IP Library › Granted Patent US 11,463,411
Granted Patent B1
US 11,463,411 · App. 17/517,598 · Granted Oct 4, 2022

Header-based authentication in a virtual private network

Inventor: Mindaugas Valkaitis (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/0272H04L9/3236H04L9/3247H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,411
App. No.
17/517,598
Granted
Oct 4, 2022
Kind
B1
Abstract

A method in a virtual private network (VPN) environment, the method including receiving, at a first processor from a second processor, a connection request for obtaining VPN services; determining, by the first processor, custom headers including a timing header, an authorization header, a digest header, and a signature header; transmitting, by the first processor to the second processor, a response including the custom headers and a payload indicating a VPN server for providing the VPN services; and transmitting, by the second processor to the VPN server, a request for obtaining the VPN services based at least in part on authenticating the custom headers. Various other aspects are contemplated.

Claims (35)

1. A method in a virtual private network (VPN) environment, the method comprising:

receiving, at a first processor from a second processor, a connection request for obtaining VPN services;

determining, by the first processor, custom headers including a timing header, an authorization header, a digest header, and a signature header;

transmitting, by the first processor to the second processor, a response including the custom headers and a payload indicating a VPN server for providing the VPN services; and

transmitting, by the second processor to the VPN server, a request for obtaining the VPN services based at least in part on authenticating the custom headers.

2. The method of claim 1 , wherein authenticating the custom headers includes determining, by the second processor, a presence of the custom headers in the response.

3. The method of claim 1 , wherein the timing header indicates a point in time or a duration of time associated with a validity of the response.

4. The method of claim 1 , wherein the authorization header includes an identifier associated with a cryptographic key utilized by the first processor to determine the signature header.

5. The method of claim 1 , wherein the authorization header includes an identifier associated with an encryption algorithm utilized by the first processor to determine the signature header.

6. The method of claim 1 , wherein the digest header includes a hash of the payload.

7. The method of claim 1 , wherein the signature header includes an encoded combination of the digest header and the timing header, the combination of the digest header and the timing header being signed utilizing a cryptographic key identified in the authorization header.

8. A virtual private network (VPN) environment, comprising:

a first processor configured to:

receive, from a second processor, a connection request for obtaining VPN services;

determine custom headers including a timing header, an authorization header, a digest header, and a signature header; and

transmit, to the second processor, a response including the custom headers and a payload indicating a VPN server for providing the VPN services; and

the second processor configured to:

transmit, to the VPN server, a request for obtaining the VPN services based at least in part on authenticating the custom headers.

9. The device of claim 8 , wherein the second processor is configured to authenticate the custom headers based at least in part on determining a presence of the custom headers in the response.

10. The device of claim 8 , wherein the timing header indicates a point in time or a duration of time associated with a validity of the response.

11. The device of claim 8 , wherein the authorization header includes an identifier associated with a cryptographic key utilized by the first processor to determine the signature header.

12. The device of claim 8 , wherein the authorization header includes an identifier associated with an encryption algorithm utilized by the first processor to determine the signature header.

13. The device of claim 8 , wherein the digest header includes a hash of the payload.

14. The device of claim 8 , wherein the signature header includes an encoded combination of the digest header and the timing header, the combination of the digest header and the timing header being signed utilizing a cryptographic key identified in the authorization header.

15. A non-transitory computer-readable medium configured to store instructions, which when executed by a first processor associated with a virtual private network (VPN) environment, cause the first processor to:

receive, from a second processor, a connection request for obtaining VPN services;

determine custom headers including a timing header, an authorization header, a digest header, and a signature header; and

transmit, to the second processor, a response including the custom headers and a payload indicating a VPN server for providing the VPN services; and

when executed by the second processor, cause the second processor to:

transmit, to the VPN server, a request for obtaining the VPN services based at least in part on authenticating the custom headers.

16. The non-transitory computer-readable medium of claim 15 , wherein the second processor is configured to authenticate the custom headers based at least in part on determining a presence of the custom headers in the response.

17. The non-transitory computer-readable medium of claim 15 , wherein the timing header indicates a point in time or a duration of time associated with a validity of the response.

18. The non-transitory computer-readable medium of claim 15 , wherein the authorization header includes an identifier associated with a cryptographic key utilized by the first processor to determine the signature header.

19. The non-transitory computer-readable medium of claim 15 , wherein the authorization header includes an identifier associated with an encryption algorithm utilized by the first processor to determine the signature header.

20. The non-transitory computer-readable medium of claim 15 , wherein the digest header includes a hash of the payload.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2021
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 058704/0722 →
Cited By (1)
US 12,719,834