and so on. N.) The its employees, who are currently far from the place of work (eg, at home, on a business trip or on vacation). In this case, there is a need to provide such a "trusted" or "authorized" persons entitled to access from outside to being inside the firewall resources (for example, to personal databases manager and so on. N.).
Until recently, such access, in response to an external request can be ensured either duplicate servers and database stores, placing them inside and outside the firewall, or by using other arrangements of the respective equipment, which increases the cost significantly the overall cost of operation of the firewall. It should also be noted, for example, the cost of such duplication or development and implementation of other technologies in the case of having a large volume and frequently updated databases stored inside the firewall. In Cheswik and Bellovin in "Firewalls and Internet Security, Repelling the Willy Hacker", publishing house Addison-Wesley Publishing Company, April 1994, pp. 86-106, discusses the various types of protection firewall. The present invention allows to obtain the desired outside access to internal objects or resources behind the firewall without requiring duplication outside the firewall.
Objects of the present invention is the system tunneling method and corresponding software which are specified in independent claims and preferred embodiments are given in the dependent claims.
In accordance with the invention, inside and outside the firewall are provided means for sharing a so-called "tunneling" (where, similar to the tunnel effect, the request must be "overcome" the firewall), which lies in the fact that, in response to requests of a certain type sent by objects, located outside the firewall between the external objects and resources inside the firewall to connect. A distinctive feature of the established way of compounds is that they are formed "from within", as if the requests for their establishment came from objects located inside the firewall, and were addressed to objects outside the firewall.
"Request for a certain type of" used specified means "tunneling" is a request addressed to the so-called "trusted sites", which may be a hardware ports such as the so-called "trusted sockets" ("trusted nests") and so on. N. Trusted facilities, in particular the trusted sockets, are the elements of the corresponding table of trusted objects, in particular the trusted sockets table, the creation and maintenance which is carried out exclusively inside the firewall. Each entry in this table contains the address of "trusted" port, protocol (for example, data transfer protocol, such as TCP / IP (Transmission Control Protocol / Internet Protocol), NNTP (Network News Transfer Protocol), and so on. N.) Associated with this address, and the ID of the host object, inside the firewall (for example, host computer, or the main application). Thus, to people and / or objects outside the firewall, could send such a request, they should be provided with information on the reliability of the moment a trusted entity, such as a trusted socket.
Creating and maintaining a table of trusted objects, in particular a trusted socket carries a so-called "application tunneling" that is installed and runs on the internal front-end server (under the control of authorized persons having direct access to the server) provides the interface between the "application tunneling "and all other" accessible "objects / resources inside the firewall (including other applications, installed and running on this internal interface server). This back-end server also sets the "control connection" (or "service connection") to the outside interface server that provides the interface between the firewall and all other objects located outside the firewall. Access to the control connection has only application tunneling, installed on the internal front-end server, and the corresponding application tunneling installed on the external front-end server, t. E. To the control connection does not have direct access to any other application installed and running on this front-end servers and have no access all other indoor and outdoor facilities are not residents of these servers.
A copy of the table of trusted objects, in particular trusted sockets is transmitted from the back-end server to the external interface server, and this table can be transmitted, for example, in the case of creating a new table and / or the modification of an existing table or to bind the transfer table to a particular time of day etc.
When an external object that is not currently connected to internal resources through the firewall, forwards the request to the external front-end server, application tunneling, installed on the server must determine addressed whether this request correct at the moment the element table of trusted objects, in particular trusted sockets. If the request is addressed incorrectly, it is ignored. If the request is addressed to a trusted statistically significant object, in particular a trusted socket, it is transmitted over the control connection tunneling application installed on the internal front-end server. At the same time the external front-end server generates a process (or task) that is associated with this request, and between this process / task and the requesting entity is established.
Upon receipt of the request internal application tunneling (t. E. Be installed on the internal front-end server) can also check addressed if the request is correct at the time of a trusted entity, such as a trusted socket, and ignore it in the event that the results of this test will It determined that the request is correctly. If the check is determined to be correct at the request addressed to the moment a trusted entity, such as a trusted socket, internal application tunneling generates (or "breeds") process within the firewall corresponding to the request. Then, the internal application of tunneling a) establishes a connection between the inner resource that corresponds to the above-described object, respectively the port (socket) and specified for the host object identifier "requested" item in the table of trusted objects, in particular a trusted socket and the internal front-end server and used ) communicates on the control connection to an external application for tunneling and with a computer that controls the firewall itself, and establishes a connection through the firewall between the tasks created / generated on the domestic and on the external front end servers. The compounds formed by internal and external applications of tunneling, in no way connected to the control connection and have been used for direct bi-directional data exchange (usually in the form of packets, the format of which is determined by the communication protocol selected for this proxy object, in particular a trusted socket) between the outer object that sent the request, and the inner lens, which is addressed to this request.
