System and method for highly secure data communications
Claim Score by NHIP
Abstract
A system and method for highly secure data communication. Embodiments of the invention may include encrypting data a first time, packetizing the data, encrypting the data a second time and transmitting the data. Encryption may occur at a data link layer and an Internet Protocol layer. Packetized, twice encrypted data may be transmitted over a network, such as, for example, the Internet. The system may include a first computer system containing data for transmission, a first interface device that receives data from the first computer system, a second interface device that receives data from the first interface device, and a second computer system that receives data from the second interface device.

Term
Term ended
Projected expiry passed 3 April 2023, 3.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
55 claims: 7 independent, 48 dependent
- 1A method for securely transmitting data comprising:obtaining data on a computer system for transmission;encrypting the data a first time such that the data is once encrypted;packetizing the once encrypted data;encrypting the packetized, once encrypted data a second time such that the data is twice encrypted;and transmitting the packetized, twice encrypted data.
- 14A method for securely receiving data comprising:receiving packetized, twice encrypted data;decrypting the packetized, twice encrypted data a first time such that the packetized data is once decrypted;reconstructing the packetized, once decrypted data;and decrypting the reconstructed, once decrypted data a second time.
- 27A method for securely transmitting and receiving data comprising:obtaining data on a first computer system for transmission;encrypting the data a first time such that the data is once encrypted;transmitting the once encrypted data from the first computer system to a first interface device;receiving the once encrypted data at the first interface device;packetizing the once encrypted data;encrypting the packetized, once encrypted data a second time such that the data is twice encrypted;and transmitting the packetized, twice encrypted data from the first interface device to a second interface device;receiving packetized, twice encrypted data at the second interface device;decrypting the packetized, twice encrypted data a first time such that the packetized data is once decrypted;reconstructing the packetized, once decrypted data;transmitting the reconstructed, once decrypted data from the second interface device to a second computer system;receiving the reconstructed, once decrypted data at the second computer system;and decrypting the reconstructed, once decrypted data a second time.
- 36A system for securely transmitting and receiving data comprising:a first computer system for encrypting and transmitting data, the first computer system having a transmission mechanism;a first interface device for receiving once encrypted data from the first computer system, and for packetizing, encrypting and transmitting data, the first interface device having a receiving mechanism and a network connection;a second interface device for receiving twice encrypted data from the first interface device, and for decrypting, reconstructing and transmitting data, the second interface device having a network connection and a transmission mechanism;and a second computer system for receiving once decrypted data from the second interface device and for decrypting data, the second computer system having a receiving mechanism, wherein the first computer system once encrypts data and transmits the once encrypted data to the first interface device via the transmission mechanism of the first computer system, and wherein the first interface device receives the once encrypted data via the receiving mechanism of the first interface device, packetizes the once encrypted data, encrypts the once encrypted data and transmits twice encrypted data to the second interface device via a network, and wherein the second interface device receives the twice encrypted data from the first interface device via a network, once decrypts the twice encrypted data, reconstructs the packetized data and transmits reconstructed, once decrypted data to the second computer system via the transmission mechanism of the second interface device, and wherein the second computer system receives once decrypted data from the second interface device via the receiving mechanism of the second computer system and decrypts again the once decrypted data.
- 42Broadest claimClaim Score 92, very broad(NHIP)A method for transmitting secure data comprising:encrypting the data at a data link layer;packetizing the data;encrypting the packetized data at an Internet Protocol layer;and transmitting the packetized, encrypted data over a network.
- 44A method for transmitting secure data comprising:encrypting the data at an Internet Protocol layer;further encrypting the encrypted data at a data link layer;and transmitting the data over a communication link.
- 50A method for receiving secure data comprising:receiving the data over a communication link;decrypting the data at a data link layer;and further decrypting the decrypted data at an Internet Protocol layer.
Independent claims7
69 paragraphs in 5 sections, as filed
RELATED APPLICATION
[0001] The present invention relates to U.S. Provisional Patent Application No. 60/201,579, filed May 1, 2000, which is incorporated herein by reference in its entirety and from which priority is claimed.
BACKGROUND
[0002] 1. Field of the Invention
[0003] The present invention relates to the field of data communications. Particular embodiments of the invention relate to systems and methods for transmitting highly secure data over public and private communication networks.
[0004] 2. Related Art
[0005] The continually increasing reliance by the commercial, industrial, military and government markets on data transmission over public and private communication networks has resulted in a continually increasing requirement that such transmission be secure. Because data that is transmitted over a network can easily be intercepted, personal, confidential and classified information can easily be compromised and used improperly and illegally absent a secure means of transmitting such information.
