IP Library Granted Patent US 9,479,426
Granted Patent B2
US 9,479,426 · App. 13/475,637 · Granted Oct 25, 2016

Agile network protocol for secure communications with assured system availability

Inventors: Edmund Colby Munger (Crownsville, MD); Vincent J. Sabio (Columbia, MD); Robert Dunham Short, III (Leesburg, VA); Virgil D. Gligor (Chevy Chase, MD); Douglas Charles Schmidt (Severna Park, MD)
Assignee: VIRNETZ, INC.
H04L45/20H04L29/1232H04L29/12216H04L29/12301H04L29/12801H04L45/24H04L61/2007H04L61/2076H04L61/2092H04L61/6004H04L63/0272H04L63/04H04L63/0407H04L63/0428H04L63/0435H04L63/1441H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,426
App. No.
13/475,637
Granted
Oct 25, 2016
Kind
B2
Abstract

A plurality of computer nodes communicates using seemingly random IP source and destination addresses and (optionally) a seemingly random discriminator field. Data packets matching criteria defined by a moving window of valid addresses are accepted for further processing, while those that do not meet the criteria are rejected. In addition to “hopping” of IP addresses and discriminator fields, hardware addresses such as Media Access Control addresses can be hopped. The hopped addresses are generated by random number generators having non-repeating sequence lengths that are easily determined a-priori, which can quickly jump ahead in sequence by an arbitrary number of random steps and which have the property that future random numbers are difficult to guess without knowing the random number generator's parameters. Synchronization techniques can be used to re-establish synchronization between sending and receiving nodes.

Claims (17)

1. A method of transmitting data over a computer network, comprising the steps of:

at an originating terminal connected to the computer network, receiving a stream of data and forming a first level packet payload based on the stream of data;

identifying a network destination address for the stream of data;

forming a first level packet including the first level packet payload and a first level header containing data representing the network destination address;

encrypting at least a portion of the first level packet to form a second level packet payload;

forming a second level packet including the second level packet payload and a second layer header containing a router address of an intermediate router connecting the originating terminal to the network destination address;

including in one of the first and second layer headers, an indicator of a number of hops to be made by the first level packet before arriving at the network destination address; and

sending the second level packet to the intermediate router at the router address;

wherein the intermediate router determines, based on the indicator, whether to forward the second level packet to another intermediate router at another router address or to forward the second level packet to the network destination address.

2. The method of claim 1 , further comprising determining the intermediate router by randomly selecting from a group of intermediate routers.

3. The method of claim 1 , the intermediate router decrementing the indicator of a number of hops and sending the first level packet to another intermediate router responsive to a value of the indicator of a number of hops.

4. The method of claim 1 , further comprising:

decrypting the second level packet payload;

determining from the first level header the network destination address;

forming a new packet containing at least the first level packet payload; and

attaching a header to the new packet containing the network destination address, whereby a true destination of the data stream is concealed behind a layer of encryption for at least a portion of its travel over the network.

5. The method of claim 4 , wherein the step of determining from the first level header the network destination address includes converting the data representing the network destination address to the network destination address using correlation data stored on the intermediate router.

Assignments (4)
CHANGE OF NAME Recorded Jan 7, 2013
From: VIRNETX, INC.
To: VIRNETX, INC.
Reel/Frame 029581/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2012
From: MUNGER, EDMUND COLBY; SABIO, VINCENT J.; SHORT, ROBERT DUNHAM, III; GLIGOR, VIRGIL D.; SCHMIDT, DOUGLAS CHARLES
To: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
Reel/Frame 029542/0932 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2012
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX INC.
Reel/Frame 029543/0024 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2012
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX, INC.
Reel/Frame 028946/0388 →
Continuity (6)
Division 11839937 · Aug 16, 2007
Continuation 11301022 · Dec 13, 2005
Division 09429643 · Oct 29, 1999
Provisional Application 60137704 · Jun 7, 1999
Provisional Application 60106261 · Oct 30, 1998
Related Publication 20130091354A1 · Apr 11, 2013