Electronic interface device, filtering method and associated computer program

The electronic interface device addresses the challenge of data compliance between networks with different labeling policies by using filtering modules specific to each policy and a transposition unit for label adaptation, thereby improving the control of sensitive data dissemination.

FR3156938A1Pending Publication Date: 2025-06-20THALES SA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
FR2023014295
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-20

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Electronic interface device, filtering method and associated computer program s This electronic interface device (10) between a first network (12), obeying a first labeling policy, and a second network (12), obeying a second labeling policy, the device (10) comprises: - a first interface unit (16), comprising a first module (22) for filtering the data according to filtering rules defined according to the first data labeling policy; - a second interface unit (18), comprising a second module for filtering the data according to filtering rules defined according to the second data labeling policy; and - a transposition unit (20), comprising a transposition module (26) being configured to transpose a label associated with the data from one of the first or second labeling policy to the other of the first or second labeling policy.Figure for abstract: Figure 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Electronic interface device, associated filtering method and computer program

[0001] The present invention relates to an electronic interface device between a first network, obeying a first data labeling policy, and a second network, obeying a second data labeling policy. The invention further relates to a method for filtering data, between such first and second networks, implemented by such an electronic interface device. The invention further relates to a computer program comprising software instructions which, when executed by a computer, implement such a method.

[0002] In the field of electronic interface devices, devices are known which provide the interface between a first network and a second network having different security constraints. For example, one of the networks is capable of allowing data to pass through having a given sensitivity level while the other network is not capable of allowing data to pass through having such a sensitivity level, and vice versa.

[0003] Furthermore, in order to ensure appropriate control of access to sensitive data, an approach known as DCS (Data Centric Security) has been developed in recent years. In this approach, labels are associated with the data in order to characterize the sensitivity of the data directly at the data level and not only at the level of the media on which this data is transmitted. It is then possible to determine, directly by the data and by a label associated with it, the sensitivity of the data.

[0004] The association of labels with data under a DCS approach is based for example on SPIF files (acronym for "Security Policy Information File"), such files being for example XML files (acronym for "Extensible Markup Language") characterizing the level of sensitivity of data, expressed according to a label of a determined security policy.

[0005] The NATO standard (acronym for "North Atlantic Treaty Organization") STANAG 4778 (acronym for "Standardization Agreement"), for example, defines the mechanisms for associating data with its label at NATO level. The NATO standard STANAG 4774 defines the syntax used for labels to characterize the sensitivity of data at NATO level. It is understood here that a sensitivity, or a level of sensitivity, is defined by multiple attributes, including for example an attribute relating to a level of confidentiality, an attribute relating to a geographical restriction on the dissemination of the data, an attribute relating to the medical nature of the data, etc.

[0006] These sets of attributes are defined and standardized within a specific labeling policy. Each labeling policy defines a plurality of labels characterizing the sensitivity of a piece of data. As seen above, an example of a labeling policy is defined by the NATO STANAG 4774 standard, characterizing, for example, data by labels such as NATO Restricted, NATO confidential, NATO Secret, Cosmic Top Secret, etc. Another example of a labeling policy is, for example, a policy specific to the national defense of a given state, characterizing, for example, data by labels such as: Unprotected, Restricted distribution, Secret, Top secret.

[0007] In order to better control the dissemination of sensitive data, electronic interface devices are known, capable of filtering data between a first network and a second network, according to a label associated with a piece of data. Such an electronic device comprises for example a filtering unit, at the interface between the first and the second network, and capable of filtering the data according to filtering rules defined according to a labeling policy.

[0008] Such electronic interface devices are not, however, entirely satisfactory. Indeed, it is common to use multiple networks obeying different data labeling policies, that is to say networks for which the data labels are expressed according to such different policies. For example, a first network obeys a NATO labeling policy while a second network obeys a labeling policy specific to national defense. In other words, and according to this example, the labels contained in the SPIF files associated with the data circulating in the first network are expressed in accordance with a NATO labeling policy while the labels contained in the SPIF files associated with the data circulating in the second network are expressed in accordance with a labeling policy specific to national defense.

[0009] Due to the differences between the labeling policies used, these devices do not allow for ensuring full compliance with the sensitivity requirements of data exchanged between networks, compared to the existing policies on the networks on which this data circulates. These devices therefore do not allow satisfactory control of the dissemination of sensitive data.

