System and method for cryptologically tethering user devices to one another in adaptable manner for trusted communication across untrusted network
A high assurance system provides for communication between trusted user devices with auxiliary adaptation for augmenting communication security across an untrusted environment. First and second main encrypting devices coupled to respective trusted user devices are cryptologically tethered to one another by a main communication link established across the untrusted environment between trusted user devices in cryptologically protected manner. An auxiliary encrypting device is cryptologically tethered to the first main encrypting device by an auxiliary communication link established across the untrusted environment between a trusted auxiliary device and one trusted user device in cryptologically protected manner. The main and auxiliary encrypting devices define portals traverse trust boundaries between trusted and untrusted environments, each including at least one encryption unit and a communication unit coupled thereto by a connectionless interconnect. The encryption unit encrypts and decrypts message data, while the communication unit transmits and receives encrypted message data through the communication links.
1 . A high assurance system for maintaining secure communication between trusted user devices in adaptable manner across an untrusted environment, comprising:
first and second main encrypting devices respectively coupled to the trusted user devices, said first and second main encrypting devices being cryptologically tethered to one another by a main communication link established exclusively therebetween to traverse the untrusted environment in cryptologically protected manner; and,
at least one auxiliary encrypting device coupled to a trusted auxiliary device, said auxiliary encrypting device being cryptologically tethered to said first main encrypting device by an auxiliary communication link established exclusively therebetween to traverse the untrusted environment between one of the trusted user devices and the trusted auxiliary device in cryptologically protected manner;
wherein each of said main and auxiliary encrypting devices includes a processor and memory, and each of said main and auxiliary communication links established between tethered encrypting devices maintains logical and physical isolation of the trusted user devices coupled to said tethered encrypting devices from the untrusted environment in a manner independent of any communication protocol of the untrusted environment; and,
wherein each of said main and auxiliary encrypting devices defines a portal for traversing a trust boundary between trusted and untrusted environments, and each of said main and auxiliary encrypting devices includes:
at least one encryption unit configured to encrypt message data for transmission and decrypt received encrypted message data; and,
at least one communication unit coupled to said encryption unit by a connectionless interconnect, said communication unit being configured to transmit and receive encrypted message data through a corresponding one of said main and auxiliary communication links.
2 . The system as recited in claim 1 , wherein:
said communication unit is disposed in the untrusted environment;
at least said first main encrypting device is of multi-channel configuration defining a plurality of channels, said first main encrypting device including:
a transit channel having at least one said encryption unit for encrypting and decrypting message data passing through said main communication link;
at least one auxiliary channel having at least one said encryption unit for encrypting and decrypting message data passing through said auxiliary communication link; and,
a manager unit coupled to said transit and auxiliary channels for controlling said encryption units thereof.
3 . The system as recited in claim 2 , comprising a plurality of said auxiliary encrypting devices coupled respectively to a plurality of trusted auxiliary devices, and said first main encrypting device defines a plurality of auxiliary channels, wherein:
a first of the trusted auxiliary devices includes an authentication token, said first auxiliary encrypting device coupling the authentication token through a first auxiliary communication link to said first main encrypting device for adaptively optimized activation thereof; and,
a second of the trusted auxiliary devices defining a management console for driving selective reconfiguration of said first main encrypting device, said second auxiliary encrypting device coupling the management console through a second auxiliary communication link to said first main encrypting device for adaptively optimized reconfiguration thereof.
4 . The system as recited in claim 2 , wherein each of said main and auxiliary encrypting devices includes at least one channel formed by a plurality of said encryption units disposed in a multiple inline encryption unit configuration, said plurality of encryption units defining at least inner and outer inline network encryption (INE) portions disposed along the channel.
5 . The system as recited in claim 4 , wherein:
the trusted auxiliary device includes an authentication token, said auxiliary encrypting device coupling the authentication token through said auxiliary communication link to said first main encrypting device for multifactored activation thereof; and,
the authentication token forms a wireless crypto-ignition key (CIK) token having a predetermined proximity range, the wireless CIK token being inoperable when disposed beyond the predetermined proximity range relative to said first main encrypting device.
