Untitled record
Abstract
The present invention relates to providing Apparatus, systems, and platforms network, and methods for providing secure communication between several networks. طــــبقـًـا لجــــهـــاز تــــوضيـــحــي، قــــد يــتــــضمــن الجــــهــــاز )40 ) تــجــهيــــزات لمنــــع اتــــصــــاالت طــبــــقــة تـــطبــــيــــق إلــــى تــــطبـــــيـــق غــيــــر منــقــطــع بــــيــــن عــــضــو شــبــكــة آمــــن وعـــــضــو( 33( أكــــثــر أو secured networked members مــؤســســة شــبــكـــة members enterprise networked أو أكــــثــر )34 )الستــبــعـــاد اتــصــال المــلفـــات النـــشــطـــــة active files أو مــــنـع The connection of active files or the affected files and the prevention of the establishment of active links or cycles between the members of a secure network or more (36) and the number of (33) members of a number of (33) members of the network.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
35 claims: 13 independent, 22 dependent
- 11- نظام حماية أمن اإلنترنت cyber security protection system يتضمن:مجموعة أولى لجهاز كمبيوتر أو أكثر يحدد وحدة مرحلة بيانات أولى data staging module )DSM( مرتبطة بمنطقة شبكة أولى التي تتضمن مستوى حماية شبكة أول، وتم تكوينها للحصول على بيانات من عضو شبكة آمن secured networked members أو أكثر مرتبط بمنطقة 5 الشبكة األولى؛ مجموعة ثانية لجهاز كمبيوتر أو أكثر يحدد وحدة مرحلة بيانات ثانية data staging module )DSM( مرتبطة بمنطقة شبكة ثانية التي تتضمن مستوى حماية شبكة ثاني، وتم تكوينها للحصول على بيانات من عضو مؤسسة شبكة أو أكثر مرتبط بمنطقة الشبكة الثانية؛ و تخزين شبكة منطقة تخزين SAN( storage area network( ونظام تبادل مقترن بشكل صالح 10 للتشغيل بوحدتي مرحلة البيانات األولى والثانية، نظام تخزين وتبادل شبكة منطقة تخزين storage SAN( area network( يشتمل على: وحدة تخزين شبكة منطقة تخزين SAN( storage area network( أو أكثر تتضمن مجموعة أولى من وحدة تخزين أو أكثر تستطيع الوصول إليها عن طريق وحدة مرحلة بيانات data DSM( staging module( األولى؛ 15 ومجموعة ثانية لوحدة تخزين أو أكثر تستطيع الوصول إليها عن طريق وحدة مرحلة بيانات data DSM( staging module( الثانية؛ و وسط اتصال غير مؤقت تم تكوين لتوفير اتصاالت البيانات بين المجموعة األولى لوسط تخزين أو أكثر والمجموعة الثانية لوسط تخزين أو أكثر لتوفير مسار بيانات بين منطقة الشبكة األولى ومنطقة الشبكة الثانية، 20 في حين يكون نظام تخزين وتبادل شبكة منطقة تخزين SAN( storage area network( مهيأ إلج ارء اتصاالت البيانات بين المجموعة األولى لوسط تخزين أو أكثر والمجموعة الثانية لوسط تخزين أو أكثر باستخدام بروتوكول ال يعتمد على اإلنترنت IP( Internet protocol( بناء على مخطط اتصاالت، حيث يشتمل مخطط اتصاالت ال يستند إلى عنوان بروتوكول اإلنترنت IP( Internet protocol( على نقل ملفات ثابتة بين مجموعات أولى وثانية لوحدة تخزين أو 25 أكثر، حيث تشتمل الملفات الثابتة على ملفات نصية تتولد من الملفات األصلية المستقبلة بواسطة 7093 -34- وحدات مرحلة بيانات DSM( data staging module( األولى للنقل إلى وحدات مرحلة بيانات DSM( data staging module( الثانية أو الملفات األصلية المستلمة بواسطة وحدات مرحلة بيانات DSM( data staging module( الثانية للنقل إلى وحدات مرحلة بيانات data DSM( staging module( األولي. 5
- 22- النظام وفقًا لعنصر الحماية 1، حيث تشتمل الملفات األصلية على ملفات نشطة تشتمل على كود تنفيذي executable code، وحيث يكون نظام تخزين وتبادل شبكة منطقة تخزين storage SAN( area network( مهيأ لمنع اتصاالت طبقة التطبيق بالتطبيق غير متداخلة وطبقة شبكة بروتوكول اإلنترنت IP( Internet protocol( غير متداخلة للملفات النشطة بين عضو أو أكثر 10 من أعضاء الشبكة المحمية أو عضو أو أكثر من أعضاء المؤسسة الشبكية networked .enterprise members
- 33- النظام وفقًا لعنصر الحماية 1، حيث تكون المجموعة األولى لوحدة أو وحدات التخزين مخصصة بشكل منفصل لالتصال المباشر من خالل وحدة قياس البيانات األولى وال يمكن 15 الوصول إليها مباشرة من خالل وحدة قياس البيانات الثانية؛ و حيث تكون المجموعة األولى لوحدة أو وحدات التخزين مخصصة بشكل منفصل لالتصال المباشر من خالل وحدة قياس البيانات الثانية وال يمكن الوصول إليها مباشرة من خالل وحدة قياس البيانات الثانية.
- 420 4- النظام وفقًا لعنصر الحماية 1، حيث تشتمل اتصاالت البيانات المجموعة األولى لوسط تخزين أو أكثر والمجموعة الثانية لوسط تخزين أو أكثر على وحدات بيانات حزمة افت ارضية virtual block data volumes تك ارر على إحدى مناطق الشبكة األولى والثانية وتبادل التخزين للجانب اآلخر لمناطق الشبكة األولى والثانية؛ و حيث تقوم وحدة قياس البيانات األولى ووحدة قياس البيانات الثانية، ونظام التخزين والتبادل لشبكة 25 منطقة التخزين بتحديد دعامة التخزين لشبكة منطقة التخزين المثبتة إلج ارء تبادل التك ارر والتخزين في وحدات القفل االفت ارضيvirtual block data volumes . 7093 -35-
- 55- النظام وفقًا لعنصر الحماية 1، حيث تكون وحدة قياس البيانات األولى مثبتة الستخدام خطة اتصاالت طبقة التطبيق للتطبيق عند الحصول على البيانات من أو تزويد البيانات إلى عضو واحد على األقل من األعضاء الشبكية المحمية ؛ حيث تكون وحدة قياس البيانات الثانية مثبتة الستخدام خطة اتصاالت التطبيق للتطبيق عند تحويل 5 البيانات إلى أو الحصول على البيانات من عضو واحد على األقل من أعضاء شبكة المؤسسة ؛ حيث تكون وحدة قياس البيانات األولى والثانية مثبتتان الستخدام خطة اتصاالت غير قائمة على بروتوكول اإلنترنت عند تبادل أو نقل البيانات بينهما، لمقاطعة أي نقل أو تبادل للبيانات تطبيقا بتطبيق بين عضو واحد على األقل من األعضاء الشبكة المحمية وعضو واحد على األقل من أعضاء الهيئة الشبكية networked enterprise members . 10
- 66- النظام وفقًا لعنصر الحماية 1، حيث يكون نظام التبادل والتخزين لشبكة منطقة التخزين مثبتا الستخدام إحدى أو كال من خطتي االتصال التاليتين:خطة اتصاالت أولي تشتمل على إج ارء اتصال البيانات بين زوج أو أكثر من األزواج المت اربطة للمجموعة األولى والثانية من وحدات التخزين في تبادل التخزين، والحزمة االفت ارضية، والمستوى 15 الداخل والخارج O/I( input/output( لتوفير تبادل للبيانات قائم على االتصاالت غير المرتبطة ببروتوكول اإلنترنت بين أحد أعضاء الشبكة المحمية وأحد أعضاء هيئة الشبكة networked enterprise members ؛ و خطة اتصاالت ثانية تشتمل على إج ارء اتصال البيانات بين زوج أو أكثر من األزواج المت اربطة للمجموعة األولى والثانية من وحدات التخزين باستخدام تبادل التخزين، والحزمة االفت ارضية، أو 20 طبقة الداخل والخارج O/I( input/output( لتوفير تبادل للبيانات قائم على االتصاالت غير المرتبطة ببروتوكول اإلنترنت بين عضو أو أكثر من أعضاء الشبكة المحمية وعضو أو أكثر من أعضاء هيئة الشبكة networked enterprise members .
- 77- النظام وفقًا لعنصر الحماية 1، حيث تكون منصة الشبكة مثبتة من أجل:25 تواصل البيانات من عضو من أحد أعضاء الشبكة المحمية إلى وحدة قياس البيانات األولى أو استعادة البيانات من عضو أو أكثر من أعضاء الشبكة المحمية من خالل وحدة قياس البيانات 7093 -36- األولى للتواصل بعضو من أعضاء المؤسسة الشبكية، واتصال البيانات التي تم الحصول عليها من نظام تخزين وتبادل شبكة منطقة التخزين من وحدة قياس البيانات األولى إلى أو االستعادة من خالل عضو من أعضاء الشبكة المحمية، تتم من خالل استخدام خطة اتصاالت تقوم على بروتوكول اإلنترنت Internet protocol ؛ 5 تواصل البيانات من عضو من أحد أعضاء الشبكة المحمية إلى وحدة قياس البيانات الثانية أو استعادة البيانات من عضو أو أكثر من أعضاء الشبكة من خالل وحدة قياس البيانات الثانية للتواصل بعضو من أعضاء المؤسسة الشبكية، واتصال البيانات التي تم الحصول عليها من نظام تخزين وتبادل شبكة منطقة التخزين من وحدة قياس البيانات الثانية إلى أو االستعادة من خالل عضو من أعضاء الشبكة المؤسسية، تتم من خالل استخدام خطة اتصاالت تقوم على بروتوكول 10 اإلنترنت Internet protocol ؛ و يتم تواصل البيانات بين وحدة قياس البيانات األولى ووحدة قياس البيانات الثانية باستخدام خطة االتصاالت التي ال تقوم على بروتوكول اإلنترنت Internet protocol.
- 88- النظام وفقًا لعنصر الحماية 7، حيث يتم تخصيص المجموعة األولى لوحدة أو وحدات 15 التخزين بصورة منفصلة للوصول المباشر من خالل وحدة قياس البيانات األولى وغير متصلة بصورة مباشرة بوحدة قياس البيانات الثانية، حيث تكون المجموعة الثانية لوحدة أو أكثر من وحدات قياس البيانات مخصصة بشكل منفصل للتواصل المباشر من خالل وحدة قياس البيانات الثانية وغير متصلة بصورة مباشرة بوحدة قياس البيانات األولى، حيث تشتمل خطة االتصاالت غير القائمة على بروتوكول اإلنترنت على نقل الملفات الثابتة بين األزواج المت اربطة للمجموعات 20 المنفصلة األولى والثانية لوحدة أو وحدات التخزين، والملفات الثابتة التي تتولد من الملفات األصلية التي تحتوي على البيانات التي تتصل أو يتم استقبالها من خالل وحدات قياس البيانات األولى والثانية على التوالي لنقل وحدات قياس البيانات األولى والثانية على التوالي.
