EP2197176A1

Agile network protocol for secure communications with assured system availability

Abstract

A plurality of computer nodes communicate using seemingly random Internet Protocol source and destination addresses. Data packets matching criteria defined by a moving window of valid addresses are accepted for further processing, while those that do not meet the criteria are quickly rejected. Improvements to the basic design include (1) a load balancer that distributes packets across different transmission paths according to transmission path quality; (2) a DNS proxy server that transparently creates a virtual private network in response to a domain name inquiry; (3) a large-to-small link bandwidth management feature that prevents denial-of-service attacks at system chokepoints; (4) a traffic limiter that regulates incoming packets by limiting the rate at which a transmitter can be synchronized with a receiver; and (5) a signaling synchronizer that allows a large number of nodes to communicate with a central node by partitioning the communication function between two separate entities.

EP2197176A1, drawing sheet 1
Sheet 1 of 45

Term

Term ended

Projected expiry passed 12 February 2021, 5.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

5 claims: 1 independent, 4 dependent

  1. 1
    A method of establishing communication between one of a plurality of client computers and a central computer that maintains a plurality of authentication tables each corresponding to one of the client computers, the method comprising the steps of :(1) in the central computer, receiving from one of the plurality of client computers a request to establish a connection ;(2) authenticating, with reference to one of the plurality of authentication tables, that the request received in step (1) is from an authorized client ;(3) responsive to a determination that the request is from an authorized client, allocating resources to establish a virtual private link between the client and a second computer ;and (4) communicating between the authorized client and the second computer using the virtual private link.