IP Library Granted Patent US 7,394,756
Granted Patent B1
US 7,394,756 · App. 10/390,250 · Granted Jul 1, 2008

Secure hidden route in a data network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,394,756
App. No.
10/390,250
Granted
Jul 1, 2008
Kind
B1
Abstract

A hidden pathway to a host is provided in an internetwork having an egress router coupled to the host. A selected port of the egress router is connected to the host as a hidden access port. A label table in the egress router is configured to associate the selected port with a predetermined label. Distribution of the predetermined label is restricted to one or more controlled access points so that access to the hidden pathway is restricted to the controlled access points. The controlled access points may reside at the users themselves, but are preferably contained within proxy devices coupled to the internetwork using secure connections.

Claims (25)

1. A method of conveying network traffic composed of packets sent in an internetwork between client users and a host, said method comprising:

operating a public traffic channel to said host based on internet protocol (IP) routing tables, said traffic channel including a first border router coupling said host to said internetwork;

configuring a label table in a router connected to said host to associate a predetermined label with said host in order to provide a limited access channel to said host;

configuring a proxy device coupled to said internetwork to recognize at least one authorized client user of said host, to detect network traffic from said authorized client user to said proxy device which is intended for said host, and to forward said network traffic to said host using said predetermined label;

using the public channel to send traffic from one of the client users to the host;

detecting a malfunction condition of said public traffic channel; and

suspending operation of said public traffic channel in response to said malfunction condition;

whereby said authorized client user continues to exchange said traffic with said host during said malfunction condition via said limited access channel.

2. The method of claim 1 wherein said router having said label table is comprised of said first border router.

3. The method of claim 1 wherein said router having said label table is comprised of a second border router separate from said first border router and coupled to said host.

4. The method of claim 1 wherein said proxy device is comprised of a relaying workstation in said internetwork.

5. The method of claim 1 wherein said malfunction condition is comprised of an excessive traffic load condition which is detected by an operational support system coupled to said first border router.

6. The method of claim 1 wherein said step of suspending operation of said public traffic channel is comprised of:

removing an entry associated with said host from a routing table located in said first border router.

7. The method of claim 1 wherein said step of suspending operation of said public traffic channel is comprised of:

designating said first border router as unreachable in other routers within said internetwork.

8. The method of claim 1 wherein said step of suspending operation of said public traffic channel is comprised of:

altering said routing tables within said internetwork to redirect network traffic away from said first border router.

9. The method of claim 1 including a plurality of authorized client users, said method further comprising the steps of:

a particular client user communicating with said host via said public traffic channel and registering as a said authorized client user;

said host sending authorization data to said proxy device to configure said particular user as one of said authorized client users; and

said host sending contact information of said proxy device to said particular client user.

10. The method of claim 9 wherein a plurality of proxy devices in said internetwork are each configured for respective ones of said plurality of client users.

11. The method of claim 1 further comprising the step of:

said proxy device authenticating and authorizing a client user prior to said forwarding of network traffic to said host on behalf of said client user.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2003
From: COOK, FRED S.
To: SPRINT COMMUNICATIONS COMPANY, LP
Reel/Frame 013886/0100 →