US 7,543,332 B2
Method and system for securely scanning network traffic
Joel Balissat, La Gaude (France); Claude Galand, Saint-Paul (France); Jean-Francois Le Pennec, Nice (France); and Jean-Marie Sommerlatt, Cagnes sur Mer (France)
Assigned to AT&T Corporation, Bedminster, N.J. (US)
Filed on Feb. 06, 2007, as Appl. No. 11/703,020.
Application 11/703020 is a continuation of application No. 10/115554, filed on Apr. 04, 2002, granted, now 7,188,365.
Prior Publication US 2007/0169187 A1, Jul. 19, 2007
Int. Cl. G06F 15/00 (2006.01)
U.S. Cl. 726—15 19 Claims
OG exemplary drawing
 
1. A method comprising:
via an obtained encryption parameter shared by a first device, a second device, and a separate computer, forwarding only each data packet, of a plurality of received packets, that is in compliance with a predetermined criterion associated with said separate computer, a decrypted copy of each data packet scanned for compliance with said predetermined criterion at a predetermined portion of said separate computer, said predetermined portion of said separate computer adapted to provide only an affirmative response or a negative response regarding compliance with said predetermined criterion, wherein contents of said decrypted copy of each data packet is restricted to said predetermined portion of said separate computer, said separate computer adapted for restricting all operators of said separate computer from accessing contents of said decrypted copy of each data packet, said separate computer adapted to communicate with second device via a public wide area network said separate computer adapted to form a first security association with said first device said separate computer adapted to form a second security association with said second device, said separate computer adapted to calculate a first secret key associated with said first security association and a second secret key associated with said second security association.