In accordance with a preferred embodiment of the invention, the tunneling software stored on the media data in machine-readable form allows the data objects that are outside a firewall to establish data connection with the data objects that are inside the firewall. Wherein said software includes the inner and outer parts of the program, designed to run on computers that are located respectively inside and outside the firewall, and which enable communication between the firewall and the objects located respectively inside and outside the firewall. In addition, the inner part of the program includes an internal computer controls for creating and maintaining the internal table of trusted objects and tools to manage internal computer in conjunction with a firewall to provide a copy of this table, the outer part of the program. In addition, the inner part of the program includes funds to establish and maintain control of their own connection to the external part of the program, which is used to transmit a request sent from the located in the outer part of the program object from the outer part of the program in its interior.
These and other features, advantages, aims and objectives of the present invention are discussed below in more detail in the following description and in the claims presented.
The invention is explained in more detail with reference to the accompanying drawings, in which: FIG. 1 - schematic diagram of a typical firewall configuration, which can be used the present invention, FIG. 2 - block diagram describing the creation and management of the trusted sockets table, FIG. 3 - a block diagram illustrating an inventive method for tunneling through a firewall in FIG. 4 - a preferred version of the organization and trusted sockets table in FIG. 5 - a block diagram detailing the operations performed in accordance with the present invention located inside and outside the firewall tunneling applications.
FIG. 1 schematically shows the configuration of a typical firewall, which may be implemented the present invention. In this system, the protection of the computer 1 functions as a firewall, working on existing conventional algorithms. This computer, in addition to establishing and maintaining the connection between internal objects, t. E. Located inside the firewall, and external objects, t. E. Located outside the firewall, perform other routine functions (in principle not critical to the present invention). Interface servers 2 and 3 (indicated in the drawing as a server A and server B respectively) operate respectively inside and outside the firewall, formed by computer 1. The server A is an interface that provides communication between the firewall and objects inside the firewall (software applications, hardware components, and so on. n.), including the objects of the server A. The server provides an interface that provides communication between the firewall and objects outside the firewall, including objects of the server B.
In conventional firewall configuration server A is connected to a network inside the firewall (e.g. a private local area network) via a connection, indicated at 4, and server B through a connection indicated at 5 is connected to an external network, ie. E. To the standing outside the network firewall ( such as the Internet).
With regard to the configuration of the present invention is provided on the server A and special software - the so-called application of "tunneling", and these servers are also stored copy of the table of "trusted sites", which may be a hardware ports such as the so-called "trusted Sockets Layer "(" trusted nests "). In the following description of the table as a trusted entity is considered a special case - the trusted sockets table. Such "tunneling application" and "table of trusted objects", in particular "trusted socket table" is a distinctive feature of the present invention and are described in more detail below.
FIG. 2 and 3 show processes (tunneling) implemented according to the present invention respectively on servers A and B.
As shown in FIG. 2, in step 10, server A creates a table of trusted sockets (which is described in more detail below with reference to FIG. 4) and then stores this table in its memory (or in any other memory that the server can handle directly). In the next step 11, server A to server B establishes a special so-called "control connection" (or "Call Connection") through the firewall (computer 1) and then transmits in step 12 on the control connection to the server in a copy of the trusted sockets table. This control connection, which is also part of the present invention uses the above-described applications of tunneling for effective exchange control (or service) information between the servers, and thus to establish other connections (hereafter referred to as a data connection) between locations inside and objects outside the firewall, in response to requests from external objects.
Those portions of the data connections that pass through the firewall, completely independent from the control connection that was used to create them, and they are always formed under the control of the processes performed inside the firewall. In order to allow the establishment of a data connection to the internal object in response to a request from an external object, this request should be compared with one of the elements of the trusted sockets table to check its validity. External demands (ie. E. Requests from external objects), which will be recognized as invalid are ignored, so the firewall and protected their domestic resources remain invisible and inaccessible to the outside of the requesting party, contained in the request on which the information is recognized as unreliable. Conversely, significant questions can only come from those authorized persons who have information about significant to date elements trusted sockets table (such a person may, for example, an employee carries out remote access to resources owned by its manager, and so on. N .).
