IP Library › Granted Patent US 8,780,905
Granted Patent B2
US 8,780,905 · App. 13/620,358 · Granted Jul 15, 2014

Third party VPN certification

Inventor: Victor Larson (Fairfax, VA)
Assignee: VirnetX, Inc.
H04L63/0823H04L63/061H04L63/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,780,905
App. No.
13/620,358
Granted
Jul 15, 2014
Kind
B2
Abstract

A virtual private network (VPN) over a telecommunications network is created by sending a request from a first VPN device to a second VPN device for establishing a VPN between the first and second VPN devices. The request includes a first signed certificate having a verified VPN parameter for the first VPN device. A reply is received at the first VPN device from the second VPN device that includes a second signed certificate having a verified VPN parameter for the second VPN device. The VPN is established between the first and second VPN devices based on each verified VPN parameter for each of the first and second VPN devices.

Claims (39)

1. A method for creating a virtual private network (VPN) connection, comprising:

querying, by a first device an online database to request a secure domain name address of a second device, wherein the querying supplies a remote name of a pre-authorized VPN name pair to the online database;

receiving the secure domain name address at the first device in response to the querying;

providing, by the first device, a verified certificate and receiving, at the first device, a verified certificate from the second device in order to establish a VPN connection using the verified certificates.

2. The method of claim 1 , further comprising:

storing, at the first device, information identifying a plurality of pre-authorized VPN name pairs, the plurality of pre-authorized VPN name pairs each including a local device name and a remote device name for a VPN connection.

3. The method of claim 2 , wherein the information stored on the first device further includes information identifying a VPN connection type for each pre-authorized VPN name pair.

4. The method of claim 2 , wherein the information stored on the first device further includes wildcard information in at least one of the local or remote device names.

5. The method of claim 1 , further comprising:

storing, on the first device, a plurality of verified certificates, the plurality of verified certificates containing different VPN parameters.

6. The method of claim 5 , further comprising:

associating, by the first device, the stored plurality of verified certificates with a plurality of different local names.

7. The method of claim 1 , wherein querying includes supplying a public key of the first device to the online database for use in verifying the identity of the first device.

8. The method of claim 1 , wherein the first device uses the received secure domain name address in at least one of the providing or the receiving.

9. The method of claim 1 , wherein:

the verified certificates provided by the first device and received from the second device each contains at least one verified VPN parameter corresponding to the first and second devices, respectively, and

the at least one verified VPN parameters from the certificates are used to establish the VPN connection.

10. A non-transitory computer-readable medium storing computer-executable instructions for performing the following:

causing a first device to query an online database to request a secure domain name address of a second device, wherein the query supplies a remote name of a pre-authorized VPN name pair to the online database;

causing the first device to receive the secure domain name address in response to the querying;

causing the first device to provide a first verified certificate for the VPN connection to the second device using said secure domain name address and to receive a second verified certificate for the VPN connection from the second device, so that a VPN connection using the first and second certificates can be established.

11. The non-transitory medium of claim 10 , further comprising computer-executable instructions for:

causing the first device to store information identifying a plurality of pre-authorized VPN name pairs, the plurality of pre-authorized name pairs each including a local device name and a remote device name for a VPN connection.

12. The non-transitory medium of claim 11 , wherein the information identifying the plurality of pre-authorized VPN name pairs further includes information identifying a VPN connection type for each pre-authorized VPN name pair.

13. The non-transitory medium of claim 11 , wherein the information identifying the plurality of pre-authorized VPN name pairs further includes wildcard information in at least one of the local or remote device names.

14. The non-transitory medium of claim 10 , further comprising computer-executable instructions for: causing the first device to store a plurality of verified certificates for the first device, the plurality of verified certificates containing different VPN parameters.

15. The non-transitory medium of claim 14 , further comprising computer-executable instructions for:

associating, by the first device, the stored plurality of verified certificates with a plurality of different local names.

16. The non-transitory medium of claim 10 , wherein the query further supplies a public key of the first device to the online database.

17. The non-transitory medium of claim 10 , wherein:

the first and second certificates each contain at least one verified VPN parameter for the first and second devices, respectively, and

the at least one verified VPN parameter from the first and second certificates is used to establish the VPN connection.

18. A virtual private network (VPN) device, comprising:

a memory storing a plurality of verified certificates for VPN connections with the device, the certificates being associated with different local names, and the device being associated with the different local names; and

a processor configured to:

receive a request for a VPN connection from a second device, and

identify a name in the request and compare the name with the plurality of different local names to identify at least one stored verified certificate for a desired VPN connection.

19. The device of claim 18 , wherein said memory further stores information identifying policy restrictions associated with one or more of the local names.

20. The device of claim 18 , wherein said device is configured to provide VPN connections for a plurality of client devices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2013
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
To: VIRNETX INC.
Reel/Frame 030854/0674 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2013
From: LARSON, VICTOR
To: VIRNETX INC.
Reel/Frame 030854/0945 →
Continuity (5)
Continuation 13110353 · May 18, 2011
Continuation 11532002 · Sep 14, 2006
Continuation 09874258 · Jun 6, 2001
Provisional Application 60262036 · Jan 18, 2001
Related Publication 20130014246A1 · Jan 10, 2013