Network filter
View Patent ↗A data filter and a method of creating a network data pathway via a network filter is disclosed the method comprising a i. selection phase and ii. operation phase. The selection phase comprises transferring over a network at least one enquiry data packet between a first network user and at least one other network participant via the filter and receiving at least one enquiry data packet response from the at least one network participant via the filter. A network participant is selected so as to switch from the selection phase to the operation phase. The operation phase comprises creating a network data pathway between the first network user and the selected network participant and prohibiting further creation of a further network data pathway between the network user and any unselected network participant.
1 . A method of creating a network data pathway via a network filter comprising:
a selection phase, during which the network filter is in a selection state, and an operation phase, during which the network filter is in an operation state,
the selection phase comprising:
transferring over a network at least one enquiry data packet between a first network participant and at least one other network participant of a plurality of other network participants via the filter;
receiving at least one enquiry data packet response from the at least one other network participant via the filter; and
selecting, from the plurality of other network participants, a selected network participant of the plurality of other network participants so as to switch from the selection phase to the operation phase, wherein a network participant from the plurality of other network participants providing a first enquiry data packet response containing a specific protocol stage trigger packet to be received by the first network participant is selected as the selected network participant, and wherein the specific protocol stage trigger packet enables the switching of the network filter from the selection state to the operation state; and
the operation phase comprising:
creating a network data pathway between the first network participant and the selected network participant and prohibiting further creation of a further network data pathway between the first network participant and any unselected other network participant; and
wherein the first network participant is prohibited from transferring over the network any further enquiry data packets to any unselected network participants.
2 . A method according to claim 1 , wherein the selected network participant is selected in dependence upon a predetermined protocol sequence.
3 . A method according to claim 1 , wherein only a single network participant is selected as the selected network participant and only a single network data pathway is created between the first network participant and the selected network participant.
4 . A method according to claim 1 , wherein passage of the at least one enquiry data response from another network participant, via the filter, is permitted in dependence upon predetermined selection criteria.
5 . A method according to claim 4 , comprising inspecting at least one enquiry data packet response to identify compliance of the predetermined selection criteria.
6 . A method according to claim 4 , wherein the predetermined selection criteria comprises a response from a predetermined recipient and/or at least one of a predetermined set of response type criteria.
7 . A method according to claim 6 , wherein the response type criteria comprises one or more of the following:
a) a packet type,
b) adherence with an expected version of a protocol; or
c) compatibility of the response with respect to the enquiry.
8 . A method according to claim 1 , wherein in the operation phase the data transfer or packet transfer along the network data pathway between the first network participant and the selected network participant and vice versa is exclusive.
9 . A method according to claim 1 , wherein the selection of the other network participant to provide the selected network participant is implemented at an IP packet layer.
10 . A method according to claim 1 , wherein prior to sending an enquiry data packet, a specific IP address is determined for a predetermined at least one other network participant.
11 . A method according to claim 10 , wherein in the selection phase the at least one enquiry requires DNS resolution of the IP address of the at least one other network participant.
12 . A method according to claim 11 , wherein the DNS resolution is performed by permitting communication with at least one DNS server.
13 . A method according to claim 11 , wherein in the operation phase all DNS queries are directed to the selected network participant.
14 . A method according to claim 11 , wherein on creation of a network data pathway subsequent DNS enquiries are prohibited.
15 . A method according to claim 1 , wherein the network data pathway comprises a VPN tunnel at least part of which passes through the filter.
16 . A method according to claim 1 , wherein the operation phase comprises a cool-down period wherein creation of a further network data pathway between the first network participant and any unselected other network participant is prohibited.
17 . A method according to claim 16 , wherein on expiry of the cool-down period, the filter reverts back to the selection phase from the operation phase.
18 . A method according to claim 16 , wherein the cool-down period is terminated by the receipt of a signal from the first network participant.
