发明名称 Method and system for automatically managing secure communications in multiple communications jurisdiction zones
摘要 Communications and data security policy data for two or more communications jurisdiction zones is obtained that includes data indicating allowed protocols for the respective communications jurisdiction zones. Data indicating a desired exchange of data between a first resource in a first communications jurisdiction zone and a second resource in a second communications jurisdiction zone is received/obtained. The first communications jurisdiction zone communications and data security policy data and the second communications jurisdiction zone policy data is automatically obtained and analyzed to determine an allowed type of secure communications security level for the desired exchange of data that complies with both the first communications jurisdiction zone communications and data security policy data and the second communications jurisdiction zone policy data. A communications channel, including the allowed type of secure communications security level, is automatically establishing between the first resource and the second resource.
申请公布号 US9444818(B2) 申请公布日期 2016.09.13
申请号 US201314070168 申请日期 2013.11.01
申请人 Intuit Inc. 发明人 Lietz M. Shannon;Cabrera Luis Felipe
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Hawley Troxell Ennis & Hawley LLP 代理人 Hawley Troxell Ennis & Hawley LLP ;McKay Philip
主权项 1. A system for automatically managing secure communications across multiple communications jurisdiction zones comprising: at least one processor; and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for automatically managing secure communications across multiple communications jurisdiction zones, the process for automatically managing secure communications across multiple communications jurisdiction zones including: identifying two or more communications jurisdiction zones from which, and/or to which, data may be transferred using one or more types of communications channels including one or more types of secure communications security levels; obtaining communications and data security policy data for the two or more identified communications jurisdiction zones, the communications and data security policy data for the identified communications jurisdiction zones including data indicating allowed types of secure communications security levels for each of the respective communications jurisdiction zones; obtaining exchange data indicating a desired exchange of data between a first virtual asset in a first communications jurisdiction zone and a second virtual asset in a second communications jurisdiction zone, the first and second communications jurisdiction zones being different from each other, the data to be exchanged being of a type, the type of data being one selected from at least messages, files, images and secrets wherein each data security policy data is based on political regulation in each zone and whereby the zones consist of local, state, national, or regional government agencies; identifying owner secure communications polices provided by an owner of the data to be transferred; determining, through examination of the actual data to be exchanged, the type of data to be exchanged; automatically obtaining first communications jurisdiction zone communications and data security policy data associated with the first communications jurisdiction zone and second communications jurisdiction zone communications and data security policy data associated with second communications jurisdiction zone from the communications and data security policy data; automatically determining, based on the results of determining the type of data to be exchanged through examining the actual data to be transferred, a required type of communications channel having a type and length of encryption required to be applied to the data to be transferred, the required type of communications channel meeting the data security policy data associated with the first communications jurisdiction zone and data security policy data associated with the second communications jurisdiction zone and the owner secure communications polices provided by the owner of the data to be transferred; automatically analyzing the first communications jurisdiction zone communications and data security policy data and the second communications jurisdiction zone communications and data security policy data to determine at least one allowed type of secure communications security level for the desired exchange of data that complies with both the first communications jurisdiction zone communications and data security policy data and the second communications jurisdiction zone communications and data security policy data; selecting one of the at least one allowed type of secure communications security level; and automatically establishing the selected allowed type of communications channel including the allowed type of secure communications security level between the first virtual asset and the second virtual asset.
地址 Mountain View CA US