IP Library Granted Patent US 8,458,341
Granted Patent B2
US 8,458,341 · App. 13/336,790 · Granted Jun 4, 2013

System and method employing an agile network protocol for secure communications using secure domain names

Inventors: Victor Larson (Fairfax, VA); Robert Dunham Short, III (Leesburg, VA); Edmond Colby Munger (Crownsville, MD); Michael Williamson (South Riding, VA)
Assignee: VirnetX, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,341
App. No.
13/336,790
Granted
Jun 4, 2013
Kind
B2
Abstract

A network device comprises a storage device storing an application program for a secure communications service and at least one processor. The processor is configured to execute the application program enabling the network device to (a) send a request to look up a network address of a second network device based on an identifier associated with the second network device; (b) receive an indication that the second network device is available for the secure communications service, the indication including the requested network address of the second network device and provisioning information for a virtual private network communication link; (c) connect to the second network device, using the received network address of the second network device and the provisioning information for the virtual private network communication link; and (d) communicate with the second network device using the secure communications service via the virtual private network communication link.

Claims (40)

1. A network device, comprising:

a storage device storing an application program for a secure communications service; and

at least one processor configured to execute the application program for the secure communications service so as to enable the network device to:

send a request to look up an internet protocol (IP) address of a second network device based on a domain name associated with the second network device;

receive, following interception of the request and a determination that the second network device is available for the secure communication service, an indication that the second network device is available for the secure communications service, the requested IP address of the second network device, and provisioning information for a virtual private network communication link;

connect to the second network device, using the received IP address of the second network device and the provisioning information for the virtual private network communication link; and

communicate with the second network device using the secure communications service via the virtual private network communication link.

2. The network device of claim 1 , wherein:

the secure communications service includes an audio-video conferencing service; and

the at least one processor is configured to execute the secure communications service application program so as to allow the network device to communicate data using the audio-video conferencing service.

3. The network device of claim 1 , wherein the at least one processor is configured to execute the application program so that at least one of video data and audio data can be communicated over the virtual private network communication link using the audio-video conferencing service.

4. The network device of claim 1 , wherein the secure communications service includes a messaging service.

5. The network device of claim 4 , wherein the messaging service includes an e-mail service.

6. The network device of claim 1 , wherein the secure communications service includes a telephony service.

7. The system of claim 6 , wherein the telephony service uses modulation.

8. The network device of claim 7 , wherein the modulation is based on one of frequency-division multiplexing (FDM), time-division multiplexing (TDM), or code division multiple access (CDMA).

9. The network device of claim 1 , wherein the network device is a mobile device.

10. The network device of claim 9 , wherein the mobile device is a notebook computer.

11. The network device of claim 1 , wherein the interception of the request consists of receiving the request to determine that the second network device is available for the secure communication service.

12. The network device of claim 1 , wherein the virtual private network communication link is based on inserting into each data packet communicated over the virtual private network communication link one or more data values that vary according to a pseudo-random sequence.

13. The network device of claim 1 , wherein the virtual private network communication link is based on a network address hopping regime that is used to pseudo-randomly change network addresses in packets transmitted between a first device and a second device.

14. The network device of claim 1 , wherein the interception occurs within another network device that is separate from the network device.

15. A method executed by a first network device for communicating with a second network device, the method comprising:

sending a request to look up an internet protocol (IP) address of a second network device based on a domain name associated with the second network device;

following interception of the request and a determination that the second network device is available for the secure communication service, receiving an indication that the second network device is available for a secure communications service, the requested IP address of the second network device, and provisioning information for a virtual private network communication link;

connecting to the second network device over the virtual private network communication link, using the received IP address of the second network device and the provisioning information for the virtual private network communication link; and

communicating with the second network device using the secure communications service via the virtual private network communication link.

16. The method of claim 15 , wherein the secure communications service includes a video conferencing service, and communicating includes communicating at least one of video data and audio data using the video conferencing service.

17. The method of claim 15 , further comprising encrypting at least one of the video data and audio data over the virtual private network communication link.

18. The method of claim 15 , wherein the secure communications service includes a messaging service.

19. The method of claim 18 , wherein the messaging service includes an e-mail service.

20. The method of claim 15 , wherein the secure communications service includes a telephony service.

21. The method of claim 20 , wherein the telephony service uses modulation.

22. The method of claim 21 , wherein the modulation is based on one of frequency-division multiplexing (FDM), time-division multiplexing (TDM), or code division multiple access (CDMA).

23. The method of claim 15 , wherein the network device is a mobile device.

24. The method of claim 23 , wherein the mobile device is a notebook computer.

25. The method of claim 15 , wherein the interception of the request consists of receiving the request to determine that the second network device is available for the secure communication service.

26. The method of claim 15 , wherein communicating with the second network device using the secure communications service via the virtual private network communication link includes inserting into data packets communicated over the virtual private network communication link one or more data values that vary according to a pseudo-random sequence.

27. The method of claim 15 , wherein communicating with the second network device using the secure communications service via the virtual private network communication link includes network address hopping regime that is used to pseudorandomly change network addresses in packets transmitted between a first device and a second device.

28. The method of claim 15 , wherein the interception occurs within another network device that is separate from the first network device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2012
From: LARSON, VICTOR; SHORT, ROBERT DUNHAM, III; MUNGER, EDMUND COLBY; WILLIAMSON, MICHAEL
To: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
Reel/Frame 027613/0163 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2012
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX, INC.
Reel/Frame 027613/0168 →
Continuity (9)
Continuation 13049552 · Mar 16, 2011
Continuation 11840560 · Aug 17, 2007
Continuation 10714849 · Nov 18, 2003
Continuation 09558210 · Apr 26, 2000
Continuation In Part 09504783 · Feb 15, 2000
Continuation In Part 09429643 · Oct 29, 1999
Provisional Application 60106261 · Oct 30, 1998
Provisional Application 60137704 · Jun 7, 1999
Related Publication 20120110103A1 · May 3, 2012