USRE42212EExpiredUtility

Protection system and method

Individually held — no corporate assignee on recordPriority: Mar 14, 2001Filed: May 3, 2006Granted: Mar 8, 2011
Est. expiryMar 14, 2021(expired)· nominal 20-yr term from priority
Inventors:Terry Hoffman
H04L 63/0428G06F 21/564G06F 21/566H04L 63/145
76
PatentIndex Score
14
Cited by
36
References
53
Claims

Abstract

An anti-virusA protection system and method for use within a data transmission network to protect against the transfer of viruses from a transmission originatororiginator, having a discrete transmission originator codecode, to a subscriber/recipientsubscriber/recipient, having a discrete subscriber/recipient IP address codecode, over the data transmission network comprising the steps ofincludes: assigning a discrete security code to the transmission originator,originator; generating a transmission pack including a discrete subscriber/recipient IP address code element corresponding to the discrete subscriber/recipient IP address code of the subscriber/recipient, a discrete security code element corresponding to the discrete security code assigned to the transmission originator, a file extension elementelement, and a data packet element; transmitting the transmission pack to a data transfer control; authenticating the transmission pack with the discrete subscriber/recipient IP address code element, discrete security code elementelement, and discrete transmission originator code; transferring the authenticated transmission pack to the subscriber/recipientsubscriber/recipient; and isolating the subscriber/recipient from an unauthenticated transmission packpack, received by the data transfer control from a transmission originatororiginator, to prevent the transfer of an unauthenticated transmission pack to the subscriber/recipient.

Claims

exact text as granted — not AI-modified
1. An anti-virus  A protection method for use within a data transmission network to protect against the transmission of unwanted data from a transmission originator having a plurality of assigned security codes corresponding to a plurality of data security levels to a subscriber/recipient having a plurality of assigned discrete subscriber/recipient IP address codes over the data transmission network including a data transfer control means and a plurality of data transmission ports corresponding to the plurality of security levels, wherein said plurality of assigned security codes includes a first data security level code element and a second data security level code element and said plurality of data transmission ports include a first data transmission port and a second data transmission port such that data are transmitted through the first data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a first data security code level element and data are transmitted through the second data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a second data security level code element, whereas the anti-virus protection  method comprising the steps of:
 generating a transmission pack including a discrete security code element corresponding to the data security level selected by the transmission originator of the data to be transmitted and a discrete subscriber/recipient IP address code element corresponding to the discrete subscriber/recipient IP address code of the subscriber/recipient,  subscriber/recipient; 
 transmitting data and said transmission pack to the data transfer control means that includes circuitry and logic to scan said transmission packets from the transmission originator for discrete security code elements and discrete subscriber/recipient IP address code elements to control the transfer of data from transmission originators to subscriber/recipients through said data transfer control means;  
 scanning said transmission pack to authenticate discrete subscriber/recipient IP address code elements and discrete security code elements; and  
 transferring data in authenticated transmission packs to the subscriber/recipient through the data transmission port corresponding to the data security level.  
 
     
     
       2. The anti-virus  protection method of  claim 1  wherein said plurality of assigned security codes further includes a third data security level code element such that data are transmitted through a third data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a third security level code element. 
     
     
       3. The anti-virus  protection method of  claim 1  wherein said plurality of assigned security codes further includes a third data security level code element such that transmitted data is isolated from the subscriber/recipient when an unauthenticated transmission pack is sent to prevent the transfer of the transmission pack to the subscriber/recipient. 
     
     
       4. The anti-virus  protection method of  claim 1  wherein said first data transmission port comprises a secure data port to transfer the data to the subscriber/recipient and said second data transmission port comprises a controlled data port wherein authenticated data are held for selective review by the subscriber/recipient before downloading by the subscriber/recipient. 
     
     
       5. The anti-virus  protection method of  claim 4  wherein said plurality of assigned security codes further includes a third data security level code element such that data are transmitted through a third data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a third security level code element. 
     
     
       6. The anti-virus  protection method of  claim 4  wherein said plurality of assigned security codes further includes a third data security level code element such that transmitted data is isolated from the subscriber/recipient when an unauthenticated transmission pack is sent to prevent the transfer of the transmission pack to the subscriber/recipient. 
     
