IP Library › Granted Patent US 10,511,573
Granted Patent B2
US 10,511,573 · App. 15/185,760 · Granted Dec 17, 2019

Agile network protocol for secure communications using secure domain names

Inventors: Victor Larson (Fairfax, VA); Robert Dunham Short, III (Leesburg, VA); Edmund Colby Munger (Crownsville, MD); Michael Williamson (South Riding, VA)
Assignee: VirnetX, Inc.
H04L63/0272G06F8/61G06F16/951G06F21/606H04L61/1511H04L61/2038H04L61/6022H04L63/0281H04L63/0421H04L63/0435H04L63/0478H04L63/0485H04L63/0853H04L63/0876H04L63/0884H04L63/10H04L63/1416H04L63/1458H04L63/1466H04L61/6013H04N7/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,573
App. No.
15/185,760
Granted
Dec 17, 2019
Kind
B2
Abstract

A network device comprises a storage device storing an application program for a secure communications service, and at least one processor configured to execute the application program for the secure communications service so as to enable the network device to send a request to look up a network address of a second device based on an identifier associated with the second device, receive an indication that the second device is available for the secure communications service, the indication including the requested network address and provisioning information for a secure communication link, connect to the second device over the secure communication link, using the received network address of the second device and the provisioning information for the secure communication link, and communicate at least one of video data and audio data with the second device using the secure communications service via the secure communication link.

Claims (38)

1. A device, comprising:

a first communication interface connected to a first link having a first bandwidth;

a second communication interface connected to a second link having a second bandwidth, wherein the first bandwidth is greater than the second bandwidth;

memory storing instructions for a link guard function; and

one or more processors configured to execute the instructions to:

receive, via the first communication interface, a packet transmitted over the first link, the packet being destined for a node on the second link, wherein the node on the second link comprises an edge server;

determine that the first bandwidth of the first link is greater than the second bandwidth of the second link;

cryptographically authenticate the packet responsive to determining that the first bandwidth of the first link is greater than the second bandwidth of the second link;

determine, based on a result of cryptographically authenticating the packet, whether the packet belongs to a virtual private network;

when it is determined that the packet belongs to the virtual private network, transmitting the packet on the second link with a first quality of service; and

when it is determined that the packet does not belong to the virtual private network, transmitting the packet on the second link with a second quality of service that is lower than the first quality of service.

2. The device of claim 1 , wherein the device is a node of an internet service provider.

3. A method, comprising:

receiving, at a first communication interface connected to a first link, a packet destined for a node on a second link, the first link having a greater bandwidth than second link, wherein the node on the second link comprises an edge server;

determining, based at least in part on the first link having the greater bandwidth than the second link, that a link guard function is to be implemented;

cryptographically authenticating the packet based at least in part on determining that the link guard function is to be implemented;

determining, based on a result of cryptographically authenticating the packet, whether the packet belongs to a virtual private network;

when it is determined that the packet belongs to the virtual private network, transmitting the packet on the second link with a first quality of service; and

when it is determined that does not belong to the virtual private network, transmitting the packet on the second link via a second communication interface with a second quality of service that is lower than the first quality of service.

4. The method of claim 3 , performed by a node of an internet service provider.

5. The device of claim 1 , wherein the virtual private network is a first virtual private network of a plurality of virtual private networks.

6. The device of claim 5 , wherein to determine whether the packet belongs to the virtual private network comprises the one or more processors to execute the instructions to determine an Internet Protocol Security (IPSEC) of the packet.

7. The device of claim 5 , wherein to determine whether the packet belongs to the virtual private network comprises the one or more processors to execute the instructions to access a table indicating individual ones of the plurality of virtual private networks.

8. The device of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

receive, via the first communication interface, a second packet transmitted over the first link, the packet being destined for a node on the second link;

determine, based at least in part on the first link having the greater bandwidth than the second link, that a link guard function is to be implemented;

cryptographically authenticate the packet based at least in part on determining that the link guard function is to be implemented;

determine, based on a result of cryptographically authenticating the packet, that the second packet does not belong to any of a plurality of virtual private networks; and

discard the second packet.

9. The method of claim 3 , wherein the virtual private network is a first virtual private network of a plurality of virtual private networks.

10. The method of claim 9 , wherein determining whether the packet belongs to the virtual private network comprises determining an Internet Protocol Security (IPSEC) of the packet.

11. The method of claim 9 , wherein determining whether the packet belongs to the virtual private network comprises accessing a table indicating individual ones of the plurality of virtual private networks.

12. The method of claim 3 , further comprising:

receiving, via the first communication interface, a second packet transmitted over the first link, the packet being destined for a node on the second link;

determining, based at least in part on the first link having the greater bandwidth than the second link, that a link guard function is to be implemented;

cryptographically authenticating the packet based at least in part on determining that the link guard function is to be implemented;

determining, based on a result of cryptographically authenticating the packet, that the second packet does not belong to any of a plurality of virtual private networks; and

discarding the second packet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2019
From: SCIENCE APPLICATIONS INTERNATIONAL CORPORATIONN
To: VIRNETX, INC.
Reel/Frame 050383/0669 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2019
From: LARSON, VICTOR; SHORT, ROBERT DUNHAM, III; MUNGER, EDMUND COLBY; WILLIAMSON, MICHAEL
To: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
Reel/Frame 050384/0647 →
Continuity (10)
Continuation 13615528 · Sep 13, 2012
Continuation 13049552 · Mar 16, 2011
Continuation 11840560 · Aug 17, 2007
Continuation 10714849 · Nov 18, 2003
Continuation 09558210 · Apr 26, 2000
Continuation In Part 09504783 · Feb 15, 2000
Continuation In Part 09429643 · Oct 29, 1999
Provisional Application 60137704 · Jun 7, 1999
Provisional Application 60106261 · Oct 30, 1998
Related Publication 20160294793A1 · Oct 6, 2016
Cited By (4)
US 12,267,314 US 12,335,336 US 12,495,042 US 12,701,415