IP Library Granted Patent US 8,572,247
Granted Patent B2
US 8,572,247 · App. 13/049,552 · Granted Oct 29, 2013

Agile network protocol for secure communications using secure domain names

Inventors: Victor Larson (Fairfax, VA); Robert Dunham Short, III (Leesburg, VA); Edmund Colby Munger (Crownsville, MD); Michael Williamson (South Riding, VA)
Assignee: VirnetX, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,572,247
App. No.
13/049,552
Granted
Oct 29, 2013
Kind
B2
Abstract

A secure domain name service for a computer network is disclosed that includes a portal connected to a computer network, such as the Internet, and a domain name database connected to the computer network through the portal. The portal authenticates a query for a secure computer network address, and the domain name database stores secure computer network addresses for the computer network. Each secure computer network address is based on a non-standard top-level domain name, such as .scom, .sorg, .snet, .snet, .sedu, .smil and .sint.

Claims (37)

1. A system for establishing a virtual private network (VPN) communication link, comprising:

a storage device having instructions stored thereon; and

one or more processors configured to execute the instructions and, on executing the instructions:

generate a Domain Name Service (DNS) request;

determine that the DNS request corresponds to one or more computers configured to communicate securely;

send, based on the determination, a request to establish a VPN communication link with a first computer of the one or more computers configured to communicate securely, the request including an identifier of a client device used for determining whether the client device is authorized to communicate with the first computer;

receive, in response to the request to establish a VPN communication link, a resource for establishing the VPN communication link; and

automatically establish the VPN communication link with the first computer using the received resource.

2. The system of claim 1 , wherein the resource is obtained from a second computer that is separate from the first computer.

3. The system of claim 1 , wherein the resource includes at least one random or pseudorandom value used to establish the VPN communication link.

4. The system of claim 3 , wherein the resource includes a set of pseudorandom IP addresses generated based on an IP address hopping regime, and the one or more processors are configured to transmit packets to the first computer using the pseudorandom IP addresses in the set.

5. The system of claim 1 , wherein the client device identifier is an IP address.

6. The system of claim 1 , wherein the one or more processors are further configured to communicate with the first computer using modulation.

7. The system of claim 6 , wherein the modulation is based on one of frequency-division multiplexing (FDM), time-division multiplexing (TDM), and code division multiple access (CDMA).

8. The system of claim 1 , wherein the client device includes a mobile device.

9. The system of claim 1 , wherein the one or more processors are further configured to:

receive a message requesting proof that the client device is authorized to access the first computer; and

send the requested proof that the client device is authorized to access the first computer.

10. The system of claim 9 , wherein the message requesting proof is generated by a second computer that is separate from the first computer.

11. The system of claim 9 , wherein the requested evidence is sent to a second computer that is separate from the first computer to determine whether the client device is authorized to access the first computer.

12. The system of claim 1 , wherein the DNS request is a request for an Internet Protocol (IP) address associated with a domain name.

13. A system for establishing a virtual private network (VPN) communication link, comprising:

storage configured to store client device identifiers; and

one or more processors configured to:

receive a request to communicate securely, the request including an identifier of a client device, the request having been sent in response to a determination that a DNS request from the client device corresponds to a first computer configured to communicate securely;

compare the received client device identifier to one or more of the stored client device identifiers;

determine, based on the comparison, whether the client device is authorized to communicate with the first computer; and

in response to determining that the client device is authorized to communicate with the first computer, make a resource available to the client device for automatically establishing the VPN communication link between the client device and the first computer.

14. The system of claim 13 , wherein the resource includes at least one random or pseudorandom value used to establish the VPN communication link.

15. The system of claim 14 , wherein the at least one random or pseudorandom value is an Internet Protocol (IP) address.

16. The system of claim 15 , wherein, to generate the resource, the one or more processors are configured to establish an IP address hopping regime that pseudorandomly changes IP addresses in packets transmitted between the client device and the first computer configured to communicate securely during a communications session.

17. The system of claim 13 , wherein the client device identifier is an IP address.

18. The system of claim 13 , wherein the VPN communication link uses modulation.

19. The system of claim 18 , wherein the modulation is based on one of frequency-division multiplexing (FDM), time-division multiplexing (TDM), and code division multiple access (CDMA).

20. The system of claim 13 , wherein the client device includes a mobile device.

21. The system of claim 20 , wherein the mobile device is a notebook computer.

22. The system of claim 13 , wherein the one or more processors are further configured to send a message to the client device requesting proof that the client device is authorized to access the first computer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2012
From: LARSON, VICTOR; SHORT, ROBERT DUNHAM, III; MUNGER, EDMUND COLBY; WILLIAMSON, MICHAEL
To: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
Reel/Frame 027613/0163 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2012
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX, INC.
Reel/Frame 027613/0168 →
Continuity (8)
Continuation 11840560 · Aug 17, 2007
Continuation 10714849 · Nov 18, 2003
Continuation 09558210 · Apr 26, 2000
Continuation In Part 09504783 · Feb 15, 2000
Continuation In Part 09429643 · Oct 29, 1999
Provisional Application 60106261 · Oct 30, 1998
Provisional Application 60137704 · Jun 7, 1999
Related Publication 20110167087A1 · Jul 7, 2011