METHOD AND SYSTEM FOR SECURELY SCANNING NETWORK TRAFFIC
    11.
    发明申请
    METHOD AND SYSTEM FOR SECURELY SCANNING NETWORK TRAFFIC 审中-公开
    用于安全扫描网络流量的方法和系统

    公开(公告)号:US20120195429A1

    公开(公告)日:2012-08-02

    申请号:US13360550

    申请日:2012-01-27

    IPC分类号: H04L9/00 H04L9/14

    摘要: Secure network communications via a firewall device are provided between a first device and a second device, where an encryption parameter is shared by the devices. A data packet sent by the first device may then be copied within the firewall device, so that the copy of the data packet can be decrypted within a portion of the firewall device. In particular, the portion of the firewall device in which decryption takes place is defined such that contents of the portion are inaccessible to an operator of the firewall device. Thus, scanning of the decrypted copy of the data packet for compliance with a predetermined criterion may take place within the firewall device, without an operator of the firewall device having access to the contents of the data packet to be transmitted. Thereafter, the original data packet can be forwarded to its originally intended recipient.

    摘要翻译: 在第一设备和第二设备之间提供通过防火墙设备的安全网络通信,其中加密参数由设备共享。 然后可以在防火墙设备内复制由第一设备发送的数据分组,使得可以在防火墙设备的一部分内解密数据分组的副本。 特别地,定义防火墙设备中发生解密的部分,使得该部分的内容对于防火墙设备的操作者是不可访问的。 因此,在防火墙设备内可以进行符合预定标准的数据分组的解密副本的扫描,而防火墙设备的操作者可以访问要发送的数据分组的内容。 此后,可以将原始数据分组转发到其原始的接收者。

    Multipoint server for providing secure, scaleable connections between a plurality of network devices
    12.
    发明授权
    Multipoint server for providing secure, scaleable connections between a plurality of network devices 有权
    多点服务器,用于在多个网络设备之间提供安全,可扩展的连接

    公开(公告)号:US07987507B2

    公开(公告)日:2011-07-26

    申请号:US12489500

    申请日:2009-06-23

    IPC分类号: G06F15/16

    摘要: A method and system for implementing secure communications between a plurality of devices are provided. The method and system generally include the provision of at least one common encryption parameter to each of the plurality of devices, as well as an identification of the plurality of devices to one another. This information can be maintained and shared by interaction of the plurality of devices with a designated server device. In this way, a secure, point-to-point connection between at least two of the plurality of devices can be established.

    摘要翻译: 提供了用于实现多个设备之间的安全通信的方法和系统。 该方法和系统通常包括向多个设备中的每一个提供至少一个公共加密参数,以及将多个设备彼此的标识。 可以通过多个设备与指定的服务器设备的交互来维护和共享该信息。 以这种方式,可以建立多个设备中的至少两个之间的安全的点对点连接。

    Method and System for Securely Scanning Network Traffic
    13.
    发明申请
    Method and System for Securely Scanning Network Traffic 有权
    安全扫描网络流量的方法和系统

    公开(公告)号:US20080192930A1

    公开(公告)日:2008-08-14

    申请号:US12105756

    申请日:2008-04-18

    IPC分类号: H04L9/14

    摘要: A method and system for implementing secure network communications between a first device and a second device, at least one of the devices communicating with the other device via a firewall device, are provided. The method and system may include obtaining an encryption parameter that is shared by the first device, second device and firewall device. A data packet sent by the first device may then be copied within the firewall device, so that decryption of the copy of the data packet within a portion of the firewall device may take place. In particular, the portion of the firewall device in which decryption takes place is defined such that contents of the portion are inaccessible to an operator of the firewall device. Thus. scanning of the decrypted copy of the data packet for compliance with a predetermined criterion may take place within the firewall device, without an operator of the firewall device having access to the contents of the data packet to be transmitted. Thereafter, the original data packet can be forwarded to its originally intended recipient.

    摘要翻译: 提供了一种用于在第一设备和第二设备之间实现安全网络通信的方法和系统,至少一个设备经由防火墙设备与另一设备通信。 该方法和系统可以包括获得由第一设备,第二设备和防火墙设备共享的加密参数。 然后可以在防火墙设备内复制由第一设备发送的数据分组,从而可以在防火墙设备的一部分内对数据分组的副本进行解密。 特别地,定义防火墙设备中发生解密的部分,使得该部分的内容对于防火墙设备的操作者是不可访问的。 从而。 扫描数据包的解密副本以符合预定标准可以在防火墙设备内进行,而防火墙设备的操作者可以访问要发送的数据包的内容。 此后,可以将原始数据分组转发到其原始的接收者。