- 99- النظام وفقًا لعنصر الحماية 8، حيث تشتمل المجموعة األولى لوحدة أو وحدات التخزين على 25 مجموعة أولى من وحدة أو وحدات التخزين، حيث تشتمل المجموعة الثانية لوحدة أو وحدات التخزين على مجموعة ثانية من وحدة أو وحدات التخزين، وحيث تشتمل خطة االتصاالت غير 7093 -37- القائمة على بروتوكول اإلنترنت Internet protocol على مجموعة أو مجموعتين من نظام التشغيل التاليتين:وحدة قياس البيانات األولى التي تقوم بتحويل ملف أو أكثر من الملفات األصلية إلى تطبيق اتصال يتم استخدامه من خالل والحصول عليه من عضو من أعضاء الشبكة المحمية إلى ملف 5 أو أكثر من الملفات الثابتة وتخزين ملف أو أكثر من الملفات الثابتة في وحدة تخزين للمجموعة األولى من وحدات التخزين، ونظام التخزين والتبادل الذي يقوم بنقل نسخة من وحدة التخزين إلى وحدة التخزين للمجموعة الثانية من وحدات التخزين، ووحدة قياس البيانات الثانية التي تقوم بإعادة إنشاء الملف أو الملفات الثابتة في ملف أصلي أو أكثر لتطبيق التواصل الذي يتم استخدامه من خالل عضو من أحد أو أكثر من أعضاء الهيئة الشبكية وتوفير نقل نسخة من التي تم إعادة 10 إنشائها أو أكثر من الملفات األصلية إلى عضو أو أكثر من أعضاء الهيئة الشبكية؛ و وحدة قياس البيانات الثانية التي تقوم بتحويل ملف أو أكثر من الملفات األصلية إلى تطبيق اتصال يتم استخدامه من خالل والحصول عليه من عضو من أعضاء الشبكة المحمية إلى ملف أو أكثر من الملفات الثابتة وتخزين ملف أو أكثر من الملفات الثابتة في وحدة تخزين للمجموعة األولى من وحدات التخزين، ونظام التخزين والتبادل الذي يقوم بنقل نسخة من وحدة التخزين إلى وحدة التخزين 15 للمجموعة الثانية من وحدات التخزين، ووحدة قياس البيانات الثانية التي تقوم بإعادة إنشاء الملف أو الملفات الثابتة في ملف أصلي أو أكثر لتطبيق التواصل الذي يتم استخدامه من خالل عضو من أحد أو أكثر من أعضاء الهيئة الشبكية وتوفير نقل نسخة من التي تم إعادة إنشائها أو أكثر من الملفات األصلية إلى عضو أو أكثر من أعضاء الشبكة المحمية networked enterprise .members 20
- 1010- النظام وفقًا لعنصر الحماية 1، حيث تكون وحدة قياس البيانات األولى مثبتة لتحويل ملف أو أكثر من الملفات األصلية المستعادة أو المستقبلة من عضو الشبكة المحمية ألعضاء الشبكة المحمية في ملف ثابت أو أكثر ولتخزين ملف أو أكثر من الملفات الثابتة على وحدة التخزين للمجموعة األولى لوحدة أو أكثر من وحدات التخزين، حيث يكون ملف أو أكثر من الملفات 25 األصلية أصليا في عضو الشبكة المحمية networked enterprise member؛ 7093 -38- حيث يكون نظام التخزين والتبادل لشبكة منطقة التخزين مثبتا لمضاعفة وحدة التخزين للمجموعة األولى لوحدة أو وحدات التخزين إلى وحدة أخرى للتخزين للمجموعة الثانية لوحدة أو وحدات التخزين التي يتم من خاللها مضاعفة الملف أو الملفات الثابتة؛ و حيث تكون وحدة قياس البيانات الثانية مثبتة الستعادة أو استقبال الملف أو الملفات المكررة الثابتة، 5 ولتحويل الملف أو الملفات المكررة الثابتة إلى ملف أو ملفات أصلية تكون أصلية لعضو المستقر ألعضاء الهيئة الشبكية networked enterprise members.
- 1111- النظام وفقًا لعنصر الحماية 1، حيث تشتمل وحدة أو وحدات تخزين شبكة منطقة التخزين على:10 وحدة التخزين األولى لشبكة منطقة التخزين مزدوجة بشكل عملي مع وحدة قياس البيانات األولى ومثبتة لتحتوي على المجموعة األولى لوحدة أو وحدات التخزين. وحدة التخزين الثانية لشبكة منطقة التخزين مزدوجة بشكل عملي مع وحدة قياس البيانات الثانية ومثبتة لتحتوي على المجموعة الثانية لوحدة أو وحدات التخزين. حيث تكون وسيلة االتصال غير االنتقالية مزدوجة بشكل عملي بين وحدة التخزين األولى لشبكة 15 منطقة التخزين ووحدة التخزين الثانية لشبكة منطقة التخزين ومثبتة لتوفير اتصال للبيانات بين وحدة تخزين شبكة منطقة تخزين SAN( storage area network( األولي ووحدة تخزين شبكة منطقة تخزين SAN( storage area network( الثانية.
- 1212- النظام وفقًا لعنصر الحماية 11، حيث:20 تشتمل وسيلة االتصال غير االنتقالية على مفتاح تحويل لشبكة منطقة التخزين أو نسيج يحتوي على مفتاح تحويل أو أكثر لتحديد النسيج المحول؛ تشتمل اتصاالت البيانات بين وحدة التخزين األولى لشبكة منطقة التخزين ووحدة التخزين الثانية لشبكة منطقة التخزين على اتصال للبيانات بين زوج أو أكثر من األزواج المتصلة لوحد التخزين للمجموعة األولى أو الثانية، 7093 -39- ويمكن الوصول إلى وحدة التخزين األولى لكل زوج من وحدات التخزين بشكل مباشر من خالل وحدة قياس البيانات األولى وال يمكن الوصول إليها بصورة مباشرة من خالل وحدة تخزين البيانات الثانية، و ويمكن الوصول إلى وحدة التخزين األولى لكل زوج من وحدات التخزين بشكل مباشر من خالل 5 وحدة قياس البيانات الثانية وال يمكن الوصول إليها بصورة مباشرة من خالل وحدة تخزين البيانات الثانية.
- 1313- النظام وفقًا لعنصر الحماية 12، حيث تشتمل اتصاالت البيانات بين وحدة التخزين األولى لشبكة منطقة التخزين ووحدة التخزين الثانية لشبكة منطقة التخزين على:10 تطبيق للبيانات ونقل لوحدة الحزمة بين وحدة التخزين األولى ووحدة التخزين الثانية لكل زوج أو أكثر من األزواج المتصلة للمجموعة األولى والثانية من وحدات التخزين.
- 1414- النظام وفقًا لعنصر الحماية 1، حيث تشتمل وحدة قياس البيانات األولى على مزود مجمع للبيانات ومزود للبيانات؛ 15 حيث يكون المجمع للبيانات مثبتا ومركبا لجمع البيانات من عضو أو أكثر من أعضاء الشبكة المحمية من خالل إنشاء واحد أو أكثر مما يلي:اتصاالت، أو استعالمات قواعد بيانات، أو تبادالت للبيانات، أو مكتبة لوضع البيانات في ملفات، أو مكتبات لعضو أو أكثر من أعضاء الشبكة المحمية، حيث يشتمل على األقل واحد أو أكثر من أعضاء الشبكة المحمية على جهاز أو أداة، مركب فردي للجهاز أو األداة، خليط منهما معا؛ و 20 حيث يكون مزود البيانات مثبتا ومركبا لدعم اتصاالت البيانات لطبقة أو أكثر من طبقات التطبيق بالتطبيق من خالل استخدام أداة نقل أو أكثر من أدوات نقل بروتوكول التحكم في اإلرسال )IP( Internet protocol بروتوكول اإلنترنت /)TCP( transmission control protocol أو بروتوكول وحدة بيانات المستخدم UDP( user datagram protocol(/ بروتوكول اإلنترنت .)IP( Internet protocol 7093 -40-
- 1515- النظام وفقًا لعنصر الحماية 1، حيث يكون المستوى الثاني من الحماية أقل من المستوى األول من الحماية، وحيث تكون منطقة الشبكة األولى هي المنطقة المحمية، وحيث تكون منطقة الشبكة الثانية هي المنطقة األقل حماية.
- 165 16- النظام وفقًا لعنصر الحماية 15، حيث تكون وحدة قياس البيانات األولى مثبتة إلج ارء عملية تحويل مصادر ملفات البيانات من عضو أو أكثر من أعضاء الشبكة المحمية الداخلة في المنطقة المحمية إلى ملفات نصية بسيطة لمضاعفة ونقل إلى وحدة أو أكثر من وحدات التخزين للمجموعة الثانية لوحدة أو وحدات قياس التخزين من خالل نظام التخزين والتبادل لشبكة منطقة التخزين؛ وحيث تكون وحدة قياس البيانات الثانية مثبتة إلج ارء عملية إعادة تحويل الملفات النصية البسيطة 10 إلى شكل ملفات أصلية يمكن استخدامها من خالل عضو المكان المقصور لعضو أو أكثر من أعضاء الهيئات الشبكية لالستعادة من خاللها أو النقل إليها.
- 1717- النظام وفقًا لعنصر الحماية 15، حيث تكون وحدة قياس البيانات األولى مرتبطة بشكل عملي بالمنطقة المحمية وبوحدة قياس البيانات الثانية، وحيث تكون وحدة قياس البيانات األولى 15 مثبتة لتعمل كحاجز ومنطقة مرحلية لجمع كل البيانات الموجودة في المنطقة المحمية والمنطقة األقل حماية وجميع البيانات الداخلة في المنطقة المحمية من المنطقة األقل حماية.
- 1818- النظام وفقًا لعنصر الحماية 17، حيث تكون وحدة قياس البيانات الثانية مرتبطة بصورة عملية بالمنطقة األقل حماية لجمع البيانات الداخلة إلى المنطقة األقل حماية من المنطقة المحمية 20 وجميع البيانات الخارجة من المنطقة األقل حماية إلى المنطقة المحمية؛ و حيث يكون نظام التبادل والتخزين لشبكة منطقة الحماية مثبتا.
- 1919- النظام وفقًا لعنصر الحماية 15، حيث يشتمل نظام شبكة منطقة تخزين storage area SAN( network( التخزين على وحدة قياس شبكة منطقة التخزين، وحيث يشتمل نظام حماية 25 أمن اإلنترنت cyber security protection system كذلك على:7093 -41- اربط محمي يحتوي على شبكة حزمة بروتوكول اإلنترنت غير المشتركة، حيث تشتمل شبكة حزمة بروتوكول اإلنترنت غير المشتركة على أداة مركزية، وتحتوي األداة المركزية على وحدة قياس البيانات األولى، ووحدة قياس البيانات الثانية، ووحدة قياس شبكة منطقة التخزين، كما تشتمل األداة المركزية على: 5 شبكة منطقة محلية مرتبطة بصورة عملية بوحدة قياس البيانات األولى والمنطقة المحمية من خالل جهاز حماية الشبكة األولى لتوفير اتصال بين وحدة قياس البيانات األولى، ومزود أو مزودات الحاسوب المشتملة داخل المنطقة المحمية، و شبكة منطقة محلية مرتبطة بصورة عملية بوحدة قياس البيانات الثانية والمنطقة األقل حماية من خالل جهاز حماية الشبكة الثانية لتوفير اتصال بين وحدة قياس البيانات الثانية، ومزود أو مزودات 10 الحاسوب أو أجهزة المستخدمين األط ارف المشتملة داخل المنطقة المحمية.
- 2020- النظام وفقًا لعنصر الحماية 19، حيث يشتمل نظام حماية أمن اإلنترنت cyber security protection system أيضا على وحدة قياس اربط اتصال مخصص محمي secured مثبت لتوفير اتصال محمي مع )SDCLM( dedicated communication link module 15 شبكة نقل البيانات، حيث يشتمل الجهاز على:مفتاح تحويل إيثرنت إلنشاء شبكة منطقة محلية مخصصة؛ جهاز حماية شبكة يقوم بتعريف جدار النار لشبكة مثبت لحماية شبكة المنطقة المحلية؛ و قناة اتصاالت تشتمل على قناة تشتمل على حبل، أو سلك، أو حبل منسوج أو سلك، مرتبط بجدار النار للشبكة ومثبت لتوفير مسار اتصال لشبكة نقل البيانات التي تقع خارج حائط نار الشبكة؛ و 20 حيث تكون وحدة قياس البيانات األولى مرتبطة المنطقة المحمية من خالل وحدة قياس اربط اتصال مخصص محمي secured dedicated communication link module )SDCLM(. 21 - النظام وفقًا لعنصر الحماية 20، 25 حيث تكون قناة االتصاالت قائمة على قناة أو أكثر من القنوات المخصصة تشتمل على واحد أو أكثر من األشياء التالية: الترتيب الهرمي الرقمي المت ازمن synchronous digital hierarchy 7093 -42- )SDH( والشبكة البصرية المت ازمنة SONET( synchronous optical networking(، واالتصال المتعدد الترددي المنقسم wave division multiplexing ، ومثبت لبروتوكول اإليثرنت المخصص configured for dedicated IP over Ethernet ، واالتصال التسلسلي على قناة االتصال serial communication over the communication channel ، أو كال من 5 بروتوكول اإلنترنت المخصص على اإليثرنت واالتصال المتسلسل على قناة االتصاالت؛ و حيث تكون وحدة قياس اربط اتصال مخصص محمي secured dedicated SDCLM( communication link module( مثبتة لتكون بروتوكول إنترنت غير عام أو مشترك خاص، لتتبع اإلج ارءات وم ارقبة وإصدار التنبيهات لتسويات حماية الحاسوب.
