IP Library Granted Patent US 9,380,023
Granted Patent B2
US 9,380,023 · App. 14/018,085 · Granted Jun 28, 2016

Enterprise cross-domain solution having configurable data filters

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,380,023
App. No.
14/018,085
Granted
Jun 28, 2016
Kind
B2
Abstract

A cross-domain system for transferring files from a client to a server. A first server in the first network domain receives and stores files from the client via the first network. The received files are processed based on predetermined instructions stored in an associated file. The processed received files are transmitted to a second server via a one-way data link. The second server in the second network domain receives and stores the processed received files. The received files are further processed based on predetermined instructions stored in an associated file. The further processed received files are transmitted to the server via the second network. The two associated files are stored in permanent memory with security policies which prevent the files from disrupting operation of the first and second servers, respectively. The security policies allow the associated files to be overwritten to update the processing performed by the associated server.

Claims (34)

1. A cross-domain system for transferring files from a client coupled to a first network in a first network domain to a server coupled to a second network in a second network domain, the cross-domain system comprising:

a first server in the first network domain having an input adapted to receive files from the client via the first network and store the received files in a first temporary memory, the first server configured to process the received files based on predetermined instructions stored in at least one associated first file stored in a first permanent memory, the first server also having an output for transmitting the processed received files;

a one-way data link having an input coupled to the output of the first server and an output; and

a second server in the second network domain having an input adapted to receive the processed received files from the first server via the one-way data link and store the received files in a second temporary memory, the second server configured to further process the received files based on predetermined instructions stored in at least one associated second file stored in a second permanent memory, the second server also having an output adapted to transmit the further processed received files to the server via the second network;

wherein the first server is configured to store the at least one associated first file in the first permanent memory with first security policies which prevent the at least one associated first file from disrupting operation of the first server;

wherein the second server is configured to store the at least one associated second file in the second permanent memory with second security policies which prevent the at least one associated second file from disrupting operation of the second server;

wherein the first and second servers are configured to allow the at least one associated first file and the at least one associated second file to be overwritten to update the processing performed by the first server and the second server, respectively, while maintaining the respective security policies applied to such files.

2. The system of claim 1 , wherein the first permanent memory and the second permanent memory each constitute a hard disk.

3. The system of claim 1 , wherein the processing performed by the first server constitutes filtering.

4. The system of claim 3 , wherein the at least one associated first file contains instructions which cause all files to be blocked from being transmitted on the output of the first server.

5. The system of claim 3 , wherein the at least one associated first file contains instructions for filtering the received file based on predetermined criteria specified by a customer.

6. The system of claim 1 , wherein the processing performed by the second server constitutes filtering.

7. The system of claim 6 , wherein the at least one associated second file contains instructions which cause all files to be blocked from being transmitted on the output of the second server.

8. The system of claim 6 , wherein the at least one associated second file contains instructions for filtering the received file based on predetermined criteria specified by a customer.

9. A cross-domain system for transferring files from a client coupled to a first network in a first network domain to a server coupled to a second network in a second network domain, the cross-domain system comprising:

a first server in the first network domain having an input adapted to receive files from the client via the first network and store the received files in a first temporary memory, the first server configured to process the received files based on predetermined instructions stored in at least one associated first file stored in a first permanent memory, the first server also having an output for transmitting the processed received files;

a one-way data link having an input coupled to the output of the first server and an output; and

a second server in the second network domain having an input adapted to receive the processed received files from the first server via the one-way data link and store the received files in a second temporary memory, the second server also having an output adapted to transmit the received files to the server via the second network;

wherein the first server is configured to store the at least one associated first file in the first permanent memory with security policies which prevent the at least one associated first file from disrupting operation of the first server;

wherein the first server is configured to allow the at least one associated first file to be overwritten to update the processing performed by the first server, while maintaining the security policies applied to such file.

10. The system of claim 9 , wherein the first permanent memory and the second permanent memory each constitute a hard disk.

11. The system of claim 9 , wherein the processing performed by the first server constitutes filtering.

12. The system of claim 11 , wherein the at least one associated first file contains instructions which cause all files to be blocked from being transmitted on the output of the first server.

13. The system of claim 11 , wherein the at least one associated first file contains instructions for filtering the received file based on predetermined criteria specified by a customer.

14. A cross-domain system for transferring files from a client coupled to a first network in a first network domain to a server coupled to a second network in a second network domain, the cross-domain system comprising:

a first server in the first network domain having an input adapted to receive files from the client via the first network and store the received files in a first temporary memory, the first server also having an output for transmitting the received files;

a one-way data link having an input coupled to the output of the first server and an output; and

a second server in the second network domain having an input adapted to receive the received files from the first server via the one-way data link and store the received files in a second temporary memory, the second server configured to process the received files based on predetermined instructions stored in at least one associated second file stored in a second permanent memory, the second server also having an output adapted to transmit the processed received files to the server via the second network;

wherein the second server is configured to store the at least one associated second file in the second permanent memory with security policies which prevent the at least one associated second file from disrupting operation of the second server;

wherein the second server is configured to allow the at least one associated second file to be overwritten to update the processing performed by the second server, while maintaining the security policies applied to such file.

15. The system of claim 14 wherein the first permanent memory and the second permanent memory each constitute a hard disk.

16. The system of claim 14 , wherein the processing performed by the second server constitutes filtering.

17. The system of claim 16 , wherein the at least one associated second file contains instructions which cause all files to be blocked from being transmitted on the output of the second server.

18. The system of claim 16 , wherein the at least one associated second file contains instructions for filtering the received file based on predetermined criteria specified by a customer.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 041136, FRAME 0223 Recorded Sep 11, 2024
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 068945/0922 →
SECURITY INTEREST Recorded Sep 11, 2024
From: OWL CYBER DEFENSE SOLUTIONS, LLC
To: RGA REINSURANCE COMPANY
Reel/Frame 068938/0313 →
MERGER AND CHANGE OF NAME Recorded Sep 2, 2022
From: OWL CYBER DEFENSE SOLUTIONS, LLC; TRESYS TECHNOLOGY, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 060978/0964 →
CHANGE OF NAME Recorded Jun 20, 2017
From: OWL COMPUTING TECHNOLOGIES, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 042902/0582 →
CORRECTIVE ASSIGNMENT TO CORRECT TO REMOVE THIS DOCUMENT SERVES AS AN OATH/DECLARATION (37 CFR 1.63) FROM THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 041765 FRAME: 0034. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER EFFECTIVE DATE 02/03/2017. Recorded Apr 21, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 042344/0033 →
MERGER Recorded Mar 28, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 041765/0034 →
SECURITY INTEREST Recorded Jan 31, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 041136/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2013
From: MRAZ, RONALD; HOPE, JAMES
To: OWL COMPUTING TECHNOLOGIES, INC.
Reel/Frame 031137/0228 →