IP Library Granted Patent US 7,869,451
Granted Patent B2
US 7,869,451 · App. 11/300,107 · Granted Jan 11, 2011

Method for operating a local computer network connected to a remote private network by an IPsec tunnel, software module and IPsec gateway

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,869,451
App. No.
11/300,107
Granted
Jan 11, 2011
Kind
B2
Abstract

The invention relates to a method in particular enabling the computer terminal (T_L) of a local network (RES_L), connected to a gateway (PASS_D) of a remote network (RES_D) by an IPsec tunnel in blocking mode, to launch a print job on a printer (E_L) belonging to the local network. To do this, the gateway (PASS_D) stores the correspondence between the public address (AD_1) of the local router (ROUT_L) providing the connection of the terminal to the Internet, and the private address (ad_3) assigned to the terminal (T_L) in the addressing plan of the remote network (RES_D) during the establishment of the tunnel, and sends the print flow to the local router (ROUT_L), which directs it to the local printer (E_L) by a port translation technique.

Claims (35)

1. A method for operating a local network and a remote network, a local terminal of the local network being connected to a gateway of the remote network by a tunnel established in blocking mode, the method comprising:

using the gateway, receiving a flow emitted from the local terminal and routed to the gateway through the tunnel, wherein the flow has a destination address equal to an internal address of local equipment located in the local network; and

when the received flow is not intended for the remote network:

using the gateway, sending the received flow to a router of the local network for the router to re-route the received flow to the internal address of the local equipment,

the gateway identifying the router using information obtained during the establishment of the tunnel.

2. The method according to claim 1 , further comprising analyzing, using the gateway, incoming flows so as to recognize that the received flow is not intended for the remote network.

3. The method according to claim 1 , further comprising:

during establishment of the tunnel:

replacing, using the router, an address of the local terminal inside the local network with a routable address of the router during a request for connection from the local terminal to the gateway;

assigning, using the gateway, a remote address inside the remote network to the local terminal during the establishment of the tunnel; and

storing, using the gateway, an entry in a correspondence table that matches the routable address with the remote address of the local terminal;

after establishment of the tunnel:

identifying, using the gateway, the routable address of the router from the correspondence table based on the remote address of the local terminal associated with the flow; and

sending, using the gateway, the received flow to the routable address of the router.

4. The method according to claim 1 , wherein the re-routing the received flow to the internal address of the local equipment is implemented by a port translation technique.

5. The method according to claim 1 , wherein the flow from the local terminal includes a print order.

6. The method according to claim 1 , further comprising establishing one of an IPsec tunnel and an SSL tunnel connecting the gateway to the router.

7. The method according to claim 1 , further comprising using the gateway to establish one of an IPsec tunnel and an SSL tunnel connecting the gateway to the local equipment, wherein the local equipment includes a printer.

8. The method according to claim 1 , wherein the local equipment includes a printer.

9. A system that includes a processor and a non-transitory tangible computer-readable medium storing instructions that, when executed by the processor, cause the processor to implement the method of claim 1 , wherein the system is implement in the gateway of the remote network.

10. The system according to claim 9 , wherein the gateway is an IPsec gateway.

11. The system according to claim 10 , wherein the tangible computer-readable medium includes instructions that analyze flows of the gateway to recognize that the flow is not intended for the remote network.

12. A gateway including a processor and a non-transitory tangible computer-readable medium storing instructions that, when executed by the processor, cause the processor to implement the method of claim 1 .

13. A network device including a processor and a non-transitory tangible computer-readable medium storing instructions that, when executed by the processor, cause the processor to implement the method of claim 1 .

14. A method of operating a gateway located between a first network and a wide area network, the method comprising:

maintaining a table that maps local addresses of the first network to routable addresses of the wide area network;

establishing a blocking tunnel with a terminal located in a second network, wherein the terminal communicates with the gateway via a router located between the second network and the wide area network, and wherein the establishing includes:

assigning the terminal a first address within the first network;

receiving a packet from the terminal via the blocking tunnel where a routable address of the router was stored in a source address field of the packet by the router; and

creating an entry in the table that maps the assigned first address to the routable address of the router;

receiving packets from the wide area network;

identifying received packets that were sent by the terminal through the blocking tunnel and that have a destination address field equal to an internal address of local equipment within the second network; and

forwarding the identified packets to the routable address of the router over the wide area network, wherein the routable address of the router is obtained from the table using the assigned first address of the terminal, and wherein the router forwards the identified packets to the internal address of the local equipment via the second network.

15. A gateway including a processor and a non-transitory tangible computer-readable medium storing instructions that, when executed by the processor, cause the processor to implement the method of claim 14 .

16. A network device including a processor and a non-transitory tangible computer-readable medium storing instructions that, when executed by the processor, cause the processor to implement the method of claim 14 .

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED ON REEL 052853 FRAME 0153. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST GRANTED PURSUANT TO THE PATENT SECURITY AGREEMENT PREVIOUSLY RECORDED. Recorded Jan 25, 2021
From: MONARCH NETWORKING SOLUTIONS LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 055100/0624 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 053654 FRAME 0254. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST GRANTED PURSUANT TO THE PATENT SECURITY AGREEMENT PREVIOUSLYRECORDED. Recorded Jan 25, 2021
From: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
To: MONARCH NETWORKING SOLUTIONS LLC
Reel/Frame 055101/0608 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 8, 2020
From: STARBOARD VALUE INTERMEDIATE FUND LP
To: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
Reel/Frame 053654/0254 →
PATENT SECURITY AGREEMENT Recorded Jun 5, 2020
From: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MERTON ACQUISITION HOLDCO LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 052853/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2019
From: ACACIA RESEARCH GROUP LLC
To: MONARCH NETWORKING SOLUTIONS LLC
Reel/Frame 051238/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2019
From: TRANSPACIFIC IP GROUP LIMITED
To: ACACIA RESEARCH GROUP LLC
Reel/Frame 051192/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2017
From: ORANGE
To: TRANSPACIFIC IP GROUP LIMITED
Reel/Frame 044625/0315 →
CHANGE OF NAME Recorded Dec 8, 2017
From: FRANCE TELECOM
To: ORANGE
Reel/Frame 044625/0361 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2006
From: CHARLES, OLIVER; BUTTI, LAURENT; VEYSSET, FRANCK
To: FRANCE TELECOM
Reel/Frame 017258/0105 →