IP Library › Granted Patent US 7,827,292
Granted Patent B2
US 7,827,292 · App. 09/911,061 · Granted Nov 2, 2010

Flexible automated connection to virtual private networks

Assignee: AT&T Intellectual Property II, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,827,292
App. No.
09/911,061
Granted
Nov 2, 2010
Kind
B2
Abstract

A network interface unit is provided for use intermediate a LAN and a public or private network, or a combination of both, for establishing secure links to a VPN gateway. Login by a LAN client with the network interface unit, addressing, authentication, and other configuration operations achieved using a web page-based GUI are applied in establishing tunnels from LAN clients to desired VPN destinations. Illustrative network interface units include a DHCP server and provide encryption-decryption and encapsulation-decapsulation of data packets for communication with VPN nodes. Configuration and connection of a client are further enhanced by a built-in DNS server and other functional servers to provide a high degree of autonomy in establishing connections to a desired VPN gateway via an ISP or other public and/or private network links to. The interface unit then performs required authentication exchanges, and required encryption key exchanges.

Claims (16)

1. A method practiced at a network interface unit (NIU) directly connected to at least one local area network (LAN), said NIU also being connected to a non-secure node of a second network, which second network is in packet communication with at least one access node of a secure virtual private network (VPN), the method comprising

receiving data packets from at least one device on said at least one LAN,

multiplexing said data packets into at least one packet data stream,

modifying said at least one packet data stream in a security server in said NIU in accordance with a secure communications protocol by encrypting packets in said at least one packet data stream and encapsulating resulting encrypted packets, and

providing network destination address information from a Domain Name System (DNS) server for at least selected ones of said at least one packet data stream.

2. The method of claim 1 wherein said modifying said at least one packet data stream in a security server comprises modifying said at least one packet data stream in an Internet Protocol security (IPsec) server.

3. The method of claim 2 further comprising

receiving at least one stream of data packets from said non-secure network,

filtering out packets in said at least one stream of received data packets that are not from said VPN network, said filtering being performed by a firewall in said security server, said filtering producing at least one filtered stream of received data packets,

modifying said packets in said at least one filtered stream of received data packets by decrypting said packets in said at least one filtered stream of received data packets and decapsulating resulting decrypted packets to produce decapsulated decrypted packets, said decrypting and decapsulating being performed by said security server,

demultiplexing at least one stream of decapsulated decrypted received data packets to form at least one demultiplexed stream of said received data packets for delivery to said at least one LAN.

4. The method of claim 3 further comprising

authenticating client devices on said at least one LAN, and

wherein packets from authenticated client devices on said at least one LAN that are received at said network interface device are processed as packets received from said VPN.

5. The method of claim 1 wherein said non-secure node of a second network is part of said NIU.

6. The method of claim 5 wherein said at least selected ones of said at least one packet data stream are applied to said non-secure node of said second network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2010
From: AT&T PROPERTIES, LLC, A NEVADA LIMITED LIABILITY COMPANY
To: AT&T INTELLECTUAL PROPERTY II, L.P., A NEVADA LIMITED PARTERSHIP
Reel/Frame 024473/0727 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2010
From: AT&T CORP., A NEW YORK CORPORATION
To: AT&T PROPERTIES, LLC, A NEVADA LIMITED LIABILITY COMPANY
Reel/Frame 024473/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2001
From: CHEN, YIHSIU; FOLADARE, MARK JEFFREY; GOLDMAN, SHELLEY B.; KILLIAN, THOMAS JOSEPH; SCHRYER, NORMAN LOREN; STONE, KEVIN; WEBER, ROY PHILLIP
To: AT&T CORP.
Reel/Frame 012048/0899 →
Continuity (1)
Related Publication 20030028650A1 · Feb 6, 2003