IP Library Granted Patent US 10,284,517
Granted Patent B2
US 10,284,517 · App. 15/800,953 · Granted May 7, 2019

Name resolving in segmented networks

Inventors: Kurt Glazemakers (Grembergen, BE); Thomas Bruno Emmanuel Cellerier (Kungalv, SE)
Assignee: Cryptzone North America, Inc.
H04L61/1511H04L63/00H04L63/0272H04L63/08H04L63/101H04L61/256H04L61/2592
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,517
App. No.
15/800,953
Granted
May 7, 2019
Kind
B2
Abstract

A method is provided, in one embodiment, which is performed on a client computing device, the method including: connecting a client computing device with a private network, wherein the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of a plurality of segments of the private network; receiving a first name request from a first application on the client computing device; in response to receiving the first name request, forwarding the first name request simultaneously to the plurality of name resolving servers; and selecting a name resolution that is first received from the plurality of name resolving servers in response to the first name request.

Claims (40)

1. A method, comprising:

connecting a client computing device with a private network, wherein the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of a plurality of segments of the private network;

providing authentication information to an authentication server;

in response to successful authentication from the authentication server, receiving a list of the plurality of name resolving servers, the list including networking addresses of the name resolving servers;

receiving a name request from an application on the client computing device;

in response to receiving the name request, forwarding the name request simultaneously to the plurality of name resolving servers, wherein the name request is forwarded to network addresses retrieved from the list; and

selecting a name resolution that is first received from the plurality of name resolving servers in response to the name request.

2. The method of claim 1 , further comprising running a name resolving service on the client computing device, wherein the name request is received by the name resolving service.

3. The method of claim 2 , wherein the name request is forwarded to the plurality of name resolving servers by the name resolving service.

4. The method of claim 1 , further comprising registering the client computing device as primary name resolving server for serving name requests for names in the private network received from applications on the client computing device, the name requests including the name request received from the application on the client computing device.

5. The method of claim 1 , further comprising returning the selected name resolution to the application on the client computing device.

6. The method of claim 1 , wherein network access is restricted from one segment to another of the plurality of segments.

7. The method of claim 1 , wherein the list of the plurality of name resolving servers is a client access list, and the client access list further identifies a selection of networking devices in the private network that the client computing device is authorized to access, the method further comprising:

sending the client access list to at least one gateway that provides access to the respective segments, wherein the client access list enables the at least one gateway to configure a firewall.

8. The method of claim 7 , wherein the at least one gateway configures the firewall with firewall rules derived from the client access list to provide network access, in accordance with the firewall rules, by the client computing device to the selection of networking devices.

9. The method of claim 1 , wherein the list of the plurality of name resolving servers is a client tunnel list, and the client tunnel list further includes information for establishing networking tunnels with at least one gateway to provide access to the respective segments.

10. The method of claim 1 , wherein the list of the plurality of name resolving servers is a client access list that identifies networking devices that the client computing device is authorized to access.

11. A system, comprising:

at least one processor; and

memory storing instructions programmed to instruct the at least one processor to:

connect a client computing device with a private network, wherein the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of a plurality of segments of the private network;

provide authentication information to an authentication server;

in response to successful authentication from the authentication server, receive a list of the plurality of name resolving servers;

receive a name request from an application on the client computing device;

in response to receiving the name request, forward the name request simultaneously to the plurality of name resolving servers in the list; and

select a name resolution that is first received from the plurality of name resolving servers in response to the name request.

12. The system of claim 11 , wherein the list is a client access list, the client access list identifies a selection of networking devices in the private network that the client computing device is authorized to access, and the instructions further instruct the at least one processor to:

send the client access list to at least one gateway that provides access to the respective segments in order to enable the at least one gateway to configure a firewall.

13. The system of claim 12 , wherein the instructions further instruct the at least one processor to receive a client tunnel list comprising information for establishing networking tunnels with the at least one gateway.

14. The system of claim 11 , wherein the instructions further instruct the at least one processor to register the client computing device as primary name resolving server for serving name requests for names in the private network received from applications on the client computing device, the name requests including the name request received from the application on the client computing device.

15. A non-transitory computer readable storage medium storing instructions configured to instruct a data processing system to:

connect a client computing device with a private network, wherein the private network comprises a plurality of name resolving servers, and each name resolving server is configured to resolve name requests for networking devices in a respective segment of a plurality of segments of the private network;

provide authentication information to an authentication server;

in response to successful authentication from the authentication server, receive an identification of the plurality of name resolving servers;

in response to receiving a name request from the client computing device, forward the name request simultaneously to the identified name resolving servers; and

select a name resolution that is received from the plurality of name resolving servers in response to the name request.

16. The non-transitory computer readable storage medium of claim 15 , wherein the instructions are further configured to instruct the data processing system to:

in response to a successful authentication, receive a client access list, wherein the client access list identifies a selection of networking devices in the private network that the client computing device is authorized to access; and

send the client access list to at least one gateway that provides access to the respective segments in order to enable the at least one gateway to configure a firewall.

17. The non-transitory computer readable storage medium of claim 16 , wherein the name resolving servers are identified by the client access list.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2019
From: GLAZEMAKERS, KURT; CELLERIER, THOMAS BRUNO EMMANUEL
To: CRYPTZONE NORTH AMERICA, INC.
Reel/Frame 048470/0488 →
Continuity (3)
Continuation 15289764 · Oct 10, 2016
Provisional Application 62242926 · Oct 16, 2015
Related Publication 20180069826A1 · Mar 8, 2018