IP Library › Granted Patent US 12,355,723
Granted Patent B2
US 12,355,723 · App. 17/656,444 · Granted Jul 8, 2025

Dynamic VPN address allocation

Inventors: Robert Dunham Short, III (Lexington, VA); Michael Williamson (South Riding, VA); Victor Larson (Fairfax, VA)
Assignee: VirnetX, Inc.
H04L61/5046G06F16/9017H04L61/2514H04L61/2592H04L61/4511H04L61/5053H04L63/0272H04L63/029H04L63/0428H04L2101/695
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,723
App. No.
17/656,444
Granted
Jul 8, 2025
Kind
B2
Abstract

Methods and related systems are presented that relate to automatically avoiding address conflicts when establishing a secure communications link over a public network between a local computer, associated with a local network, and a remote device, located outside the local network. Local network addresses on the local network reserved for use, and a block of local network addresses that do not conflict with the reserved local network addresses, are identified. At least one local network address is selected from the block and assigned as an address of the local device for use in communicating with the remote device securely over the public network. Communication is facilitated with the remote device using the network driver based on the assigned at least one local network address.

Claims (48)

1. A local device, associated with a local network, for automatically avoiding address conflicts when communicating securely over a public network with a remote device, located outside the local network, the local device comprising:

a network driver; and

at least one processor, coupled to memory, is configured to:

identify a block of local network addresses that are available for use, wherein each of the local network addresses includes an IP address and network mask;

send, to the remote device, the block of local network addresses that are available for use;

receive, from the remote device, at least one local network address, including corresponding IP addresses and corresponding network masks;

assign, to the network driver, the selected at least one local network address as an address of the local device for use in communicating with the remote device securely over the public network;

identify at least one remote network address based at least in part on the selected at least one local network address for the remote device for use in communicating with the local device securely over the public network;

encapsulate at least one of a private address of the local device or a private address of the remote device with the at least one local network address;

add the at least one remote network address to a list of reserved local network addresses; and

communicate with the remote device using the network driver based on the assigned at least one local network address.

2. The local device of claim 1 , wherein the at least one processor is further configured to:

receive a name service request for a name corresponding to the remote device, wherein to identify the block of local network addresses that are available for use is based at least in part on the name service request.

3. The local device of claim 1 , wherein the at least one processor is further configured to:

identify at least one remote network address that lacks conflict with the at least one local network address.

4. The local device of claim 1 , wherein the at least one processor is further configured to:

identify local network addresses on the local network reserved for use.

5. The local device of claim 1 , wherein the network driver is a software module.

6. The local device of claim 1 , wherein the at least one processor is further configured to:

encrypt packets transmitted to the remote device over the public network.

7. The local device of claim 1 , wherein the at least one processor is further configured to:

communicate with the remote device using a communication link over a virtual private network.

8. The local device of claim 1 , wherein the at least one processor is further configured to:

encrypt the at least one of the private address of the local device or the private address of the remote device.

9. The local device of claim 1 , wherein the communication with the remote device is enabled by a host-to-host connection or a host-to-network connection.

10. A method, associated with a local network, for automatically avoiding address conflicts when communicating securely over a public network with a remote device, located outside the local network, the method comprising:

identifying, by a local device comprising at least one processor, a block of local network addresses that are available for use, wherein each of the local network addresses includes an IP address and network mask;

sending, to the remote device, the block of local network addresses that are available for use;

receiving, from the remote device, at least one local network address, including corresponding IP addresses and corresponding network masks;

assigning, by the local device and to a network driver, the at least one local network address as an address of the local device for use in communicating with the remote device securely over the public network;

identifying, by the local device, at least one remote network address based at least in part on the at least one local network address for the remote device for use in communicating with the local device securely over the public network;

encapsulating at least one of a private address of the local device or a private address of the remote device with the at least one local network address;

adding, by the local device, the at least one remote network address to a list of reserved local network addresses; and

communicating with the remote device using the network driver based on the assigned at least one local network address.

11. The method of claim 10 , further comprising:

receiving a name service request for a name corresponding to the remote device, wherein to identify the block of local network addresses that are available for use is based at least in part on the name service request.

12. The method of claim 10 , further comprising:

identifying at least one remote network address that lacks conflict with the selected at least one local network address.

13. The method of claim 10 , further comprising:

identifying local network addresses on the local network reserved for use.

14. The method of claim 10 , wherein the network driver is a software module.

15. The method of claim 10 , further comprising:

encrypting packets transmitted to the remote device over the public network.

16. The method of claim 10 , further comprising:

communicating with the remote device using a communication link over a virtual private network.

17. The method of claim 10 , further comprising:

encrypt the at least one of the private address of the local device or the private address of the remote device.