- 2110 22- النظام وفقًا لعنصر الحماية 21، حيث تشتمل المنطقة المحمية على عضو أو أكثر من أعضاء الشبكة المحمية؛ حيث يشتمل عضو أو أكثر من أعضاء الشبكة المحمية على تثبيتات المهمة الحاسمة البعيدة أو المحلية، أو أدوات، أو أنظمة، أو شبكات، أو تطبيقات، أو أدوات تحكم controllers ، أو حواسيب، أو أي أجهزة إدارة بيانات data management devices أخرى أو مستشع ارت data collecting or transmitting devices أو أي أجهزة تجميع أو نقل للبيانات sensors 15 بما في ذلك األجهزة الداخلة والخارجة والمعدات، أو مزيج منهما؛ حيث تشتمل المنطقة األقل حماية على عضو أو أكثر من أعضاء الهيئة الشبكية؛ حيث يشتمل عضو أو أكثر من أعضاء الهيئة الشبكية على أدوات المهمة غير الحاسمة البعيدة أو المحلية، أو أنظمة، أو شبكات، أو حواسيب، أو أي أجهزة ربط أخرى للمستخدم، أو مزيج من 20 ذلك.
- 2223- النظام وفقًا لعنصر الحماية 1، حيث يشتمل نظام حماية أمن اإلنترنت cyber security protection system أيضا على أداة مركزية أو للتوزيع، تكون األداة المركزية أو أداة التوزيع مثبتة لتشكيل شبكة حزمة بروتوكول إنترنت مهجنة غير 25 مشتركة تقوم بتوفير وسيلة اتصاالت آمنة لتوفير البيانات بين كل عضو أو أكثر من أعضاء الشبكة المحمية وكل عضو من أعضاء الهيئة الشبكية، 7093 -43- تكون شبكة حزمة بروتوكول اإلنترنت المهجنة غير المشتركة مثبتة لتوفير قناة اتصال تقوم على بروتوكول اإلنترنت متداخلة من خالل جزء قناة االتصاالت غير القائم على بروتوكول اإلنترنت الذي ال يدعم االتصاالت القائمة على بروتوكول اإلنترنت.
- 235 24- النظام وفقًا لعنصر الحماية 23، حيث تشتمل اتصاالت البيانات على وحدات بيانات حزمة افت ارضية virtual block data volumes تك ارر على إحدى مناطق الشبكة األولى والثانية وتبادل التخزين للجانب اآلخر لمناطق الشبكة األولى والثانية؛ و حيث تقوم وحدة قياس البيانات األولى ووحدة قياس البيانات الثانية، ونظام التخزين والتبادل لشبكة منطقة التخزين بتحديد دعامة التخزين لشبكة منطقة التخزين المثبتة إلج ارء التبادل والتك ارر في 10 وحدات القفل االفتارضي. حيث تشتمل األداة المركزية على دعامة تخزين لشبكة منطقة التخزين المرتبطة بشبكة المنطقة المحلية المخصصة في منطقة الشبكة األولى وشبكة المنطقة المحلية غير المخصصة في منطقة الشبكة الثانية لتوفير اتصاالت بروتوكول اإلنترنت بينهما.
- 2415 25- نظام حماية أمن اإلنترنت cyber security protection system يشتمل على:مجموعة أولى لجهاز كمبيوتر أو أكثر يحدد وحدة مرحلة بيانات أولى مرحلة بيانات data DSM( staging module( مرتبطة بمنطقة شبكة أولى التي تتضمن مستوى حماية شبكة أول، وتم تكوينها للحصول على بيانات من عضو شبكة آمن secured networked membersأو أكثر مرتبط بمنطقة الشبكة األولى؛ 20 مجموعة ثانية لجهاز كمبيوتر أو أكثر يحدد وحدة مرحلة بيانات ثانية مرحلة بيانات data DSM( staging module( مرتبطة بمنطقة شبكة ثانية التي تتضمن مستوى حماية شبكة ثاني، وتم تكوينها للحصول على بيانات من عضو مؤسسة شبكة أو أكثر مرتبط بمنطقة الشبكة الثانية؛ و تخزين شبكة منطقة تخزين SAN( storage area network( ونظام تبادل مقترن بشكل عملي 25 بوحدتي مرحلة البيانات األولى والثانية، نظام تخزين وتبادل شبكة منطقة تخزين storage area SAN( network( يشتمل على: 7093 -44- وحدة تخزين لشبكة منطقة التخزين تشتمل على المجموعة األولى لوحدة أو وحدات التخزين التي يمكن الوصول إليها من خالل وحدة قياس البيانات األولى؛ وحدة التخزين الثانية لشبكة منطقة التخزين تشتمل على المجموعة الثانية لوحدة أو وحدات التخزين والتي يمكن الوصول إليها من خالل وحدة قياس البيانات الثانية، و 5 مفتاح تحويل شبكة منطقة التخزين يحتوي على مفتاح تحويل أو أكثر يقوم بتحديد النسيج المحول، حيث يكون النسيج المحول مرتبطا بصورة عملية بين وحدة التخزين لشبكة منطقة التخزين األولى ووحدة التخزين لشبكة منطقة التخزين الثانية ومثبتة لتزويد اتصال البيانات يقوم على بروتوكول ال يعتمد على اإلنترنت IP( Internet protocol( بين وحدة تخزين شبكة منطقة تخزين storage SAN( area network( األولى ووحدة تخزين شبكة منطقة تخزين storage area network 10 )SAN( الثانية ليتم من خالل ذلك توفير مسار للبيانات بين منطقة الشبكة األولى ومنطقة الشبكة الثانية، يشتمل اتصال البيانات الذي يقوم على بروتوكول ال يعتمد على اإلنترنت Internet IP( protocol( على نقل الملفات الثابتة بين وحدة تخزين شبكة منطقة تخزين storage area SAN( network( األولي ووحدة تخزين شبكة منطقة تخزين storage area network )SAN( الثانية، وتشتمل الملفات الثابتة على ملفات نصية تتولد من الملفات األصلية المستلمة 15 بواسطة وحدات مرحلة بيانات DSM( data staging module( األولى للنقل إلى وحدات مرحلة بيانات DSM( data staging module( الثانية أو من الملفات األصلية المقابلة المستلمة بواسطة وحدات مرحلة بيانات DSM( data staging module( الثانية للنقل إلى وحدات مرحلة بيانات DSM( data staging module( األولي.
- 2520 26- النظام وفقًا لعنصر الحماية 25، حيث تشتمل اتصاالت البيانات بين وحدة التخزين األولى لشبكة منطقة التخزين ووحدة التخزين الثانية لشبكة منطقة التخزين على اتصال للبيانات بين زوج أو أكثر من األزواج المتصلة لوحد التخزين للمجموعة األولى أو الثانية، ويمكن الوصول إلى وحدة التخزين األولى لكل زوج من وحدات التخزين بشكل مباشر من خالل وحدة قياس البيانات األولى وال يمكن الوصول إليها بصورة مباشرة من خالل وحدة تخزين البيانات 25 الثانية، و 7093 -45- ويمكن الوصول إلى وحدة التخزين األولى لكل زوج من وحدات التخزين بشكل مباشر من خالل وحدة قياس البيانات الثانية وال يمكن الوصول إليها بصورة مباشرة من خالل وحدة تخزين البيانات الثانية.
- 265 27- النظام وفقًا لعنصر الحماية 25، حيث يشتمل اتصال البيانات بين وحدة تخزين شبكة منطقة التخزين األولى ووحدة تخزين شبكة منطقة التخزين الثانية على تك ارر البيانات ونقل الوحدة بين وحدة التخزين األولى ووحدة التخزين الثانية لكل زوج أو أكثر من األزواج المرتبطة للمجموعات األولى والثانية لوحدات التخزين.
- 2710 28- النظام وفقًا لعنصر الحماية 25، يشتمل كذلك على منصة الشبكة على أداة مركزية مثبتة لتشكيل شبكة حزمة بروتوكول اإلنترنت المهجنة غير المشتركة التي توفر وسيلة اتصاالت آمنة للحاسوب لتوفير البيانات بين كل عضو من أعضاء الشبكة المحمية وكل عضو من أعضاء الهيئة الشبكية، حيث أن األداة المركزية مثبتة لتوفير قناة اتصال تقوم على بروتوكول اإلنترنت المتداخلة من خالل قناة االتصاالت غير القائمة على 15 بروتوكول اإلنترنت التي ال تدعم االتصاالت القائمة على بروتوكول اإلنترنت؛ حيث تكون وحدة قياس البيانات األولى مثبتة للتواصل على جزء من قناة االتصال القائمة على بروتوكول اإلنترنت لتوفير نقل للبيانات أو استقبالها أو استعادتها من عضو أو أعضاء الشبكة المحمية التي تستخدم اتصاالت بروتوكول اإلنترنت كقاعدة اتصال لها؛ حيث تكون وحدة قياس البيانات الثانية مثبتة للتواصل على الجزء الثاني من قناة االتصال القائمة 20 على بروتوكول اإلنترنت لتوفير نقل للبيانات أو استقبالها أو استعادتها من عضو أو أعضاء الهيئة الشبكية التي تستخدم اتصاالت بروتوكول اإلنترنت كقاعدة اتصال لها؛ و حيث تكون وحدة قياس البيانات األولى ووحدة قياس البيانات الثانية مثبتة للتواصل على جزء قناة االتصاالت غير القائمة على بروتوكول اإلنترنت عندما يتم تبادل أو نقل البيانات بينها باستخدام خطة االتصاالت غير القائمة على بروتوكول اإلنترنت ليتم من خاللها منع أي اتصاالت مباشرة 25 قائمة على بروتوكول اإلنترنت بين عضو أو أكثر من أعضاء الشبكة المحمية وعضو أو أكثر من أعضاء المؤسسة الشبكية networked enterprise members. 7093 -46-
- 2829- نظام حماية أمن اإلنترنت يشتمل على:وحدة مرحلة بيانات أولى DSM( data staging module( تشتمل على مجموعة أولى من مزود أو أكثر من مزودات الحاسوب الموجودة داخل منطقة شبكة محمية أولى Secured Zone (SZ) التي تشتمل على المستوى األول من حماية الشبكة، حيث تشتمل منطقة شبكة محمية 5 SZ) Secured Zone) على واحد أو أكثر من مصادر بيانات المهمات الحاسمة، وحيث تكون وحدات مرحلة بيانات DSM( data staging module( األولى مثبتة للحصول على البيانات من واحد أو أكثر من مصادر بيانات المهمات الشبكية الخاصة بـمنطقة شبكة محمية Secured SZ) Zone) ؛ وحدات مرحلة بيانات DSM( data staging module( ثانية تشتمل على مجموعة ثانية من 10 مزود أو مزودات الحاسوب الموجودة داخل منطقة شبكة محمية ثانية Less Secured Zone LSZ)) والتي تشتمل على مستوى ثان من حماية الشبكة، حيث يكون المستوى الثاني من حماية الشبكة أقل من المستوى األول لحماية الشبكة، حيث تشتمل منطقة شبكة محمية ثانية Less LSZ) Secured Zone) على واحد أو أكثر من مستهلكي بيانات المهمات غير الحاسمة، حيث تكون وحدات مرحلة بيانات DSM( data staging module( الثانية مثبتة لتزويد البيانات 15 إلى واحد أو أكثر من مستهلكي بيانات المهمات غير الحاسمة الخاصة بـمنطقة شبكة محمية ثانية LSZ) Less Secured Zone) ، وحيث يكون واحد أو أكثر من مصادر بيانات المهمات الحاسمة الخاصة بـمنطقة شبكة محمية SZ) Secured Zone) مثبت لالتصال بواحد أو أكثر من مستهلكي بيانات المهمات غير الحاسمة الخاصة بـمنطقة شبكة محمية ثانية Less Secured LSZ) Zone) ؛ و 20 نظام تخزين وتبادل لشبكة منطقة تخزين SAN( storage area network( مثبتة لتبادل البيانات بين المنطقة المحمية والمنطق األقل حماية، ومثبتة لتوفير اتصال غير قائم على بروتوكول اإلنترنت IP( Internet protocol( بين المنطقة المحمية والمنطقة األقل حماية ليتم من خالل ذلك توفير اتصال آمن بين منطقة شبكة محمية SZ) Secured Zone) و منطقة شبكة محمية ثانية LSZ) Less Secured Zone)، يشتمل نظام تخزين وتبادل شبكة منطقة 25 تخزين SAN( storage area network( على: مجموعة أولى من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدات مرحلة بيانات DSM( data staging module( األولى؛ 7093 -47- ومجموعة ثانية من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدات مرحلة بيانات DSM( data staging module( الثانية، يشتمل اتصال البيانات غير القائم على بروتوكول اإلنترنت IP( Internet protocol( على نقل الملفات الثابتة بين المجموعة األولى لوحدات التخزين التي يمكن الوصول إليها عن طريق وحدات مرحلة بيانات data staging module 5 )DSM( األولى ومجموعة ثانية لوحدات التخزين التي يمكن الوصول إليها عن طريق وحدات مرحلة بيانات DSM( data staging module( الثانية، تشتمل الملفات الثابتة على ملفات نصية تتولد من الملفات األصلية المقابلة المستلمة من وحدات مرحلة بيانات data staging DSM( module( األولى للنقل إلى وحدات مرحلة بيانات DSM( data staging module( الثانية أو الملفات األصلية المستلمة من وحدات مرحلة بيانات )DSM( data staging module 10 الثانية للنقل إلى وحدات مرحلة بيانات DSM( data staging module( األولي.
