发明名称 Cross domain gateway having temporal separation
摘要 A computer network is disclosed that includes a first domain and a second domain. The second domain has a higher security classification than the first domain. The computer network also comprises a Temporal Separation Cross Domain Gateway (TSEP-CDG) having a temporal separation hardware interlock. The interlock is configured to physically prevent communication between the first and second domains. It connects with the first domain in a first state to allow the TSEP-CDG to receive data from the first domain. The TSEP-CDG executes an information-invariant data transformation (IIDT) on the received data before it is available to the second domain. The IIDT alters the representation of the data while conveying the same information, disrupting anti-malware present in the received data. The temporal separation hardware interlock is configured for connection with the second domain in a second state to allow the TSEP-CDG to transmit the transformed data to the second domain.
申请公布号 US9560012(B1) 申请公布日期 2017.01.31
申请号 US201313929403 申请日期 2013.06.27
申请人 The Boeing Company 发明人 Bonang James Joseph;Corrado Marco Anthony;Hogan Michael Cohen;Singer Kevin Dale
分类号 H04L29/06;H04L12/66;G06F9/00;G06F15/16;G06F7/04 主分类号 H04L29/06
代理机构 Kunzler Law Group, PC 代理人 Kunzler Law Group, PC
主权项 1. A computer network comprising: a first domain, the first domain having a first security classification such that the first domain accepts data in response to the data complying with the first security classification; a second domain, the second domain having a second security classification such that the second domain accepts data in response to the data complying with the second security classification, wherein the security classification of the second domain has a higher level of security classification than the security classification of the first domain; and a Temporal Separation Cross Domain Gateway (TSEP-CDG) having a temporal separation hardware interlock configured to physically prevent communication between the first and the second domains, wherein the TSEP-CDG is configured to: connect, via the temporal separation hardware interlock, with the first domain;receive data from the first domain, the data complying with the first security classification of the first domain, but not the second security classification of the second domain;disconnect the temporal separation hardware interlock from the first domain;execute an information-invariant data transformation on the received data to transform the data to comply with the security classification of the second domain;connect, via the temporal separation hardware interlock, with the second domain;transmit the transformed data to the second domain, the transformed data complying with the security classification of the second domain; anddisconnect the temporal separation hardware interlock from the second domain.
地址 Chicago IL US