×

Secure network architecture

  • US 8,959,334 B2
  • Filed: 11/20/2007
  • Issued: 02/17/2015
  • Est. Priority Date: 11/20/2006
  • Status: Expired due to Fees
First Claim
Patent Images

1. A star-connected network having a number of client nodes and a server node, the star-connected network configured to enable the client nodes to establish indirect communication sessions with one another via the server node wherein:

  • each client node includes a tamper resistant hardware module that enforces a restriction on the client node such that it is restricted in terms of which types of direct communications it can set up across the network to being able to set up direct communications to the server node using a respective encrypted connection but not being able to set up communications directly with any other of the client nodes and is configured to request initiation of an indirect communications session to the server node via a respective encrypted connection, the session request specifying one or more session parameters including an application identifier associated with the application initiating the indirect communication session; and

    wherein the server node comprises;

    a connection controller configured to establish an encrypted connection with each client node;

    a store storing, in respect of each permitted current session initiated by an application running on a client node, a session parameter set including an application identifier;

    a routing controller configured to route packets between two client nodes using two respective encrypted connections; and

    a firewall configured to allow or block said packets depending on whether or not each such packet includes an application identifier associated with or contained in a stored session parameter set.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×