Network data files are secure through the operation of an infrastructure
gateway-based network file access appliance. Network file data,
corresponding to network pocket payload data, are further reduced to a
sequence of data blocks that are secured through any combination of block
encryption, compression, and digital signatures. File meta-data,
including encryption, compression and block-level digital signatures are
persistently stored with the file data, either in-band in the file as
stored or out-of-band key as a separately stored file or file policy
record. File meta-data is recovered with accesses of the file data to
support bidirectional encryption and compression and to detect tampering
with the file data by comparison against block-level digital signatures.