[0006] Commercial activity over networks such as the Internet frequently involve the transmission of confidential data such as credit card numbers, social security numbers and the like. Unfortunately, transmitted confidential data can be and is frequently compromised by the interception of such data by unscrupulous network users, typically resulting in serious financial and emotional detriment to the victim.
[0007] Likewise, data transmission activities in the industrial sector also require transmissions that are secure. Industrial espionage in the United States results in losses totaling billions of dollars each year for American businesses. Industrial enterprise operates at a distinct disadvantage due to the illegal interception of proprietary data transmitted over public and private communication networks, ultimately resulting in decreased corporate profits and corporate viability.
[0008] The requirement for secure transmission of data in military and government intelligence operations cannot be overemphasized. Indeed, considering the ever-present threat of aggression by foreign military establishments against United States allies and the United States itself, along with the constant and crippling threat of terrorism nationally and abroad, the security of the United States and other countries is threatened and well at risk by the transmission of sensitive or classified information in an unsecure manner.
[0009] The requirement for secure data transmission over communication networks has prompted the development of various systems and methods that attempt to satisfy such requirements. One such attempt is to implement a private data communication link or network as shown in FIG. 1. A private data communication link or network may be implemented to securely transmit data by utilizing a dedicated line of communication <b>6</b>. The dedicated line of communication may be interconnected between a first computer <b>2</b> and a second computer <b>4</b>, each implementing a standard network protocol <b>2</b>A, <b>4</b>A to facilitate data transmission over the dedicated line of communication <b>6</b>. This approach has the advantage that only those persons or organizations that have access to the dedicated communication line <b>6</b> may access data being transmitted across it. Consequently, this approach to data communications is very easy to manage. However, a dedicated line is expensive compared to public networks such as the Internet, and such expense may become cost prohibitive even for organizations with abundant resources.
[0010] Other attempts for providing secure transmission of data over communication networks implement data encryption prior to transmission over a public network. Protocols such as the Secure Sockets Layer (SSL) and Secure HTTP (S-HTTP), an extension to the ubiquitous HTTP, have become widely used for transmitting information over the Internet. Use of the Internet for the transmission of confidential or sensitive information has given rise to the Virtual Private Network (VPN), a network constructed using the Internet to connect various nodes through which encrypted data is transmitted using IP Security (IPSec), a set of protocols supporting the secure exchange of packets at the IP layer. Although such protocols currently provide high levels of security (some supporting 128-bit encryption and higher), the rapid advances in processing technology will soon make such protocols easy to compromise. Furthermore, the aforementioned protocols do not prevent a hacker from determining that data is being transmitted and, possibly, observing how much data is being transmitted, which information may be valuable in itself. Accordingly, such protocols can provide only limited security.
[0011] Clearly, the commercial, industrial, military and government markets currently face a shortage of increasingly secure, cost-effective systems and methods of data transmission. Thus, the need for such systems and methods remains critical.
SUMMARY
[0012] A method for securely transmitting and receiving data according to an embodiment of the present invention may comprise obtaining data on a first computer system for transmission. The data may be encrypted a first time such that the data is once encrypted. Subsequently, the first computer system may transmit the once encrypted data to a first interface device. The first interface device may receive the once encrypted data, packetize it, and encrypt the packetized, once encrypted data a second time such that the data is then twice encrypted. The first interface device may then transmit the packetized, twice encrypted data to a second interface device.
[0013] The second interface device may receive the packetized, twice encrypted data and decrypt it and reconstruct, or depacketize, the data such that the data is then once decrypted and reconstructed. The second interface device may then transmit the reconstructed, once decrypted data to a second computer system. The second computer system may receive the reconstructed, once decrypted data and decrypt the reconstructed, once decrypted data a second time such that it is then available for use.
[0014] Data encrypted a first time may be encrypted at a data link layer. Such data link layer encrypted data may be transmitted and received using a modem. Data encrypted a second time may be encrypted at an Internet Protocol layer. Packetized, twice encrypted data may be transmitted and received over a network using a network interface card. The network may be the Internet.
[0015] Data decrypted a first time may be decrypted at an Internet Protocol layer. Data decrypted a second time may be decrypted at a data link layer.
[0016] A system for securely transmitting and receiving data may include a first computer system for encrypting and transmitting data. The first computer system may have a transmission mechanism such as a modem. The system may also include a first interface device for receiving once encrypted data from the first computer system, and for packetizing, encrypting and transmitting data. The first interface device may have a receiving mechanism, such as a modem, and a network connection utilizing a network interface card.
[0017] The system may also include a second interface device for receiving twice encrypted data from the first interface device, and for decrypting, reconstructing and transmitting data. The second interface device may a network connection utilizing a network interface card and a transmission mechanism such as a modem.