FIG. 3 shows the tunneling operations performed on servers A and B, upon receipt of a copy of the server in the trusted sockets table from server A.
In step 20, the server B (in particular, the application of tunneling on the server) is idle external demand, which is caused when you receive the team at tunneling, t. E. The establishment of a data connection between the internal "host" -Moving specified in the request, and an external object, sent the request. Upon receipt of the request (step 21, Fig. 3) In the server (in particular its application tunneling) validates received requests (section 22 decision, Fig. 3). With regard to the last operation should be noted that the server B receives only the requests addressed directly to him, and application tunneling, available on a server in, accept only those requests that are clearly intended for transmission to the port inside the firewall, and recognizes such requests correct only in that case, if they are addressed to correct at the current element trusted sockets table.
If the request is invalid, it is ignored and the server B (t. E. The application installed on it for tunneling) resumes waiting for a request. If the request is valid, the server B (installed on the applications of tunneling) generates a process or task "B. 1" for the management of the external system components, intended for communication with the requesting entity (step 23, Fig. 3). Problem B. 1 sets adapted for a data connection between itself and the requesting object (also see. Step 23, FIG. 3) and sends on the control connection received from an external object request to server A (or a tunneling application at), and transmits an indication that the request relates to task B. 1 (step 24, FIG. 3).
Upon receipt of the request, which confirmed the reliability of the server A (or its application tunneling) forms (generates) the process or task management A. I internal system components designed for data exchange between the external object that made the request, and the host object specified in the request (step 25, Fig. 3; the latter of these objects must be an element specified in the trusted sockets table, as described above). Problem A. 1 generates plot of a data connection between the host and target computer firewall (also see. Step 25, Fig. 3), and instructs the firewall computer to connect to task B. 1 (see also. Step 25 , Fig. 3), thus completing the process of establishing the data connection between the inside host object and the outside object that sent the request. Note that when setting-described data connection to servers A and B and a computer firewall may need to provide the buffers, the capacity of which is determined by the communication protocol (described in more detail below) and the requirements of this protocol for the transmission rate (in particular packets).
The structure of the trusted sockets table is shown in Fig. 4. The figure shows as an example two specific elements of the table indicated by reference numeral 30, and its other elements, indicated by reference numeral 31, shown by a dotted line extending downwardly from the second element. Each table entry contains a port number, information describing the data transfer protocol (as which typically use a protocol packet), and information identifying a host object. The port number is the address inside the firewall, assigned by the host object. Examples of data transfer protocols for the first two items in the table indicates the NNTP-protocol (from the English. "Network News Transport Protocol", Network News Transfer Protocol) and HTTP (from the English. "HyperText Transport Protocol", the Hypertext Transfer Protocol).
FIG. 5 shows in greater detail the operations performed by tunneling applications on front end servers A and B. The operations are identical to those of FIG. 2 and 3, the same numerals. Operations also that are part of any operation or in a suit against it differs from them in FIG. 2 and 3 are given the same numerals, but with the addition of certain letters (a, b and t. D.). All other operations have not been used previously marked positions.
Operation 10a, running on server A, and is a combination of operations, 10 and 12 of FIG. 2, is to create and update (expansion, modification, and so on. N.) The trusted sockets table and copy it to the server B. Operation 11a running on the server, which is an operation on the primary or (as described below) re-establishment of control connection between servers A and B (or tunneling applications). The need to re-establish the control connection arises in case of an unexpected interruption, and the operations that detect such an interruption of communication and respond to it are indicated in FIG. 5 positions 46-48 (in more detail, these operations are described below).
After receiving a copy of the trusted sockets table in the server (or its application tunneling) enters standby mode external requests (step 20, Fig. 5). Upon receipt of a valid request for an external tunneling and after the formation of the corresponding data processing tasks (eg, Problem B. 1, Fig. 3) pertaining to this request (steps 21-22a, 24a, FIG. 5), the server B transmits to the server And the resulting query (step 23a, FIG. 5), as well as control signals to indicate receipt of the request, and information identifying the problem (eg, B. 1), which is formed on the server B in response to the request. Then the server B expects the server A confirmation of acceptance of the request (steps 23b, 23c, FIG. 5), upon which the server B establishes a connection for data transmission at the site of the newly formed task - the requesting entity B (step 24b, FIG. 5, for example from B. 1 - object C, as shown in FIG. 3). Then the server B waits for establishment of a data connection on site from the firewall to the task that has just been created on the server B (step 24c, FIG. 5), which means establishing a connection on the section between the host object (the identifier of which is contained in the query ) and server B. This tunneling connection to the server in the final until the termination of a data connection on the section between the firewall and the tasks performed on the server B (step 40, FIG. 5), and server B's site to establish and maintain this compound, as well as the corresponding request processing ends (step 41, FIG. 5).
