IP Library Granted Patent US 7,181,613
Granted Patent B2
US 7,181,613 · App. 10/854,602 · Granted Feb 20, 2007

System and method for providing secure internetwork services via an assured pipeline

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,181,613
App. No.
10/854,602
Granted
Feb 20, 2007
Kind
B2
Abstract

A system and method for the secure transfer of data between a workstation connected to a private network and a remote computer connected to an unsecured network. A secure computer is inserted into the private network to serve as the gateway to the unsecured network and a client subsystem is added to the workstation in order to control the transfer of data from the workstation to the secure computer. The secure computer includes a private network interface connected to the private network, an unsecured network interface connected to the unsecured network, wherein the unsecured network interface includes means for encrypting data to be transferred from the first workstation to the remote computer and a server function for transferring data between the private network interface and the unsecured network interface.

Claims (58)

1. A system comprising:

a processor;

a memory;

a first network interface;

a second network interface; and

software in the memory that is operable on the processor for causing the system to:

establish an assured pipeline between the first network interface and the second network interface;

encrypt outbound network traffic received on the first network interface;

send the encrypted outbound network traffic via the assured pipeline to the second network interface;

decrypt inbound network traffic received on the second network interface; and

send the inbound decrypted network traffic via the assured pipeline to the first network interface.

2. The system of claim 1 , wherein the software includes secure operating system software.

3. The system of claim 2 , wherein the system includes a virtual page translator having page access control bits and wherein the secure operating system software uses the page access control bits to ensure that file protection checks are not avoided.

4. The system of claim 2 , wherein the software establishing an assured pipeline includes software for performing a UNIX file permission check and software for performing a secure operating system permission check.

5. The system of claim 4 , wherein the secure operating system permission check is part of a system call.

6. The system of claim 2 , wherein the software establishing an assured pipeline includes software for performing a file permission check and wherein the secure operating system permission check is part of a system call.

7. The system of claim 2 , wherein a fork system call returns a child process that inherits domain attributes of a parent process.

8. The system of claim 1 , wherein the software implements a multilevel secure computer.

9. The system of claim 8 , wherein the system prevents execution of executable objects that have not been recognized as a trusted executable object.

10. The system of claim 1 , wherein the software implements a Type Enforcing Secure Computer.

11. The system of claim 10 , wherein the system prevents execution of executable objects that have not been recognized as a trusted executable object.

12. The system of claim 1 , wherein the system prevents execution of executable objects that have not been recognized as a trusted executable object.

13. The system of claim 12 , wherein the system includes a virtual page translator having page access control bits and wherein the secure operating system software uses the page access control bits to ensure that Type Enforcement checks are not avoided.

14. The system of claim 1 , wherein the first network interface is a wireless network interface.

15. A router comprising:

a processor;

a memory;

a first network interface;

a second network interface; and

a firewall program stored in the memory and operable on the processor for causing the router to:

implement a security policy program enforcing a Type Enforcement security mechanism to restrict access to network resources, wherein the Type Enforcement security mechanism establishes an assured pipeline for transfer of data and programs between the first and second network interfaces.

16. The router of claim 15 , wherein the router includes a virtual page translator having page access control bits and wherein the firewall program is further operable on the processor to use the page access control bits to ensure that resource protection checks are not avoided.

17. The router of claim 15 , wherein the firewall program is further operable on the processor to prevent access to executable objects that have not been recognized as a trusted executable object.

18. The router of claim 15 , wherein the network resources include data and programs.

19. The router of claim 15 , wherein the router further includes software in the memory that is operable on the processor for causing the router to:

run in either an administrative or operational state; and

disable the second network interface when in the administrative state and only accept commands from an authenticated client over the first network interface.

20. The router of claim 19 , wherein the router further includes software in the memory that is operable on the processor for causing the router to:

disable the Type Enforcement security mechanism when the router is in the administrative state.

21. The router of 15 , wherein the first network interface is a wireless network interface for wireless network communication.

22. A method for network protection, comprising:

establishing an assured pipeline between a first network interface and a second network interface;

encrypting outbound network traffic received on the first network interface;

sending the encrypted outbound network traffic via the assured pipeline to the second network interface;

decrypting inbound network traffic received on the second network interface; and

sending the inbound decrypted network traffic via the assured pipeline to the first network interface.

23. The method of claim 22 , further comprising: implementing a security policy to restrict access to network resources.

24. The method of claim 23 , wherein the security policy enforces a Type Enforcement security mechanism for transferring data and programs between the first and second networking interfaces.

25. The method of claim 24 wherein establishing an assured pipeline includes using page access control bits for ensuring Type Enforcement checks are performed.

26. The method of claim 23 wherein establishing an assured pipeline includes preventing execution of executable objects that have not been recognized as trusted executable objects.

27. The method of claim 22 , wherein establishing an assured pipeline includes preventing execution of executable objects that have not been recognized as trusted executable objects.

28. The method of claim 22 , wherein establishing an assured pipeline includes performing a file permission check.

29. The method of claim 22 , further comprising:

performing a fork system call; and

receiving as a return from the fork system call, a child process that inherits domain attributes of a parent process.

30. A machine readable medium containing executable instructions for implementing a security mechanism preventing execution of executable objects that have not been recognized as trusted executable objects and for implementing an assured pipeline based on the security mechanism, for transfer of data and programs between a first network interface and a second network interface.

31. The machine readable medium of claim 30 , wherein the security mechanism assigns processes to domains and restricts access of a process to data and programs as a function of the domain assigned the process.

32. The machine readable medium of claim 30 , wherein the security mechanism partitions the system to isolate security critical subsystems from non-security critical subsystems and restricts access to certain data to security critical subsystems.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
CHANGE OF NAME Recorded Jan 9, 2018
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 045029/0406 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →