IP Library Granted Patent US 9,866,519
Granted Patent B2
US 9,866,519 · App. 15/289,764 · Granted Jan 9, 2018

Name resolving in segmented networks

Inventors: Kurt Glazemakers (Grembergen, BE); Thomas Bruno Emmanuel Cellerier (Kungalv, SE)
Assignee: CRYPTZONE NORTH AMERICA, INC.
H04L61/1511H04L63/00H04L61/256H04L61/2592
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,866,519
App. No.
15/289,764
Granted
Jan 9, 2018
Kind
B2
Abstract

A method is provided, in one embodiment, which is performed on a client computing device, the method comprising: connecting the client with a plurality of segments of a private network, wherein the private network comprises a plurality of name resolving servers; registering the client as primary name resolving server for serving name requests for names in the private network received from applications on the client; and then forwarding the received name requests simultaneously to the plurality of name resolving servers.

Claims (43)

1. A method, comprising:

connecting a client computing device with a plurality of segments of a private network, wherein network access is restricted from one segment to another of the plurality of segments, the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of the plurality of segments;

registering the client computing device as primary name resolving server for serving name requests for names in the private network received from applications on the client computing device, the name requests including a first name request from a first application;

in response to receiving the first name request, forwarding the first name request simultaneously to the plurality of name resolving servers;

selecting a name resolution that is first received from the plurality of name resolving servers in response to the first name request; and

returning the selected name resolution to the first application.

2. The method of claim 1 , wherein the connecting is performed over one or more network interfaces of the client computing device, and wherein the registering comprises assigning the client computing device as primary name resolving server to the one or more network interfaces.

3. The method of claim 2 , wherein the connecting further comprises establishing networking tunnels with gateways providing access to the respective segments.

4. The method of claim 2 , wherein the one or more network interfaces correspond to virtual network interfaces.

5. The method of claim 3 , further comprising:

providing authentication information to an authentication server; and

in response to successful authentication from the authentication server, receiving a listing of the plurality of name resolving servers.

6. The method of claim 4 , further comprising:

providing authentication information to an authentication server; and

in response to successful authentication from the authentication server, receiving a listing of the plurality of name resolving servers.

7. The method of claim 5 , wherein the connecting further comprises:

in response to successful authentication, receiving a client access list in return, wherein the client access list identifies a selection of networking devices in the private network that the client computing device is authorized to access;

establishing the networking tunnels with tunnel modules of the respective gateways providing network access to the private network; and

sending the client access list over the networking tunnels to the gateways in order to enable the gateways to configure a firewall with firewall rules derived from the client access list to allow the client computing device network access to the selection of the networking devices in accordance with the firewall rules.

8. The method of claim 7 , wherein the plurality of name resolving servers is specified in the client access list.

9. The method of claim 7 , further comprising:

in response to successful authentication from the authentication server, receiving a client tunnel list comprising information for establishing the networking tunnels; and

using the client tunnel list for the establishing the networking tunnels.

10. The method of claim 9 , wherein the plurality of name resolving servers is specified in the client tunnel list.

11. The method of claim 9 , wherein the client tunnel list comprises addressing information about the gateways and tunnel authentication information, the method further comprising:

retrieving the addressing information from the client tunnel list;

sending requests to the tunnel modules by the addressing information together with the tunnel authentication information; and

in response to successful authentication with the tunnel modules, establishing the networking tunnels.

12. The method of claim 7 , wherein the client access list is readable by the client computing device, and wherein the client access list further comprises a digital signature made by a key shared between the authentication server and the gateways thereby making the client access list not alterable by the client computing device without notification from the gateways.

13. A non-transitory computer readable storage medium storing instructions configured to instruct a data processing system to:

connect a client computing device with a plurality of segments of a private network, wherein network access is restricted from one segment to another of the plurality of segments, the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of the plurality of segments;

register the client computing device as primary name resolving server for serving name requests for names in the private network received from applications on the client computing device, the name requests including a first name request from a first application;

in response to receiving the first name request, forward the first name request simultaneously to the plurality of name resolving servers;

select a name resolution that is first received from the plurality of name resolving servers in response to the first name request; and

return the selected name resolution to the first application.

14. A system, comprising:

at least one processor; and

memory storing instructions programmed to instruct the at least one processor to:

connect a client computing device with a plurality of segments of a private network, wherein network access is restricted from one segment to another of the plurality of segments, the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of the plurality of segments;

register the client computing device as primary name resolving server for serving name requests for names in the private network received from applications on the client computing device, the name requests including a first name request from a first application;

in response to receiving the first name request, forward the first name request simultaneously to the plurality of name resolving servers;

select a name resolution that is first received from the plurality of name resolving servers in response to the first name request; and

return the selected name resolution to the first application.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: GLAZEMAKERS, KURT; CELLERIER, THOMAS BRUNO EMMANUEL
To: CRYPTZONE NORTH AMERICA, INC.
Reel/Frame 040217/0323 →
Continuity (2)
Provisional Application 62242926 · Oct 16, 2015
Related Publication 20170111310A1 · Apr 20, 2017