IP Library Granted Patent US 10,257,157
Granted Patent B2
US 10,257,157 · App. 15/982,753 · Granted Apr 9, 2019

Restricting communication over an encrypted network connection to internet domains that share common IP addresses and shared SSL certificates

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L61/2007H04L29/12066H04L61/1511H04L63/0209H04L63/0227H04L63/0823H04L63/10H04L63/101H04L67/02H04L63/0236H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,257,157
App. No.
15/982,753
Granted
Apr 9, 2019
Kind
B2
Abstract

An apparatus prevents communication by a client device to a domain that cannot be uniquely identified by relocating the DNS mapping of the domain to a destination IP Address that is uniquely identifiable and that represents a location of an apparatus that provides a data path to the domain.

Claims (43)

1. A computer-implemented method executed by one or more hardware processors, the method comprising:

receiving an encrypted request for a resource, the encrypted request directed to a particular IP address;

determining that the particular IP address is a spoofed IP address associated with a particular domain name;

determining that the encrypted request is directed to the particular domain name based on the association between the spoofed IP address and the particular domain name, wherein the determination is made without decrypting the encrypted request; and

selectively allowing the encrypted request based at least in part on determining that the encrypted request is directed to the particular domain name.

2. The method of claim 1 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be blocked based at least in part on a rule associated with the particular domain name; and

blocking the encrypted request.

3. The method of claim 1 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be allowed based at least in part on a rule associated with the particular domain name; and

forwarding the encrypted request to a corresponding IP address for the particular domain name.

4. The method of claim 1 , wherein the association between the spoofed IP address and the particular domain name is created by a domain name server in response to receiving a request to resolve the particular domain name.

5. The method of claim 1 , wherein the spoofed IP address includes an IP port.

6. The method of claim 1 , wherein receiving the encrypted request for the resource includes receiving a request according to Hypertext Transfer Protocol Secure (HTTPS).

7. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one hardware processor to perform operations comprising:

receiving an encrypted request for a resource, the encrypted request directed to a particular IP address;

determining that the particular IP address is a spoofed IP address associated with a particular domain name;

determining that the encrypted request is directed to the particular domain name based on the association between the spoofed IP address and the particular domain name, wherein the determination is made without decrypting the encrypted request; and

selectively allowing the encrypted request based at least in part on determining that the encrypted request is directed to the particular domain name.

8. The non-transitory, computer-readable medium of claim 7 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be blocked based at least in part on a rule associated with the particular domain name; and

blocking the encrypted request.

9. The non-transitory, computer-readable medium of claim 7 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be allowed based at least in part on a rule associated with the particular domain name; and

forwarding the encrypted request to a corresponding IP address for the particular domain name.

10. The non-transitory, computer-readable medium of claim 7 , wherein the association between the spoofed IP address and the particular domain name is created by a domain name server in response to receiving a request to resolve the particular domain name.

11. The non-transitory, computer-readable medium of claim 7 , wherein the spoofed IP address includes an IP port.

12. The non-transitory, computer-readable medium of claim 7 , wherein receiving the encrypted request for the resource includes receiving a request according to Hypertext Transfer Protocol Secure (HTTPS).

13. A system comprising:

memory for storing data; and

one or more hardware processors operable to perform operations comprising:

receiving an encrypted request for a resource, the encrypted request directed to a particular IP address;

determining that the particular IP address is a spoofed IP address associated with a particular domain name;

determining that the encrypted request is directed to the particular domain name based on the association between the spoofed IP address and the particular domain name, wherein the determination is made without decrypting the encrypted request; and

selectively allowing the encrypted request based at least in part on determining that the encrypted request is directed to the particular domain name.

14. The system of claim 13 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be blocked based at least n part on a rule associated with the particular domain name; and

blocking the encrypted request.

15. The system of claim 13 , wherein selectively allowing the encrypted request includes:

determining that the encrypted request should be allowed based at least in part on a rule associated with the particular domain name; and

forwarding the encrypted request to a corresponding IP address for the particular domain name.

16. The system of claim 13 , wherein the association between the spoofed IP address and the particular domain name is created by a domain name server in response to receiving a request to resolve the particular domain name.

17. The system of claim 13 , wherein the spoofed IP address includes an IP port.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2018
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 046404/0816 →
CHANGE OF NAME Recorded Jul 19, 2018
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 047570/0875 →
Continuity (4)
Continuation 15394625 · Dec 29, 2016
Continuation 15094900 · Apr 8, 2016
Continuation 13455116 · Apr 24, 2012
Related Publication 20180270192A1 · Sep 20, 2018
Cited By (2)
US 12,316,599 US 12,432,183