U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Firewall providing enhanced network security and user transparency

Patent 5898830 Issued on April 27, 1999. Estimated Expiration Date: Icon_subject October 17, 2016. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Secure data processing system architecture with format control
Patent #: 4713753
Issued on: 12/15/1987
Inventor: Boebert ,   et al.

Method and apparatus for enhancing security of communications in a packet-switched data communications system
Patent #: 4799153
Issued on: 01/17/1989
Inventor: Hann ,   et al.

Interactive market management system
Patent #: 4799156
Issued on: 01/17/1989
Inventor: Shavit ,   et al.

Method and apparatus for protecting material on storage media and for transferring material on storage media to various recipients
Patent #: 5191611
Issued on: 03/02/1993
Inventor: Lang

One-time logon means and methods for distributed computing systems
Patent #: 5241594
Issued on: 08/31/1993
Inventor: Kung

Method and apparatus for key-management scheme for use with internet protocols at site firewalls
Patent #: 5416842
Issued on: 05/16/1995
Inventor: Aziz

Method of verifying identification data in data driven information processing system
Patent #: 5483661
Issued on: 01/09/1996
Inventor: Yoshida, et al.

System for increasing the difficulty of password guessing attacks in a distributed authentication scheme employing authentication tokens
Patent #: 5491752
Issued on: 02/13/1996
Inventor: Kaufman, et al.

Personal key archive
Patent #: 5495533
Issued on: 02/27/1996
Inventor: Linehan, et al.

Method of conducting secure operations on an uncontrolled network
Patent #: 5548721
Issued on: 08/20/1996
Inventor: Denslow

More ...

Inventors

Assignee

Application

No. 733361 filed on 10/17/1996

US Classes:

709/225, Computer network access regulating709/227COMPUTER-TO-COMPUTER SESSION/CONNECTION ESTABLISHING

Examiners

Primary: Palys, Joseph E.

Attorney, Agent or Firm

International Class

G06F 001/00

Abstract

The present invention, generally speaking, provides a firewall that achieves maximum network security and maximum user convenience. The firewall employs "envoys" that exhibit the security robustness of prior-art proxies and the transparency and ease-of-use of prior-art packet filters, combining the best of both worlds. No traffic can pass through the firewall unless the firewall has established an envoy for that traffic. Both connection-oriented (e.g., TCP) and connectionless (e.g., UDP-based) services may be handled using envoys. Establishment of an envoy may be subjected to a myriad of tests to "qualify" the user, the requested communication, or both. Therefore, a high level of security may be achieved. The usual added burden of prior-art proxy systems is avoided in such a way as to achieve fall transparency-the user can use standard applications and need not even know of the existence of the firewall. To achieve full transparency, the firewall is configured as two or more sets of virtual hosts. The firewall is, therefore, "multi-homed," each home being independently configurable. One set of hosts responds to addresses on a first network interface of the firewall. Another set of hosts responds to addresses on a second network interface of the firewall. In one aspect, programmable transparency is achieved by establishing DNS mappings between remote hosts to be accessed through one of the network interfaces and respective virtual hosts on that interface. In another aspect, automatic transparency may be achieved using code for dynamically mapping remote hosts to virtual hosts in accordance with a technique referred to herein as dynamic DNS, or DDNS.

Other References

  • Kiuchi et al., "C-HTTP The Development of a Secure, Closed HTTP Based Network on the Internet", PRoceedings of SNDSS, IEEE, pp. 64-75, Jun. 1996
  • Neuman, "Proxy Based Authorization and Accounting for Distributed Systems", IEEE, pp. 283-291, 1993
  • Network Firewalls; IEEE Communications Magazine; (Ballovin et al.) pp. 50-57; Sep., 1994
  • The MITRE Security Perimeter; IEEE Communications Magazine; (Goldberg); pp. 212-218; 1994
  • IpAccess--An Internet Service Access System for Firewall Installations; IEEE Communications Magazine; (Stempel); pp. 31-41; 1995
  • Remote Control of Diverse Network Elements Using SNMP; IEEE Communications Magazine; (Aicklen et al.); pp. 673-667; 1995
  • Firewall's Information is Money|, Scientific Management Corporatio
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$18.95more info
 
Sign InRegister
Username  
Password   
forgot password?