18. The method of claim 10 , wherein the communication with the remote device is enabled by a host-to-host connection or a host-to-network connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2022
From: SHORT, ROBERT DUNHAM; LARSON, VICTOR; WILLIAMSON, MICHAEL
To: VIRNETX, INC.
Reel/Frame 059510/0947 →
Continuity (5)
Continuation 16834718 · Mar 30, 2020
Continuation 14687875 · Apr 15, 2015
Continuation 13544582 · Jul 9, 2012
Provisional Application 61505754 · Jul 8, 2011
Related Publication 20220286427A1 · Sep 8, 2022
References Cited (43)
US 7085836B1 · Turner · 2006 [cited by applicant]
US 8661158B2 · Hoover · 2014 [cited by examiner]
US 10608986B2 · Short et al. · 2020 [cited by applicant]
US 20040054902A1 · Fujimoto et al. · 2004 [cited by applicant]
US 20070061887A1 · Hoover · 2007 [cited by examiner]
US 20080298367A1 · Furukawa · 2008 [cited by applicant]
US 20090036111A1 · Danford et al. · 2009 [cited by applicant]
US 20110078784A1 · Ohtani · 2011 [cited by applicant]
US 20110134907A1 · Parolkar et al. · 2011 [cited by applicant]
US 20140181248A1 · Deutsch et al. · 2014 [cited by applicant]
US 20160154403A1 · Arbogast · 2016 [cited by applicant]
US 20160294793A1 · Larson et al. · 2016 [cited by applicant]
US 20190141128A1 · Hallak et al. · 2019 [cited by applicant]
US 20200296074A1 · Short et al. · 2020 [cited by applicant]
CN 1495631A · 2004 [cited by applicant]
CN 101060391A · 2007 [cited by applicant]
CN 101068189A · 2007 [cited by applicant]
CN 101212374A · 2008 [cited by applicant]
CN 101304388A · 2008 [cited by applicant]
CN 101562639A · 2009 [cited by applicant]
CN 101677291A · 2010 [cited by applicant]
IN 101808038A · 2010 [cited by applicant]
JP 2007027818A · 2007 [cited by applicant]
JP 2008301024 · 2008 [cited by applicant]
JP 2009010606 · 2009 [cited by applicant]
JP 2009017429 · 2009 [cited by applicant]
JP 2009171132A · 2009 [cited by applicant]
JP 2010268145A · 2010 [cited by applicant]
JP 2010278636A · 2010 [cited by applicant]
WO WO2007072254A1 · 2007 [cited by applicant]
WO WO2008146384A1 · 2008 [cited by applicant]
Chinese Office Action mailed on Jan. 16, 2020 for Chinese Patent Application No. 201710493159.5, a counterpart of U.S. Appl. No. 14/687,875, 29 pages. [cited by applicant]
Chinese Office Action mailed Dec. 9, 2020 for Chinese Patent Application No. 20128034033.7, a counterpart foreign application of U.S. Pat. No. 10,608,986, 14 pages. [cited by applicant]
Chinese Office Action mailed Apr. 1, 2021 for Chinese Patent Application No. 20128034033.7, a foreign counterpart of U.S. Pat. No. 10,608,986, 10 pages. [cited by applicant]
Chinese Office Action mailed on Jan. 16, 2020, for Chinese Patent Application No. 201710493159.5, a counterpart foreign application of U.S. Appl. No. 14/687,875, 14 pages. [cited by applicant]
Japanese Office Action mailed Sep. 30, 2020 for Japanese Patent Application No. 2019-120672, a counterpart foreign application of U.S. Appl. No. 16/834,718, 8 pages. [cited by applicant]
Japanese Office Action mailed Sep. 13, 2021 for Japanese Application No. 2019-120672, a foreign counterpart to U.S. Pat. No. 10,608,986, 3 pages. [cited by applicant]
English-language translation of Japanese Notice of Reasons for Refusal dated Sep. 13, 2021 in corresponding Application No. JP 2019-120672 (3 pages). [cited by applicant]
US Office Action for U.S. Appl. No. 16/834,718, mailed on Mar. 29, 2021, Short, “Dynamic VPN Address Allocation”, 24 Pages. [cited by applicant]
US Office Action for U.S. Appl. No. 16/834,718, mailed on Aug. 18, 2021, Short, “Dynamic VPN Address Allocation”, 24 Pages. [cited by applicant]
US Office Action dated Oct. 26, 2020 for U.S. Appl. No. 16/834,718, “Dynamic VPN Address Allocation”, Short, 8 pages. [cited by applicant]
Japanese Office Action mailed May 9, 2023 for Japanese Patent Application No. 2022-038771, a foreign counterpart to U.S. Pat. No. 10,608,986, 4 pages. [cited by applicant]
Office Action for Japanese Application No. 2023-194047, Dated Nov. 6, 2024, 8 pages. [cited by applicant]