Patents Assigned to WATERFALL SECURITY SOLUTIONS LTD
-
Patent number: 11706194Abstract: In one embodiment, a secure network system includes a two-way bridge connecting a protected packet data network with an external packet data network so as to allow bidirectional communication between the protected and external networks, a one-way link unidirectionally connecting the protected network to the external network and physically configured to carry signals in one direction from the protected network to the external network and to be incapable of carrying signals in the opposite direction from the external packet data network to the protected packet data network, and a security server to receive an indication of a security threat to at least one of the networks, and in response to the indication, to deactivate the two-way bridge and activate the one-way link so as to prevent the protected network from receiving packets from the external network while allowing forwarding of packets from the protected network to the external network.Type: GrantFiled: October 6, 2021Date of Patent: July 18, 2023Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventor: Lior Frenkel
-
Patent number: 11190486Abstract: In one embodiment, a secure network system includes a two-way bridge connecting a protected packet data network with an external packet data network so as so allow bidirectional communication between the protected and external networks, a one-way link unidirectionally connecting the protected network to the external network and physically configured to carry signals in one direction from the protected network to the external network and to be incapable of carrying signals in the opposite direction from the external packet data network to the protected packet data network, and a security server to receive an indication of a security threat to at least one of the networks, and in response to the indication, to deactivate the two-way bridge and activate the one-way link so as to prevent the protected network from receiving packets from the external network while allowing forwarding of packets from the protected network to the external network.Type: GrantFiled: August 8, 2019Date of Patent: November 30, 2021Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventor: Lior Frenkel
-
Patent number: 10432404Abstract: Communication apparatus includes a one-way, hardware-actuated data relay, which includes a first hardware interface configured to receive a command from a communications network and a second hardware interface configured to convey the received command to a protected destination when the relay is actuated. A decoder includes a third hardware interface configured to receive a digital signature for the command from the communications network and hardware decoding logic coupled to verify the digital signature and to actuate the relay upon verifying the digital signature, whereby the command is conveyed via the second hardware interface to the protected destination.Type: GrantFiled: March 14, 2017Date of Patent: October 1, 2019Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Andrew Ginter, Tomer Maor
-
Patent number: 10063517Abstract: A method for secure communications between a transmitting computer and a receiving computer includes transmitting data from the transmitting computer over a first one-way link to a data security engine, receiving and validating the data within the data security engine, and, after validating the data, transmitting the data from the data security engine to the receiving computer over a second one-way link.Type: GrantFiled: November 8, 2017Date of Patent: August 28, 2018Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 9847972Abstract: A method for secure communications between a transmitting computer and a receiving computer includes transmitting data from the transmitting computer over a first one-way link to a data security engine, receiving and validating the data within the data security engine, and, after validating the data, transmitting the data from the data security engine to the receiving computer over a second one-way link.Type: GrantFiled: February 27, 2017Date of Patent: December 19, 2017Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 9762536Abstract: A method for secure communications between a transmitting computer (24) and a receiving computer (22) includes transmitting data from the transmitting computer over a first one-way link (28) to a data security engine (26), receiving and validating the data within the data security engine, and, after validating the data, transmitting the data from the data security engine to the receiving computer over a second one-way link (30).Type: GrantFiled: December 28, 2006Date of Patent: September 12, 2017Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 9635037Abstract: Communication apparatus includes a one-way, hardware-actuated data relay, which includes a first hardware interface configured to receive a command from a communications network and a second hardware interface configured to convey the received command to a protected destination when the relay is actuated. A decoder includes a third hardware interface configured to receive a digital signature for the command from the communications network and hardware decoding logic coupled to verify the digital signature and to actuate the relay upon verifying the digital signature, whereby the command is conveyed via the second hardware interface to the protected destination.Type: GrantFiled: September 6, 2012Date of Patent: April 25, 2017Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Andrew Ginter, Tomer Maor
-
Patent number: 9584521Abstract: Apparatus for communication includes a single one-way link, which is physically capable of carrying the communication signals in one direction and incapable of carrying the communication signals in the opposite direction. Ancillary circuitry is coupled so as to cause the single one-way link to convey both first communication signals from a first station to a second station and second communication signals from the second station to the first station.Type: GrantFiled: July 20, 2016Date of Patent: February 28, 2017Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventor: Lior Frenkel
-
Patent number: 9519616Abstract: Storage apparatus (20) includes a memory (30) and an encryption processor (28), which is configured to receive and encrypt data transmitted from one or more computers (24) for storage in the memory. A one-way link (32) couples the encryption processor to the memory so as to enable the encryption processor to write the encrypted data to the memory but not to read from the memory.Type: GrantFiled: July 16, 2015Date of Patent: December 13, 2016Assignee: WATERFALL SECURITY SOLUTION LTD.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 9419975Abstract: Apparatus for communication includes a single one-way link, which is physically capable of carrying the communication signals in one direction and incapable of carrying the communication signals in the opposite direction. Ancillary circuitry is coupled so as to cause the single one-way link to convey both first communication signals from a first station to a second station and second communication signals from the second station to the first station.Type: GrantFiled: April 22, 2013Date of Patent: August 16, 2016Assignee: Waterfall Security Solutions Ltd.Inventor: Lior Frenkel
