IP Library Granted Patent US 7,900,249
Granted Patent B2
US 7,900,249 · App. 12/256,999 · Granted Mar 1, 2011

Method, system and software for maintaining network access and security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,900,249
App. No.
12/256,999
Granted
Mar 1, 2011
Kind
B2
Abstract

A system, method and apparatus for securing communications between a trusted network and an untrusted network are disclosed. A perimeter client is deployed within the trusted network and communicates over a session multiplexing enabled protocol with a perimeter server deployed within a demilitarized zone network. The perimeter client presents requests to make available and communication initiation requests to the perimeter server which presents corresponding sockets to the entrusted network. The session multiplexing capabilities of the protocol used between the perimeter server and perimeter client permit a single communication session therebetween to support a plurality of communication sessions between the perimeter server and untrusted network. In the event data flows across the communication sessions are encrypted, decryption of the data flows is left to the components at the end points of the communication session, thereby restricting exposure of privileged information to areas within trusted networks.

Claims (54)

1. A software for facilitating communications between a trusted network and a untrusted network, the software embodied in non-transitory computer readable storage media and when executed, by a processor, operable to direct a computer to:

establish at least one communication session between a trusted network and a demilitarized (DMZ) network, the at least one communication session operating on a protocol P operable to facilitate communication transactions between the DMZ network and the trusted network;

receive a request from a perimeter client operated within the trusted network to initiate a communication connection to an untrusted network component through the at least one communication session between the trusted network and the DMZ network;

convert the request for communication connection initiation to a protocol P format;

communicate the request to initiate a communication connection to a perimeter server operated within the DMZ network, the perimeter server operable to connect the trusted network component and the untrusted network component via the at least one communication session and to receive communication from the untrusted network component, wrap the untrusted network component communications in protocol P and communicate the untrusted network component communication via protocol P to the trusted network;

receive a request to make the perimeter client available for communication with the untrusted network;

convert the request to make the perimeter client available to protocol P;

communicate the request to make available to the perimeter server using protocol P and the established communication session, the perimeter server operable to present one or more passive sockets for communication to the untrusted network, await communication on the one or more passive sockets from one or more untrusted network components, upon receipt of a communication from an untrusted network component convert the untrusted network component communication to protocol P and communicate the untrusted network component communication to the trusted network using protocol P via the perimeter server and the perimeter client;

unwrap untrusted network component communications from protocol P; and

direct the untrusted network component communication to its trusted network destination, the trusted network destination operable to perform necessary cryptographic operations on the untrusted network component communication.

2. A method for providing network security between a trusted network and an untrusted network, comprising:

configuring at least one processor to perform the steps of:

establishing at least one communication session between the trusted network and a demilitarized (DMZ) network, the at least one communication session operating on a protocol P operable to facilitate communication transactions between the DMZ network and the trusted network;

receiving a request from a perimeter client operated within the trusted network to initiate a communication connection to an untrusted network component through the at least one communication session between the trusted network and the DMZ network;

converting the request for communication connection initiation to a protocol P format;

communicating the request to initiate a communication connection to the perimeter server operated within the DMZ network, the perimeter server operable to connect the trusted network component and the untrusted network component via the at least one communication session and to receive communication from the untrusted network component, wrap the untrusted network component communications in protocol P and communicate the untrusted network component communication via protocol P to the trusted network;

receiving a request to make the perimeter client available for communication with the untrusted network;

converting the request to make the perimeter client available to protocol P;

communicating the request to make the trusted network component available to the perimeter server using protocol P and the established communication session, the perimeter server operable to present one or more passive sockets for communication to the untrusted network, await communication on the one or more passive sockets from one or more untrusted network components, upon receipt of a communication from an untrusted network component convert the untrusted network component communication to protocol P and communicate the untrusted network component communication to the trusted network using protocol P via the perimeter server and the perimeter client;

unwrapping untrusted network component communications from protocol P; and

directing the untrusted network component communication to its trusted network destination, the trusted network destination operable to perform necessary cryptographic operations on the untrusted network component communication.

3. The method of claim 2 , further comprising establishing the at least one communication session between the perimeter server and the trusted network via the perimeter client.

4. The method of claim 2 , further comprising enabling a plurality of TCP/IP communication sessions within each communication session maintained between the perimeter server and the perimeter client within the trusted network.

5. The method of claim 2 , further comprising:

receiving, in the perimeter server, communication connection requests from one or more untrusted network components;

wrapping the received communication connection requests in protocol P by the perimeter server; and

communicating the communication connection requests to the perimeter client via the one or more communication sessions using protocol P and over the communication session maintained between the perimeter server and the trusted network.

6. The method of claim 5 , further comprising:

unwrapping the communication connection request from protocol P; and

forwarding the unwrapped communication connection requests to it trusted network destination.

7. The method of claim 6 , further comprising effecting one or more security operations on the communication connection request by the trusted network component within the trusted network.

8. The method of claim 2 , further comprising implementing transport level security over protocol P in the perimeter server and the perimeter client.

9. The method of claim 2 , further comprising limiting initiation of communications between the trusted and untrusted networks to communication initiation requests received from communication participant components within the trusted or untrusted network.