[0010] One of the aims of the invention is then to obtain an interface device improving the control of the dissemination of sensitive data.

[0011] To this end, the invention relates to an electronic interface device between a first network, obeying a first data labeling policy, and a second network, obeying a second data labeling policy, the device comprising: - a first interface unit, configured to be connected to the first network, the first interface unit comprising a first filtering module, configured to filter data according to filtering rules defined according to the first data labeling policy; - a second interface unit, configured to be connected to the second network, the second interface unit comprising a second filtering module configured to filter data according to filtering rules defined according to the second data labeling policy; and

[0012] a transposition unit, connected to the first interface unit and to the second interface unit, the transposition unit comprising a transposition module being configured to transpose a label associated with the data passing through the transposition unit between the first and second interface units, from one of the first or second labeling policy to the other of the first or second labeling policy.

[0013] The use of a first and a second filtering unit, each configured to filter data according to filtering rules defined according to a first, respectively second, data labeling policy, is particularly advantageous, such filtering units ensuring filtering at the input and output of the device, according to the policies specific to the different networks to which the interface device is connected. This thus improves the control of the dissemination of sensitive data.

[0014] According to other advantageous aspects of the invention, the electronic interface device comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations:

[0015] - the first filtering module is configured to block data if the label associated with the data does not comply with the filtering rules defined according to the first data labeling policy and in which the second filtering module is configured to block data if the label associated with the data does not comply with the filtering rules defined according to the second data labeling policy;

[0016] - the first filtering module is configured to filter data from the first network to the transposition unit and / or from the transposition unit to the first network, and wherein the second filtering module is configured to filter data from the transposition unit to the second network and / or from the second network to the transposition unit

[0017] - the first filtering module is configured to filter data from the first network to the transposition unit according to a first set of filtering rules defined according to the first labeling policy, and to filter data from the transposition unit to the first network according to a second set of filtering rules defined according to the first labeling policy, said first and second sets of filtering rules being different,

[0018] the second filtering module being configured to filter data from the transposition unit to the second network according to a first set of filtering rules defined according to the second labeling policy, and to filter data from the second network to the transposition unit according to a second set of filtering rules defined according to the second labeling policy, said first and second sets of filtering rules being different

[0019] - the transposition unit further comprises a signature module, configured to affix a signature to the data and / or to the transposed label associated with the data;

[0020] - the transposition unit further comprises an encryption module, configured to encrypt the data for which the label was transposed;

[0021] - the transposition unit further comprises a decryption module, configured to decrypt the data for which the transposition module is configured to transpose the label and / or to decrypt the label associated with said data; and

[0022] - the first interface unit comprises a plurality of first modules of filtering and / or wherein the second interface unit comprises a plurality of second filtering modules.

[0023] The invention further relates to a method for filtering data between a first network, obeying a first data labeling policy, and a second network, obeying a second data labeling policy, the method being implemented by an interface device as mentioned above and comprising the following steps:

[0024] - filtering, by the first filtering module of the first interface unit, of data based on filtering rules defined according to the first data labeling policy;

[0025] - filtering, by the second filtering module of the second interface unit, data based on filtering rules defined according to the second data labeling policy; and

[0026] - transposition, by the transposition module of the transposition unit, of the label associated with data passing through the transposition unit between the first and second interface units, from one of the first or second labeling policies to the other of the first or second labeling policies.

[0027] The invention further relates to a computer program comprising software instructions which, when executed by a computer, implement a data filtering method as mentioned above.

[0028] The invention will be better understood on reading the description which follows, given solely by way of non-limiting example and with reference to the following figures, in which:

[0029] [Fig-1] [Fig.l] is a general schematic representation of a device interface electronics according to the invention; and

[0030] [Fig.2] [Fig.2] is a representative flowchart of a filtering process implemented work by the device of [Fig.l].

[0031] With reference to [Fig.l], an electronic interface device 10 is an interface device between a first network 12 and a second network 14, i.e. the electronic interface device 10 is configured to be connected to the first network 12 and to the second network 14.

