EP0887979A2

Method and apparatus for client-host communication over a computer network

Abstract

According to the invention, a method and apparatus are provided for dynamically configuring authorized clients with the address of a protected host and the key and address of an intermediate device (e.g., encrypting firewall, encrypting router, secure gateway) which is protecting a number of hosts on a private network located topologically behind that intermediate device. The registered name server for a domain is configured to return a new resource record type, herein called an SX record, in response to requests for information needed for secure communications with protected hosts in that domain. The resolver on (or otherwise associated with) the authorized client is configured to use the data in the SX record to dynamically update the information used by the client to handle secure communications.

EP0887979A2, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Projected expiry passed 25 June 2018, 8.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

70 claims: 7 independent, 63 dependent

  1. 1
    A method for dynamically updating information used by a first machine for facilitating secure access by said first machine to a second machine, comprising the steps of:(a) receiving a query related to a domain containing said second machine;(b) contacting a first name server for said domain to request information necessary for responding to said query;(c) receiving a first response from said first name server;(d) extracting an identifier of a secure exchanger corresponding to said second machine from a resource record in said first response;and (e) using said identifier, updating a first data structure to be used by said first machine for facilitating secure access to said second machine.
  2. 42
    A method for dynamically updating information used by a first machine for facilitating secure access by said first machine to a second machine, comprising the steps of:(a) obtaining an address of said second machine;(b) using a data structure to be used by said first machine for facilitating secure access to said second machine, determining from said data structure a pre-existing data set containing a pre-existing original database name best matching a name of said second machine;and (c) using said pre-existing data set, storing in a second data set: (i) said address of said second machine, (ii) a pre-existing parameter of a secure exchanger, and (iii) said pre-existing original database name.
  3. 46
    A method for facilitating secure access by a first machine to a second machine, comprising the steps of:(a) receiving, at a first name server, a query from said first machine related to a domain containing said second machine;(b) obtaining an identifier of a secure exchanger corresponding to said second machine;(c) generating a response including said identifier;and (d) transmitting said response for said first machine, said response being usable by said first machine to facilitate secure access to said second machine.
  4. 63
    A system for facilitating secure access by a first machine to a second machine, comprising:(a) control logic configured to receive a query related to a domain containing said second machine;(b) control logic configured to contact a first name server for said domain to request information necessary for responding to said query;(c) control logic configured to receive a first response from said first name server;(d) control logic configured to extract an identifier of a secure exchanger corresponding to said second machine from a resource record in said first response;and (e) control logic configured to use said identifier to update a first data structure to be used by said first machine for facilitating secure access to said second machine, said first data structure to include a data set corresponding to said second machine.
  5. 65
    A computer-readable medium comprising a data structure for facilitating secure access by a first machine to a second machine, said data structure including a tunnel map having:(a) an address of said second machine;(b) a parameter of a secure exchanger corresponding to said second machine;and (c) an original database name pertaining to said secure exchanger.
  6. 69
    A computer-readable medium embodying a software program for facilitating secure access by a first machine to a second machine, said software program comprising:(a) program code configured to receive a query related to a domain containing said second machine;(b) program code configured to contact a first name server for said domain to request information necessary for responding to said query;(c) program code configured to receive a first response from said first name server;(d) program code configured to extract an identifier of a secure exchanger corresponding to said second machine from a resource record in said first response;and (e) program code configured to use said identifier to update a first data structure to be used by said first machine for facilitating secure access to said second machine, said first data structure to include a data set corresponding to said second machine.
  7. 70
    A computer data signal, embodied in a carrier wave, for facilitating secure access by a first machine to a second machine, said data signal comprising:(a) a code segment configured to receive a query related to a domain containing said second machine;(b) a code segment configured to contact a first name server for said domain to request information necessary for responding to said query;(c) a code segment configured to receive a first response from said first name server;(d) a code segment configured to extract an identifier of a secure exchanger corresponding to said second machine from a resource record in said first response;and (e) a code segment configured to use said identifier to update a first data structure to be used by said first machine for facilitating secure access to said second machine, said first data structure to include a data set corresponding to said second machine.