CA2320715A1 - Procede et appareil de securisation des informations - Google Patents

Procede et appareil de securisation des informations Download PDF

Info

Publication number
CA2320715A1
CA2320715A1 CA002320715A CA2320715A CA2320715A1 CA 2320715 A1 CA2320715 A1 CA 2320715A1 CA 002320715 A CA002320715 A CA 002320715A CA 2320715 A CA2320715 A CA 2320715A CA 2320715 A1 CA2320715 A1 CA 2320715A1
Authority
CA
Canada
Prior art keywords
computer
communication
secured
mode
controller
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
CA002320715A
Other languages
English (en)
Inventor
Lior Netzer
Yariv Kaplan
Erez Diamant
Amir Prescher
Nir Brachel
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Voltaire Advanced Data Security Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US09/025,221 external-priority patent/US6202153B1/en
Application filed by Voltaire Advanced Data Security Ltd filed Critical Voltaire Advanced Data Security Ltd
Publication of CA2320715A1 publication Critical patent/CA2320715A1/fr
Abandoned legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • G06F21/80Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in storage media based on magnetic or optical technology, e.g. disks with sectors
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/83Protecting input, output or interconnection devices input devices, e.g. keyboards, mice or controllers thereof
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/84Protecting input, output or interconnection devices output devices, e.g. displays or monitors
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2207/00Indexing scheme relating to methods or arrangements for processing data by operating upon the order or content of the data handled
    • G06F2207/72Indexing scheme relating to groups G06F7/72 - G06F7/729
    • G06F2207/7219Countermeasures against side channel or fault attacks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2211/00Indexing scheme relating to details of data-processing equipment not covered by groups G06F3/00 - G06F13/00
    • G06F2211/005Network, LAN, Remote Access, Distributed System
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2211/00Indexing scheme relating to details of data-processing equipment not covered by groups G06F3/00 - G06F13/00
    • G06F2211/1097Boot, Start, Initialise, Power

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Communication Control (AREA)

Abstract

L'invention concerne un procédé permettant la connexion sélective de postes informatiques à une pluralité de dispositifs de communication. Ledit procédé consiste à recevoir une demande de connexion en provenance d'un poste informatique pour la connexion à l'un des dispositifs de communication demandés; à déconnecter le poste informatique choisi de tous les dispositifs de communication; à détecter si le poste informatique choisi est configuré selon le dispositif de communication demandé; et le cas échéant, à connecter le poste informatique choisi au dispositif de communication demandé. L'invention concerne également un dispositif de protection de zones sécurisées d'un système informatique, lequel dispositif comprend une interface de communication assurant la connexion réseau, une interface de dispositif sécurisée assurant la connexion à une zone sécurisée, un contrôleur de gestion connecté à l'interface de communication, entre l'interface de dispositif sécurisée et le système informatique, et un système d'arrêt/reprise. Le contrôleur de gestion détecte l'établissement d'une communication entre le système informatique et le réseau, connecte le système informatique à l'interface de dispositif sécurisée lorsque la communication n'est pas en cours d'établissement, et déconnecte le système informatique de l'interface de dispositif sécurisée lorsque la communication est établie. Le système d'arrêt/reprise fait passer le système informatique d'un état où la communication est en cours d'établissement à un état où elle ne l'est pas et vice versa.
CA002320715A 1998-02-18 1999-02-17 Procede et appareil de securisation des informations Abandoned CA2320715A1 (fr)

Applications Claiming Priority (5)

Application Number Priority Date Filing Date Title
US09/025,221 1998-02-18
US09/025,221 US6202153B1 (en) 1996-11-22 1998-02-18 Security switching device
US24511699A 1999-02-04 1999-02-04
US09/245,116 1999-02-04
PCT/IL1999/000103 WO1999042915A2 (fr) 1998-02-18 1999-02-17 Procede et appareil de securisation des informations

Publications (1)

Publication Number Publication Date
CA2320715A1 true CA2320715A1 (fr) 1999-08-26

Family

ID=26699462

Family Applications (1)

Application Number Title Priority Date Filing Date
CA002320715A Abandoned CA2320715A1 (fr) 1998-02-18 1999-02-17 Procede et appareil de securisation des informations

Country Status (6)