[0032] The first network 12 obeys a first data labeling policy PI and the second network 14 obeys a second data labeling policy P2. As will be presented in more detail later, the first security policy PI and the second security policy P2 are separate security policies.

[0033] By obeying a security policy PI, P2, it is meant here that data D, transiting / hosted on the network 12, 14 and obeying the security policy, are labeled using a label L, according to said security policy PI, P2. In the remainder of the description, a DL-labeled data item is called a D-labeled data item associated with a label L. Thus, and as will be presented in more detail later, the DL-labeled data transiting / hosted by the first network 12 comprise a label L expressed according to a syntax defined by the first labeling policy PI and the DL-labeled data transiting / hosted by the second network 14 comprise a label L expressed according to a syntax defined by the second labeling policy P2.

[0034] The labeled data DL are for example data D formed by a file of any format, associated with a label contained in a file characterizing the sensitivity of the data, such a file being for example an XML file (acronym for “Extensible Markup Language”) and for example a SPIF file (acronym for “Security Policy Information File”). Such a file defines the attributes of a labeling policy. The label L contained in such a file is then compliant with the first labeling policy PI for the data circulating on the first network 12 and the L label contained in such a file then complies with the second P2 labeling policy for data circulating on the second network 14.

[0035] The PI, P2 labeling policy is for example defined by the NATO standard STANAG 4774 (NATO labeling policy), reflects a nomenclature of sensitivity specific to the national defense of a country (labeling policy of the national defense of said country), etc.

[0036] For example, when the PI, P2 labeling policy is defined by the NATO STANAG 4774 standard, the L labels associated with the D data are chosen, for example, from NATO Restricted, NATO confidential, NATO Secret, Cosmic Top Secret (from the least sensitive to the most sensitive).

[0037] For example, when the PI, P2 labeling policy is defined by a standard specific to the national defense of a country, for example by a standard relating to French national defense, the labels L associated with the data D are chosen, for example, from unprotected, Restricted distribution, Secret, Very secret (from the least sensitive to the most sensitive).

[0038] For example, the first labeling policy PI is here defined by the NATO standard STANAG 4774 and the second labeling policy P2 is here defined by the labeling standard specific to the national defense of a country, for example a labeling policy specific to French national defense.

[0039] As illustrated in [Fig.l], the electronic interface device 10 comprises a first interface unit 16, a second interface unit 18 and a transposition unit 20.

[0040] The first interface unit 16 is configured to be connected to the first network 12 and the second interface unit 18 is configured to be connected to the second network 14. By connected to the first network 12 and connected to the second network 14, it is meant here that the first interface unit 16 is configured to exchange data D with the first network 12 and that the second interface unit 18 is configured to exchange data D with the second network 14.

[0041] As illustrated in [Fig.l], the first interface unit 16 comprises a first filter module 22. In an embodiment not illustrated, the first interface unit 16 comprises a plurality of first filter modules 22.

[0042] The first filtering module 22 is configured to filter data D according to filtering rules RI defined according to the first data labeling policy. Such filtering rules RI comprise for example a list of authorized labels L and / or a list of unauthorized labels L, the labels L being expressed according to the first data labeling policy PL.

[0043] The first filtering module 22 is for example configured to block a data item D if the label L associated with the data item D (or in other words the label L of the data item labeled DL) does not comply with the RI filtering rules of the first filtering module 22. The first filtering module 22 is then, for example, further configured to allow data to pass through that it does not block.

[0044] For example, when the filtering rules RI comprise a list of authorized labels L and / or a list of unauthorized labels L, the first filtering module 22 is configured to block a data item D if the label L associated with the data item D is not included in the list of authorized labels and / or if the label L associated with the data item D is included in the list of unauthorized labels.

[0045] The first filtering module 22 is for example configured to filter data from the first network 12 to the transposition unit 20 and / or from the transposition unit 20 to the first network 12.

[0046] It will then be understood that when the first filtering module 22 is configured to filter data from the first network 12 to the transposition unit 20 and from the transposition unit 20 to the first network 12, the first filtering module 22 is configured to filter both the data D entering the interface device 10 via the first interface unit 16 but also the data leaving the interface device 10 via the first interface unit 16.