     
       7. An anti-virus  A protection method for use within a data transmission network to protect against the transmission of unwanted data from a transmission originator having a plurality of assigned security codes corresponding to a plurality of data security levels to a subscriber/recipient having an assigned discrete subscriber/recipient IP address code over the data transmission network including a data transfer control means and a plurality of data transmission ports corresponding to the plurality of security levels, wherein said plurality of assigned security codes includes a first data security level code element and a second data security level code element and said plurality of data transmission ports include a first data transmission port and a second data transmission port such that data are transmitted through the first data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a first data security code level element and data are transmitted through the second data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a second data security level code element, whereas the anti-virus protection  method comprising the steps of:
 generating a transmission pack including a discrete security code element corresponding to the data security level selected by the transmission originator of the data to be transmitted and a discrete subscriber/recipient IP address code element corresponding to the discrete subscriber/recipient IP address code of the subscriber/recipient, a file extension element and a data packet element;  
 transmitting data and said transmission pack to the data transfer control means that includes circuitry and logic to scan the transmission packets from the transmission originator for discrete security code elements and discrete subscriber/recipient IP address code elements to control the transfer of data from transmission originators to subscriber/recipients through the data transfer control means;  
 scanning said transmission pack for discrete subscriber/recipient IP address code elements and discrete security code elements; and  
 transferring data from authenticated transmission packs to the subscriber/recipient through the data transmission port corresponding to the data security level.  
 
     
     
       8. The anti-virus  protection method of  claim 7  wherein said plurality of assigned security codes further includes a third data security level code element such that data are transmitted through a third data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a third security level code element. 
     
     
       9. The anti-virus  protection method of  claim 7  wherein said plurality of assigned security codes further includes a third data security level code element such that data is isolated from the subscriber/recipient when an unauthenticated transmission pack to prevent the transfer of to the subscriber/recipient. 
     
     
       10. The anti-virus  protection method of  claim 7  wherein said first data transmission port comprises a secure data port to transfer the data to the subscriber/recipient and said second data transmission port comprises a controlled data port wherein authenticated data are held for selective review by the subscriber/recipient before downloading by the subscriber/recipient. 
     
     
       11. The anti-virus  protection method of  claim 10  wherein said plurality of assigned security codes further includes a third data security level code element such that data are transmitted through a third data transmission port to the subscriber/recipient when said discrete security code element is authenticated as a third security level code element. 
     
     
       12. The anti-virus  protection method of  claim 10  wherein said plurality of assigned security codes further includes a third data security level code element such that transmitted data is isolated from the subscriber/recipient when an unauthenticated transmission pack is sent to prevent the transfer of the transmission pack to the subscriber/recipient. 
     
     
       13. A data transmission controller, comprising:
   circuitry and control logic configured to:      authenticate a received transmission pack of data, including determining if the transmission pack includes a discrete security code element corresponding to a discrete security code assigned to an external transmission originator, where the discrete security code is one of plural pre - assigned security codes, and where each security code and corresponding security code element represents one of plural predetermined security levels; and        in accordance with a result of authentication, establish a discrete data port for transmitting data of the transmission pack, where a type of the discrete data port is selected from plural predetermined data port types corresponding to the plural predetermined security levels.       
     
     
       14. The data transmission controller of  claim 13 , wherein the circuitry and control logic further are configured to authenticate the transmission pack by scanning and comparing elements of the transmission pack with an authentic transmission pack format. 
     
     
       15. The data transmission controller of  claim 13 , wherein the circuitry and control logic further are configured to determine if the transmission pack includes a discrete recipient IP address code element corresponding to a discrete recipient IP address code of an external recipient. 
     
     
       16. The data transmission controller of  claim 15 , wherein:
   if the circuitry and control logic authenticate the IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then the circuitry and control logic establish a secure data port to transmit the data of the transmission pack to the external recipient.     
     
     
       17. The data transmission controller of  claim 16 , wherein the discrete security code element is an encrypted key code, and the circuitry and control logic are configured to decode the encrypted key code. 
     
     
       18. The data transmission controller of  claim 15 , wherein:
   if the circuitry and control logic authenticate the IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then the circuitry and control logic establish a controlled data port to transmit the data of the transmission pack to a holding structure of the external recipient.     
     
     
       19. The data transmission controller of  claim 18 , wherein the circuitry and control logic establish the controlled data port to transmit the data of the transmission pack to a mailbox of the external recipient. 
     