-
Patent number: 9369446Abstract: A method for communication includes receiving in a secure installation via a network from a remote user terminal an input comprising a stream of symbols that has been encrypted using a preselected encryption key. The encrypted stream of symbols is decoded in the secure installation using a decryption key corresponding to the preselected encryption key, to produce a clear stream of symbols. A computer program running on a processor in the secure installation is used in processing the symbols in the clear stream and generating a graphical output in a predefined display format in response to processing the symbols. The graphical output is outputted from the secure installation to the network in an unencrypted format for display on the remote user terminal.Type: GrantFiled: July 30, 2015Date of Patent: June 14, 2016Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Andrew Ginter
-
Patent number: 9268957Abstract: Decryption apparatus includes an input memory (48), which is coupled to receive encrypted data, and an output transducer (28), for presenting decrypted data to a user. A decryption processor (50) is coupled to read and decrypt the encrypted data from the input memory but is incapable of writing to the input memory, and is coupled to convey the decrypted data to the output transducer for presentation to the user.Type: GrantFiled: December 11, 2007Date of Patent: February 23, 2016Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 9116857Abstract: Storage apparatus (20) includes a memory (30) and an encryption processor (28), which is configured to receive and encrypt data transmitted from one or more computers (24) for storage in the memory. A one-way link (32) couples the encryption processor to the memory so as to enable the encryption processor to write the encrypted data to the memory but not to read from the memory.Type: GrantFiled: April 9, 2014Date of Patent: August 25, 2015Assignee: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 8891546Abstract: Communication apparatus includes at least first and second communication interfaces, configured for digital communication with first and second nodes. At least one processor is coupled between the communication interfaces, and is configured, upon receiving a message from one of the first and second nodes that is directed to the other of the first and second nodes, to carry out the following actions: when the message contains a command, to convey the command to the other of the first and second nodes; when the message contains status information, to convey the status information to the other of the first and second nodes; when the message contains a response to a command, to discard the response; and when the message contains a query, to block the query from reaching the other of the first and second nodes.Type: GrantFiled: April 27, 2014Date of Patent: November 18, 2014Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Andrew Ginter, Tomer Maor
-
Publication number: 20140317753Abstract: Apparatus for communication includes a single one-way link, which is physically capable of carrying the communication signals in one direction and incapable of carrying the communication signals in the opposite direction. Ancillary circuitry is coupled so as to cause the single one-way link to convey both first communication signals from a first station to a second station and second communication signals from the second station to the first station.Type: ApplicationFiled: April 22, 2013Publication date: October 23, 2014Applicant: Waterfall Security Solutions Ltd.Inventor: Lior Frenkel
-
Publication number: 20140244780Abstract: Storage apparatus (20) includes a memory (30) and an encryption processor (28), which is configured to receive and encrypt data transmitted from one or more computers (24) for storage in the memory. A one-way link (32) couples the encryption processor to the memory so as to enable the encryption processor to write the encrypted data to the memory but not to read from the memory.Type: ApplicationFiled: April 9, 2014Publication date: August 28, 2014Applicant: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 8793302Abstract: Sensing apparatus includes a network camera, which is configured to capture images of a scene and to output a sequence of data packets containing digitized video data responsively to the images. A one-way link is coupled to the network camera so as to transmit the data packets from the network camera to a packet communication network.Type: GrantFiled: June 4, 2012Date of Patent: July 29, 2014Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Amir Zilberstein
-
Patent number: 8756436Abstract: Storage apparatus (20) includes a memory (30) and an encryption processor (28), which is configured to receive and encrypt data transmitted from one or more computers (24) for storage in the memory. A one-way link (32) couples the encryption processor to the memory so as to enable the encryption processor to write the encrypted data to the memory but not to read from the memory.Type: GrantFiled: January 16, 2008Date of Patent: June 17, 2014Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Amir Zilberstein
-
Publication number: 20140068712Abstract: Communication apparatus includes a one-way, hardware-actuated data relay, which includes a first hardware interface configured to receive a command from a communications network and a second hardware interface configured to convey the received command to a protected destination when the relay is actuated. A decoder includes a third hardware interface configured to receive a digital signature for the command from the communications network and hardware decoding logic coupled to verify the digital signature and to actuate the relay upon verifying the digital signature, whereby the command is conveyed via the second hardware interface to the protected destination.Type: ApplicationFiled: September 6, 2012Publication date: March 6, 2014Applicant: WATERFALL SECURITY SOLUTIONS LTD.Inventors: Lior Frenkel, Andrew Ginter, Tomer Maor
-
Patent number: 8635441Abstract: A computer-implemented method for protecting a computer network (22) includes receiving at a gateway (24) data transmitted from a source address for delivery to a destination on the computer network. The data are encrypted at the gateway using an encryption key selected from a set of one or more keys that are not available to the source address. The encrypted data are transmitted over the computer network toward the destination. The transmitted encrypted data are received and decrypted for use at the destination by means of one of the keys in the set.Type: GrantFiled: August 29, 2007Date of Patent: January 21, 2014Assignee: Waterfall Security Solutions Ltd.Inventors: Lior Frenkel, Amir Zilberstein