6 . The system as recited in claim 4 , wherein the trusted auxiliary device includes a management console for driving selective reconfiguration of said first main encrypting device, said auxiliary encrypting device coupling said management console through said auxiliary communication link to said first main encrypting device for adaptively optimized reconfiguration thereof.
7 . The system as recited in claim 6 , wherein said first main encrypting device includes an agent unit operably coupled to an inner INE portion of said auxiliary channel for cryptologically tethered communication with said management console, said agent unit being configured responsive to said management console to monitor communication traffic between said first main encrypting device and the trusted user device coupled thereto.
8 . The system as recited in claim 4 , further comprising a management console disposed in locally integrated manner within the trusted environment of said first main encrypting device for driving selective reconfiguration thereof, said management console being operably coupled to said manager unit of said first main encrypting device by both a data channel and a command-response channel, wherein commands are passed between said management console and said manager unit in vectorized form for optimal local isolation therebetween.
9 . The system as recited in claim 1 , further comprising:
an enterprise server configured to include a plurality of said second main encrypting devices for a plurality of trusted user devices and a manager unit coupled to said second main encrypting devices for controlling said encryption units thereof, said enterprise server adaptively establishing different main communication links between said first main encrypting device and selected ones of said second main encrypting devices; and,
a management console disposed in locally integrated manner within the trusted environment of said enterprise server for driving selective reconfiguration of said second main encrypting devices thereof, said management console being operably coupled to said manager unit of said enterprise server by both a data channel and a command-response channel, wherein commands are passed between said management console and said manager unit in vectorized form for optimal local isolation therebetween.
10 . A trusted system for cryptologically secured communication in adaptable manner between remotely disposed trusted devices operating within respective trusted environments separated by an untrusted environment, comprising:
a plurality of encrypting devices respectively coupled to different trusted devices, corresponding ones of said encrypting devices being mutually paired to establish a uniquely dedicated communication link therebetween across the untrusted environment, said encrypting devices being thereby cryptologically tethered;
at least one of said encrypting devices having a multi-channel configuration defining a plurality of encryption channels;
wherein each of said encrypting devices includes a processor and memory, and each of said communication links established between mutually paired encrypting devices maintains logical and physical isolation between the trusted and untrusted environments in a manner independent of any communication protocol of the untrusted environment; and,
wherein each of said encrypting devices defines a portal for traversing a trust boundary between trusted and untrusted environments, and each of said encrypting devices includes:
at least one encryption unit configured to encrypt data traffic for transmission and decrypt received encrypted data traffic; and,
at least one communication unit coupled to said encryption unit by a connectionless interconnect, said communication unit being configured to transmit and receive encrypted data traffic through a corresponding communication link.
11 . The trusted system as recited in claim 10 , wherein:
said encrypting device of multi-channel configuration includes:
a transit channel having at least one said encryption unit for encrypting and decrypting message data passing through a first of said communication links;
at least one auxiliary channel having at least one said encryption unit for encrypting and decrypting message data passing through a second of said communication links; and,
a manager unit coupled to said transit and auxiliary channels for controlling said encryption units thereof; and,
at least one of the trusted devices includes a management console coupled through one of said communication links to said auxiliary channel of said multi-channel encrypting device for adaptively optimized reconfiguration thereof.
12 . The trusted system as recited in claim 11 , wherein said multi-channel encrypting device includes an agent unit operably coupled to an encryption unit of said auxiliary channel for cryptologically tethered communication with said management console, said agent unit being configured responsive to said management console to monitor communication traffic between said multi-channel encrypting device and the trusted user device coupled thereto.
13 . The trusted system as recited in claim 11 , wherein:
said encrypting device of multi-channel configuration includes a plurality of auxiliary channels; and,
at least one of the trusted devices includes an authentication token coupled through one of said communication links to one of said auxiliary channels of said multi-channel encrypting device for multifactored activation thereof.
