Trusted network access control system and method
A trusted network access control system has a remote computing platform running an advisor. A first trusted network access control device is coupled to the remote computer by a network. A director is coupled to the first trusted network access control device and controls the first trusted network access control device.
1 . A trusted network access control system, comprising:
a remote computing platform running an advisor;
a first trusted network access control device coupled to the remote computing platform by a network; and
a director coupled to the first trusted network access control device controlling the first trusted network access control device.
2 . The system of claim 1 , further including:
a remote access controller coupled to the first trusted network access control device;
a second trusted network access control device coupled to the remote access controller.
3 . The system of claim 1 , further including a protected network coupled to the first trusted network access control device.
4 . The system of claim 2 , further including a protected network coupled to the second trusted network access control device.
5 . The system of claim 2 , wherein the director controls the second trusted network access control device.
6 . The system of claim 1 , wherein the advisor sends a trusted state information packet to the director.
7 . The system of claim 6 , wherein the director evaluates the trusted state information packet and sends a network access control information packet to the first trusted network access control device.
8 . The system of claim 1 , wherein the first network access control device is a router.
9 . A method of trusted network access control, comprising the steps of:
a) sending a trusted state information packet from a remote computing platform through a network to a director;
b) determining a level of access allowed by the remote computing platform at the director using the trusted state information packet; and
c) transmitting an access control information from the director to a trusted network access control device.
10 . The method of claim 9 , further including the step of:
d) when the remote computing platform is allowed access by the director, communicating between the remote computing platform and a device on a protected network.
11 . The method of claim 9 , further including the steps of:
d) when the remote computing platform is allowed access by the director, sending a remote access control information from the remote computer to a remote access controller;
e) when the remote computing platform is allowed access by the remote access controller, sending a second trusted state information packet to a second director.
12 . The method of claim 11 , further including the steps of:
f) transmitting an access control information from the second director to a second trusted network access control device including a remote computer identifier.
13 . The method of claim 9 , wherein step (c) further includes the step of:
c1) transmitting a location identifier.
14 . The method of claim 9 , wherein step (b) further includes the step of:
b) determining a level of trustworthiness.
15 . A method of trusted network access control, comprising the steps of:
a) requesting access to a protected network by a remote computer;
b) determining a trustworthiness of the remote computer by a network access controller; and
c) providing a level of access to the protected network by the remote computer.
16 . The method of claim 15 , wherein step (c) further includes the step of:
c1) denying access to the protected network by the remote computer.
17 . The method of claim 15 , wherein step (c) further includes the step of:
c1) allowing access to a part of the protected network by the remote computer.
18 . The method of claim 15 , wherein step (c) further includes the step of:
c1) allowing access to all of the protected network by the remote computer.
19 . The method of claim 15 , wherein step (b) further includes the steps of:
b1) determining a plurality of trust policies;
b2) evaluating by comparing a trust state of the remote computer to the plurality of trust policies.
20 . The method of claim 19 , further including the step of:
b3) when the trust state fails one of the plurality of trust policies, setting the level of access to no access.