Patent · US Active

High-assurance architecture for routing of information between networks of differing security level

US8161529B1 · kind B1 · utility

11Cited by
1References
24Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 19, 2007
Grant dateApr 17, 2012
Priority date
Expiry dateJun 20, 2030

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/101
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The present invention is directed to routing information between networks of differing security level. Communication to/from each network is handled by a dedicated Offload Engine (OE). Each OE interfaces to a Guard Engine through a Guard Data Mover (GDM) and includes an interface for connecting to an external network. A first OE receives a data packet from a first network intended to be transmitted to a second network. The Guard Engine analyzes the data packet. The Guard Engine includes an ACL (Access Control List) which are rules data packets must meet before being passed onto a destination network. If allowed, the Guard Engine delivers the data packet to the second network via a second OE utilizing a GDM associated with the first OE and a GDM associated with the second OE. The architecture of the present invention reduces the time and effort needed to attain high-assurance certification.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.