[0047] Furthermore, when the first filtering module 22 is configured to filter data from the first network 12 to the transposition unit 20 and from the transposition unit 20 to the first network 12, the filtering rules RI of the first filtering module 22 comprise, for example, a first set J1R1 of filtering rules defined according to the first labeling policy and a second set J2R1 of filtering rules defined according to the first labeling policy. Said first J1R1 and second J2R1 sets of filtering rules are preferably different.

[0048] The first filtering module 22 is then configured to filter data D from the first network 12 to the transposition unit 20 according to the first set of filtering rules J1R1 defined according to the first labeling policy, and to filter data D from the transposition unit 20 to the first network 12 according to the second set of filtering rules J2R1 defined according to the first labeling policy.

[0049] In the non-illustrated embodiment according to which the first interface unit 16 comprises a plurality of first filtering modules 22, each first filtering module 22 is configured to filter data D according to filtering rules RI defined according to the first data labeling policy PI, the filtering rules RI of each first filtering module 22 being for example different. For example, each first filtering module 22 is configured to be connected to a respective portion of the first network 12, the respective portions of the first network 12 being for example intended for the transit and / or storage of D data of different sensitivities.

[0050] As illustrated in [Fig.l], the second interface unit 18 comprises a second filtering module 24. For example, and as illustrated in [Fig.l], the second interface unit 18 comprises a plurality of second filtering modules 24.

[0051] The second filtering module 24 is configured to filter data D according to filtering rules R2 defined according to the second data labeling policy P2. Such filtering rules R2 comprise for example a list of authorized labels L and / or a list of unauthorized labels L, the labels L being expressed according to the second data labeling policy P2.

[0052] In a similar manner to the first filtering module 22, the second filtering module 24 is for example configured to block a data item D if the label L associated with the data item D (or in other words the label L of the data item labeled DL) does not comply with the filtering rules R2 of the second filtering module 24. The second filtering module 24 is then for example further configured to allow the data that it does not block to pass through.

[0053] For example, when the filtering rules R2 comprise a list of authorized labels L and / or a list of unauthorized labels L, the second filtering module 24 is configured to block a data item D if the label L associated with the data item D is not included in the list of authorized labels and / or if the label L associated with the data item D is included in the list of unauthorized labels.

[0054] The second filtering module 24 is for example configured to filter data from the transposition unit 20 to the second network 14 and / or from the second network 14 to the transposition unit 20.

[0055] It will then be understood that when the second filtering module 24 is configured to filter data from the transposition unit 20 to the second network 14 and from the second network 14 to the transposition unit 20, the second filtering module 24 is configured to filter both the data D entering the interface device 10 via the second interface unit 18 but also the data leaving the interface device 10 via the second interface unit 18.

[0056] Furthermore and in a manner similar to the first filtering module 22, when the second filtering module 24 is configured to filter data from the transposition unit 20 to the second network 14 and from the second network 14 to the transposition unit 20, the filtering rules R2 of the second filtering module 24 comprise for example a first set J1R2 of filtering rules defined according to the second labeling policy and a second set J2R2 of filtering rules. filtering defined according to the second labeling policy. Said first J1R2 and second J2R2 sets of filtering rules are preferably different.

[0057] The second filtering module 24 is then configured to filter data D from the transposition unit 20 to the second network 14 according to the first set of filtering rules J1R2 defined according to the second labeling policy, and to filter data D from the second network 14 to the transposition unit 20 according to the second set of filtering rules J2R2 defined according to the second labeling policy.

[0058] In the embodiment illustrated in [Fig.l] according to which the second interface unit 18 comprises a plurality of second filtering modules 24, each second filtering module 24 is configured to filter data D according to filtering rules R2 defined according to the second data labeling policy PI, the filtering rules R2 of each second filtering module 24 being for example different. For example, each second filtering module 24 is configured to be connected to a respective portion of the second network 14, the respective portions of the second network 14 being for example intended for the transit and / or storage of data D of different sensitivities.

[0059] The transposition unit 20 is connected to the first interface unit 16 and to the second interface unit 18. In particular, the transposition unit 20 is connected to the first interface unit 16 and to the second interface unit 18 so as to be able to exchange data D, in particular data labeled DL, with the first interface unit 16 and with the second interface unit 18.

[0060] As visible in [Fig.l], the transposition unit 20 comprises a transposition module 26. Furthermore, the transposition unit 20 further comprises, for example, a signature module 28, an encryption module 30 and / or a decryption module 32.

