US2008209560A1PendingUtilityA1

Active intrusion resistant environment of layered object and compartment key (airelock)

Individually held — no corporate assignee on recordPriority: Nov 15, 2000Filed: May 15, 2007Published: Aug 28, 2008
Est. expiryNov 15, 2020(expired)· nominal 20-yr term from priority
Inventors:Michael C. Dapp
H04L 63/20H04L 63/1416
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure infrastructure system and method with user transparent signaling for communicating detection of signals at a network node having characteristics of a potential attack and for controlling communications at a node from another node in response to the user transparent signals. A processor is connected to routers and the network through an encryption engine and includes a manager object to issue control commands to nodes of a locally lower hierarchical tier and managed objects to detect potential attacks and exercise control over the routers responsive to signals from a node of a locally higher hierarchical tier. Faults or potential attacks are compartmentalized to a node or sector of the network and isolated while normal communications are continued over redundant network links.

Claims

exact text as granted — not AI-modified
1 - 10 . (canceled) 
   
   
       11 . A digital network comprising:
 a plurality of nodes connected to said digital network;   at least two locking devices associated with each of said plurality of nodes;   a security policy manager device associated with respective pairs of said at least two locking devices, said security policy manager device configured to detect network activity having characteristics different from characteristics of normal usage and providing a user transparent signal to at least one other node of said plurality of nodes; and   means responsive to a user transparent signal received from at least one other of said plurality of nodes for controlling said at least two locking devices to isolate said at least one other of said plurality of nodes by selecting redundant communication paths in said digital network to maintain network communications between other, non-isolated nodes in said digital network.   
   
   
       12 . A digital network as recited in  claim 11 , further including a memory which stores information corresponding to said user transparent signals. 
   
   
       13 . A digital network as recited in  claim 11 , wherein said means responsive to a user transparent signal controls said locking devices to isolate said other of said plurality of nodes of said digital network in real time. 
   
   
       14 . A digital network as recited in  claim 11 , wherein said plurality of nodes are hierarchically arranged locally in said digital network. 
   
   
       15 . A digital network as recited in  claim 11 , further including means for defining a secure session between said plurality of nodes. 
   
   
       16 . A digital network as recited in  claim 15 , wherein said means for defining a secure session includes means for transmitting information corresponding to one of an authenticated user and an identification of a communicating node. 
   
   
       17 . A digital network as recited in  claim 11 , wherein said characteristics which differ from characteristics of normal usage are characteristics of a potential attack. 
   
   
       18 . A digital network as recited in  claim 11 , wherein said characteristics which differ from characteristics of normal usage correspond to a fault at said associated node or link of said digital network. 
   
   
       19 . A digital network as recited in  claim 11 , wherein said programmed data processor includes a manager object and at least one managed object corresponding to each said connected node. 
   
   
       20 . A method of operating a digital network including the steps of:
 detecting communications having characteristics differing from characteristics of normal usage at a node of said digital network;   communicating a user transparent signal to another node also configured to detect communications having characteristics differing from characteristics of normal usage, in response to said detecting step;   controlling communications at said node from said another node in response to said user transparent signal.   
   
   
       21 . A method as recited in  claim 20 , wherein said step of controlling communications includes steps of:
 isolating said node from said network to encapsulate said communications having characteristics differing from normal usage, and routing other communications in said digital network through redundant links between nodes of said digital network.   
   
   
       22 . A method as recited in  claim 20 , wherein said detecting step is performed by a managed object associated with a node of said digital network and said controlling step is performed responsive to a managed object at said another node of said digital network. 
   
   
       23 . A method as recited in  claim 20 , wherein said detecting, communicating and controlling steps are performed substantially in real time. 
   
   
       24 . A method as recited in  claim 20 , further including a step of defining a secure session between a plurality of pairs of connected nodes in a communication path in said digital network. 
   
   
       25 . The digital network of  claim 11 , wherein the security policy manager further comprises:
 a programmed data processor including a memory to store data corresponding to said user transparent communications;   a manager object; and   at least one managed object;   wherein each said locking device is provided in communication with the other locking devices and is configured to interrupt communication to said at least one other node.   
   
   
       26 . The digital network of  claim 25 , wherein the security policy manager device further comprises a first network port and a second network port. 
   
   
       27 . The digital network of  claim 26 , wherein said controlling routing of communications includes isolating said first node of said digital network by selectively controlling one of the locking devices such that communication with the first node is restricted. 
   
   
       28 . The digital network of  claim 27 , wherein said isolating the first node of said digital network is performed in real time. 
   
   
       29 . The digital network of  claim 15 , wherein said means for defining a secure session includes a communication module configured to transmit information corresponding to one of an authenticated user and an identification of a communicating node, wherein the identification of the communicating node can be used to isolate nodes corresponding to the secure session. 
   
   
       30 . A heterogeneous digital network comprising:
 a router interface comprising a plurality of router network interface controllers; and   one or more trusted nodes, each said trusted node operably coupled to one of said router network interface controllers via a security policy manager device;   wherein at least one other router network interface controller is configured to communicate with a corresponding at least one untrusted node;   wherein the security policy manager device is associated with respective pairs of at least two locking devices associated with each said trusted node;   wherein said security policy manager device is configured to detect communications activity having characteristics different from characteristics of normal usage and, upon detection of communications activity having characteristics different from characteristics of normal usage occurring at a first trusted node, to output a first user transparent signal to at least a second trusted node; and   wherein the security policy manager device associated with said first trusted node is configured to control, in response to a second user transparent signal received from said second trusted node, said at least two locking devices to isolate said first trusted node by selecting redundant communication paths in said heterogeneous digital network to maintain network communications between other, non-isolated trusted nodes in said heterogeneous digital network, such that substantially full functionality is maintained for said heterogeneous digital network while the proliferation of an attack or of damage resulting therefrom is prevented within said trusted nodes.   
   
   
       31 . The heterogeneous digital network of  claim 30 , wherein said control of said at least two locking devices to isolate said first trusted node is performed substantially in real time. 
   
   
       32 . The heterogeneous digital network of  claim 30 , wherein at least said trusted nodes are hierarchically arranged locally in said heterogeneous digital network. 
   
   
       33 . The heterogeneous digital network of  claim 30 , further including means for defining at least one secure session among said trusted nodes, wherein said means for defining a secure session includes means for transmitting information corresponding to one of an authenticated user and an identification of a communicating node. 
   
   
       34 . The heterogeneous digital network of  claim 30 , wherein said characteristics which differ from characteristics of normal usage are characteristics of a potential attack.

Join the waitlist — get patent alerts

Track US2008209560A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.