- 2930- النظام وفقًا لعنصر الحماية 29، حيث تشتمل مجموعة أولى لوحدات التخزين على وحدة data staging module ومرحلة بيانات (SZ) Secured Zone منطقة شبكة محمية )DSM( و شبكة منطقة تخزين SAN( storage area network( مخصصة لالستخدام 15 بواسطة وحدات مرحلة بيانات DSM( data staging module( األولى، ومجموعة ثانية لوحدات التخزين تشتمل على وحدة منطقة شبكة محمية ثانية LSZ) Less Secured Zone) وشبكة منطقة تخزين SAN( storage area network( وحدة مرحلة بيانات data staging DSM( module( مخصصة لالستخدام بواسطة وحدات مرحلة بيانات data staging DSM( module( الثانية. 20
- 3031- النظام وفقًا لعنصر الحماية 29، حيث تشتمل المجموعات األولى والثانية لوحدات التخزين لنظام تخزين وتبادل شبكة منطقة تخزين SAN( storage area network( على زوج من وحدات التخزين مخصص بشكل منفصل؛ و حيث يشتمل االتصال غير القائم على بروتوكول اإلنترنت IP( Internet protocol( بين وحدات 25 مرحلة بيانات DSM( data staging module( األولى و وحدات مرحلة بيانات data DSM( staging module( الثانية تحويل الملفات األصلية من منطقة شبكة محمية Secured 7093 -48- SZ) Zone) إلى ملفات نصية بسيطة، وتحويل الملفات النصية البسيطة بين زوج من وحدات التخزين المخصصة بشكل منفصل، وإعادة تحويل الملفات النصية إلى صيغة يمكن استخدامها من قبل منطقة شبكة محمية ثانية LSZ) Less Secured Zone).
- 315 32- النظام وفقًا لعنصر الحماية 29، حيث يشتمل نظام التخزين والتبادل لشبكة منطقة التخزين على:محول لشبكة منطقة التخزين أو نسيج يحتوي على محول أو أكثر من محوالت شبكة منطقة التخزين التي تقوم بتعريف نسيج محول؛ و زوج من روابط شبكة منطقة التحويل متصلة بأط ارف االتصاالت المتعاكسة للنسيج المحول، حيث 10 يكون اربط شبكة منطقة التحويل األول لزوج روابط شبكة منطقة التحويل مثبت لالتصال بوحدة قياس البيانات األولى لنقل البيانات التي تم استقبالها من المنطقة األقل حماية إلى النسيج المحول، ويكون اربط شبكة منطقة التخزين الثانية لزوج روابط شبكة منطقة التخزين مثبت لالتصال بوحدة قياس البيانات الثانية لنقل البيانات التي تم استقبالها من النسيج المحول إلى المنطقة األقل حماية.
- 3215 33- طريقة لتوفير حماية أمن اإلنترنت، تشتمل الطريقة على الخطوات التالية:استالم، بواسطة، مزود حاسوب أول لوحدة مرحلة بيانات أولي data staging module )DSM( مرتبط بمنطقة شبكة أولى SZ) Secured Zone) بها مستوي حماية شبكة أول ومن عضو واحد على األقل من واحد أو أكثر من أعضاء الشبكة المحمية لمنطقة الشبكة األولى، الملفات األصلية للنقل إلى وحدات مرحلة بيانات DSM( data staging module( الثانية 20 المرتبطة بمنطقة شبكة ثانية LSZ) Less Secured Zone) بها مستوي حماية شبكة ثاني، ويكون مستوي حماية الشبكة الثاني أقل من مستوي حماية الشبكة األول؛ تحويل، بواسطة مزود الحاسوب األول وحدات مرحلة بيانات DSM( data staging module( األولى، الملفات األصلية إلى ملف أو ملفات ثابتة، حيث يشتمل واحد أول أكثر من الملفات الثابتة على واحد أو أكثر من الملفات النصية البسيطة؛ 25 التواصل، بواسطة نظام تخزين وتبادل لشبكة منطقة تخزين SAN( storage area network( عن طريق اتصال غير قائمة على بروتوكول اإلنترنت IP( Internet protocol( ، بنسخ من 7093 -49- الملف أو الملفات الثابتة بين زوج من وحدات تخزين شبكة منطقة التخزين، حيث يشتمل زوج وحدات التخزين شبكة منطقة تخزين SAN( storage area network( على: مجموعة أولى من واحدة أو أكثر من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدات مرحلة بيانات DSM( data staging module( األولى وتكون مرتبطة بـ منطقة شبكة محمية 5 SZ) Secured Zone) ؛ مجموعة ثانية من واحدة أو أكثر من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدة مرحلة بيانات DSM( data staging module( الثانية وتكون مرتبطة بـمنطقة شبكة محمية ثانية LSZ) Less Secured Zone)؛ يشتمل اتصال البيانات القائم على بروتوكول ال يعتمد على بروتوكول اإلنترنت Internet 10 IP( protocol( على نقل واحد أو أكثر من الملفات الثابتة من المجموعة األولى لواحدة أو أكثر من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدة مرحلة بيانات data staging DSM( module( األولى إلى المجموعة الثانية لواحدة أو أكثر من وحدات التخزين التي يمكن الوصول إليها عن طريق وحدة مرحلة بيانات DSM( data staging module( الثانية؛ استالم، بواسطة مزود حاسوب أول لوحدة مرحلة بيانات DSM( data staging module( 15 الثانية، نسخ واحد أو أكثر من الملفات الثابتة؛ وإعادة تحويل، بواسطة مزود الحاسوب الثاني لـوحدة مرحلة بيانات data staging module DSM(( ، النسخ لملف ثابت واحد أو أكثر إلى صيغة يتم استخدامها من خالل منطقة شبكة محمية ثانية .(LSZ) Less Secured Zone
- 3320 34- الطريقة وفقًا لعنصر الحماية 33، حيث يكون اتصال البيانات القائم على بروتوكول ال يعتمد على بروتوكول اإلنترنت IP( Internet protocol( مثبت لمنع إنشاء اتصال ببروتوكول اإلنترنت بين المنطقة المحمية والمنطقة األقل حماية ليتم من خالل ذلك توفير اتصال آمن بين منطقة شبكة محمية SZ) Secured Zone) و منطقة شبكة محمية ثانية Less Secured Zone .(LSZ) 25 7093 -50-
- 3435- الطريقة وفقًا لعنصر الحماية 33، حيث تشتمل الملفات األصلية على ملفات نشطة تشتمل على كود تنفيذي executable code.
- 3536- نظام يشتمل على:5 وحدة مرحلة بيانات DSM( data staging module( أولى تشتمل على مزود بيانات شبكة أول مقترن بشكل قابل لالتصال بمجموعة أولى من أجهزة الشبكة المقترنة بشكل قابل لالتصال بشبكة أولى، ويكون للشبكة األولى مستوى حماية شبكة أول، ويكون مزود بيانات الشبكة األول مثبت للحصول على بيانات من المجموعة األولى ألجهزة الشبكة؛ وحدة مرحلة بيانات DSM( data staging module( ثانية تشتمل على مزود بيانات شبكة ثاني 10 مقترن بشكل قابل لالتصال بمجموعة ثانية من أجهزة الشبكة المقترنة بشكل قابل لالتصال بشبكة ثانية تختلف عن الشبكة األولى، ويكون للشبكة الثانية مستوي حماية شبكة ثاني، ويكون مزود بيانات الشبكة الثاني مثبت للحصول على بيانات من المجموعة الثانية ألجهزة الشبكة؛ نظام تخزين وتبادل لشبكة منطقة تخزين SAN( storage area network( مثبت لتوفير نقل البيانات بين وحدة مرحلة بيانات DSM( data staging module( األولي و وحدة مرحلة بيانات 15 DSM( data staging module( الثانية من خالل مخطط اتصاالت قائم على بروتوكول ال يعتمد على اإلنترنت IP( Internet protocol( ، ويشتمل نظام تبادل وتخزين شبكة منطقة تخزين SAN( storage area network( على: وحدة تخزين أولى مقترنة بشكل قابل لالتصال بمزود بيانات الشبكة األول؛ وحدة تخزين ثانية مقترنة بشكل قابل لالتصال بمزود بيانات الشبكة الثاني؛ 20 وحيث يكون مزود بيانات الشبكة األول مثبت لـ: الحصول، من جهاز شبكة لمجموعة أولى من أجهزة الشبكة من خالل مخطط اتصاالت قائم على بروتوكول اإلنترنت IP( Internet protocol( ، على ملف أصلي يحتوي على كود تنفيذي ؛executable code توليد ملف نصي مطابق لمحتويات الملف األصلي؛ 25 وتنفيذ عملية التخزين لكي يتم تخزين الملف النصي على وحدة التخزين األولى؛ 7093 -51- حيث يكون نظام تخزين وتبادل شبكة منطقة تخزين SAN( storage area network( مثبت لنقل الملف النصي من وحدة التخزين األولى إلى وحدة التخزين الثانية باستخدام مخطط اتصاالت قائم على بروتوكول ال يعتمد على اإلنترنت IP( Internet protocol( ؛ ويكون مزود بيانات الشبكة الثاني مثبت لـ: 5 الحصول، من وحدة التخزين الثانية، على الملف النصي المنقول إلى وحدة التخزين الثانية؛ توليد ملف نصي مطابق لمحتويات الملف األصلي المنقول إلى وحدة التخزين الثانية؛ ونقل، إلى جهاز شبكة لمجموعة ثانية من أجهزة الشبكات، من خالل مخطط اتصاالت قائم على بروتوكول اإلنترنت IP( Internet protocol( ، الملف األصلي. 7093 -52- شكن ١ 7093 -53- شكن ٢ 7093 -54- شكن٣ 7093 -55- 7093 -56- شكن ٥ 7093 -5Ί- 7093
Independent claims35
296 paragraphs in 1 section, as filed
full description
Sister's wallpaper
The present invention relates to a connection between a group of network domains or areas, in particular network platforms, device, systems, and methods that use or use inter-network platforms to provide cyber security protection system across protection areas, which include different levels
5 protection between them.