[0061] The transposition module 26 is configured to transpose the label L associated with the data D passing through the transposition unit 20 between the first interface unit 12 and the second interface unit 14, from one of the first PI or second P2 labeling policy to the other of the first PI or second P2 labeling policy.

[0062] In particular, the transposition module 26 is configured to transpose the label L associated with the data D circulating by the transposition unit 20 from the first interface unit 12 to the second interface unit 14 from the first labeling policy PI to the second labeling policy P2.

[0063] Furthermore, and for example, the transposition module 26 is configured to transpose the label L associated with the data D circulating by the transposition unit 20 from the second interface unit 14 to the first interface unit 12 of the second labeling policy P2 to the first labeling policy PI.

[0064] For example, the transposition module transposes the label from one of the first PI or second P2 labeling policy to the other of the first PI or second P2 labeling policy by following RT transposition rules. The transposition rules are for example arranged in the form of at least one correspondence table between the labels according to the first PI and the second P2 labeling policy.

[0065] The signature module 28 is for example configured to affix a signature S to the data and / or to the transposed label L associated with the data D, that is to say to the label having been transposed from one of the first PI or second P2 labeling policy to the other of the first PI or second P2 labeling policy. For example, the signature module 28 is configured to affix a signature to the labeled data DL whose label L has been transposed.

[0066] The signature module 28 is for example configured to generate a signature as a function of the labeled data D and / or the transposed label L associated with this data so as to guarantee the integrity of the association of the transposed label L with the labeled data D.

[0067] The encryption module 30 is configured to encrypt the data D for which the label has been transposed and / or to encrypt the label L associated with such data D. The encryption module 30 is for example configured to encrypt said data D as well as the label L associated with said data D. In other words, the encryption module 30 is for example configured to encrypt the data labeled DL.

[0068] For this purpose, the encryption module 30 is for example configured to encrypt the data D using a symmetric key and to encrypt the encryption key of said data D using an asymmetric key obtained as a function of the label L associated with the data D. The encryption module 30 is then for example, and in other words, configured to encrypt the label L into an encryption key of the symmetric encryption key of the data D.

[0069] In a particular embodiment, the encryption module 30 is configured to encrypt only the label L associated with the data D for which the label has been transposed. This is for example the case when the data D is encrypted and only the asymmetric key obtained as a function of the label L is decrypted by the decryption module 32 prior to the transposition of the label L, as will be presented in more detail later.

[0070] The encryption module 30 is for example configured to apply ABE type encryption (acronym for “Attribute Based Encryption”) to encrypt the data D and / or the label L associated with the data.

[0071] The decryption module 32 is configured to decrypt the data D for which the transposition module 26 is configured to transpose the label L and / or to decrypt the label L associated with said data. For example, the decryption module 32 is configured to decrypt said data labeled DL before its transposition by the transposition module 26.

[0072] For this purpose, the decryption module 32 is for example configured to decrypt the data D using a symmetric key and to decrypt the encryption key of said data D using an asymmetric key obtained as a function of the label L associated with the data D. The decryption module 32 is then for example, and in other words, configured to encrypt the label L into an encryption key of the symmetric encryption key of the data D.

[0073] In a particular embodiment, the decryption module 32 is configured to decrypt only the label L associated with the data D whose label is to be transposed by the transposition module 26. This is for example the case when the data D is intended to remain encrypted in the electronic interface device 10, the decryption module then decrypting only the asymmetric encryption key, obtained as a function of the label L, of the symmetric encryption key of the data D. The decryption module 32 is for example configured to decrypt an ABE type encryption of the data D and / or of the label L associated with the data.

[0074] In a particular example (not shown), the electronic interface device 10 comprises an information processing unit formed for example of an electronic memory associated with a processor.

[0075] In such an example, the first interface unit 16, the second interface unit 18 and the transposition unit 20 are each implemented in the form of software executable by the processor. The memory is then capable of storing a first interface software, a second interface software and a transposition software. The processor of the information processing unit is then capable of executing the first interface software, the second interface software and the transposition software.

[0076] According to another variant, the first interface unit 16, the second interface unit 18 and the transposition unit 20 are each produced in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array) or in the form of a dedicated integrated circuit, such as an ASIC (Application Specific Integrated Circuit).