The following are the tunneling operations performed by the server A. After establishing or re-establishing the control connection server A goes into standby mode signals (forward the request) from the server (step 46, Fig. 5). If such a signal is not received (step 47, FIG. 5), but the specified timeout period, counted from the date of transition to the standby mode, has not yet expired (block 48 decision, Fig. 5) A server continues to wait for the signal. If the specified timeout (which corresponds to the choice of "Yes" in block 48 decision, Fig. 5), the server said A control connection (suddenly) is interrupted, and it is therefore necessary to re-establish (step 11a repeats).
Upon receiving a request from the server A to the server can independently verify the accuracy of the request (step 49, FIG. 5), which, however, is not obligatory operation to determine whether the request is addressed to the confidence in the current trusted socket. In the case of such optional operations and in case of recognition of the wrong query back to the server B will be transmitted error signal, and the acknowledgment signal is not expected to step 23b. If the optional step is not used, or it is used and the request is deemed valid, server A proceeds to the formation of its own internal problems, such as A. 1, which, as described above, designed to establish a data connection in the area from the host facility to the firewall, and then instructs the firewall computer to set for transferring data on the connection portion to the task B. 1 (step 50, FIG. 5). At the server A terminates its participation in the process of handling the current request, and may go to sleep and processing other requests (step 51, FIG. 5).
Software The foregoing tunneling applications can be delivered as a software product to "machine-readable", for example, in standard media or through communication networks. It is obvious that such program can be distributed either in a single software package (for example, for installation on an internal server A with the subsequent transfer - completely or partially - the server B), or as two separate packages (or pieces), each of which is designed for separate installation of internal and external servers. It should also be noted that the firewall computer is a necessary component in the establishment of a data connection through a firewall type of security system.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7882251B2 | Cited by | United States of America | Applicant |
| US8918525B2 | Cited by | United States of America | Applicant |
| US8266294B2 | Cited by | United States of America | Applicant |
| WO2008136786A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
27 members in 17 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 73180096 | United States of America | A | |
| 73180096 | United States of America | A | |
| 08731800 | – | – | – |
| US19960731800 | – | – | – |
Members27
| Document | Office | Kind | |
|---|---|---|---|
| CA2269544A1 | Canada | A1 | |
| WO9818248A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN1180871A | China | A | |
| TW362177B | Taiwan Province of China | B | |
| BR9705094A | Brazil | A | |
| EP0932965A1 | European Patent Office (EPO) | A1 | |
| CZ138799A3 | Czechia | A3 | |
| US5944823A | United States of America | A | |
| PL332828A1 | Poland | A1 | |
| BR9712635A | Brazil | A | |
| JP2000505270A | Japan | A | |
| US6061797A | United States of America | A | |
| HUP0000336A2 | Hungary | A2 | |
| KR20000048930A | Republic of Korea | A | |
| HUP0000336A3 | Hungary | A3 | |
| RU2178583C2This record | Russian Federation | C2 | |
| KR100330619B1 | Republic of Korea | B1 | |
| JP3285882B2 | Japan | B2 | |
| CN1107400C | China | C | |
| EP0932965B1 | European Patent Office (EPO) | B1 | |
| CA2269544C | Canada | C | |
| ATE285151T1 | Austria | T1 | |
| DE69731965D1 | Germany | D1 | |
| ES2231895T3 | Spain | T3 | |
| CZ295858B6 | Czechia | B6 | |
| DE69731965T2 | Germany | T2 | |
| MY127656A | Malaysia | A |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A | |
| Official registration of the transfer of exclusive rightPC41 | PC41 |
Numbers
- Publication, DOCDB
- 2178583
- Publication, EPODOC
- RU2178583
- Application
- 9910996809
- Application, DOCDB
- 99109968
- Application, EPODOC
- RU19990109968
Titles
- English
- METHOD AND DEVICE FOR GAINING ACCESS TO COMPUTER RESOURCES THROUGH FIRE WALL
Classification
- CPC, 3
- H04L63/0272
- H04L63/029
- H04L9/40
- IPC, 6
- G06F12 14
- G06F13 36
- H04L12 56
- G06F13 00
- H04L12 66
- H04L29 06