×

Security gateway system, method thereof, and program

  • US 8,739,268 B2
  • Filed: 04/11/2006
  • Issued: 05/27/2014
  • Est. Priority Date: 04/12/2005
  • Status: Expired due to Fees
First Claim
Patent Images

1. A security gateway system for connecting a plurality of networks each of which uses a standard protocol the standardized specifications of which have been published, the security gateway system comprising two sub-gateways realized by mutually independent and physically separated computers with one of the two sub-gateways connected to a wide-area network accessible to general public and the other of the two sub-gateways connected to an internal network necessary to be protected, and the two sub-gateways exchanging communication data with each other using a nonstandard protocol of which specifications have not been published, whereineach of said sub-gateways has a standard protocol communication portion which communicates with said network to which the same sub-gateway is connected using said standard protocol, a nonstandard protocol communication portion which communicates with the other sub-gateway using the nonstandard protocol, a protocol conversion portion which is provided between the standard protocol communication portion and the nonstandard protocol communication portion and performs protocol conversion of communication data between the standard protocol and the nonstandard protocol, and a relay permission setting information storage portion which is connected to the protocol conversion portion and stores relay permission setting information used to confirm relay permission for communication data;

  • said two sub-gateways have a shared memory which can be accessed by the respective nonstandard protocol communication portion of each of said sub-gateways, and are configured such that the communication data converted by the protocol conversion portion of one of the sub-gateways into a nonstandard protocol format and written in the shared memory by said nonstandard protocol communication portion of the one of the sub-gateways is detected by said nonstandard protocol communication portion of the other of the sub-gateways and passed to the protocol conversion portion of the other of the sub-gateways and converted into a standard protocol format;

    said nonstandard protocol communication portion of each of said sub-gateways is an original communication portion which has an implemented application layer which is a seventh layer of the Open Systems Interconnection (OSI) model, and which has unpublished and original communication layers implemented for first through sixth layers of the OSI model, so that data exchange between the nonstandard protocol communication portion and said standard protocol communication portion within the same sub-gateway is performed only in the application layer which is the seventh layer, and data exchange between the nonstandard protocol communication portion and said standard protocol communication portion within the same sub-gateway is not possible using any published protocol of the first through sixth layers; and

    when performing protocol conversion of communication data, said protocol conversion portion of each of said sub-gateways refers to said relay permission setting information to confirm relay permission for the communication data, and performs protocol conversion of the communication data only when relay is permitted.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×