[0077] When the first interface unit 16, the second interface unit 18 and the transposition unit 20 are implemented in the form of one or more software programs, i.e. in the form of a computer program, they are furthermore capable of being recorded on a medium, not shown, that is readable by a computer. The computer-readable medium is, for example, a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. For example, the readable medium is a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, NVRAM). A computer program including software instructions is then stored on the readable medium.

[0078] A method 100 for filtering data, between a first network 12, obeying a first data labeling policy PI, and a second network 14, obeying a second data labeling policy P2, implemented by an electronic interface device 10 as presented above, will now be described.

[0079] This method 100 comprises a first filtering step 110, a transposition step 120 as well as a second filtering step 130.

[0080] During the first filtering step 110, the first filtering module 22 of the first interface unit 16 filters data according to RI filtering rules defined according to the first data labeling policy PI.

[0081] The first filtering module 22 filters, for example, data from the first network 12 to the transposition unit 20.

[0082] During the transposition step 120, the transposition module 26 of the transposition unit 20 transposes the label associated with the data D passing through the transposition unit 20 between the first 16 and the second 18 interface units from one of the first PI or second P2 labeling policy to the other of the first PI or second P2 labeling policy.

[0083] For example, the transposition module 26 transposes the label L of the data D filtered by the first filtering module 22 from the first labeling policy PI to the second labeling policy P2.

[0084] During the second filtering step 130, the second filtering module 24 of the second interface unit 18 filters data D according to filtering rules defined according to the second data labeling policy P2.

[0085] The second filtering module 24 filters, for example, data from the transposition unit 20 to the second network 14.

[0086] The data D passing through the electronic interface device 10 are then for example filtered by the first filtering module 22 during the first filtering step 110, the labels L associated with the filtered data D are transposed by the transposition module 26 of the transposition unit 20 from the first data labeling policy PI to the second data labeling policy P2 during the transposition step and the data D whose labels have been transposed are filtered by the second filtering module 24 during the second filtering step 130.

[0087] Furthermore, and as an optional addition, the data D passing through the electronic interface device 10 are filtered by the second filtering module 22 during of the first filtering step 110, the labels L associated with the data D thus filtered are transposed by the transposition module 26 of the transposition unit 20 from the second P2 data labeling policy to the first PI data labeling policy during the transposition step and the data D whose labels have been transposed are filtered by the first filtering module 22 during the second filtering step 130.

[0088] As seen above, the use of an electronic interface device 10 comprising a first interface unit 16, a second interface unit 18 and a transposition unit 20 as presented above is particularly advantageous for improving the control of the dissemination of potentially sensitive data D.

[0089] The use of a first 22 and a second 24 filtering modules configured to block data D if the label L associated with a data D does not comply with filtering rules contributes to further improving the control of the dissemination of potentially sensitive data D.

[0090] The use of a first filtering module 22 configured to filter data D from the first network 12 to the transposition unit 20 and / or from the transposition unit 20 to the first network 12, and of a second filtering module 24 configured to filter data D from the transposition unit 20 to the second network 14 and / or from the second network 14 to the transposition unit 20 is particularly advantageous for filtering the data independently of the direction of circulation of the data in the device 10, the use of separate filtering sets depending on the direction of circulation of the data in the first 16 and second 18 interface units being particularly advantageous for improving the versatility of the interface device 10.

[0091] The use of a transposition unit 20 comprising a signature module 28 and / or an encryption module 30 and / or a decryption module 32 is particularly advantageous for ensuring the integrity of the data passing through the interface device 10.

[0092] The use of a first interface unit 16 comprising a plurality of first filtering modules 22 and / or a second interface unit 18 comprising a plurality of second filtering modules 24 is particularly advantageous for ensuring appropriate filtering for specific portions of the first 12 and / or the second 14 network, thus making the interface device 10 particularly efficient and versatile.