The architecture of modern industrial processes such as that found in modern petroleum and gas applications is enabled at the field level, process level, application level, system level, and building level through multiple network devices. Where these devices monitor, control and collect information such as measurements and reflection of the operation of automated processes
10 process. These devices are connected or connected to electronic devices and machines that are known to be controllers operating at various levels to process the data collected and to issue commands back to networked devices or other devices.
In such a typical installation, these components form the networks and systems of the building. 15 Most of them are remote or local buildings, devices, systems, networks, applications, controls, computers, or other information management devices, sensors or other data collection devices.
or moving, including indoor and outdoor equipment, equipment, and other hardware installed in what may be called a protected mission critical area. These networks and industrial systems can be connected to multiple networks within the protected area or to non-mission critical networks outside the device such as
7093
-3-
The network of an organization or entity, which is installed within a least protected area, that is, that has less computer security, and which may also be connected to public networks such as the Internet. This makes such industrial networks highly vulnerable to external attacks on computer security or any other security threats. Such attacks may, among other things, lead to loss of vision and/or loss of control of components
5 The individual or the overall structure of a network or system. The loss of vision occurs when the user's robotic controller is unable to access the system, either partially or completely, and therefore cannot see the operation process. Loss of control occurs when the user automation is unable to send and/or receive control messages to the process control system to perform the operation and/or action.
Security measures can be applied to computers to communicate between networks and industrial systems
<p>10 And it took the form of these procedures applied to information technology systems, because the known traditional spreads of the network need a full end-to-end Internet protocol connection between the data source and the restricted place. Other methodologies include the application of the need for a firewall and/or a buffer zone between the protected area and the least protected area. These methods were not, however, sufficiently effective, in the event of a possible loss of capital, life and product in the event of a failure.</p>
<p>15th Control system or industrial process.</p>
IAS 99/46882 describes secure interconnection techniques between different networks to prevent hackers from exploiting weaknesses in network protocols.
Thus, inventors realized the need for device, systems, network platforms, and methods to provide secure communication for industrial processes, for power, electricity, systems and networks; They also realized the need for industrial systems
<p>20 and other non-industrial ones that require for example security and protection from the least secure body or internet connection. They also recognized the need for a device, systems, platforms and methods to provide secure communication between different areas such as the protected mission critical area interconnected with the devices, systems, networks, computers or any other interconnected devices for the user including these devices with the user’s parties in the least protected area, which Accounting for full communication protocol</p>
<p>25 The Internet for both information sources and their respective locations.</p>
7093
-4-
The inventors also realized the need for a device, systems, platforms and methods that provide the exchange of information from the protected area to the least protected area without a complete (unbroken) IP connection end-to-end; it can remove the exchange of corrupted files between the protected area and the less protected area, and vice versa; and it can also Remove the active links or cycles (bidirectional) between the zone
5 the protected area and the least protected area; It can also provide control over the exchange of information between the protected area and the less protected area; It can also block active files, files that contain executable code and/or files that are not removable as a text file, or binary data such as Uniform Resource Locator links (URLs) and materials that originate from an executable file, among other things that may be worms. Computer or viruses, from the exchange between the protected area and the area
<p>10 least protected; and vice versa by removing it from any information exchanged; which may provide the possibilities of exchanging information, and it is better to be on the memory drive at the internal and external level between two different points; which can overcome the need for a network such as IP communications; a physical firewall (or firewalls), and/or a buffer zone between the protected area and the least protected area.</p>
<p>15th In the event that a system combines, for example, ERP storage, or both in an enterprise network or LAN, any data flowing generally on the way is lost or must be stored through the data source.</p>
The inventors also realized the need for storage on the way to save the data that should be in the ERP cache or whether the data is moved to the least protected area
<p>20 lost it. Congruently, the inventors recognized the need for a device, systems, platforms, and methods that provide centralized data aggregation and delivery to less protected area systems and/or to manually upload or download data for catastrophic situations such as the central repository for data collection and exchange; which provides a centralized collection of data for use in a disaster recovery plan; Which provides central data collection for the protected area and least protected area systems for use in storing and placing data in</p>
25 Date.
7093
-5-
General description of the invention
By reviewing the various previous models of the current invention, they characteristically provide a device, systems, network platforms, and methods that can provide computer protection and security for industrial processes, energy and electricity, hardware systems, networks, and other industrial and non-industrial systems that require, for example
5 For example, security and protection from less secure bodies or communication over the Internet. Different models provide a device, systems, network platforms, and methods that can provide secure communications between different areas, such as a protected mission critical area associated with devices, systems, networks, computers or any other associated devices of the user including these devices with end users installed in the least protected area, which . Prepares for full IP connectivity for each of the sources
<p>10 Data and its compartment.</p>
The different models also show a device, systems, platforms and methods that provide information exchange from the protected area to the least protected area without a complete (unbroken) IP connection end-to-end; it can remove the exchange of corrupted files between the protected area and the least protected area, and vice versa; it can also Remove the active links or cycles (bidirectional) between the zone
<p>15th the protected area and the least protected area; It can also provide control over the exchange of information between the protected area and the less protected area; It can also prevent active files, files containing executable code and/or non-transferable files as a text file, binary data such as URL links and materials from which the executable file originates, among other things, which may be computer worms or viruses, from being exchanged between the protected area the least protected area; And vice versa by removing it from any</p>
<p>20 information is exchanged; which may provide the possibilities of exchanging information, and it is better to be on the memory drive at the internal and external level between two different points; which can overcome the need for a network such as IP communications; a physical firewall (or firewalls), and/or a buffer zone between the protected area and the least protected area.</p>
Moreover, the different models characteristically present in this invention device, systems and platforms
<p>25 . Network and methods that provide data availability and integrity through the complete anonymity of the means of information transmission to prevent </p>
7093
-6-
Certified access to aggregate data regardless of its data classification. Moreover, the various models cut off the connectivity of the IP address to a minimum (i.e. in the incoming and outgoing hard memory) and transfer information using data transfer to dual memory with the intermediate server to translate and coordinate the raw data through neighboring servers, such as management systems
<p>5 The path of data, unlike the concept of the delegate server model of the IP packet between different networks.</p>
The different models also illustrate a device, systems, platforms, and methods that provide centralized data collection and delivery to the systems of the least protected area and/or to manually upload or download data for catastrophic situations such as the central repository for data collection and exchange; which provides centralized data collection for its use
<p>10 in the disaster recovery plan; Which provides central data collection for protected area and least protected area systems for use in archiving and historical data.</p>
In particular, it is an example of a device model to protect the data exchange connection between multiple networks that use a storage network area and platforms running through the Internet. An analog device can have an analog platform that can operate to remove connections with Internet protocols between
<p>15th The protected area and the least protected area for bidirectional data exchange. The work of the platform, according to the analog structure, depends on the exchange of data between the first network, which contains the mission-critical members of a protected area, and the second network, which contains the non-critical members of the overall least protected area. The transfer of data between regions can be at the storage level such as the default shutdown level at the inbound and outbound level, simple text, or storage level</p>
<p>20 binary files. Platform storage is designed to be accessed from one side of the inter-area communication routes by systems or components associated with the protected area and accessed from the other side by systems and components associated with the less protected area.</p>
A representative platform may include the following main components: a central device; and/or a unit of measure
Double Dedicated Communication Link Module (DCLM) Dedicated Communication Link Module
<p>25 to the next central organ. Depending on the alternative models, the distributed device may be used. Could</p>
7093
-7-
Central or distributed devices shall contain: First, a local area network, a group or more of Data Staging Modules (DSMs), one or more SAN (storage area network), storage and exchange systems, each in the form of A storage area network and an interconnected networking unit aggregated through at least a data meter,
<p>5 And at least a second local area network, fully connected to the organization's network or system. The central device can form a hybrid non-shared IP network that includes IP communications that overlap with non-IP communications across the SAN that allow data to be exchanged.</p>
Where the exchange of data through the storage area depends on the exchange of storage, the virtual lock,
<p>10 Inbound and outbound layers, and the storage disk layer to provide data exchange based on non-IP connections between different layers, networks, systems, agencies, devices, and/or any other data sources (data generators) and data stabilizers (data end). This form of data exchange is characterized by the fact that it can provide connections between each of the data sources.</p>
<p>15th Ultimate data that uses IP communications as its base of communications, but still prevents active files, files with executable code and/or extended tasks that cannot be transmitted as a text or binary file, for example URL links, stuff whose origin is an executable file, among other things, which may be the tasks of a computer worm or virus, from exchanging it between information sources and the ultimate information in the protected area and the lower area</p>
<p>20 protection; And vice versa, they are automatically removed as part of the exchange between regions.</p>
The data units shall include at least one located in the protected area or the least protected area. Each unit of measurement includes aggregate servers or other computers, and/or one or more information servers or other computers. A network storage unit includes a storage area adapter or a fabric containing one or more storage area adapters,
<p>25 and at least a group of data storage centers, where each group contains a storage unit</p>
7093
-8-
For a protected area of storage areas and a storage unit for the less protected areas, connected and connected to a switch or a storage unit fabric. A switch or texture is used to exchange data between a protected area and a less protected area in storage exchange, virtual lock, in and out layer, for example, a storage disk data layer, and use flat files as an exchange
<p>5 Data that is not linked to Internet protocols, and is not linked to an Internet format.</p>
Provides Protected Zone and Least Protected Zone volumes located in the same volume or various other volumes that may be mounted or part of each other providing at least one, but more if a set of volumes or integrated disks in each of the Storage areas that provide one storage area accessible to the next provider in
<p>10 next area. The original volumes can be mirrored on the Protected Zone and Least Protected Zone volumes with the Zone Protected Zone and Least Protected Zone Data Scales to be used when read-write access is needed for data in the original volumes via the following PAs, and applications The least protected area.</p>
<p>15th The protected metering unit of the communication unit includes: an Internet switch to install the local area network; At least a network protection device to protect the local area network; A communications circuit used to connect different data sources to a pooled, unshared IP network, from one or two directions. The protection network of the device may include a firewall installed, for example, on the basic parts if not on all the parts of the communications circuit. can</p>
<p>20 An ad hoc communications circuit includes a transport network aggregated by one or more safety net devices, and a group of transport nodes, at the rate of one node for each LAN or other connected network. In this embodiment, one or more protection devices may include, for example, one or more firewalls for each LAN or other connected network.</p>
The device illustration includes a network platform that provides protection and security for the computer. 25 Network platforms can uniquely provide computer protection for one or more local or remote networks or systems
7093
-9-
Networks, network assets, or other data sources Identifies one or more secure network members associated with a first domain or area Identifies a first network area that includes first level security Network in combination with one or more local or remote networks, systems, or devices An end user identifies one or more network organization members Linked to a second zone or zone Define a second network zone that includes a German second level of protection
5 the network. According to the illustrative model, the network platform contains a first set of computer defining the unit of measure for the first degree of data associated with the first network area and which contains the first level of network protection, which is installed to receive or retrieve data from the member or members of the protected networks connected to the first network area; The second set of one or more computers defines the second unit of measurement for data associated with the second network area that includes the second level of security,
<p>10 installed to receive or retrieve data from members of a network authority connected to the second network area; Storage area network, storage and exchange system associated with the unit of data measurement. A storage area storage system may include a storage area storage unit or units containing a first set of storage measures that can be connected to the first data UoM, a second set of storage measure(s) that can be connected to the second data UoM, and a non-transitional communication device installed</p>
<p>15th To provide data communication between the first set of storage metric(s) and the second set of storage metric(s) to provide a path for data between the first network area and the second network area. According to the illustration of the network platform installed to prevent application-to-application layer connections</p>
Uninterrupted between one or more secure network members and one or more network organization members to exclude active file connection or prevent connection of active files or files and prevent the establishment of links or active sessions between
<p>20 One or more secure network members and one or more network organization members.</p>
Another illustrative model could include, for example, a device comprising a network platform to provide Internet security protection One or more local or remote networks, network systems, network assets, or other data sources identifying one or more secure network members associated with a first domain or region that identifies A first network area that includes a first level network security in combination with a local or remote network
<p>25 One or more end-user systems or devices that identifies one or more network organization members associated with a domain </p>
7093
-10-
or Second Zone defines a second network area that includes a second network security level. The network platform includes a first set of computer defining a unit of measure for the first degree of data associated with the first network area that contains the first level of network protection, and is installed to receive or retrieve data from the member or members of the protected networks connected to the first network area; And the group
5 the second for one or more computers by specifying the second unit of measurement of data associated with the second network area that includes the second level of security, and installed to receive or retrieve data from members of the network authority connected to the second network area; Storage area network, storage and exchange system associated with the unit of data measurement. The SAN may include a SAN storage unit that is practically linked to the data measurement unit and fixed to include a first set of unit or
10 Units of measure can be accessed through the data unit of measure, the storage area network storage unit is practically linked to the second data unit and fixed to include a second group of the unit or units of storage accessible by the second data unit, and the storage area network is practically linked between the unit of measure SAN-1 storage and SAN-2 storage are installed to provide data communication between them to provide a data path between
15th The first network area and the second network area.