10. A system for maintaining secure communications between a trusted network and an untrusted network, comprising:

memory;

at least one processor operably coupled to the memory;

at least one communications interface operably associated with the memory and the processor;

a perimeter client operable within the trusted network;

a perimeter server operable within a demilitarized zone network; wherein at least one communication session is established between the trusted network and a demilitarized (DMZ) network, the at least one communication session operating on a protocol P operable to facilitate communication transactions between the DMZ network and the trusted network;

a request from a perimeter client operated within the trusted network is received to initiate a communication connection to an untrusted network component through the at least one communication session between the trusted network and the DMZ network;

the request for communication connection initiation is converted to a protocol P format;

the request to initiate a communication connection is communicated to the perimeter server operated within the DMZ network, wherein the perimeter server is operable to connect the trusted network component and the untrusted network component via the at least one communication session and to receive communication from the untrusted network component, wrap the untrusted network component communications in protocol P and communicate the untrusted network component communication via protocol P to the trusted network;

a request to make the perimeter client available for communication with the untrusted network is received;

the request from the perimeter client to make the trusted network component available is converted to protocol P;

the request to make the trusted network component available is communicated to the perimeter server using protocol P and the established communication session, the perimeter server operable to present one or more passive sockets for communication to the untrusted network, await communication on the one or more passive sockets from one or more untrusted network components, upon receipt of a communication from an untrusted network component convert the untrusted network component communication to protocol P and communicate the untrusted network component communication to the trusted network using protocol P via the perimeter server and the perimeter client;

the untrusted network component communications is unwrapped from protocol P; and

the untrusted network component communication is directed to its trusted network destination, the trusted network destination operable to perform necessary cryptographic operations on the untrusted network component communication.

11. The system of claim 10 , further comprising the perimeter client operable to enable one or more transport level security measures on communications with the perimeter server.

12. The system of claim 10 , further comprising the perimeter client operable to establish the one or more communication connections with the perimeter server.

13. The system of claim 10 , further comprising the perimeter client operable to receive trusted network component requests to make available, wrap the requests in protocol P, and forward the wrapped requests to the perimeter server for processing.

14. The system of claim 10 , further comprising the perimeter client operable to receive trusted network component outward bound untrusted network component connection requests, wrap the requests in protocol P, and forward the wrapped requests to the perimeter server for processing.

15. The system of claim 10 , further comprising the perimeter client operable to unwrap the untrusted network component communication connection requests received from the perimeter server from protocol P and forward the unwrapped communication connection requests to a trusted network component destination.

16. The system of claim 10 , further comprising the perimeter client operable to manage a plurality of TCP/IP communication sessions over each communication session between the perimeter client and the perimeter server.

17. The system of claim 10 , further comprising the perimeter client operable to restrict communication initiation to trusted network and untrusted network component communication participant initiation requests.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056396/0942 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: IBM TECHNOLOGY CORPORATION
To: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
Reel/Frame 053452/0537 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTEDPATENT ON THE SCHEDULE A. PATENT NUMBER 7,792,767WAS REMOVED FROM THE SCHEDULE A PREVIOUSLY RECORDED ON REEL 051170 FRAME 0722. ASSIGNOR(S) HEREBY CONFIRMS THE PATENTNUMBER 7,792,767 WAS ERRONEOUSLY LISTED ON THESCHEDULE A. Recorded Mar 19, 2020
From: IBM INTERNATIONAL L.P.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 052190/0464 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOULY LISTED PATENT ON THE SCHEDULE A. PATENT NUMBER 7,792,767 WAS REMOVED FROM THE SCHEDULE A. PREVIOUSLY RECORDED AT REEL: 051170 FRAME: 0255. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 19, 2020
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 052190/0394 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUS LISTED PATENT NUMBER 7,792,767 ON THE SCHEDULE A PREVIOUSLY RECORDED AT REEL: 051170 FRAME: 0745. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 19, 2020
From: IBM INTERNATIONAL C.V.
To: IBM INTERNATIONAL L.P.
Reel/Frame 052190/0986 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL L.P.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 051170/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 051170/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2019
From: IBM INTERNATIONAL C.V.
To: IBM INTERNATIONAL L.P.
Reel/Frame 051170/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2011
From: STERLING COMMERCE, INC.
To: IBM INTERNATIONAL GROUP BV
Reel/Frame 027024/0247 →
NUNC PRO TUNC ASSIGNMENT Recorded Sep 23, 2010
From: AT&T INTELLECTUAL PROPERTY I, L.P.
To: STERLING COMMERCE, INC.
Reel/Frame 025066/0336 →
CHANGE OF NAME Recorded Dec 10, 2008
From: AT&T KNOWLEDGE VENTURES, L.P.
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 021955/0499 →
CHANGE OF NAME Recorded Dec 4, 2008
From: SBC KNOWLEDGE VENTURES, L.P.
To: AT&T KNOWLEDGE VENTURES, L.P.
Reel/Frame 021925/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2008
From: BURCHAM, BILL; CHERIAN, SANJAY; SHAFFER, DARRON
To: SBC KNOWLEDGE VENTURES, L.P.
Reel/Frame 021839/0283 →