14 . A high assurance method for cryptologically tethered communication in adaptable manner between first and second user devices operating within respective trusted environments separated by an untrusted environment, comprising:
establishing at least one set of first and second main encrypting devices coupled respectively to the first and second user devices, said first and second main encrypting devices each having a processor and memory;
mutually pairing said first and second main encrypting devices to establish a uniquely dedicated main communication link therebetween across the untrusted environment;
establishing at least one auxiliary encrypting device coupled to an auxiliary device operating within a trusted environment, said auxiliary encrypting device having a processor and memory;
mutually pairing said first main encrypting device and said auxiliary encrypting device to establish a uniquely dedicated auxiliary communication link therebetween across the untrusted environment; and,
establishing said main and auxiliary communication links between mutually paired encrypting devices to maintain logical and physical isolation between the trusted and untrusted environments in a manner independent of any communication protocol of the untrusted environment, said main and auxiliary communication links thereby defining a portal traversing a trust boundary between the trusted and untrusted environments; and,
wherein each of said main and auxiliary encrypting devices:
executes at least one encryption unit to encrypt message data for transmission and decrypt received encrypted message data; and,
executes at least one communication unit coupled to said encryption unit by a connectionless interconnect to transmit and receive encrypted message data through a corresponding one of said main and auxiliary communication links.
15 . The method as recited in claim 14 , wherein:
said communication unit is executed in the untrusted environment; and,
at least said first main encrypting device is established to be of multi-channel configuration defining a plurality of channels, said first main encrypting device thereby establishing:
a transit channel wherein at least one said encryption unit is executed for encrypting and decrypting message data passing through said main communication link;
at least one auxiliary channel wherein at least one said encryption unit is executed for encrypting and decrypting message data passing through said auxiliary communication link; and,
a manager unit executed to control said encryption units of said transit and auxiliary channels.
16 . The method as recited in claim 15 , comprising coupling a plurality of said auxiliary encrypting devices respectively to a plurality of trusted auxiliary devices, and
configuring said first main encrypting device to define a plurality of auxiliary channels, wherein:
a first of the trusted auxiliary devices includes an authentication token coupled by said first auxiliary encrypting device through a first auxiliary communication link for adaptively optimized activation of said first main encrypting device; and,
a second of the trusted auxiliary devices defines a management console executable to drive selective reconfiguration of said first main encrypting device, said second auxiliary encrypting device coupling the management console through a second auxiliary communication link for adaptively optimized reconfiguration of said first main encrypting device.
17 . The method as recited in claim 15 , wherein:
the trusted auxiliary device is configured to include an authentication token coupled by said auxiliary encrypting device through said auxiliary communication link for multifactored activation of said first main encrypting device; and,
the authentication token is configured to remain inoperable beyond a predetermined proximity range relative to said first main encrypting device.
18 . The method as recited in claim 15 , wherein the trusted auxiliary device is configured to include a management console for driving selective reconfiguration of said first main encrypting device, said auxiliary encrypting device coupling said management console through said auxiliary communication link for adaptively optimized reconfiguration of said first main encrypting device.
19 . The method as recited in claim 18 , wherein said first main encrypting device is configured to include an agent unit operably coupled to an inner INE portion of said auxiliary channel for cryptologically tethered communication with said management console, said agent unit being configured responsive to said management console to monitor communication traffic between said first main encrypting device and the trusted user device coupled thereto.
20 . The system as recited in claim 14 , further comprising:
establishing an enterprise server to include a plurality of said second main encrypting devices for a plurality of trusted user devices and a manager unit coupled to said second main encrypting devices for controlling said encryption units thereof;
adaptively establishing different main communication links between said first main encrypting device and selected ones of said second main encrypting devices of said enterprise server;
locally integrating a management console within the trusted environment of said enterprise server for driving selective reconfiguration of said second main encrypting devices thereof;
operably coupling said management console to said manager unit of said enterprise server by both a data channel and a command-response channel; and,
passing commands between said management console and said manager unit in vectorized form for optimal local isolation therebetween.