According to these models, the data connection between the first storage network storage unit and the second storage network storage unit includes the data communication between two or more pairs that are related to the first and second set of storage units, where the first volume of each pair of storage units can be accessed through the data metric The first is directly and indirectly accessible
20 It can be accessed directly through the second data measurement unit, and the second storage unit for each pair of storage units can be accessed directly through the second data measurement unit, and indirectly through the first data measurement unit. Also or as an alternative method, the data communication between the first SAN volume and the second SAN volume can include data redundancy and a lock-down of unit transfers between the first volume and the second volume for each pair of pairs.
25 associated with the first and second groups of volumes.
7093
-11-
According to another model of a computer security and protection device for one or more local or remote mission-critical networks, grid systems, network clusters, or other data sources that identify one or more secure members included within the protected area that must connect to one or more mission-local networks or remote, user-end systems or devices,
5 or other data consumers that identify one or more members of the networked body included within the least protected area or connected to one or more members of the networked body. The device may include a networked storage area network platform comprising a first set of one or more computer servers defining the unit of measure for data installed within the protected area that includes a first level of network protection, and a second set of computer servers or
<p>10 More than one provider, and the second level of network protection is less than the first level of network protection; A storage area network for the storage and exchange system is linked through the first and second data measurement units installed to exchange data between the protected area and the least protected area, each of which is internally connected based on one or more IP communications plans, and to provide an unsupported Internet protocol connection between the unit of measurement. The first data and the second data unit of measure to prevent the establishment of a connection</p>
<p>15th An Internet protocol between the protected area and the least protected area, through which a secure connection can be provided between them. According to this model, a SAN is used to exchange data (a connection that is not supported by IP) between the protected area and the least protected area, both of which contain a connection internally based on IP-supported communication plans. In addition, the storage and exchange system of a network The data area can contain a pair of volumes</p>
<p>20 assigned to the data UoM, with the first comprising a unit dedicated to the protected area of the data measure and the SAN, and the second comprising a unit dedicated to the least protected area, the SAN, and the UAN; The SAN storage and exchange system is installed to provide non-IP communications by transferring simple, repeating text files between the PAU, the data meter, the SAN, and the SAN.</p>
<p>25 assigned to the least protected area, the unit of data measurement, and the storage area network.</p>
7093
-12-
According to another paradigm of the method for providing computer security and protection to one or more local or remote mission-critical networks, networked systems, network groups, or other data sources that specify one or more secure members included within the protected area that must connect to one or more mission-local networks or remote, user-end systems or devices,
5 or other data consumers that identify one or more members of the networked body included within the least protected area or connected to one or more members of the networked body. Where the method may include steps to prevent application layer communications of a non-overlapping application between one or more protected network members, and one or more protected enterprise members by using a proven network platform to interfere with IP-based data communications
<p>10 Its base with non-IP connections. The step of preventing layer connections in the application for a non-overlapping application can include the following steps: Transfer of original files from at least one member of the protected network to static files, and the transfer step is done through the first computer provider; Connected to at least copies of static files between a pair of storage area network volumes, where the first pair of volumes is for the protected area,</p>
<p>15th The second pair of SAN volumes is for the least protected area, and the least protected area has a lower level of protection than that of the protected area; And re-transfer files for fixed files in the form of files that can be used through the second least protected area, and the re-transfer step is done through the second computer provider, with the connection between the two storage area network units in the form of closed virtual data units for closed virtual data units.</p>
<p>20 that contain at least copies of the file or static files.</p>
According to this model, a static file or files includes a static text file or files, in which the first computer provider is a second information provider consisting of at least parts of the second data unit, and where the connection is made to copy the file or static files through a storage and exchange system For the storage area network associated with the first and second information providers and installed for data exchange
<p>25 Between the protected area and the least protected area, each of which is internally connected according to plans </p>
7093
-13-
An Internet Protocol connection, to provide a non-IP connection between the protected area and the least protected area through which a secure connection is provided between them. In addition, the file or static files can be generated from the original files which are received from the first and second data utensils for transfer to the following other first and second data utensils.
5 The various embodiments of this invention include a device, a tool, functions, operations, methods, and designs of platforms for exchanging data between one or more groups of domains or areas, such as a protected area and a least protected area that can provide data exchange based on the storage level of the device, and provide a data collection and retrieval center, which Using the capabilities of the data unit and removing the Internet protocol communication by linking two different networks, systems, or devices. Templates are also provided
<p>10 Different secure data transfer methods can be used to transfer data between different databases and use the inbound and outbound data layer to exchange data between networks.</p>
Various embodiments of this invention can provide a device that has a network platform based on: a non-shared packet network that extends between an ad hoc LAN and an enterprise LAN, and defines a central device that is used to connect a pair of applications, regions, or networks that
<p>15th It includes different levels of security, such as the collection of networks and systems in the protected area, the collection of enterprise networks and systems, and the access of remote users to the less protected area; The circuit or dedicated communication channel used to connect networks and systems to a non-shared IP packet network.</p>
The various embodiments of this invention show methods for exchanging platform data based on a data exchange procedure
<p>20 In storage exchange, virtual lock and in and out layer, i.e. non-IP communication between two layers, two networks or different devices that use IP-based communication as a base for the communication between them, unlike the procedure for exchanging data in the software application layer.</p>
This and previous platform models can be used for applications used in oil and gas, electricity and other industrial and non-industrial applications and devices that require safe interchange.
<p>25 for the data.</p>
7093
-14-
Various embodiments of this invention may include device, systems, network platforms, and methods that provide a centralized collection of data for use in an emergency data recovery plan. The data meter of the protected area side can recover data if the remote machine of the protected area is not connected to the network of the less protected area. In a similar way, the unit of data measurement can be
5 The protected area side recovers data if the remote device of the protected area is not connected to the network of the least protected area. Usefully, the central pool of data in each domain or area of the network (for example, protected area or least protected area) can be used in support of an emergency data recovery plan and a continuity plan to provide primary storage and distribution of data as when the enterprise network is problematic and isolated The aggregator servers have the ability to connect with
<p>10 End users within the central data collection area.</p>
The different models of this invention also provide secure data transfer methods that can use data transfer between different databases and use the incoming and outgoing data layer to exchange data between networks.
Usefully, one or more pairs of data measurement units can provide a bridge between application layers on the first side of the SAN, and they can work with the SAN.
<p>15th To send data over the network to the second side of the storage area network. In addition, the enterprise-side UOM, for example, can be used as a medium for exchanging data with distributed and remote devices and can be responsible for data recovery in the event of no connection to remote devices and/or loss of connection to the enterprise network.</p>
Brief explanation of the drawings
<p>20 In order for the method that includes the advantages of this invention and others to be clear and can be understood in more detail, more detail for this invention that was previously summarized can be in the models shown in the attached diagrams, which form part of these characteristics. It should be noted, however, that the illustrations only illustrate the different models of the invention. Therefore, it is not specific to the invention perspective, as it may contain other influential models.</p>
7093
-15-
Figure 1, is a graphic depiction of a data exchange communication platform model between a pair of domains or regions that have different levels of security impact, such as the mission-critical safe region and the least-protected non-critical region, according to the current invention model.
Figure 2 is an illustration showing a basic illustrative model of the platform through
<p>5 The Internet is fixed between the protected area and the least protected area, according to the current invention model.</p>
Figure 3 is a diagram illustrating an illustrative device comprising an illustrative network platform comprising a central device, in the form of a data exchange model for a central storage area network, that is installed to remove the IP communications between the protected area and the least protected area, to exchange data from two directions according to the model The current option.
<p>10 Figure 4 is an illustrative central device diagram showing the network bus switch assembly connections, according to the current invention embodiment;</p>
Figure 5 is a graph showing the steps of data processing and the passage of data between the networks and systems of the organization located in the protected area and the institutional networks and systems located in the less protected area, through the central illustrative device of Figure 4, according to the model of this invention; And
<p>15th Figure 6 is a diagram illustrating a device comprising an illustrative network platform that includes a distributed device in the form of a data exchange model for a distributed storage area, according to this invention.</p>
Detailed description:
This invention will now be fully described with reference to the attached drawings that will show examples of this invention. This invention, however, may be represented in many different forms and should not be limited to the models shown below. Rather, these models are provided for clarification
Accurate and complete, it will fully convey the perspective of this invention to professionals in the field. The numbers in the illustrations indicate their meaning in the elements. If the main fee group disclaimer is used, it indicates alternative models.
7093
-16-
Figure 1 shows an illustrative communication platform model for exchanging data between a pair of domains or regions that have different security levels. Secure communication between different areas such as protected mission critical area, remote or local critical devices, devices, systems, networks, applications, controllers, computers, other data management devices, sensors, and other devices.
5 Other data collection including inbound and outbound devices, equipment, and/or other combinations or combinations thereof associated with the Least Protected Area such as devices, systems, computers, or any user interface devices including end users, and other industrial and non-industrial systems . These systems and networks generally require, for example, security and protection from the least secure organization or connection to the Internet. It should be noted that the terms “data exchange” and “communication”
10 “Data” can refer to a single path of a data connection, such as a file transfer or a copy of a file transferred as a result of data being sent or retrieved on the communication medium, along with it, but it cannot include a two-way data connection.
In order to provide computer protection for these systems and networks, several models usefully include a device, systems, network platform, and methods that provide clearing the data exchange of corrupted files between the area.
15th the protected area and the least protected area, and vice versa; remove active links or (bi-directional) loops between the protected area and the least secure area; and/or provide an exchange of controller data between the protected area and the less secure area; centralize data collection and communicate it to the less secure area systems for manual data upload or download in emergency situations; and/or central collection of data for protected area and least protected area systems to be used for data archiving and placed in the register.
20 The data and put in the log. Alternatively, these models can provide methods for secure data transfer that can use traffic flow between different databases that use the inbound and outbound data layer to exchange data between networks. It should be noted that although the terms “protected area” and “least protected area” are used across these models, ordinary skill in the field will recognize that the models for this invention described here can be applied
7093
-17-
Directly to achieve the security and protection of computers across networks that use similar or identical levels of security to form isolated areas that are approximately equal or identical to the protected area.