[0018] The system may also include a second computer system for receiving once decrypted data from the second interface device and for decrypting data. The second computer system may also have a receiving mechanism such as a modem.
[0019] The first computer system may once encrypt data and transmit the once encrypted data to the first interface device via the transmission mechanism of the first computer system. The first interface device may receive the once encrypted data via the receiving mechanism of the first interface device, packetize the once encrypted data, encrypt the once encrypted data and transmits twice encrypted data to the second interface device via a network. The network may be the Internet.
[0020] The second interface device may receive the twice encrypted data from the first interface device via the network, once decrypt the twice encrypted data, reconstruct the packetized data and transmit reconstructed, once decrypted data to the second computer system via the transmission mechanism of the second interface device. The second computer system may receive once decrypted data from the second interface device via the receiving mechanism of the second computer system and decrypt the once decrypted data a second time.
[0021] A method for securely transmitting data according to an embodiment of the present invention may also packetize data, encrypt data at an Internet Protocol layer, encrypt data again at a data link layer, and transmit the data over a communication link.
BRIEF DESCRIPTION OF THE DRAWINGS
[0022] These and other features, aspects, and advantages of the present invention will become better understood when viewed in light of the accompanying drawings where:
[0023]FIG. 1 is a block diagram of a prior art system for transmitting data.
[0024]FIG. 2 is a block diagram of a system for securely transmitting data according to an embodiment of the present invention.
[0025]FIG. 3 is a block diagram of a network model for securely transmitting data according to an embodiment of the present invention.
[0026]FIG. 4A is a block diagram of an Open System Interconnection reference model.
[0027]FIG. 4B is a block diagram of a network model according to a TCP/IP protocol stack.
[0028]FIG. 5 is a flow chart of a general method for securely transmitting data according to an embodiment of the present invention.
[0029]FIG. 6 is a flow chart of a method for securely transmitting and receiving data according to an embodiment of the present invention.
[0030]FIG. 7 is a block diagram of data as data is prepared for transmission over a packet switched network according to an embodiment of the present invention.
[0031]FIG. 8 is a block diagram of a system with multiple users and a remote access security according to an embodiment of the present invention.
[0032]FIG. 9 is a block diagram of a system for securely transmitting data according to an embodiment of the present invention.
[0033]FIG. 10 is a flow chart of a method for securely transmitting data according to an embodiment of the present invention.
[0034]FIG. 11 is block diagram of a network model for securely transmitting data according to an embodiment of the present invention.
DETAILED DESCRIPTION
[0035] A block diagram of a system according to an embodiment of the present invention is shown in FIG. 2. Generally, a first computer system <b>10</b> containing data for transmission comprises a first modem <b>12</b> or other mechanism for the transmission of data to a first interface device <b>16</b> over a transmission medium <b>14</b>. The first computer system <b>10</b> may also include a mechanism for encrypting data. The first modem <b>12</b> may also be used by the first computer system <b>10</b> to receive data.
[0036] The first interface device <b>16</b> connects to the transmission medium <b>14</b> via a second modem <b>18</b> or other mechanism such that it may receive data from the first computer system <b>10</b>. The first interface device <b>16</b> may also interface to a packet switched network <b>22</b>, such as, for example, the Internet, utilizing, for example, a network interface card (NIC) <b>20</b>, which may have an Ethernet connection. The packet switched network <b>22</b> may be implemented in a variety of ways, and may be a wired or wireless network. The interface <b>20</b> to the packet switched network <b>22</b> may be used to transmit data to a second interface device <b>24</b>. The first interface device <b>16</b> may include a mechanism for packetizing and encrypting data. The first interface device <b>16</b> may also receive information from the second interface device <b>24</b> and transmit data to the first computer system <b>10</b>.
[0037] The second interface device <b>24</b> may also interface to the packet switched network <b>22</b> utilizing, for example, a NIC <b>26</b> and an Ethernet connection such that it may receive data transmitted from the first interface device <b>16</b> . The second interface device <b>24</b> may also comprise a third modem <b>28</b> or other transmission mechanism for the transmission of data to a second computer system <b>32</b> over a transmission medium <b>30</b>. The second interface device <b>24</b> may also include a mechanism for decrypting data and reconstructing, or depacketizing, data. The third modem <b>28</b> may also be used by the second interface device <b>24</b> to receive data from the second computer system <b>32</b>. Additionally, the second interface device <b>24</b> may transmit data to the first interface device <b>16</b> via its interface <b>26</b> to the packet switched network <b>22</b>.
[0038] The second computer system <b>32</b> comprises a fourth modem <b>34</b> or other mechanism for receiving data from the second interface device <b>24</b> over a transmission medium <b>30</b>. The second computer system <b>32</b> may also include a mechanism for decrypting data. The fourth modem <b>34</b> may also be used by the second computer system <b>32</b> to transmit data.
