Firewall+storage apparatus, method and system
First Claim
1. A data storage firewall apparatus for preventing writes and/or reads between a host processor and a local storage component, comprising:
- a storage firewall for communicatively coupling the local storage component and the host processor, said storage firewall being operative to provideapplication software authentication including application registration, runtime authentication of application identity and permission to execute, and/oruser authentication and authorization in the execution of an application'"'"'s request to write and/or read, and/orexamination, verification, and authentication of all storage access requests.
0 Assignments
0 Petitions
Accused Products
Abstract
A storage firewall architecture, method and system that works in parallel with existing security technologies and, inter alia, provides application software authentication, user authentication & authorization in the execution of an application, examination, verification, and authentication of all storage access requests, monitoring of protected storage to detect & repair anomalous changes, encryption of protected storage, both data and software, provisioning (deployment) of patches, configuration changes, and software through a secure synchronization link to a configuration and patch management server, and server-based system administration & configuration to prevent malware from penetrating local configuration mechanisms.
-
Citations
32 Claims
-
1. A data storage firewall apparatus for preventing writes and/or reads between a host processor and a local storage component, comprising:
a storage firewall for communicatively coupling the local storage component and the host processor, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, and/or user authentication and authorization in the execution of an application'"'"'s request to write and/or read, and/or examination, verification, and authentication of all storage access requests. - View Dependent Claims (2, 3, 4)
-
5. A storage firewall and remote management system, comprising:
-
a local data storage apparatus, including a protected storage component; a local host interface for coupling said protected storage component to a host processor; and a storage firewall adapted to communicatively couple said protected storage component to said host interface, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests; a remote update server including a configuration database; and an Internet interfacing means for communicating with said local storage apparatus via the Internet to provide updates, configuration changes, new software, and other information to said local data storage apparatus; and a remote configuration web server coupled to said update server for enabling end users to select customization options for their storage firewall protected storage and endpoint devices. - View Dependent Claims (6, 7, 8)
-
-
9. A method of providing secure data storage in a computing device and for communicatively coupling and facilitating secure data exchange between a digital logic component and an associated local data storage component, comprising:
-
providing a local data storage component; providing a host interface for coupling data stored in said local data storage component to a host processor; and providing a storage firewall adapted to communicatively couple said local data storage component and said host interface, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests. - View Dependent Claims (10, 11, 12)
-
-
13. A method of providing a storage firewall and remote management system, comprising:
-
providing a data storage means, including providing a host interface for coupling said storage apparatus to a host processor; providing a protected storage component; and providing a storage firewall adapted to communicatively couple said protected storage component to said host interface, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests; providing an update server including a configuration database; and an Internet interfacing means for communicating with said host computer via the Internet to provide updates, configuration changes, new software, and other information to said data storage apparatus; and providing a configuration web server coupled to said update server for enabling end users to select customization options for their storage firewall protected storage and endpoint devices. - View Dependent Claims (14, 15, 16)
-
-
17. A storage firewall for communicatively coupling and facilitating secure data exchange between a digital logic component and an associated local data storage component, comprising:
-
means providing application software authentication including application registration, runtime authentication of application identity and permission to execute, means providing user authentication &
authorization in the execution of an application, andmeans providing examination, verification, and authentication of all storage access requests to said protected storage component.
-
-
18. A storage firewall for facilitating secure data exchange between a digital logic component and a protected data storage component, comprising:
-
a transaction processor component for processing storage access requests and other requests related to the administration of the storage firewall, a working memory component for providing local memory storage that persists across transactions, an encryption/decryption component for providing encryption and decryption functionality for both storage firewall processing, and encryption and decryption of data of authorized transactions, and an application rights &
credentials component for storing, processing, and providing user and application credentials and access parameters for authentication, authorization, and access control purposes. - View Dependent Claims (19, 20)
-
-
21. A storage firewall and remote management system, comprising:
-
a data storage means, including an interface for coupling said data storage means to a digital logic means; a protected storage component; and a storage firewall adapted to communicatively couple said protected storage component to said interface, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests to said protected storage component; an update server including a configuration database; and an Internet interfacing means for communicating with said digital logic means via the Internet to provide updates, configuration changes, new software, and other information to said data storage component; and a configuration web server coupled to said update server for enabling end users to select customization options for their storage firewall protected storage and endpoint devices. - View Dependent Claims (22, 23, 24)
-
-
25. A method of providing secure data storage in an apparatus including a digital logic component and an associated data storage component, comprising:
providing a storage firewall communicatively coupling the digital logic component and the data storage component, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests to the data storage component.
-
26. A method of providing secure data storage in a system including a digital logic component and a data storage component, comprising:
using a storage firewall to communicatively couple data between the digital logic component and the data storage component, said storage firewall including means for processing storage access requests and other requests related to the administration of the storage firewall using a transaction processor component, providing local working memory storage that persists across transactions, providing an encryption/decryption functionality for both storage firewall processing, and encryption and decryption of the data of authorized transactions, and using an application rights &
credentials component for storing, processing, and providing user and application credentials and access parameters for authentication, authorization, and access control purposes.- View Dependent Claims (27, 28)
-
29. A method of providing a storage firewall and remote management system, comprising:
-
providing a storage means including a protected storage component; providing a host interface for coupling data to and from a digital logic component; and providing a storage firewall adapted to communicatively couple said protected storage component to said host interface, said storage firewall being operative to provide application software authentication including application registration, runtime authentication of application identity and permission to execute, user authentication &
authorization in the execution of an application, andexamination, verification, and authentication of all storage access requests; providing an update server including a configuration database; and an Internet interfacing means for communicating with said digital logic component via the Internet to provide updates, configuration changes, new software, and other information to said protected storage component; and providing a configuration web server coupled to said update server for enabling end users to select customization options for their storage firewall protected storage and endpoint devices. - View Dependent Claims (30, 31, 32)
-
Specification