IP Library Granted Patent US 10,666,688
Granted Patent B2
US 10,666,688 · App. 16/299,087 · Granted May 26, 2020

Systems and methods for providing network security using a secure digital device

Inventor: Omar Nathaniel Ely (Paris, FR)
Assignee: CUPP Computing AS
H04L63/20H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,688
App. No.
16/299,087
Granted
May 26, 2020
Kind
B2
Abstract

A system may include a traffic interception module configured to intercept network traffic of a host device. A traffic virtualization module may be configured to generate a virtual file on the host device containing the intercepted network traffic. A security system interface module may be configured to provide the virtual file to a secure digital security system over a virtualized file interface coupling the host device to the secure digital security system, and to receive instructions to allow or to deny the network traffic from the secure digital security system over the virtualized file interface. A traffic access management module may be configured to allow or to deny the network traffic based on the instructions.

Claims (66)

1. A secure digital security system comprising:

a data store;

a file management module configured to receive a transfer file from a host device over a virtual file interface configured to assist in transferring data at file transfer speeds between the host device and the secure digital security system, the transfer file possibly containing a data store command or a virtual file containing network traffic intercepted at the host device, the transfer file including header information indicating whether the transfer file includes the data store command or the virtual file containing the network traffic, the network traffic including one of incoming network traffic to the host device or outgoing network traffic from the host device, the data store command including a particular command to retrieve or store data in the data store;

a controller configured to manage the data store command by retrieving or storing the data in the data store;

a security policy management module configured to evaluate the network traffic in the virtual file for compliance with a security policy;

a traffic access determination module configured to generate a security indication whether to allow or to deny the network traffic in accordance with the evaluation; and

a module configured to provide to the host device over the virtual file interface the security indication whether to allow or to deny the network traffic.

2. The secure digital security system of claim 1 , wherein the virtual file comprises one or more encrypted virtual files.

3. The secure digital security system of claim 1 , wherein the secure digital security system is incorporated into a Secure Digital (SD) card coupled to the host device.

4. The secure digital security system of claim 1 , wherein the host device comprises a portable electronic device.

5. The secure digital security system of claim 1 , wherein the virtual file includes one or more data packets, and the header information is located within each data packet.

6. A method in a secure digital security system, the secure digital security system including a data store and at least one security engine, the method comprising:

receiving a transfer file from a host device over a virtual file interface configured to transfer data at file transfer speeds, the transfer file possibly containing a data store command or a virtual file containing network traffic intercepted at the host device, the transfer file including header information indicating whether the transfer file includes the data store command or the virtual file containing the network traffic, the network traffic including one of incoming network traffic to the host device or outgoing network traffic from the host device, the data store command including a particular command to retrieve or store data in the data store;

if the header information indicates that the transfer file includes the data store command, then

receiving the data store command;

managing the data store command by retrieving or storing the data in the data store;

if the header information indicates that the transfer file includes the virtual file containing the network traffic, then

using the at least one security engine to evaluate the network traffic in the virtual file for compliance with a security policy;

generating a security indication whether to allow or to deny the network traffic in accordance with the evaluation; and

providing to the host device the security indication whether to allow or to deny the network traffic.

7. The method of claim 6 , wherein the virtual file comprises one or more encrypted virtual files.

8. The method of claim 6 , wherein the secure digital security system is incorporated into a Secure Digital (SD) card coupled to the host device.

9. The method of claim 6 , wherein the host device comprises a portable electronic device.

10. The method of claim 6 , wherein the virtual file includes one or more data packets, and the header information is located within each data packet.

11. A system comprising:

a host device including:

at least one processor;

a virtual file interface configured to assist in transferring file data at file transfer speeds to a secure digital security system, the secure digital security system including a security engine configured to conduct a security process on network traffic; and

memory storing computer instructions, the computer instructions configured to cause the at least one processor to:

receive a data store command including a particular command to retrieve or store data in a data store;

intercept network traffic, the intercepted network traffic including one of incoming network traffic to the host device or outgoing network traffic from the host device;

package the intercepted network traffic as one or more virtual files containing the intercepted network traffic, the one or more virtual files including header information, the header information indicating that the one or more virtual files contain intercepted network traffic and not file data;

provide the one or more virtual files with the header information to the virtual file interface, the virtual file interface configured to assist in transferring the one or more virtual files with the header information as the file data at the file transfer speeds to the secure digital security system, the secure digital security system configured to use the header information to determine whether the one or more virtual files contain intercepted network traffic, the secure digital security system further configured to conduct the security process on the intercepted network traffic contained in the one or more virtual files and to generate a security indication indicating whether the intercepted network traffic is deemed safe according to the security process;

