Method and system for establishing a security perimeter in computer networks
    5.
    发明授权
    Method and system for establishing a security perimeter in computer networks 失效
    在计算机网络中建立安全边界的方法和系统

    公开(公告)号:US06272538B1

    公开(公告)日:2001-08-07

    申请号:US09127280

    申请日:1998-07-31

    IPC分类号: G06F1300

    摘要: A multi-level network security system is disclosed for a computer host device coupled to at least one computer network. The system including a secure network interface Unit (SNIU) contained within a communications stack of the computer device that operates at a user layer communications protocol. The SNIU communicates with other like SNIU devices on the network by establishing an association, thereby creating a global security perimeter for end-to-end communications and wherein the network may be individually secure or non-secure without compromising security of communications within the global security perimeter. The SNIU includes a host/network interface for receiving messages sent between the computer device and network. The interface operative to convert the received messages to and from a format utilized by the network. A message parser for determining whether the association already exists with another SNIU device. A session manager coupled to said network interface for identifying and verifying the computer device requesting access to said network.

    摘要翻译: 公开了一种耦合到至少一个计算机网络的计算机主机设备的多级网络安全系统。 该系统包括在用户层通信协议下操作的计算机设备的通信栈内的安全网络接口单元(SNIU)。 SNIU通过建立关联来与网络上的其他类似的SNIU设备进行通信,从而为端到端通信创建全局安全边界,并且其中网络可以单独地安全或不安全,而不会影响全局安全性内的通信的安全性 周长。 SNIU包括用于接收在计算机设备和网络之间发送的消息的主机/网络接口。 该接口可操作以将所接收的消息转换为网络所使用的格式和从该网络使用的格式。 用于确定关联是否已经与另一个SNIU设备存在的消息解析器。 耦合到所述网络接口的会话管理器,用于识别和验证请求访问所述网络的计算机设备。

    Stand alone device for providing security within computer networks
    7.
    发明授权
    Stand alone device for providing security within computer networks 失效
    独立设备,用于在计算机网络中提供安全性

    公开(公告)号:US5802178A

    公开(公告)日:1998-09-01

    申请号:US688525

    申请日:1996-07-30

    IPC分类号: G06F21/00 H04L29/06 H04L9/00

    摘要: A multi-level security device is disclosed for providing security between a user and at least one computer network, wherein the user is selected from the group consisting of a host computer and at least a second network. A secure network interface Unit (SNIU) that operates at a user layer communications protocol, which communicates with other like SNIU devices by establishing an association at a session layer of a communication stack in order to create a global security perimeter for end-to-end communications. The SNIU includes a host/network interface for receiving messages sent between the user and the at least one network, which is operative to convert the received messages to and from a format utilized by the at least one network. A message parser for determining whether the association already exists with another SNIU device. A session manager coupled to the interface for identifying and verifying the user requesting access to the network. The session manager also for transmitting the messages received from the user when the message parser determines the association already exists. An association manager coupled to the interface for establishing an association with other like SNIU devices when the message parser determines the association does not exist.

    摘要翻译: 公开了一种用于在用户和至少一个计算机网络之间提供安全性的多级安全设备,其中,所述用户从由主计算机和至少第二网络组成的组中选择。 一种安全网络接口单元(SNIU),其在用户层通信协议上操作,该协议通过在通信栈的会话层建立关联来与其它类似的SNIU设备进行通信,以便为端对端创建全局安全边界 通讯。 SNIU包括用于接收在用户与至少一个网络之间发送的消息的主机/网络接口,其用于将所接收的消息转换为和从所述至少一个网络所使用的格式转换。 用于确定关联是否已经与另一个SNIU设备存在的消息解析器。 耦合到接口的会话管理器,用于识别和验证请求访问网络的用户。 会话管理器还用于当消息解析器确定关联已经存在时发送从用户接收的消息。 当消息解析器确定关联不存在时,耦合到该接口的关联管理器用于与其它类似的SNIU设备建立关联。