RU2178583C2

Method and device for gaining access to computer resources through fire wall

Abstract

protective means such as fire walls isolating computer and network resources residing behind fire walls from networks, computers, and application programs beyond the latter. SUBSTANCE: internal resources are usually private data bases and local computer networks; peripheral objects are users and computer application programs operating in public communication networks such as Internet. Fire wall usually enables internal users and objects to establish communication with peripheral objects or networks but makes it impossible to do so in reverse direction, that is, from outside. Novelty is introduction of tunneling system enabling communication either side of fire wall from outside upon request for said communication from authorized persons, users, objects, or computer application programs residing beyond fire wall. Provision is made for minimizing number of resources engaged in establishing such tunnel connections (that is, communications through fire wall upon request of peripherals) and for minimizing risk of unauthorized intervention through fire wall. Method and device use application programs executed by means of interface servers mounted behind and beyond fire wall; they also use special table of authorized sockets whose generation and operation is conducted by internal application program for tunneling. Items of said table of authorized sockets determine objects residing behind fire wall and identify special internal port, data transmission protocol used for each port, and host object coupled with each port. EFFECT: provision for establishing communications either side of fire wall on request of authorized objects or users. 6 cl, 6 dwg

Term

Term ended

Expired 2 October 2017, 9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

6 claims: 6 independent, 0 dependent

  1. 1
    A system for tunneling data network having a firewall (1), which separates the inner and outer zone and forms a protective barrier to retrieve the object from the outer zone of direct access to the objects in the inner zone and simultaneously allows the object of the inner zone directly to request and obtain access to the objects in the outer zone, and having an external interface computer (3) located in the outer zone and providing interaction between the firewall (1) and objects in the outer zone, inside interface computer (2) located in the inner zone and providing interaction between the firewall (1) and objects in the inner zone, means provided on the external and the internal interface computer and enables identification of trusted objects in the inner zone, which allow access from the outer zone, means provided on the external interface computer and operates in response to request sent by an object from the outer zone, as well as interacting with these means of ensuring the identification, for checking, addressed whether the said request to one of the trusted sites and, in the case of a positive test result, to forward the query back-end computer, and means provided on the external and the internal interface computer and operates in response to the request, addressed to one of the trusted entity to establish a connection for data transmission between the proxy object and an external object, send the appropriate request, and those portions of the data connection which are located in the inner zone and pass through the firewall are formed under the exclusive control of the internal interface of the computer and the portion of said data connection, which extends from the outside interface computer to the object that sent the request is formed under control of the external interface of the computer with on the domestic front-end computer means are provided to establish and maintain their own control connection to an external computer interface, which is used for transmitting a request from the external interface to the internal computer interface computer. 1. Система туннелирования для сети передачи данных, имеющая брандмауэр (1), который разделяет внешнюю и внутреннюю зоны и образует защитный барьер, препятствующий получению объектами из внешней зоны прямого доступа к объектам во внутренней зоне и одновременно позволяющий объектам из внутренней зоны напрямую запрашивать и получать доступ к объектам во внешней зоне, и имеющая внешний интерфейсный компьютер (3), расположенный во внешней зоне и обеспечивающий взаимодействие между брандмауэром (1) и объектами во внешней зоне, внутренний интерфейсный компьютер (2), расположенный во внутренней зоне и обеспечивающий взаимодействие между брандмауэром (1) и объектами во внутренней зоне, средства, предусмотренные и на внешнем, и на внутреннем интерфейсных компьютерах и обеспечивающие идентификацию доверенных объектов во внутренней зоне, к которым разрешен доступ из внешней зоны, средства, предусмотренные на внешнем интерфейсном компьютере и срабатывающие в ответ на запрос, посланный от объекта из внешней зоны, а также взаимодействующие с указанными средствами, обеспечивающими идентификацию, для проверки, адресован ли указанный запрос к одному из доверенных объектов и, в случае положительного результата проверки, для пересылки этого запроса внутреннему интерфейсному компьютеру, и средства, предусмотренные и на внешнем, и на внутреннем интерфейсных компьютерах и срабатывающие в ответ на указанный запрос, адресованный одному из доверенных объектов, для установления соединения для передачи данных между этим доверенным объектом и внешним объектом, пославшим соответствующий запрос, причем те участки этого соединения для передачи данных, которые расположены во внутренней зоне и проходят через брандмауэр, формируются исключительно под управлением внутреннего интерфейсного компьютера, а тот участок указанного соединения для передачи данных, который проходит от внешнего интерфейсного компьютера к объекту, пославшему запрос, формируется под управлением этого внешнего интерфейсного компьютера, при этом на внутреннем интерфейсном компьютере предусмотрены средства для установления и поддержания собственного управляющего соединения с внешним интерфейсным компьютером, которое используется для передачи запроса от внешнего интерфейсного компьютера к внутреннему интерфейсному компьютеру.
  2. 2
    The system of claim. 1, characterized in that said means provided on the internal and external interfaces computers and provides identification of the trusted object, have the means to create and maintain a table with a list of these trusted sites, means for transferring a copy of this table through the firewall ( 1) an external interface computer (3), and means provided on the external interface computer for storing a copy of the table and the facing. 2. Система по п. 1, отличающаяся тем, что указанные средства, предусмотренные на внутреннем и внешнем интерфейсных компьютерах и обеспечивающие идентификацию доверенного объекта, имеют средства для создания и ведения таблицы со списком указанных доверенных объектов, средства для передачи копии этой таблицы через брандмауэр (1) на внешний интерфейсный компьютер (3) и средства, предусмотренные на внешнем интерфейсном компьютере для хранения копии этой таблицы и обращения к ней.