Figure 2 shows a basic illustrative model of online platforms 30 located between the protected area and the least protected area. Platform 30 provides computer protection and security, for example
5 For example, for mission-critical groups, such as device network or networks, hardware systems, client devices, near or remote devices, systems, networks or applications, controllers, computers, or other data management devices, sensors or any other combination data or transmission devices (including incoming and outgoing devices), equipment or a combination thereof, collectively referred to as hardware systems or any other data sources, located in the protected area, that are connected or interconnected
<p>10 For example with non-critical groups, such as the authority network, authority systems, client devices, remote or local devices, systems, other networks, applications, computers, or any other data management devices, or a combination of all of these, located in the area Least protection. Demonstrative Platform 30 components can be strengthened by applying computer access limitation and anti-virus capabilities. Physical protection of platform items and maintenance orders can be defined</p>
<p>15th As understood by any expert in the field. Platform 30 can serve as a means of exchanging data in oil and gas, energy, and utilities uses, among other things, removing the need for a VoIP connection with the Authority or other less secure networks, which include the Internet.</p>
Platform 30 can provide data exchange based on the level of the storage device provided for: Transfer
<p>20 Data from the protected area to the least protected area without full end-to-end IP connectivity, removing the IP connection across the interconnection of two different networks, two systems, and/or two devices within the protected area and least protected area, and the data collection and recovery center (which will be described later on). According to the illustrative structure, platform 30 includes intermediate groups of computer servers 31, 32 in each region such as block 181, 182 and/or data server 191,</p>
<p>25 192 (see Figure 3), which will be described later, installed on both sides of the storage area network</p>
7093
-18-
40 To transfer and re-transfer original files to applications or servers for downstream systems 33, 34, such as data systems 33, and agency systems 34. SAN 40 can be usefully used to interrupt what would otherwise be an IP network connection between 33 data systems associated with a protected area and regulations of the Authority 34 associated with the least protected area, resulting from the removal of
5 The need for a firewall and/or buffer zone between the protected area and the least protected area.
The storage area network may include linking the protected area with the storage area network 41 and linking the less protected area with the storage area network 42 located in the same storage location or other storage places. Each SAN connection 41, 42 contains at least one but preferably a group of SAN units or disks that each provide 10 single storage areas accessible to the next provider 31, 32.
A SAN can have one or more switches. In a preferred combination, the switch or switches are part of the fabric or, more practically, the fabric with a switch in the fabric channel that specifies the fabric channel of the SAN 43 consisting of one or more switches of the SAN fabric channel (not shown separately 15 Data exchange can take place between SAN units, which are located in the same storage location or any location
Various storage carried out using eg microcomputer system laces and/or tissue channel protocols. Other protocols that provide the same functionality exist within the scope of this invention.
Platform 30 can advantageously use the channel or circuit 53 assigned for communications based on the 20 dedicated channels such as Synchronous Digital Hierarchy
SDH and SONET (Synchronous Optical Networking),
split-frequency multiplexing, dedicated power connector, digital DSL Subscriber Line, dedicated fabric, and/or variants of unshared IP packet networks as understood by experts in the field, to create independence from the public and 25 / or a data-sharing private IP network. The platform can 30
7093
-19-
Provide data exchange between the protected area and the least protected area using a storage area central network data exchange model (see Figure 3) and/or a storage area distribution network data exchange model.
Figure 3 shows an illustration device 100 with an illustration grid platform 130 installed to remove it
5 Internet protocol communication between the protected area and the less secure area for bi-directional data exchange. For example, according to the demo installation, the task of the data exchange platform is to exchange storage, virtual lock, and in and out layer; Any storage disk layer that uses static files, such as simple text files or binary files, to provide data exchange that is not based on IP communications, such as a non-Internet format for exchanging data between
<p>10 The different layers, applications, systems, networks, devices, equipment, and/or anything else that consumes or produces data, that use Internet Protocol communications as their base of communication. This is contrary to the traditional applications that provide data exchange based on the application layer (API). Usefully, the network platform 130 can be used according to different communication plans and users, to include oil and gas, power and other applications</p>
<p>15th Industrial and non-industrial, networks, and devices that require secure computer data exchange. Platform 130 can be used for other purposes, as professionals in this field understand.</p>
According to the models shown, the work of the Demonstrative Network Platform 130 is mainly based on: a non-shared packet network that extends between the allocated LAN 151 and the enterprise LAN 152, and is used to exchange data between the protected area and the least protected area; where
<p>20 Platform storage is designed to be accessed on the one hand by systems or components associated with the protected area and accessed on the other by systems or components associated with the less protected area; Optionally, the dedicated circuit or communication channel used to connect networks and systems to a unidirectional or bidirectional non-shared IP packet network is used. Data sources can, for example, include devices</p>
<p>25 critical or indecisive remote or local, systems, networks, applications, controllers, or</p>
7093
-20-
Computers, servers or other data control devices, sensors or other data collection and transmission devices (including input and output devices), equipment, and/or other combinations or combinations of such things, collectively referred to as 133 Hardware data sources or systems for simplicity Communication can be directly with the 133 mounting system or
5 By connecting to the following LANs 155. You should note that a non-shared hybrid IP packet network is referred to as “hybrid” because it can include IP connections overlapping with other non-IP connections.
The Demonstrative Network Platform 130 includes a "central tool" 157 in the form of a data exchange model
<p>10 Demonstrative central storage area network comprising dedicated LAN 151, a combination of struts 161, 162, Storage 1, 2, and enterprise LAN 152. Strings 161, 162, Storage 1, 2 collectively include data volumes 131, 132 and Internet Network Units of SAN 140 spanning between them and used to exchange data between the protected area and the least protected area. The components of the central tool constitute 157 with</p>
<p>15th A non-shared hybrid IP packet network that can conduct data transfer between regions using non-IP or Ethernet data exchange. In addition, the central tool 157 in connection with the channel designated for communication forms 153 protected links 159.</p>
The illustrative central instrument is interconnected 157 on one side through the dedicated circuit (channel) 153, and on the other
<p>20 On the other hand, they are interconnected through the unallocated circuit, i.e. the common packet network that forms at least an important part of the least protected area. Other structures of the basal central instrument model are found within the perspective of this present invention. For example, under an alternative model, a hybrid non-shared IP packet network could instead connect to two different, unassigned circuits (ie, packet-based networks).</p>
7093
-21-
There are other alternative tool models within the perspective of this invention. For example, according to an alternative model, the central tool 157 includes a dedicated LAN 151 with a back-up 161 for storage connected to the remote tool with a 162 - a storage 2 and a LAN 152. For example, according to one of the other alternative models, the central tool has Network 5 Local Area 151, Backup 161 for Storage 1, Backup 162 for Storage 2, Remote Tool with Network
Local area 152.
The reference is still made to Figure 3, where the Network platform 130 may also include a model
Secured Dedicated Communication Link Module
<p>(171) SDCLM. The hardware components of a protected custom ligation form are</p>
<p>10 Included example: an Ethernet switch 173 to create a dedicated LAN 151 and a network security tool 175 such as one or more firewalls 175 to protect the LAN 151; and a dedicated communication circuit 153 comprising a switching network 177 connected to a network protection device 175, such as four firewalls 175, a set of transmission nodes, and appropriate optical or electrical wiring and/or radio transmitters or receivers . The software components of the central software that have</p>
<p>15th Capable of bonding to different solids of a custom protected bonding form</p>
<p>(171) SDCLM that collects performance streams. The software can also track events, screen and connected objects and identify abnormalities. The software can also alert computer security that includes a local display system and/or a remote central security center, as the average professional in this field understands.</p>
<p>20 According to one illustrative model, ADCC 153 is based on dedicated channels such as SDH Synchronous Digital Hierarchy, SONET Synchronous Optical Networking, Split-Frequency Communication, Dedicated Fabric, and Digital Subscriber Line (DSL), and/or jumper wire. Uses the SDCLM model.</p>
<p>25 171 is a private Internet protocol that is not public or shared. It includes a protected channel based on either</p>
7093
-22-
Internet protocol over Ethernet and/or serial connection over the connection link. The dedicated communication circuit 153 is connected to the network protection device 175 like firewalls 175. The four firewalls on the hard body or combination of solids and software are to select the connection to isolate the transport network 177, which only allows these protocols and data to enter the transport network 177, to prevent the spread of
5 malicious code. The SDCLM 171 form provides the required capability to connect the 133 mounting systems to the 130 network platform.
Referring to Figure 3, as shown briefly, according to the representative model, the network platform 130 includes a data unit or units of measure for the first region 131 each identifying the unit of measure for data 130 in the first region or protected area, the unit or units of measure
<p>10 Data for the second zone 132 Each defines the unit of data measurement for the least protected zone installed in the second zone or the less protected zone. The data units for the protected area and the least protected area 131, 132 are data galleries to collect all the data that needs to be exchanged between different areas. Each of the data standard units 131, 132 collects data favorable to networks, systems, or other data sources that comprise one of the regions</p>
<p>15th associated protection. For example, a data meter in a protected area is connected to various local or remote installation systems 133 or other data sources through a protected ad hoc link model 171, and is used as a loading and staging area for all data entering or leaving the protected area. The unit of measure can data in the least protected area 132, but you do not need to use a connection to a secure network such as the common packet switched network to include the Internet</p>
<p>20 To carry data to end users. Each of the data modules 131, 132 is connected to a protection device, such as a firewall 175, on one communication side and a storage backbone of the SAN such as the SAN 140 on the other. The storage strut is located in the SAN between protected area data meter 131 and the least protected area data meter 132.</p>
7093
-23-
Each of the data units 131,132 is concerned with the task of transmitting data such as time series data from the data source to the data stabilizer. Data sources can go singly, multiple and/or multi-cycle data sources originating from the interconnection of individual and/or multiple application programs. The protected area data module 131 is connected to the area data sources
5 Protected circuits, such as mount systems 133, that use one or more dedicated communication circuits 153, or other preferred secure circuits or channels, can be IP-based or serialized. Protected area data sources include, for example, one or more providers that are installed on or otherwise connected to 133 installation systems, both remote and local. Data sources within or that make up cascading installation systems 133 can include a syntax query language or
10 Another database provider known to the average professional in the field, serving cascading installation systems 133. The data sources can also be a provider running an application that exchanges data templates based on TCP/IP or UDP/IP.
Depending on the illustration, each of the protected area data units may include 15 131 and the least protected area data unit 132, which form part of the illustration.
Centralization 157 contains one or more data collectors 181, 182, and/or one or more data providers 191, 192 respectively, and is compatible with the UoM stored on it, to provide a wider range of different data types and communication characteristics for different installation systems 133. These 181 collectors, 182 which may be servers, responsible for collecting data from different installation systems 133 or any other sources
20 Other data, by creating connections, databases, and exchanges of data, putting data into a file or files for each installation/tool or, alternatively, for each component of the individual installation system, and managing data transfer. The primary method for exchanging data is generally based on a standard form of databases, such as the database links for CSL. The complementary data servers 191, 192 are responsible for supporting the exchange of data in application layers after application based on
7093
-24-
Use standard support protocols such as TCP/IP vectors or UDP/IP vectors.
According to the installation and illustrative work, the stabilizer feeders are on PAMS 131, or on the remote or local site of cascading stabilization systems 133 depending on the direction
5 the traffic. For example, data originating from a protected area data source for transmission to the least protected area stable is sent to collector 181 or data provider 191 as a data exchange stable, using application script links. The data retrieved from the Least Protected Area Data Meter 132 through the SAN units that need to be sent to the protected area installation systems contains servers linked to the LAN Serial 155 installed on
10 Or rather associated with local or remote cascading installation systems 133 such as the data stabilizer or alternatively the actual installation system component itself.
For data originating from the least protected area data source such as party networks, systems, and users, referred to as enterprise systems 134, the protected area data meter 131 restores the data to the next stable data provider or servers associated with the installation system
15th Sequential Data Stabilizer 133. For data transmission from protected area data sources, the following server, or servers 181, 191, on the protected area data meter 131 retrieve or receive data from the protected area data source.