     
       20. The data transmission controller of  claim 18 , wherein the circuitry and control logic establish the controlled data port to transmit the data of the transmission pack to a mini- server of the external recipient.   
     
     
       21. The data transmission controller of  claim 18 , wherein the discrete security code element is a secure key code. 
     
     
       22. The data transmission controller of  claim 15 , wherein:
   if the circuitry and control logic fail to authenticate an IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then the circuitry and control logic transmit the transmission pack back to the external transmission originator.     
     
     
       23. The data transmission controller of  claim 15 , wherein:
   if the circuitry and control logic fail to authenticate an IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then the circuitry and control logic transmit the transmission pack to the external recipient for discrete review by the external recipient.     
     
     
       24. The data transmission controller of  claim 15 , wherein:
   if the circuitry and control logic authenticate the IP address code element, a discrete security code element corresponding to a first security level, and the transmission originator, then the circuitry and control logic establish a secure data port to transmit the data of the transmission pack to the external recipient;        if the circuitry and control logic authenticate the IP address code element, a discrete security code element corresponding to a second security level, and the transmission originator, then the circuitry and control logic establish a controlled data port to transmit the data of the transmission pack to a holding structure of the external recipient; and        if the circuitry and control logic fail to authenticate the IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then the circuitry and control logic transmit the transmission pack back to the external transmission originator.     
     
     
       25. The data transmission controller of  claim 13 , wherein the data transmission controller is a router. 
     
     
       26. The data transmission controller of  claim 13 , wherein the data transmission controller is a hub router. 
     
     
       27. The data transmission controller of  claim 13 , wherein the data transmission controller is located at an internet service provider hub router. 
     
     
       28. The data transmission controller of  claim 13 , wherein the data transmission controller is located at an NAP distribution point. 
     
     
       29. The data transmission controller of  claim 13 , wherein the data transmission controller is part of a recipient personal computer. 
     
     
       30. The data transmission controller of  claim 13 , wherein the data transmission controller is part of an Intranet terminal receiver/router. 
     
     
       31. A data transmission controller, comprising:
   means for authenticating a transmission pack of data, including means for determining if the transmission pack includes a discrete security code element corresponding to a discrete security code assigned to an external transmission originator, where the discrete security code is one of plural pre - assigned security codes, and where each security code and corresponding security code element represents one of plural predetermined security levels; and        means for establishing a discrete data port for transmitting data of the transmission pack, where a type of the discrete data port is selected from plural predetermined data port types corresponding to the plural predetermined security levels.     
     
     
       32. The data transmission controller of  claim 31 , wherein the means for authenticating further comprises means for scanning and comparing elements of the transmission pack with an authentic transmission pack format. 
     
     
       33. The data transmission controller of  claim 31 , wherein the means for authenticating comprises means for determining if the transmission pack includes a discrete recipient IP address code element corresponding to a discrete recipient IP address code of an external recipient. 
     
     
       34. A protection method for controlling data transmission, comprising:
   authenticating a received transmission pack of data, including determining if the transmission pack includes a discrete security code element corresponding to a discrete security code assigned to an external transmission originator, where the discrete security code is one of plural pre - assigned security codes, and where each security code and corresponding security code element represents one of plural predetermined security levels; and        in accordance with a result of the authenticating, establishing a discrete data port for transmitting data of the transmission pack, where a type of the discrete data port is selected from plural predetermined data port types corresponding to the plural predetermined security levels.     
     
     
       35. The protection method of  claim 34 , wherein the authenticating further comprises:
   scanning and comparing elements of the transmission pack with an authentic transmission pack format.     
     
     
       36. The protection method of  claim 35 , wherein the authenticating further comprises:
   determining if the transmission pack includes a discrete recipient IP address code element corresponding to a discrete recipient IP address code of an external recipient.     
     
     
       37. The protection method of  claim 36 , further comprising:
   if the scanning and comparing authenticate the IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then establishing a secure data port to transmit the data of the transmission pack to the external recipient.     
     
     
       38. The protection method of  claim 37 , wherein the discrete security code element is an encrypted key code, and the authenticating further comprises decrypting the encrypted key code. 
     
     
       39. The protection method of  claim 36 , further comprising:
   if the scanning and comparing authenticate the IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then establishing a controlled data port to transmit the data of the transmission pack to a holding structure of the external recipient.     
     