  3. 3
    The system of claim. 2, characterized in that each element (30) in said table of trusted objects list consists of a first group unit data identifying an object in the inner area of ​​the second elementary group data identifying a data port corresponding highlighted object, and a third unit of data groups defining the communication protocol to be used for transmitting data through said port. 3. Система по п. 2, отличающаяся тем, что каждый элемент (30) в указанной таблице со списком доверенных объектов состоит из первой элементарной группы данных, идентифицирующих объект во внутренней зоне, из второй элементарной группы данных, идентифицирующих порт передачи данных, выделенный соответствующему объекту, и из третьей элементарной группы данных, определяющей протокол передачи данных, который должен использоваться для передачи данных через указанный порт.
  4. 4
    The system of claim. 1, characterized in that the external and internal areas are respectively external and internal data network, and the internal and external interface computers are servers installed respectively between the firewall and nodes of internal and external networks. 4. Система по п. 1, отличающаяся тем, что во внешних и внутренних зонах имеются соответственно внешняя и внутренняя сети передачи данных, а внутренний и внешний интерфейсные компьютеры представляют собой серверы, установленные соответственно между брандмауэром и узлами этих внутренней и внешней сетей.
  5. 5
    tunneling device serving to provide the data objects that are outside the firewall capabilities establish a data connection with the data objects that are inside the firewall, and comprising inner and outer components designed to run on computers located respectively inside and outside the firewall and are used for communication between the firewall and the specified objects located respectively inside and outside the firewall, and the inner component includes controls internal computer to create and maintain a table of internal trusted sites and tools to manage internal computer and a firewall to provide copies of the Table external component, and also includes means for establishing and maintaining its own control connection with an external component, which is used for transmission from the external component, an internal component of a request sent from an object located in the external component. 5. Устройство туннелирования, служащее для предоставления объектам обработки данных, которые находятся вне брандмауэра, возможности устанавливать соединения для передачи данных с теми объектами обработки данных, которые находятся внутри брандмауэра, и содержащее внутренние и внешние компоненты, предназначенные для выполнения на компьютерах, которые расположены соответственно внутри и вне брандмауэра и служат для взаимодействия между брандмауэром и указанными объектами, находящимися соответственно внутри и вне брандмауэра, при этом внутренний компонент включает средства управления внутренним компьютером по созданию и ведению таблицы внутренних доверенных объектов и средства для управления внутренним компьютером и брандмауэром по предоставлению копии этой таблицы внешнему компоненту, а также включает средства для установления и поддержания собственного управляющего соединения с внешним компонентом, которое используется для передачи от внешнего компонента внутреннему компоненту запроса, посланного от объекта, находящегося в этом внешнем компоненте.
  6. 6
    The method of objects that are outside the firewall (1) protecting the computer system against unauthorized access, the ability to install intended for data connections to selected objects, located inside the firewall, which consists in the fact that they create and maintain a table of selected objects inside the firewall (1), each element (30) which is composed of data items that identify the corresponding selected object identifying data port, dedicated to this project, and determine the data transfer protocol to be used to transmit data via this port in the area, located outside the firewall, transmit a copy of the specified table, external objects having a specific access to protected information, provide access to data items constituting element of said table corresponding to external objects are granted the right to send requests to access the elements identifying the selected object that identifies the transmission port data and determines the type of data transfer protocol and formed data items allocated to these external objects, and the use of computer systems within and outside the firewall, set designed for a data connection between a specific internal object specified in the request, and an external object, who sent this request, and those portions of the data connections that are inside the firewall and pass therethrough, are formed exclusively under the control of a computer system inside the firewall, while using a computer system inside the firewall establishes and maintains its own control connection to located outside the firewall computer system which is used to transfer requests from the computer system, located outside the firewall, to the computer system inside the firewall. 6. Способ предоставления объектам, которые находятся вне брандмауэра (1), защищающего компьютерную систему от несанкционированного доступа, возможности устанавливать предназначенные для передачи данных соединения с выбранными объектами, находящимися внутри этого брандмауэра, заключающийся в том, что создают и ведут таблицу выбранных объектов внутри брандмауэра (1), каждый элемент (30) которой состоит из элементарных групп данных, идентифицирующих соответствующий выбранный объект, идентифицирующих порт передачи данных, выделенный этому объекту, и определяющих протокол передачи данных, который должен использоваться для передачи данных через этот порт, в зону, находящуюся вне брандмауэра, передают копию указанной таблицы, внешним объектам, имеющим определенный допуск к защищенной информации, предоставляют доступ к элементарным группам данных, образующим элемент указанной таблицы, соответствующим внешним объектам предоставляют право посылать запросы для получения доступа к элементу, идентифицирующему выбранный объект, идентифицирующему порт передачи данных и определяющему тип протокола передачи данных и образованному элементарными группами данных, выделенными этим внешним объектам, и с использованием компьютерных систем, находящихся внутри и вне брандмауэра, устанавливают предназначенное для передачи данных соединение между конкретным внутренним объектом, указанным в запросе, и внешним объектом, пославшим этот запрос, причем те участки этого соединения для передачи данных, которые находятся внутри брандмауэра и проходят через него, формируют исключительно под управлением компьютерной системы, находящейся внутри брандмауэра, при этом с помощью компьютерной системы, находящейся внутри брандмауэра, устанавливают и поддерживают собственное управляющее соединение с находящейся вне брандмауэра компьютерной системой, которое используют для передачи запросов от компьютерной системы, находящейся вне брандмауэра, к компьютерной системе, находящейся внутри брандмауэра.