Claims

Claims

1. Electronic interface device (10) between a first network (12), obeying a first data labeling policy (PI), and a second network (12), obeying a second data labeling policy (P2), the device (10) comprising: - a first interface unit (16), configured to be connected to the first network (12), the first interface unit (16) comprising a first filtering module (22), configured to filter data (D) according to filtering rules (RI) defined according to the first data labeling policy; - a second interface unit (18), configured to be connected to the second network (14), the second interface unit (18) comprising a second filtering module (24) configured to filter data (D) according to filtering rules (R2) defined according to the second data labeling policy;and - a transposition unit (20), connected to the first interface unit (16) and to the second interface unit (18), the transposition unit (20) comprising a transposition module (26) being configured to transpose a label (L) associated with the data (D) passing through the transposition unit (20) between the first (16) and the second (18) interface units, from one of the first (PI) or second (P2) labeling policy to the other of the first (PI) or second (P2) labeling policy.;

2. Electronic interface device (10) according to claim 1, wherein the first filtering module (22) is configured to block a data item (D) if the label (L) associated with the data item (D) does not comply with the filtering rules (RI) defined according to the first data labeling policy and wherein the second filtering module (24) is configured to block a data item (D) if the label (L) associated with the data item (D) does not comply with the filtering rules (R2) defined according to the second data labeling policy.

3. An electronic interface device (10) according to claim 1 or 2, wherein the first filtering module (22) is configured for filtering data (D) from the first network (12) to the transposition unit (20) and / or from the transposition unit (20) to the first network (12), and wherein the second filtering module (24) is configured to filter data (D) from the transposition unit (20) to the second network (14) and / or from the second network (14) to the transposition unit (20).

4. An electronic interface device (10) according to claim 3, wherein the first filtering module (22) is configured to filter data (D) from the first network (12) to the transposition unit (20) according to a first set (J1R1) of filtering rules defined according to the first labeling policy, and to filter data from the transposition unit (20) to the first network (12) according to a second set (J2R1) of filtering rules defined according to the first labeling policy, said first (J1R1) and second sets (J2R1) of filtering rules being different, the second filtering module (24) being configured to filter data (D) from the transposition unit (20) to the second network (14) according to a first set (J1R2) of filtering rules defined according to the second labeling policy,and to filter data (D) from the second network (14) to the transposition unit (20) according to a second set of filtering rules (J2R2) defined according to the second labeling policy, said first (J1R2) and second sets of filtering rules (J2R2) being different.,

5. Electronic interface device (10) according to any one of the preceding claims, wherein the transposition unit (20) further comprises a signature module (28), configured to affix a signature (S) to the data and / or to the label (L) transposed associated with the data (D).

6. Electronic interface device (10) according to any one of the preceding claims, wherein the transposition unit (20) further comprises an encryption module (30), configured to encrypt the data (D) for which the label (L) has been transposed.

7. Electronic interface device (10) according to any one of the preceding claims, wherein the transposition unit (20) further comprises a decryption module (32), configured to decrypt the data (D) for which the transposition module (26) is configured to transpose the label (L) and / or to decipher the label (L) associated with said data (D).

8. An electronic interface device (10) according to any preceding claim, wherein the first interface unit (16) comprises a plurality of first filter modules (22) and / or wherein the second interface unit (18) comprises a plurality of second filter modules (24).

9. Method for filtering data (100), between a first network (12), obeying a first data labeling policy (PI), and a second network (14), obeying a second data labeling policy (P2), the method (100) being implemented by an interface device (10) according to any one of claims 1 to 8 and comprising the following steps: - filtering (110), by the first filtering module (22) of the first interface unit (16), of data (D) according to filtering rules (RI) defined according to the first data labeling policy; - filtering (130), by the second filtering module (24) of the second interface unit (18), of data according to filtering rules (R2) defined according to the second data labeling policy;and - transposition (120), by the transposition module (26) of the transposition unit (20), of the label (L) associated with the data (D) passing through the transposition unit (20) between the first (16) and the second (18) interface unit, from one of the first (PI) or second (P2) labeling policy to the other of the first (PI) or second (P2) labeling policy.;

10. A computer program comprising software instructions which, when executed by a computer, implement a method according to claim 9.

Citation Information

Patent Citations

  • Multi-level security data processing architecture

    EP2428910A2

  • Multi-level security device

    EP3367628A1

  • Apparatus, method, and system for hardware-based filtering in a cross-domain infrastructure

    US20150135254A1

  • Containerized cross-domain solution

    US20220407894A1