IP Library Granted Patent US 7,958,550
Granted Patent B2
US 7,958,550 · App. 10/040,573 · Granted Jun 7, 2011

Method and system for secure communication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,958,550
App. No.
10/040,573
Granted
Jun 7, 2011
Kind
B2
Abstract

A method and system for secure communication is presented. A virtual private proxy is generated based on an agreement between a first entity and a second entity. A first virtual private proxy is associated with the first entity and a second virtual private proxy is associated with the second entity. Data associated with the first entity is monitored at the virtual private proxy. Whether the data violates the agreement is determined and communication of the data from the first virtual private proxy to the second virtual private proxy is disallowed when the data violates the agreement.

Claims (51)

1. A method for secure communication comprising:

receiving a first profile from a first entity, the first profile indicating electronic commerce information, including a first document exchange protocol, pertaining to the first entity;

receiving a second profile from a second entity, the second profile indicating electronic commerce information, including a second document exchange protocol, pertaining to the second entity;

automatically generating an agreement based on the first profile and the second profile, wherein the agreement includes information pertaining to electronic commerce transactions between the first and second entities;

generating a first virtual private proxy and a second virtual private proxy;

establishing a first secure connection between the first virtual private proxy and the first entity and establishing a second secure connection between the second virtual private proxy and the second entity;

establishing a logical connection between the first virtual private proxy and the second virtual private proxy;

monitoring data at least one of the first virtual private proxy and the second virtual private proxy;

determining whether monitored data violates the agreement; and

disallowing communication of the monitored data between the first virtual private proxy and the second virtual private proxy when the data violates the agreement;

wherein establishing the first secure connection includes establishing a secure connection with a private session manager of the first entity wherein said private session manager excludes all other remote connections to the first entity.

2. The method for secure communication according to claim 1 , wherein determining whether the data violates the agreement comprises:

determining whether the data includes a security violation.

3. The method for secure communication according to claim 2 , wherein the security violation is selected from the group comprising: a virus, a malicious program, and an intrusion attempt.

4. The method for secure communication according to claim 1 , further comprising:

hiding the existence of at least one of the first virtual private proxy or the second virtual private proxy to entities other than the first entity and the second entity of the agreement.

5. The method for secure communication according to claim 1 , wherein the agreement indicates allowable types of data.

6. The method for secure communication according to claim 5 , wherein the agreement further indicates a transport protocol and a transport security protocol.

7. The method for secure communication according to claim 6 , wherein the agreement further indicates process specification information.

8. A system for secure communication comprising:

a processor having access to processor executable instructions, stored on a memory medium, the instructions including instructions to:

receive a first profile from a first entity, the first profile indicating electronic commerce information, including a first document exchange protocol, pertaining to the first entity;

receive a second profile from a second entity, the second profile indicating electronic commerce information, including a second document exchange protocol, pertaining to the second entity;

automatically generate an agreement based on the first profile and the second profile, wherein the agreement includes information pertaining to electronic commerce transactions between the first and second entities;

generate a first virtual private proxy and a second virtual private proxy;

establish a first secure communication between the first virtual private proxy and the first entity and establish a second secure connection between the second virtual private proxy and the second entity;

establish a logical connection between the first virtual private proxy and the second virtual private proxy;

monitor data at least one of the first virtual private proxy and the second virtual private proxy;

determine whether the data violates the agreement; and

disallow communication of the data from the first virtual private proxy to the second virtual private proxy when the data violates the agreement;

wherein the instructions to establish the first secure connection include instructions to establish a secure connection with a private session manager of the first entity wherein said private session manager excludes all other remote connections to the first entity.

9. The system for secure communication according to claim 8 , wherein the agreement further comprises a transport protocol indication and a transport security protocol indication.

10. The system for secure communication according to claim 9 , wherein the agreement indicates a document exchange protocol indication and a process specification.

11. The system for secure communication according to claim 8 , wherein the instructions to determine whether the data violates the agreement determine whether the data includes an intrusion attempt.

12. The system for secure communication according to claim 8 , wherein the instructions to determine whether the data violates the agreement determine whether the data includes a virus or malicious program.

13. A non-transitory computer readable medium, including a computer program, executable by a processor, for:

receiving a first profile from a first entity, the first profile indicating electronic commerce information, including a first document exchange protocol, pertaining to the first entity;

receiving a second profile from a second entity, the second profile indicating electronic commerce information, including a second document exchange protocol, pertaining to the second entity;

automatically generating an agreement based on the first profile and the second profile, wherein the agreement includes information pertaining to electronic commerce transactions between the first and second entities;

generating a first virtual private proxy and a second virtual private proxy;

establishing a first secure connection between the first virtual private proxy and the first entity and establishing a second secure connection between the second virtual private proxy and the second entity;

establishing a logical connection between the first virtual private proxy and the second virtual private proxy;

monitoring data at least one of the first virtual private proxy and the second virtual private proxy;

determining whether monitored data violates the agreement; and

disallowing communication of the monitored data between the first virtual private proxy and the second virtual private proxy when the data violates the agreement;

wherein establishing the first secure connection includes establishing a secure connection with a private session manager of the first entity wherein said private session manager excludes all other remote connections to the first entity.

14. The computer readable medium of claim 13 , wherein the document exchange protocol comprises an electronic data interchange (EDI) compliant protocol.

15. The computer readable medium of claim 13 , wherein the first virtual private proxy comprises a logical access point at a secure switch to the first secure connection and wherein the second virtual private proxy comprises a logical access point at the secure switch to the second secure connection.

16. The computer readable medium of claim 13 , wherein the first virtual private proxy comprises a logical representation of a hard-wired access point at a secure switch for a fiber optic connection between the secure switch and the first entity.

17. The computer readable medium of claim 13 , wherein the agreement further indicates process specification information indicative of businesses processes of at least one of the first entity and the second entity.

18. The computer readable medium of claim 17 , wherein the process specific information indicates roles, message payloads, message sequence, and operation signals supported by the business processes.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056396/0942 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: IBM TECHNOLOGY CORPORATION
To: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
Reel/Frame 053452/0537 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOULY LISTED PATENT ON THE SCHEDULE A. PATENT NUMBER 7,792,767 WAS REMOVED FROM THE SCHEDULE A. PREVIOUSLY RECORDED AT REEL: 051170 FRAME: 0255. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 19, 2020
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 052190/0394 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTEDPATENT ON THE SCHEDULE A. PATENT NUMBER 7,792,767WAS REMOVED FROM THE SCHEDULE A PREVIOUSLY RECORDED ON REEL 051170 FRAME 0722. ASSIGNOR(S) HEREBY CONFIRMS THE PATENTNUMBER 7,792,767 WAS ERRONEOUSLY LISTED ON THESCHEDULE A. Recorded Mar 19, 2020
From: IBM INTERNATIONAL L.P.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 052190/0464 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUS LISTED PATENT NUMBER 7,792,767 ON THE SCHEDULE A PREVIOUSLY RECORDED AT REEL: 051170 FRAME: 0745. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 19, 2020
From: IBM INTERNATIONAL C.V.
To: IBM INTERNATIONAL L.P.
Reel/Frame 052190/0986 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 051170/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL L.P.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 051170/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL C.V.
To: IBM INTERNATIONAL L.P.
Reel/Frame 051170/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: STERLING COMMERCE, INC.
To: IBM INTERNATIONAL GROUP, B.V.
Reel/Frame 030758/0376 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2013
From: STERLING COMMERCE, INC.
To: IBM INTERNATIONAL GROUP B.V.
Reel/Frame 030662/0729 →