IP Library Granted Patent US 7,735,118
Granted Patent B2
US 7,735,118 · App. 11/052,260 · Granted Jun 8, 2010

Method and apparatus for preventing bridging of secure networks and insecure networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,735,118
App. No.
11/052,260
Granted
Jun 8, 2010
Kind
B2
Abstract

The invention comprises a method and apparatus for preventing a bridge between a secure network and an insecure network. Specifically, the method comprises monitoring a network device supporting a secure network connection for an attempt to establish an insecure network connection, and terminating the secure network connection in response to detecting the attempt to establish the insecure network connection, where the secure network connection comprises a network layer connection.

Claims (48)

1. A method for preventing a bridge between a secure network and an insecure network at a network device, comprising:

receiving, at a node associated with the secure network, a request to establish a secure network connection with the secure network, wherein the request to establish the secure network connection with the secure network is associated with the network device; and

in response to a determination that the request to establish the secure network connection has associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device, accepting the request to establish the secure network connection with the secure network;

in response to a determination that the request to establish the secure network connection does not have associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device, denying the request to establish the secure network connection with the secure network.

2. The method of claim 1 , wherein the request to establish the secure network connection is initiated by the network device using a process comprising:

obtaining a request for establishing the secure network connection;

determining, in response to the request, whether an insecure network connection exists at the network device;

in response to a determination that an insecure network connection does not exist at the network device, generating a token indicative that an insecure network connection to an insecure network does not exist at the network device; and

transmitting the token toward the node associated with the secure network.

3. The method of claim 2 , wherein determining whether an insecure network connection exists at the network device comprises:

calling at least one function for determining whether an insecure network connection exists at the network device.

4. The method of claim 2 , wherein generating the token comprises:

generating the token using at least one algorithm, the at least one algorithm generating the token in a manner for enabling the node associated with the secure network to determine whether or not an insecure network connection exists for the network device.

5. The method of claim 1 , wherein the token is received as at least a portion of a dynamic host configuration protocol (DHCP) class identifier option.

6. The method of claim 1 , wherein the token is received as at least a portion of at least one extensible authentication protocol (EAP) parameter.

7. The method of claim 1 , wherein the token is received at a virtual private network (VPN) gateway associated with the secure network, wherein the token is received as at least a portion of a virtual private network (VPN) setup phase.

8. The method of claim 1 , wherein the token is received as at least a portion of a point-to-point protocol (PPP) setup phase.

9. The method of claim 1 , further comprising:

validating the token, wherein the token is validated by comparing the token associated with the request to establish the secure network connection to at least one token stored locally by the node associated with the secure network; and

establishing the secure network connection in response to a determination that the token associated with the request to establish the secure network connection matches at least one token stored locally by the node associated with the secure network.

10. The method of claim 1 , further comprising:

monitoring the network device for an attempt to establish an insecure network connection to an insecure network; and

invalidating the token in response to detecting an attempt to establish an insecure network connection with an insecure network.

11. A computer readable storage medium storing a software program, that, when executed by a computer, causes the computer to perform a method for preventing a bridge between a secure network and an insecure network at a network device, the method comprising:

receiving, at a node associated with the secure network, a request to establish a secure network connection with the secure network, wherein the request to establish the secure network connection with the secure network is associated with the network device; and

in response to a determination that the request to establish the secure network connection has associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device, accepting the request to establish the secure network connection with the secure network;

in response to a determination that the request to establish the secure network connection does not have associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device, denying the request to establish the secure network connection with the secure network.

12. The computer readable storage medium of claim 11 , wherein the request to establish the secure network connection is initiated by the network device using a process comprising:

obtaining a request for establishing the secure network connection;

determining, in response to the request, whether an insecure network connection exists at the network device;

in response to a determination that an insecure network connection does not exist at the network device, generating a token indicative that an insecure network connection to an insecure network does not exist at the network device; and

transmitting the token toward the node associated with the secure network.

13. The computer readable storage medium of claim 12 , wherein determining whether an insecure network connection exists at the network device comprises:

calling at least one function for determining whether an insecure network connection exists at the network device.

14. The computer readable storage medium of claim 12 , wherein generating the token comprises:

generating the token using at least one algorithm, the at least one algorithm generating the token in a manner enabling the secure network to determine whether or not an insecure network connection to an insecure network exists for the network device.

15. The computer readable storage medium of claim 11 , wherein the token is received as at least one of: at least a portion of a dynamic host configuration protocol (DHCP) class identifier option, at least a portion of at least one extensible authentication protocol (EAP) parameter, at least a portion of a virtual private network (VPN) setup phase, and at least a portion of a point-to-point protocol (PPP) setup phase.

16. The computer readable storage medium of claim 11 , further comprising:

validating the token, wherein the token is validated by comparing the token associated with the request to establish the secure network connection to at least one token stored locally at the node associated with the secure network; and

establishing the secure network connection in response to a determination that the token associated with the request to establish the secure network connection matches at least one token stored locally by the node associated with the secure network.

17. The computer readable storage medium of claim 11 , further comprising:

monitoring the network device for an attempt to establish an insecure network connection to an insecure network; and

invalidating the token in response to detecting an attempt to establish an insecure network connection to an insecure network.

18. An apparatus for preventing a bridge between a secure network and an insecure network at a network device, comprising:

a receiver for receiving a request to establish a secure network connection with the secure network, wherein the request to establish the secure network connection with the secure network is associated with the network device; and

a processor for processing the request, the processor configured for:

accepting the request to establish the secure network connection with the secure network in response to a determination that the request to establish the secure network connection has associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device; and

denying the request to establish the secure network connection with the secure network in response to a determination that the request to establish the secure network connection does not have associated therewith a token indicative that an insecure network connection to an insecure network does not exist for the network device.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
MERGER Recorded Apr 15, 2010
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 024234/0976 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2005
From: BROK, JACCO; ROMIJN, WILLEM ADRIAAN
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 016269/0853 →