receive the security indication from the secure digital security system; and

allow the system to process the intercepted network traffic when the security indication indicates that the intercepted network traffic is safe according to the security process;

the secure digital security system comprising:

the data store;

a controller configured to manage the data store command by retrieving or storing the data in the data store;

a file management module configured to receive the one or more virtual files from the host device over the virtual file interface;

a security policy management module configured to evaluate the network traffic in the one or more virtual files for compliance with a security policy;

a traffic access determination module configured to generate the security indication whether to allow or to deny the network traffic in accordance with the evaluation; and

a module configured to provide to the host device over the virtual file interface the security indication whether to allow or to deny the network traffic.

12. The system of claim 11 , wherein the secure digital security system is a secure digital (SD) card.

13. The system of claim 11 , wherein the computer instructions configured to cause the at least one processor to intercept the network traffic include computer instructions configured to cause the at least one processor to monitor application-level processes.

14. The system of claim 13 , wherein the computer instructions configured to cause the at least one processor to monitor the application-level processes include computer instructions configured to cause the at least one processor to monitor for network calls from one or more applications.

15. The system of claim 11 , wherein the computer instructions configured to cause the at least one processor to intercept the network traffic include computer instructions configured to cause the at least one processor to monitor root-level processes.

16. The system of claim 11 , wherein the computer instructions configured to cause the at least one processor to package the intercepted network traffic as the one or more virtual files include computer instructions configured to cause the at least one processor to use virtual private network (VPN) tables to package the intercepted network traffic as the one or more virtual files.

17. The system of claim 11 , wherein the one or more virtual files include a plurality of data packets, and the header information is located within each packet.

18. The system of claim 11 , wherein the computer instructions are further configured to cause the at least one processor to encrypt the one or more virtual files before the one or more virtual files are transferred to the secure digital security system.

19. A method comprising:

receiving a data store command by a host device, the data store command including a particular command to retrieve or store data in a data store, the host device including at least one processor and a virtual file interface configured to assist in transferring file data at file transfer speeds to a secure digital security system, the secure digital security system including the data store and including a security engine configured to conduct a security process on network traffic;

intercepting network traffic by the host device, the intercepted network traffic including one of incoming network traffic to the host device or outgoing network traffic from the host device;

packaging by the host device the intercepted network traffic as one or more virtual files containing the intercepted network traffic, the one or more virtual files including header information, the header information indicating that the one or more virtual files contain intercepted network traffic and not file data;

providing by the host device the one or more virtual files with the header information to the virtual file interface, the virtual file interface assisting in transferring the one or more virtual files with the header information as the file data at the file transfer speeds to the secure digital security system;

receiving by the secure digital security system the one or more virtual files from the host device over the virtual file interface;

using by the secure digital security system the header information to determine that the one or more virtual files contain intercepted network traffic;

evaluating by the secure digital security system the network traffic in the one or more virtual files for compliance with a security policy;

generating by the secure digital security system a security indication whether to allow or to deny the network traffic in accordance with the evaluation;

providing by the secure digital security system to the host device over the virtual file interface the security indication whether to allow or to deny the network traffic;

receiving by the host device the security indication from the secure digital security system; and

processing by the host device the intercepted network traffic when the security indication indicates that the intercepted network traffic is safe according to the security process.

20. The method of claim 19 , wherein the intercepting the network traffic includes monitoring application-level processes.

21. The method of claim 20 , wherein the monitoring the application-level processes includes monitoring for network calls from one or more applications.

22. The method of claim 19 , wherein the intercepting the network traffic includes monitoring root-level processes.

23. The method of claim 19 , wherein the packaging the intercepted network traffic as the one or more virtual files includes using virtual private network (VPN) tables to package the intercepted network traffic as the one or more virtual files.

24. The method of claim 19 , wherein the one or more virtual files include a plurality of data packets, and the header information is located within each packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2019
From: ELY, OMAR NATHANIEL
To: CUPP COMPUTING AS
Reel/Frame 048566/0437 →
Continuity (5)
Continuation 15701365 · Sep 11, 2017
Continuation 14622764 · Feb 13, 2015
Provisional Application 61939644 · Feb 13, 2014
Provisional Application 61943364 · Feb 22, 2014
Related Publication 20190207984A1 · Jul 4, 2019
Cited By (5)
US 12,192,170 US 12,255,926 US 12,301,574 US 12,314,396 US 12,380,476