IP Library Granted Patent US 9,391,957
Granted Patent B2
US 9,391,957 · App. 14/246,447 · Granted Jul 12, 2016

System and method for secure communication between domains

Inventor: Paul C. Clark (Bethesda, MD)
H04L63/0236G06F21/00G06F21/606H04L29/06H04L67/42H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,391,957
App. No.
14/246,447
Granted
Jul 12, 2016
Kind
B2
Abstract

A system and method of executing secure communications between first and second domains includes a first logical unit and a second logical unit. The first logical unit periodically calculates timestamps and hashes. The first logical unit also transmits a web form to a node of a first domain responsive to a request and the web form is displayed to a user. The first logical unit receives data input to said web form by the user and enhances the data by adding one or more security services. The first logical unit translates the received data from a first network application level protocol to a target network application level protocol while preserving said data security enhancements and transmits the translated data across a public network. A second logical unit de-enhances the translated data and filters the translated data data. The second logical unit further authorizes the filtered data and transmits the filtered data to a node of the second domain for use in an application.

Claims (39)

1. A method for secure communication between first and second domains comprising:

in a first logical unit:

periodically calculating timestamps and hashes;

transmitting a web form to a node of a first domain responsive to a request where the web form is displayed to a user;

receiving data input to the web form by the user;

enhancing the data by adding one or more security services;

translating the received data from a first network application level protocol to a target network application level protocol while preserving said data security enhancements;

transmitting the translated data across a public network, the first logical unit including a firewall and a protocol gateway that comprise a VPN server;

in a second logical unit:

de-enhancing the translated data;

filtering the translated data to block unauthorized transmissions;

authorizing the filtered data and transmitting the filtered data to a node of the second domain for use in an application;

whereby the one or more security services are added without apparent modification of the application.

2. A method for secure communication between first and second domains comprising:

In a first logical unit:

periodically calculating timestamps and hashes;

transmitting a web form to a node of a first domain responsive to a request where the web form is displayed to a user;

receiving data input to the web form by the user;

enhancing the data by adding one or more security services;

translating the received data from a first network application level protocol to a target network application level protocol while preserving said data security enhancements;

transmitting the translated data across a public network, the first logical unit residing on a first physical platform;

in a second logical unit:

de-enhancing the translated data;

filtering the translated data to block unauthorized transmissions;

authorizing the filtered data and transmitting the filtered data to a node of the second domain for use in an application, the second logical unit residing on a second logical platform;

whereby the one or more security services are added without apparent modification of the application.

3. A method for secure communication between first and second domains comprising:

In a first logical unit:

periodically calculating timestamps and hashes;

transmitting a web form to a node of a first domain responsive to a request where the web form is displayed to a user;

receiving data input to the web form by the user;

enhancing the data by adding one or more security services;

translating the received data from a first network application level protocol to a target network application level protocol while preserving said data security enhancements;

transmitting the translated data across a public network;

in a second logical unit:

de-enhancing the translated data;

filtering the translated data to block unauthorized transmissions;

authorizing the filtered data and transmitting the filtered data to a node of the second domain for use in an application, said first and second logical units residing on a physical platform;

whereby the one or more security services are added without apparent modification of the application.

Continuity (3)
Continuation 13532246 · Jun 25, 2012
Continuation 09568215 · May 9, 2000
Related Publication 20150074767A1 · Mar 12, 2015