IP Library Granted Patent US 7,516,174
Granted Patent B1
US 7,516,174 · App. 10/979,409 · Granted Apr 7, 2009

Wireless network security mechanism including reverse network address translation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,516,174
App. No.
10/979,409
Granted
Apr 7, 2009
Kind
B1
Abstract

Methods, apparatuses and systems directed to preventing unauthorized access to internal network addresses transmitted across wireless networks. According to the invention, mobile stations are assigned virtual client network addresses that are used as the outer network addresses in a Virtual Private Network (VPN) infrastructure, as well as unique internal network addresses used as the inner network addresses. In one implementation, the virtual client network addresses have little to no relation to the internal network addressing scheme implemented on the network domain. In one implementation, all clients or mobile stations are assigned the same virtual client network address. A translation layer, in one implementation, intermediates the VPN session between the mobile stations and a VPN server to translate the virtual client network addresses to the internal network addresses based on the medium access control (MAC) address corresponding to the mobile stations. In this manner, the encryption inherent in the VPN infrastructure prevents access to the internal network addresses assigned to the mobile stations.

Claims (15)

1. In a wireless network system comprising an access point providing wireless service to a mobile station and a Virtual Private Network (VPN) server operative to establish a VPN session with the mobile station, a method comprising

intercepting an address assignment message from a network address configuration server to the mobile station, wherein the mobile station has a unique link layer address, wherein the network address configuration server is operative to provide internal network addresses to requesting mobile stations, and wherein the address assignment message contains an internal network address for the mobile station;

associating, in a data structure, the unique link layer address of the mobile station with the internal network address provided by the network address configuration server in the address assignment message;

replacing the internal network address in the address assignment message with a virtual network address; and

forwarding the modified address assignment message to the mobile station;

intermediating a VPN session between the VPN server and the mobile station; wherein the VPN session involves the exchange of encapsulated packets comprising an encapsulating VPN header including an outer network address corresponding to the mobile station, and wherein as to packets sourced from the mobile station, replacing the virtual network address used by the mobile station as the outer network address in the encapsulating VPN headers with the internal network address corresponding to the mobile station.

2. The method of claim 1 further comprising associating the unique link layer address of the mobile station with the internal network address provided by the network address configuration server.

3. The method of claim 1 further comprising

as to packets sourced from the VPN server to the mobile station, replacing the internal network address corresponding to the mobile station in the encapsulating VPN headers of the packets with the virtual network address corresponding to the mobile station.

4. The method of claim 1 wherein the virtual network address is a non-routable address.

5. The method of claim 1 wherein the virtual network address is an Internet Protocol (IP) address.

6. The method of claim 5 wherein the virtual client network address is a first host address corresponding to a subnet consisting of a network address, a broadcast address, the first host address, and a second host address.

7. The method of claim 6 wherein the VPN server is configured with the second host address.

8. The method of claim 1 wherein the virtual network address is uniform for all mobile stations.

9. The method of claim 1 wherein the network address configuration server is a Dynamic Host Configuration Protocol (DHCP) server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2011
From: CISCO SYSTEMS, INC.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 027370/0854 →
MERGER Recorded Jun 23, 2008
From: AIRESPACE, INC.
To: CISCO SYSTEMS, INC.
Reel/Frame 021138/0063 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2004
From: TASHJIAN, ROBERT W.; VAKIL, SUMIT; WANG, JING
To: AIRESPACE, INC.
Reel/Frame 015954/0864 →