According to the illustration, PAU 131 provides access to current data from different sources in a unified manner. The 131 20 protected area data metric and/or work units save the data in the storage area network unit of the data metric unit in
A protected area, for example, that which is installed on or rather associated with the storage area network storage
Protected area 141, as static files containing symbols that can be printed, to transfer/or iterate to SANU SAU of least protected area 142, to gain UoM data in least protected area 132 and access through or re-transfer to stable 25 final data. In the illustrative data transfer plan, fixed or duplicate files are transferred with an image
7093
-25-
pure in a write-only method that uses a SAN support such as SAN fabric 143, to the SAN unit of the data meter in the least protected area. By converting files to static files before transferring between regions, active files, and files containing executable code and/or strings of commands that cannot be transferred as text or binary files such as
<p>5 URL links, executable files, among other things, which can carry computer worms or viruses, are removed from the data, and prevented from being exchanged between the protected area and the least protected area, and vice versa.</p>
According to the illustrative installation, the SAN SAN modules of the data meter in the least protected area can be used for the following less protected area applications that require
<p>10 Communicate through reading and writing for the unit that contains its data. The read-write-access example includes a scenario in which the database on the installation side is exchanging data to the other on an enterprise network, for example, Shared Packet Network 179. Another example includes a scenario in which the installation information system within the installation data exchange with The enterprise network is 179 at the software application level, but it uses a unit of data measurement for the area</p>
<p>15th Protected data 131, such as the data provider 191, and SAN 140 for transmission of data on the incoming and outgoing layer, ie using the non-IP network connection. This mirror unit can synchronize and break from the SAN unit to the data slug unit in the least protected area in the time interval which depends on the SANU capability and the total storage time required between the data source and the end users. can unit of measure</p>
<p>20 The data in the least protected area 132 manages the length of time that must be completed for synchronous mirror units based on both the time it takes to create the file and the time it takes to read the file.</p>
According to the illustration, multiple SAN units can be used. For example, each unit of data measurement in protected area 181, 191 can
<p>25 One different unit is used on storage area network storage as a means of data transmission. Add to</p>
7093
-26-
However, multipath data passing in a single data UoM 131 can use either a single unit or a separate unit of the data path. Each of the 181, 191 DSM servers can include a DSM loader, as the ordinary specialist in the field understands, to manage the recovery and transmission of data to the next stable data provider within the target window
5 previously specified. In addition, multiple data units of measure can be used to support different remote sites and/or applications, and can provide the appropriateness of data processing, delaying storage exchange time and storage capacity requirements.
According to the illustrative structure, each data meter provider of the least protected area 132 above the read-only unit and/or reflective unit can read the static data file. And for
<p>10 For time-sensitive data, the data includes a time stamp, at the registry level, to prioritize file processing to its final stability. According to the explanatory processing process, the lower zone DSM 132 servers read the data protection from the higher units and ensure that the statistics are synchronized with the servers of the end users or clients, and up-to-date. This functionality can be supported by standard software application technology such as the Inquiry and Constructive Language Service</p>
<p>15th Vehicle and/or standard protocol such as Object Linking and Embedding (Object Linking OLEDB and Embedding). The required snapshot rate will depend on the SAN capabilities and the time required to transfer data between the data source and its stabilizer. The SAN snapshot rate is fixed in the data exchange Between the two data units to be in the application probability on calling and loading the application layer static file.</p>
<p>20 Each of the 132 data modules can include one or more validators or controllers in the static file that can only verify that static files are written or read to or to SAN units, and/or may include other modules For software to check files, network connectivity, systems, and modules free from computer or network worms, viruses, or aggregated data cycles, and to perform advanced data transfer and cleanup operations.</p>
<p>25 Characteristically, aggregate servers 181, data servers 191, 192 can provide </p>
7093
-27-
An environment for sanitizing data before it is transferred to SAN 140, i.e. advanced processing before exchanging data over the DAU. The ability to take advantage of data purge on aggregate servers 181, 182, 191, 192 data servers, and SAN 140 provides an environment for secure data transmission.
5 Various data metric tasks can include management of waiting actions and rate of procedure storage, which helps ensure sustainable data transfer and data integrity if components fail during data transfer, when data connection is resumed. Other DMU tasks, naturally supported by standard software application technology such as this one supported by the CSL, and/or standard software implementation, include:
10 applying context to information to link and visualize data; Create advanced data analytics structures; Create a unit
Measure to analyze and visualize KPIs by integrating the performance key setup required for the end user for various tasks, (such as queries, data transmission, data storage, etc.) advanced data validation procedure, data transmission, and validation control
15th And the transmission through the runtime of the installation data by integrating these tasks in support of the data transmission integration, as understood by the average professional in the field.
Still referring to Figure 3, as indicated earlier, according to one illustrative example, the network platform 130 includes storage for the storage area network and a data exchange system 140 includes the unit of measure for the mesh networks of the storage area network 140 which is practically between the unit 20 of data measurement . Protected area 131 and the unit of data measurement for the least protected area, to provide an exchange
data between the protected area and the least protected area. According to the SANU illustration, the SANU bracket includes for SANU 140 a protected area storage area network repository referred to as “Store 1 SAN installation,” and a storage area network storage area network storage less protected 142 referred to It is referred to as "Store 2 Body 25 Storage Area Network", each of which contains one or more storage devices that supply a
7093
-28-
At least one or more groups to form a single data center that can be evaluated by associated data units of measure 131, 132. The SAN 140 also includes a SAN switch at least 143 in the form of one or more network switches, and more Ideally in the form of a switch fabric 143 comprising a set of network adapter switches,5 and more preferably in the form of a transformer fabric in a microcomputer system/or textile ligament channel.
In particular, the illustrative SAN unit base architecture is based on a single SAN storage system (Store 1 and Warehouse 2) that uses single and/or multiple storage spaces, and SAN 143 switch fabric including one or more SAN switches The storage area, which can provide a design for a faulty bearing system through which each component is
10 completely surplus.
The installation of the storage area network metering unit involved several distinct works. Featured works include the SAN meter's ability to provide storage capacity as well as data archiving for both the protected area and the least protected area. The storage area network unit of measure (SAN) data storage capability can be usefully used eg for data retention 15 The source agency layout store must become formed or if data that is moved to the least protected area is lost. can this
The works may alternatively contain: an exchange of virtual data lock units between real-time data snapshots; Frequency of data storage; Controlled read and write capabilities between volumes to serve traffic purposes for end-to-end data exchange; 20 Remote redundancy operation that can include both synchronous and asynchronous modes to provide flexibility for transferring data exchange between different types of applications; and/or the ability to write the output file directly to any of
A SAN volume, such as writing an output file that has a data default lock to the SAN volume static file for transmission over networks that have any of the same or different levels of security.
These works can alternatively contain: backup database synchronization across systems; 25 the ability to establish the processes necessary to transmit and store information; And the ability to maintain not to
7093
-29-
disconnect and continue to communicate based on the basis of the operating system, database and/or capabilities of the application; The ability to access data from various data sources such as processing historians, related databases, network services, and third-party applications, for example through a storage area network storage application; and/or the ability to access and transfer large amounts of
5 Information at the international level (i.e. a large amount of data), applied for example through the connection of remote distributed shared tools with the protected ad hoc link model
171. (SDCLM)
Operations can also, or alternatively, include the ability to use a non-IP connection, such as the Fire Channel Protocol 143 for fabric communication within a network unit of measure.
10 Storage area 140, between the hosts (eg collectors 181, 182 and data provider 191, 192) of the protected area UoS 131, 132, and their respective volumes on 141, 142. The UoS 131, 132 can be Picture it as close or as far as the storage area mesh fabric can provide.
15th Alternatively, these works could include: the ability to create, develop, and specify values to make copies in bulk, extract retries based on failures between UoM 131, 132, and the data source, to log retry exceptions, say retries, and and/or to provide dynamic and on-site control of the extract, load, and transform packages, using available application software technology such as the Syntax and Inquiry Language Service Pack and/or application software
20 standard.
Also referring to Figure 4, each PAMS 181, 182, 191, 192 PAMS 131, 132 system that requires a connection to a data source or stabilizer can have 195 network bus switches installed to provide communication with a data storage SAN 141, 142, which also includes one or more switches
25 . There are 197 network bus switches. In addition, each store can contain
7093
-30-
SAN 141, 142, must have at least one of the 198 SAN fabric switches to connect to the SAN fabric switch 143. As is evident to the average industry professional, the SAN 143 fabric switch can be set up to ensure that every system of The data scale 181, 182, 191, 192 is only connected to the volume it is assigned to.
5 Figure 5 summarizes the data processing steps and the traffic of data from stabilization systems 133 referred to as node S1, to enterprise systems 134 referred to as node S5, as a result of the processing process performed by SAU data 131 referred to as S2 and SAN Storage 140 referenced by node S3, and the least protected area data unit of measure referred to by node S4. As shown above, the data path between S1
10 S2 includes native files for data exchange based on standard software application interfaces. Represent
Data path from node S2 to node S3 Generate (convert) the original file to a static file and store it in the storage. At node S3, copies of the static files travel through the protected area and the least protected parts of SAN 140. And the data from S3 To S4 represents restoring or transferring the static file from node S3 to node S4, followed by file conversion
15th The firmware is transferred to a native file to systems, networks, and/or end-users represented by node S4. The transmission of data from node S4 to node S5 asymptotically represents the restoration or migration of the original file to node S5. The transmission of data from the opposite direction i.e. from node S5 to S1 is the opposite of the above.
Although different models are initially described regarding the data interchange model for a central storage area network 20, the different data demonstrate platforms that use a data interchange model for a distributed storage area network. For example, Figure 6 shows a device 200 comprising a network platform 230 illustrating a distributed device 257 as a DSN data interchange model. The data exchange model of the distribution area network is similar to the data exchange model of the distribution area network shown in Figure 3, except that some of the installation systems 133 for at least PA 25 are connected from different locations to the common packet network 179 through three zones
7093
-31-
Multiple separate fitted between protected area firewalls 175 and firewalls 175 adjacent to the local area network links of the least protected area.
In the model shown in Figure 6, LANs 152, 252, 252' represent any of the three separate parts of the same LAN 152, shown in Figure 3, which are
5 measured over the three separate positions; or which represent the three separate LANs 152, 252, 252’, similarly in the form of shared packet networks interconnected with three separate storage-friendly pilings 162, 262, 262’, which are generally interconnected with the same storage strut 161 to connect to systems Installation 133, each of which connects to the Enterprise Network 134 to provide enhanced data exchange between Enterprise 134 systems and installation 133 systems.
10 In the embodiments shown, the SAN fabric transfer switch 143 is connected to the three switches '143, 243, 243' of the SAN fabric of the least protected area. The first transfer switch 143' of the three switches is associated with Storage Area Network 1 of the least protected area 142 to provide file acquisition by the data meter in the least protected area 132, i.e. data collector 182 and/or data provider 192, and access by retransfer to headquarters
15th The second transfer switch 243 of the three switches is associated with the storage area network storage of the least protected area 242 to provide file acquisition via the second LMU 232, i.e. an aggregate data 282 and/or data provider 292, and access by retransmission to the final data location through or part of the local area network 252 to provide
20 Acquisition of the file through the third data module 232, i.e. data collector 282 and/or data provider 292, and access through or back-transfer to the final premises through or part of the LAN 252 and enterprise network 179, to provide a third path to enterprise systems 134.
In the illustrations and the specification, a referenced model of the invention is attached, and despite the use of special clauses, the clauses are used in a descriptive sense only and not for the purpose of limitation. It was completed
25 Describe the invention in detail with special reference to these examples shown. It will be apparent, that
7093
-32-
Various modifications and changes can take place within the spirit and perspective of the invention as described in the previous characteristics. For example, although it has been described primarily in relation to supporting data exchange in hydrocarbon energy, oil and gas, ordinary professionals in this field will recognize that the perspective of the various models illustrated for the present invention described below is ready
<p>5 For use in industrial and non-industrial applications, networks, and devices.</p>
7093
-33-
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
8 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 14274279 | United States of America | – | |
| 201414274279 | United States of America | A | |
| 2015029925 | United States of America | W |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2015326582A1 | United States of America | A1 | |
| WO2015172045A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9503422B2 | United States of America | B2 | |
| EP3140976A1 | European Patent Office (EPO) | A1 | |
| SA516380065A | Saudi Arabia | A | |
| EP3140976B1 | European Patent Office (EPO) | B1 | |
| SA516380065B1 | Saudi Arabia | B1 | |
| SA7093B1This record | Saudi Arabia | B1 |
Numbers
- Publication
- 7093
- Publication, DOCDB
- 7093
- Application
- 418400019
- Application, DOCDB
- 418400019
Titles2
- Arabic
- جهاز، وأنظمة، ومنصات، وطرق لتأمين عمليات تبادل بيانات الاتصال بين عدة شبكات للتطبيقات الصناعية وغير الصناعية
- English
- Device, systems, platforms, and methods for providing communication data exchanges between multiple networks for industrial and non-industrial applications
Classification
- CPC, 8
- H04L63/0209
- H04L63/105
- H04L63/14
- H04L63/18
- Y02D30/00
- H04L63/0245
- H04L67/06
- H04L67/1097