Systems and methods for providing network security using a secure digital device

US9762614B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9762614-B2
Application numberUS-201514622764-A
CountryUS
Kind codeB2
Filing dateFeb 13, 2015
Priority dateFeb 13, 2014
Publication dateSep 12, 2017
Grant dateSep 12, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system may include a traffic interception module configured to intercept network traffic of a host device. A traffic virtualization module may be configured to generate a virtual file on the host device containing the intercepted network traffic. A security system interface module may be configured to provide the virtual file to a secure digital security system over a virtualized file interface coupling the host device to the secure digital security system, and to receive instructions to allow or to deny the network traffic from the secure digital security system over the virtualized file interface. A traffic access management module may be configured to allow or to deny the network traffic based on the instructions.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system comprising: a host device; a secure digital device including a data store and at least one security engine; a virtual file interface configured to assist in transferring data at file transfer speeds between the host device and the secure digital device; a traffic interception module configured to intercept network traffic of the host device, the network traffic of the host device including one of incoming network traffic or outgoing network traffic; a host interface configured to receive data store commands to retrieve or store data in the data store and to receive the network traffic of the host device intercepted by the traffic interception module; a virtualization module on the host device configured to identify the data store commands and the network traffic, to generate one or more virtual files containing the network traffic, to send the one or more virtual files containing the network traffic to the virtual file interface, and to send the data store commands to the data store; the virtual file interface being configured to provide the one or more virtual files to the secure digital device at the file transfer speeds; the at least one security engine being configured to evaluate the network traffic in the one or more virtual files, to generate an instruction whether to allow or deny the network traffic based on a security policy, and to assist in sending the instruction to the host device; and a traffic access management module on the host device configured to allow or deny the network traffic based on the instruction. 2. The system of claim 1 , wherein the network traffic comprises outgoing network traffic. 3. The system of claim 1 , wherein the network traffic comprises incoming network traffic. 4. The system of claim 1 , further comprising a virtualized traffic encryption module configured to encrypt the one or more virtual files before the virtual file interface provides the one or more virtual files to the secure digital device. 5. The system of claim 1 , wherein the traffic interception module is further configured to monitor one or more applications and/or processes for a presence or absence of the network traffic. 6. The system of claim 1 , wherein the traffic interception module is further configured to monitor one or more root-level processes of a network interface for a presence or absence of the network traffic. 7. The system of claim 1 , wherein the secure digital device is incorporated into a Secure Digital (SD) card coupled to the host device. 8. The system of claim 1 , wherein the host device comprises a portable electronic device. 9. A secure digital device comprising: a data store; a virtualized file management module configured to receive one or more virtual files from a host device over a virtual file interface configured to assist in transferring data at file transfer speeds between the host device and the secure digital device, the one or more virtual files containing network traffic intercepted at the host device, the network traffic of the host device including one of incoming network traffic or outgoing network traffic, the virtualized file management module further configured to receive data store commands to retrieve or store data in the data store; a controller configured to manage the data store commands by retrieving or storing the data in the data store; a security policy management module configured to evaluate the network traffic in the one or more virtual files for compliance with a security policy; a traffic access determination module configured to generate an instruction whether to allow or deny the network traffic in accordance with the evaluation; and an instruction providing module configured to provide to the host device over the virtual file interface the instruction whether to allow or deny the network traffic. 10. The secure digital device of claim 9 , wherein the network traffic comprises outgoing network traffic. 11. The secure digital device of claim 9 , wherein the network traffic comprises incoming network traffic. 12. The secure digital device of claim 9 , wherein the one or more virtual files comprises one or more encrypted virtual files. 13. The secure digital device of claim 9 , wherein the secure digital device is incorporated into a Secure Digital (SD) card coupled to the host device. 14. The secure digital device of claim 9 , wherein the host device comprises a portable electronic device. 15. A method comprising: receiving at a host device data store commands to retrieve or store data in a data store of a secure digital device, the secure digital device including the data store and at least one security engine; intercepting network traffic of the host device, the network traffic of the host device including one of incoming network traffic or outgoing network traffic; using a virtualization module to identify the data store commands and the network traffic; sending the data store commands to the data store; using the virtualization module to generate one or more virtual files containing the network traffic of the host device; sending the one or more virtual files containing the network traffic to a virtual file interface; using the virtual file interface to transfer the one or more virtual files at file transfer speeds to the secure digital device; using the at least one security engine to evaluate the network traffic in the one or more virtual files to determine whether to allow or deny the network traffic based on a security policy; generating an instruction whether to allow or deny the network traffic based on the evaluation; sending the instruction to the host device; and allowing or denying the network traffic based on the instruction. 16. The method of claim 15 , wherein the network traffic comprises outgoing network traffic. 17. The method of claim 15 , wherein the network traffic comprises incoming network traffic. 18. The method of claim 15 , wherein the one or more virtual files is encrypted before being provided to the secure digital device. 19. The method of claim 15 , further comprising monitoring the network traffic by monitoring one or more applications and/or processes. 20. The method of claim 15 , further comprising monitoring the network traffic by monitoring one or more root-level processes of a network interface. 21. The method of claim 15 , wherein the secure digital device is incorporated into a Secure Digital (SD) card coupled to the host device. 22. The method of claim 15 , wherein the host device comprises a portable electronic device. 23. A method comprising: in a secure digital device including a data store and at least one security engine: receiving one or more virtual files from a host device over a virtual file interface configured to transfer data at file transfer speeds, the one or more virtual files containing network traffic intercepted at the host device, the network traffic of the host device including one of incoming network traffic or outgoing network traffic; receiving data store commands to retrieve or store data in the data store; managing the data store commands by retrieving or storing the data in the data store; using the at least one security engine to evaluate the network traffic in the one or more virtual files for compliance with a security policy; generating an instruction whether to allow or deny the network traffic in accordance with the evaluation; and providing to the h

Assignees

Inventors

Classifications

  • for detecting or protecting against malicious traffic · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9762614B2 cover?
A system may include a traffic interception module configured to intercept network traffic of a host device. A traffic virtualization module may be configured to generate a virtual file on the host device containing the intercepted network traffic. A security system interface module may be configured to provide the virtual file to a secure digital security system over a virtualized file interfa…
Who is the assignee on this patent?
Cupp Computing As
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 12 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).