IP Library Granted Patent US 6,839,759
Granted Patent B2
US 6,839,759 · App. 10/702,522 · Granted Jan 4, 2005

Method for establishing secure communication link between computers of virtual private network without user entering any cryptographic information

Assignee: Science Applications International Corp.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,839,759
App. No.
10/702,522
Granted
Jan 4, 2005
Kind
B2
Abstract

A technique is disclosed for establishing a secure communication link between a first computer and a second computer over a computer network. Initially, a secure communication mode of communication is enabled at a first computer without a user entering any cryptographic information for establishing the secure communication mode of communication. Then, a secure communication link is established between the first computer and a second computer over a computer network based on the enabled secure communication mode of communication. The secure communication link is a virtual private network communication link over the computer network in which one or more data values that vary according to a pseudo-random sequence are inserted into each data packet.

Claims (45)

1. A method for establishing a secure communication link between a first computer and a second computer over a computer network, the method comprising steps of:

enabling a secure communication mode of communication at the first computer without a user entering any cryptographic information for establishing the secure communication mode of communication; and

establishing the secure communication link between the first computer and a second computer over a computer network based on the enabled secure communication mode of communication, the secure communication link being a virtual private network communication link over the computer network.

2. The method according to claim 1 , further comprising steps of:

determining whether a secure communication software module is stored on the first computer in response to the step of enabling the secure communication mode of communication;

accessing a predetermined computer network address for loading the secure communication software module when the software module is not stored on the first computer; and

storing the software module in the first computer.

3. The method according to claim 1 , wherein the virtual private network is based on inserting into each data packet one or more data values that vary according to a pseudo-random sequence.

4. The method according to claim 1 , wherein the virtual private network is based on inserting into at least one data packet at least one data value representing a predetermined level of service associated with the virtual private network.

5. The method according to claim 1 , wherein the virtual private network is based on a computer network address hopping regime that is used to pseudorandomly change computer network addresses in packets transmitted between the first computer and the second computer.

6. The method according to claim 1 , wherein the virtual private network is based on comparing a value in each data packet transmitted between the first computer and the second computer to a moving window of valid values.

7. The method according to claim 1 , wherein the virtual private network is based on a comparison of a discriminator field in a header of each data packet to a table of valid discriminator fields maintained for the first computer.

8. The method according to claim 1 , wherein the computer network includes the Internet.

9. The method according to claim 1 , wherein the step of enabling the secure communication mode of communication includes a step of entering a command into the first computer that specifies the secure communication mode.

10. The method according to claim 9 , wherein the command is entered to define a setup parameter associated with the secure communication mode of communication, and

wherein the secure communication link is automatically established when a communication link is established over the computer network.

11. The method according to claim 1 , wherein the step of enabling a secure communication link mode of operation includes a step of selecting an icon displayed on a display device of the first computer.

12. The method according to claim 1 , further comprising a step of displaying an indication on a display of the first computer that the secure communication link is established.

13. The method according to claim 12 , wherein the indication is an icon.

14. The method according to claim 1 , wherein the secure communication link is one of a plurality of secure communication links in a hierarchy of secure communication links.

15. The method according to claim 1 , wherein the secure communication link is through a secure portal connected to the computer network, and

wherein the second computer comprises a secure domain name service.

16. A computer-readable storage medium, comprising:

a storage area; and

computer-readable instructions for a method for establishing a secure communication link between a first computer and a second computer over a computer network, the method comprising steps of:

enabling a secure communication mode of communication at a first computer without a user entering any cryptographic information for establishing the secure communication mode of communication; and

establishing a secure communication link between the first computer and a second computer over a computer network based on the enabled secure communication mode of communication, the secure communication link being a virtual private network communication link over the computer network.

17. The computer-readable storage medium according to claim 16 , further comprising steps of:

determining whether a secure communication software module is stored on the first computer in response to the step of enabling the secure communication mode of communication;

accessing a predetermined computer network address for loading the secure communication software module when the software module is not stored on the first computer; and

storing the software module in the first computer.

18. The computer-readable medium according to claim 16 , wherein the virtual private network is based on inserting into at least one data packet at least one data value representing a predetermined level of service associated with the virtual private network.

19. The computer-readable storage medium according to claim 16 , wherein the virtual private network is based on inserting into each data packet one or more data values that vary according to a pseudo-random sequence.

20. The computer-readable storage medium according to claim 16 , wherein the virtual private network is based on a computer network address hopping regime that is used to pseudorandomly change computer network addresses in packets transmitted between the first computer and the second computer.

21. The computer-readable storage medium according to claim 16 , wherein the virtual private network is based on comparing a value in each data packet transmitted between the first computer and the second computer to a moving window of valid values.

22. The computer-readable storage medium according to claim 16 , wherein the virtual private network is based on a comparison of a discriminator field in a header of each data packet to a table of valid discriminator fields maintained for the first computer.

23. The computer-readable storage medium according to claim 16 , wherein the computer network includes the Internet.

24. The computer-readable storage medium according to claim 16 , wherein the step of enabling the secure communication mode of communication includes a step of entering a command into the first computer that specifies the secure communication mode.

25. The computer-readable storage medium according to claim 24 , wherein the command is entered to define a setup parameter associated with the secure communication mode of communication, and

wherein the secure communication link is automatically established when a communication link is established over the computer network.

26. The computer-readable storage medium according to claim 16 , wherein the step of enabling a secure communication link mode of operation includes a step of selecting an icon displayed on a display device of the first computer.

27. The computer-readable storage medium according to claim 16 , further comprising a step of displaying an indication on a display of the first computer that the secure communication link is established.

28. The computer-readable storage medium according to claim 27 , wherein the indication is an icon.

29. The computer-readable storage medium according to claim 16 , wherein the secure communication link is one of a plurality of secure communication links in a hierarchy of secure communication links.

30. The computer-readable storage medium according to claim 16 , wherein the secure communication link is through a secure portal connected to the computer network, and wherein the second computer comprises a secure domain name service.

Assignments (3)
CHANGE OF ADDRESS OF ASSIGNEE Recorded Jan 19, 2012
From: VIRNETX INC.
To: VIRNETX INC.
Reel/Frame 027558/0281 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2007
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX INC.
Reel/Frame 018757/0326 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2003
From: LARSON, VICTOR; SHORT, ROBERT DUNHAM III; MUNGER, EDMUND COLBY; WILLIAMSON, MICHAEL
To: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
Reel/Frame 014689/0578 →
Continuity (6)
Continuation 0955820900 · Apr 26, 2000
Continuation In Part 0950478300 · Feb 15, 2000
Continuation In Part 0942964300 · Oct 29, 1999
Provisional Application 6013770400 · Jun 7, 1999
Provisional Application 6010626100 · Oct 30, 1998
Related Publication 20040107286A1 · Jun 3, 2004