19 . A method according to claim 1 , wherein in the operation phase there is provided a first data traffic type and a second data traffic type, wherein the filter is configured to permit the first data traffic type to be forwarded along a first data pathway and the second data traffic type to be forwarded along a second data pathway.
20 . A method according to claim 1 , wherein the enquiry data packets comprise information concerning the one or more specific protocol types to be transmitted between the first network participant and the selected network participant.
21 . A method according to claim 20 , wherein there is provided a first protocol type prior to receipt of the enquiry data packet response and a second protocol type subsequent to receipt of the enquiry data packet response.
22 . A method according to claim 21 , wherein the second protocol type comprises a new protocol differing to the first protocol type, a combination of new protocol stage and new protocol, or an entirely new protocol stage.
23 . A method according to claim 1 , wherein creation of a further network data pathway between the first network participant and any unselected network participants is dependent upon a further specified protocol criteria.
24 . A method according to claim 1 , wherein after the creation of a data pathway and on determination of a termination trigger, the method further comprises:
a. terminating the network data pathway;
b. rebooting compute associated with the first network participant;
and
c. reverting the method to the selection phase.
25 . A method according to claim 24 , wherein the termination trigger comprises the selected network participant being determined to be an untrusted network participant.
26 . A method according to claim 1 , wherein selection of the selected network participant occurs independently of any determination of an untrusted state or an indeterminable state of the selected network participant.
27 . A network filter comprising:
at least one processing unit; and
a computer-readable media comprising computer executable instructions, which when executed by the at least one processing unit causes the network filter to:
operate in a selection state during a selection phase and an operation state during an operation phase;
transfer, during the selection phase, at least one enquiry data packet between a first network participant and at least one other network participant of a plurality of other network participants;
permit receipt, during the selection phase, of at least one enquiry data packet response from the at least one other network participant;
select, during the selection phase, from the plurality of network participants, a selected network participant so as to switch from the selection phase to the operation phase, wherein the selected network participant is the network participant from the plurality of the network participants that provides a first enquiry data packet response containing a specific protocol stage trigger packet, and wherein the specific protocol stage trigger packet enables the switching of the network filter from the selection state to the operation state;
create, during the operation phase, a network data pathway between the first network participant and the selected network participant;
prohibit, during the operation phase, further creation of a further network data pathway between the first network participant and any unselected network participant; and
prohibit, during the operation phase, the first network participant from transferring over the network any further enquiry data packets to any unselected network participants.
28 . A network filter according to claim 27 , further configured to create a network data pathway between the first network participant and the other network participant providing a first data packet response to be received by the first network participant.
29 . A network filter according to claim 27 , wherein the computer executable instructions specify a predetermined protocol sequence to be implemented.
30 . A network filter according to claim 27 , wherein the network data pathway comprises a secure VPN tunnel enabling a data connection between the first network participant and the selected network participant.
31 . A network filter according to claim 27 , comprising a timing means for determining a cool-down period of the network data pathway.
32 . A network filter according to claim 31 , comprising a reset mechanism to revert the network filter back to a selection phase in the case that the timing means indicates that the predetermined cool-down period has been exceeded.
33 . A network filter according to claim 31 , comprising a reset mechanism to revert the network filter back to a selection phase on receipt of a termination trigger.
34 . A network filter according to claim 33 , wherein the termination trigger comprises a signal from the first network participant or determination that the selected network participant is untrusted.
35 . A network filter according to claim 27 , comprising a comparator for comparing the enquiry data with predetermined selection criteria and for outputting a comparison output.
36 . A network filter according to claim 35 , wherein the computer executable instructions are further executable by the at least one processing unit to cause the network filter to:
configure the passage or block the enquiry data response in dependence upon the comparison output.
37 . An electronic device comprising a network filter according to claim 27 .
38 . A server comprising a network filter according to claim 27 .
39 . A network communications gateway comprising a network filter according to claim 27 .
40 . A network comprising a network filter according to claim 27 .