Secure computer system and method of providing secure access to a computer system including a stand alone switch operable to inhibit data corruption on a storage device
DCFirst Claim
1. A digital computer system comprising:
- first and second electrically isolated buses;
first and second independent central processing units connected to a respective one of said first and second buses;
a storage device connected to each of said buses for selectively storing data; and
a manually operative switch selectively controlling access by said first central processing unit to inhibit storing data to said storage device by said first central processing unit without inhibiting storing data by said second central processing unit.
1 Assignment
Litigations
1 Petition
Accused Products
Abstract
A computer system includes hardware for selectively disabling alteration of data residing on a mass storage device which is subject to remote access. In one embodiment, a hard disk drive is operated in a conventional manner including both read and write modes when the system is being operated in a non-secure mode of operation, such as when remote access is not allowed. In a secure mode of operation, a locally operated switch is used to disable writing to the hard disk drive to maintain data integrity on the drive. The system may also include first and second electrically isolated buses and corresponding processors. In this configuration, the hard disk drive may be selectively connected to the first bus and processor for the storage of data, or to the second bus and processor when in a secure mode to provide for read-only remote access to the information stored on the hard drive. A write-only hard drive may also be included for storage of confidential information provided by remote users so that other remote users cannot access that information. In a master/slave processor configuration, all system programming is resident in an isolated portion of the system inaccessible to remote users. The slave processor receives instructions only from the master processor so that the operation of the slave processor cannot be compromised by viruses uploaded by remote users.
244 Citations
45 Claims
-
1. A digital computer system comprising:
-
first and second electrically isolated buses;
first and second independent central processing units connected to a respective one of said first and second buses;
a storage device connected to each of said buses for selectively storing data; and
a manually operative switch selectively controlling access by said first central processing unit to inhibit storing data to said storage device by said first central processing unit without inhibiting storing data by said second central processing unit. - View Dependent Claims (2, 3, 4)
-
-
5. A digital computer system comprising:
-
first and second independent local buses;
first and second storage devices, each responsive to a control signal for selectively operating in (i) a read mode of operation for reading previously stored data and (ii) a write mode of operation for storing data;
first and second central processing units respectively connected to said first and second local buses, each of said first and second central processing units capable of providing said control signal;
a first manually operative switch alternatively providing said control signals from said first and second local buses to said first and second storage devices, said switch further configured to selectively operate said first and second storage devices in a protected mode of operation, said protected mode of operation including at least one of a write-only and read-only mode of operation. - View Dependent Claims (6, 7, 8, 9, 10, 11, 12)
-
-
13. A digital computer system comprising:
-
first and second system buses electrically independent of each other;
master and slave central processing units connected to respective ones of said system buses;
first and second controllers respectively connected to said master and slave central processing units by respective ones of said system buses;
a data storage device responsive to a write control signal from one of said master and slave processing units on a respective one of said first and second system buses for selectively storing data said data storage device including first and second storage devices; and
a manually operative switch selectively enabling and disabling receipt by said data storage device of said write control signal from said first and second system buses. - View Dependent Claims (14, 15, 16, 17, 18)
-
-
19. A digital computer system comprising:
-
a first data processing unit including a first central processing unit and a first disk controller connected to each other by a first system bus;
a second data processing unit including a second central processing unit and a second disk controller connected to each other by a second system bus, said second system bus electrically independent of said first system bus;
a secure data storage device responsive to a write control signal from each of said first and second data processing units for selectively storing data, said secure data storage device comprising a first disk drive; and
a manually operative switch selectively enabling and disabling receipt by said secure data storage device of said write control signal. - View Dependent Claims (20, 21, 22)
said digital computer system further comprising a second disk drive; - and a second disk controller connected to said second system bus and to said second disk drive for selectively writing data to and reading data from said second disk drive.
-
-
23. A digital computer system comprising:
-
master and slave central processing units;
master and slave system buses electrically isolated from each other and respectively connected to said master and slave central processing units;
a secure data storage device responsive to a write control signal from each said master and slave central processing units for selectively storing data;
a manually operative switch configured to selectively enable and disable receipt by said secure data storage device of said write control signal so as to selectively operate said secure data storage device in a read-only mode of operation; and
first and second disk controllers connected to said master and slave system buses, said secure data storage device including a first disk drive electrically connected through said manually operative switch to said first and second disk controllers for receiving said write control signal from one of said master and slave central processing units whereby said manually operative switch selectively enables and disables transmission of said write control signal. - View Dependent Claims (24, 25, 26)
a first program memory connected to and stoning instructions executable by said master central processing unit, a second program memory connected to and storing instructions executable by said slave central processing unit, and a processor bus connecting said master and slave central processing units.
-
-
26. The digital computer system according to claim 23 further comprising a communications controller connected to said slave system bus.
-
27. A digital computer system comprising:
-
a first central processing unit;
a first system bus connected to said first central processing unit;
a second central processing unit;
a second bus connected to said second central processing unit and centrically isolated from said first system bus;
a disk controller;
a first manual switch selectively providing a conductive path between said disk controller and, in a first position, said first system bus and, in a second position, said second system bus; and
a hard disk drive connected to said disk controller and responsive to a write control signal from said disk controller for selectively storing information. - View Dependent Claims (28)
-
-
29. A digital computer system comprising:
-
a first system bus;
a second system bus a first processor connected to said first system bus;
a second processor connected to said second system bus;
a data storage device connected to said first and second system buses for selectively operating in a plurality of operating modes so as to access said data storage device; and
a switch operable to selectively enable and disable at least one of said operating modes, said switch controllable by means distinct and separate from at least one of said processors whereby said one processor is inhibited from controlling said operation of said switch. - View Dependent Claims (30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43)
-
-
44. A method of accessing a digital storage device using a digital computer system, the digital computer system including first and second independent local buses, first and second central processing units respectively connected to said first and second local buses, and a manually operative switch, the method comprising the steps of:
-
transmitting control signals from said first and second central processing units to respective ones of said fist and second local buses;
operating said switch to alternatively provide ones of said control signals from said first and second local buses to the digital storage device and to select a protected mode of operation thereof;
selectively operating the digital storage device in said protected mode of operation, said protected mode of operation including at least one of a write-only and read-only mode of operation; and
selectively operating said digital storage device responsive to said control signals in (i) a read mode of operation for reading previously stored data and (ii) a write mode of operation for storing data.
-
-
45. A method of accessing a digital storage device using a digital computer system, the digital computer system including first and second system buses electrically independent of each other, master and slave central processing units connected to respective ones of said system buses, and a manually operative switch, the method comprising the steps of:
-
transmitting a write control signal from one of said master and salve processing units;
selectively storing data on said data storage device responsive to said write control signal; and
operating said switch to selectively enable and disable receipt by the data storage device of said write control signal from said first and second system buses.
-
Specification