     
       40. The protection method of  claim 39 , further comprising transmitting the data of the transmission pack via the controlled data port to a mailbox of the external recipient. 
     
     
       41. The protection method of  claim 39 , further comprising transmitting the data of the transmission pack via the controlled data port to a mini- server of the external recipient.   
     
     
       42. The protection method of  claim 39 , wherein the discrete security code element is a secure key code. 
     
     
       43. The protection method of  claim 36 , further comprising:
   if the scanning and comparing fail to authenticate an IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then transmitting the transmission pack back to the external transmission originator.     
     
     
       44. The protection method of  claim 36 , further comprising:
   if the scanning and comparing fail to authenticate an IP address code element, a discrete security code element corresponding to a predetermined security level, and the transmission originator, then transmitting the transmission pack to the external recipient for discrete review by the external recipient.     
     
     
       45. The protection method of  claim 36 , further comprising:
   if the scanning and comparing authenticate the IP address code element, a discrete security code element corresponding to a first security level, and the transmission originator, then establishing a secure data port to transmit the data of the transmission pack to the external recipient;        if the scanning and comparing authenticate the IP address code element, a discrete security code element corresponding to a second security level, and the transmission originator, then establishing a controlled data port to transmit the data of the transmission pack to a holding structure of the external recipient; and        if the scanning and comparing fail to authenticate an IP address code element, a discrete security code element corresponding to a predetermined security level, or the transmission originator, then transmitting the transmission pack back to the external transmission originator.     
     
     
       46. A data transmission recipient, comprising:
   a data processor; and        in - line circuitry and control logic associated with the data processor and configured to:      authenticate a received transmission pack of data, including determining if the transmission pack includes a discrete security code element corresponding to a discrete security code assigned to an external transmission originator, where the discrete security code is one of plural pre - assigned security codes, and where each security code and corresponding security code element represents one of plural predetermined security levels;        in accordance with a result of authentication, establish a discrete data port for transmitting data of the transmission pack, where a type of the discrete data port is selected from plural predetermined data port types corresponding to the plural predetermined security levels; and        transmit data of the authenticated transmission pack via the discrete data port to the data processor.       
     
     
       47. The data transmission recipient of  claim 46 , wherein the data transmission recipient is a personal computer. 
     
     
       48. The data transmission recipient of  claim 46 , wherein the data transmission recipient is a local area network. 
     
     
       49. The data transmission recipient of  claim 46 , wherein the data transmission recipient is an Intranet terminal receiver/router. 
     
     
       50. A data transmission system, comprising:
   at least one transmission originator, each transmission originator having at least one discrete security code assigned thereto;        at least one recipient, each recipient having at least one discrete recipient IP address code assigned thereto; and        a data transmission controller arranged in communication with the at least one transmission originator and the at least one recipient,        wherein the data transmission controller comprises circuitry and control logic configured to:      authenticate a transmission pack of data received from a discrete transmission originator, including      determining if the transmission pack includes a discrete security code element corresponding to a discrete security code assigned to the discrete transmission originator, where the discrete security code is one of plural pre - assigned security codes, and where each security code and corresponding security code element represents one of plural predetermined security levels;        in accordance with a result of authentication, establish a discrete data port for transmitting data of the transmission pack, where a type of the discrete data port is selected from plural predetermined data port types corresponding to the plural predetermined security levels; and          transmit data of the transmission pack via the discrete data port to a discrete recipient.       
     
     
       51. The system of  claim 50 , wherein the at least one transmission originator is pre- assigned plural discrete security codes having different security levels.   
     
     
       52. The system of  claim 50 , wherein the data transmission controller comprises circuitry and control logic configured to:
   authenticate the transmission pack of data received from the discrete transmission originator, including      scanning and comparing elements of the transmission pack with an authentic transmission pack format.       
     
     
       53. The system of  claim 50 , wherein said data transmission controller comprises circuitry and control logic configured to:
   authenticate a transmission pack of data received from a discrete transmission originator, including      determining if the transmission pack includes a discrete recipient IP address code element corresponding to a discrete recipient IP address code of the discrete recipient, and          transmit the data of the transmission pack via the discrete data port to the discrete recipient.

Join the waitlist — get patent alerts

Track USRE42212E — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.