Country Link
EP (1) EP1060590A2 (fr)
CN (1) CN1305675A (fr)
AU (1) AU2543799A (fr)
CA (1) CA2320715A1 (fr)
IL (1) IL137855A0 (fr)
WO (1) WO1999042915A2 (fr)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002007233A (ja) * 2000-06-16 2002-01-11 Ionos:Kk 通信路のスイッチ接続制御装置
AU2002220540A1 (en) * 2000-12-11 2002-06-24 Apomon Aps Changing of operating modes in a computer
FR2824404A1 (fr) * 2001-05-04 2002-11-08 Scaling Software Systeme inviolable de generation de traces
JP3513147B2 (ja) 2002-05-29 2004-03-31 株式会社ハギワラシスコム Usbストレージデバイス及びその制御装置
JP3989383B2 (ja) * 2003-02-06 2007-10-10 富士通株式会社 情報処理装置、情報処理システム、プログラム、ゲートウェイカード、ゲートウェイ装置およびゲートウェイ制御プログラム
TWI261757B (en) * 2003-04-30 2006-09-11 Hagiwara Sys Com Co Ltd USB storage device
DE102004034902B3 (de) * 2004-07-19 2005-09-08 Adrian Degwert Datentransfermodul zum Durchschleusen von Daten zwischen zwei voneinander getrennten Netzwerken
FR2895615B1 (fr) * 2005-12-23 2008-04-04 Cs Systemes D Information Sa Systeme d'echange de donnees entre deux reseaux de communication de donnees dissocies
EP2360611B1 (fr) * 2010-01-22 2014-09-10 ST-Ericsson SA Gestion d'environnement sécurité pendant les commutations entre différents modes de systèmes multicolores
US8429735B2 (en) * 2010-01-26 2013-04-23 Frampton E. Ellis Method of using one or more secure private networks to actively configure the hardware of a computer or microchip
US9503422B2 (en) 2014-05-09 2016-11-22 Saudi Arabian Oil Company Apparatus, systems, platforms, and methods for securing communication data exchanges between multiple networks for industrial and non-industrial applications
DE102015219999A1 (de) * 2015-10-15 2017-04-20 Robert Bosch Gmbh Verfahren zur Generierung eines Geheimnisses in einem Netzwerk mit mindestens zwei an ein Übertragungsmedium angeschlossenen Teilnehmern

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4498716A (en) * 1982-04-01 1985-02-12 Ward Marvin W Data monitoring connector for testing transmission links
US4769833A (en) * 1986-03-31 1988-09-06 American Telephone And Telegraph Company Wideband switching system
DE69218011T2 (de) * 1991-12-13 1997-06-12 Hydro-Quebec, Montreal, Quebec Anordnung und verfahren zur auswahl und prüfung von kommunikationsleitungen
US5384854A (en) * 1992-02-14 1995-01-24 Ericsson Ge Mobile Communications Inc. Co-processor controlled switching apparatus and method for dispatching console
US5559883A (en) * 1993-08-19 1996-09-24 Chipcom Corporation Method and apparatus for secure data packet bus communication
US6137476A (en) * 1994-08-25 2000-10-24 International Business Machines Corp. Data mouse
US5913037A (en) * 1996-07-03 1999-06-15 Compaq Computer Corporation Dynamic management information base manager
US5815571A (en) * 1996-10-28 1998-09-29 Finley; Phillip Scott Computer system with secured data paths and method of protection

Also Published As

Publication number Publication date
AU2543799A (en) 1999-09-06
CN1305675A (zh) 2001-07-25
WO1999042915A2 (fr) 1999-08-26
WO1999042915A3 (fr) 2000-06-29
IL137855A0 (en) 2001-10-31
EP1060590A2 (fr) 2000-12-20

Similar Documents

Publication Publication Date Title
US6202153B1 (en) Security switching device
US6268789B1 (en) Information security method and apparatus
US6272533B1 (en) Secure computer system and method of providing secure access to a computer system including a stand alone switch operable to inhibit data corruption on a storage device
KR101487865B1 (ko) 판독전용 영역과 판독/기록 영역, 분리형 매체 구성부품, 시스템 관리 인터페이스, 네트워크 인터페이스를 가진 컴퓨터 기억장치
US5815571A (en) Computer system with secured data paths and method of protection
US20020166067A1 (en) Apparatus and method for protecting a computer system against computer viruses and unauthorized access
US6009518A (en) Computer system for providing improved security for stored information
GB2411988A (en) Preventing programs from accessing communication channels withut user permission
CN108595982B (zh) 一种基于多容器分离处理的安全计算架构方法及装置
CN110334512B (zh) 基于双体系架构的可信计算平台的静态度量方法和装置
EP2316092A1 (fr) Systèmes et procédés permettant le contrôle d accès à des données via des couches de virtualisation d application
US8245054B2 (en) Secure and convenient access control for storage devices supporting passwords for individual partitions
CA2320715A1 (fr) Procede et appareil de securisation des informations
WO2018212474A1 (fr) Unité de mémoire auxiliaire ayant une zone de restauration indépendante, et dispositif appliqué à celle-ci
KR100429144B1 (ko) 컴퓨터 네트워크상의 컴퓨터에 보안을 제공하기 위한 방법
EP3623978B1 (fr) Ordinateur ayant une unité informatique d'utilisateur isolée
US8307175B2 (en) Data recovery and overwrite independent of operating system
JP2001318797A (ja) 自動データ処理装置
EP1193586A2 (fr) Système de sécurité pour applications de traitement de données
CN101820438B (zh) 一种局域网中的计算机启动方法和一种局域网
KR101873974B1 (ko) 디스크리스 솔루션을 활용한 확장형 물리적 망분리 시스템
GB2411748A (en) Anti-virus system for detecting abnormal data outputs
US20080104232A1 (en) System And Method For Preventing Unauthorized Bridging To A Computer Network
CN113553632A (zh) 一种数据安全传输接口设备、系统及方法
Guinier Sensitive security points in PC microcomputers: understanding for building secure solutions to intrusions

Legal Events

Date Code Title Description
FZDE Discontinued