[0039] Examining FIG. 2 in more detail, the first computer system <b>10</b> may be a single computer containing a processor, memory, input and output, and other functions common to computer systems. Alternatively, the first computer system <b>10</b> may be a network of computers arranged in a variety of fashions. For example, the first computer system <b>10</b> may be arranged in a client-server fashion, wherein a server computer functions as a system controller for one or more client computers. The server computer and the client computers may be connected via a local area network (LAN).
[0040] The first modem <b>12</b> or other mechanism used to transmit data from the first computer system <b>10</b> to the first interface device <b>16</b> may also serve as a data encryption device as well as a modulator. Thus, the data may be encrypted at the first computer system <b>10</b> using the first modem <b>12</b>. Alternatively, the data encryption device may be independent of the first modem <b>12</b>. The transmission medium <b>14</b> over which the first computer system <b>10</b> transmits data may be a public switched telephone network (PSTN) or other type of dedicated communication link, such as an Integrated Services Data Network (ISDN) line, a Digital Subscriber Line (DSL), a T-1 line, a dedicated wireless connection or the like.
[0041] The first interface device <b>16</b> may also be a single computer containing a processor, memory, input and output, and other functions common to computer systems. Alternatively, the first interface device <b>16</b> may also be a network of computers arranged in a variety of fashions or may simply be a dedicated processing system functioning solely to packetize and encrypt a second time data received from the first computer system <b>10</b> and transmit the packetized, twice encrypted data to the second interface device <b>24</b> via the packet switched network <b>22</b>.
[0042] The second interface device <b>24</b> may be similar to the first interface device <b>16</b> and may be a single computer containing a processor, memory, input and output, and other functions common to computer systems or may be a network of computers arranged in a variety of fashions. Alternatively, the second interface device <b>24</b> may simply be a dedicated processing system functioning solely to decrypt and reconstruct packetized, encrypted data received from the first interface device <b>16</b> and transmit such data to the second computer system <b>32</b> via a modem <b>28</b> or other transmission mechanism. The transmission medium <b>30</b> over which the second interface device <b>24</b> sends data to the second computer system <b>32</b> may also be a PSTN. Alternatively, the transmission medium <b>30</b> may be another type of dedicated communication link, such as ISDN, DSL, T-1, a dedicated wireless connection or the like.
[0043] The second computer system <b>32</b> may be similar to the first computer system <b>10</b> and may be a single computer containing a processor, memory, input and output, and other functions common to computer systems. Alternatively, the second computer system <b>32</b> may be a network of computers arranged in a variety of fashions. For example, the second computer system <b>32</b> may be arranged in a client-server fashion, wherein a server computer functions as a system controller for one or more client computers. The server computer and the client computers may be connected via a LAN.
[0044] The fourth modem <b>34</b> or other mechanism used by the second computer system <b>32</b> to receive transmitted data from the second interface device <b>24</b> may also serve as a data decryption device as well as a demodulator. Thus, the data may be decrypted at the second computer system <b>32</b> using the fourth modem <b>34</b>. Alternatively, the data encryption device may be independent of the fourth modem <b>34</b>. The transmission medium <b>30</b> over which the second computer system <b>32</b> receives data may be a PSTN or other type of dedicated communication link, such as ISDN, DSL, T-1 or the like.
[0045] A block diagram according to an embodiment of the present invention using a network model may be seen in FIG. 3. For purposes of elucidation, the Open Systems Interconnection (OSI) reference model <b>50</b> is shown in FIG. 4A. The OSI reference model <b>50</b> is well-known in the art and will be described here only briefly. The OSI reference model <b>50</b> is a conceptual model and describes how data in one computer is transferred through a network to another computer, i.e., it provides a framework for communication between computers over a network. The OSI reference model <b>50</b> comprises seven layers, each layer specifying a function of the network. As shown in FIG. 4A, the OSI reference model <b>50</b> comprises an application layer (layer <b>7</b>) <b>52</b>, a presentation layer (layer <b>6</b>) <b>54</b>, a session layer (layer <b>5</b>) <b>56</b>, a transport layer (layer <b>4</b>) <b>58</b>, a network layer (layer <b>3</b>) <b>60</b>, a data link layer (layer <b>2</b>) <b>62</b>, and a physical layer (layer <b>1</b>) <b>64</b>.
[0046] Data that is transferred from a software application in one computer (i.e., at the application layer <b>52</b>) to another computer must pass through each layer of the OSI reference model <b>50</b>. For example, if a document created in a word processing application on one computer were to be transferred to another computer, the word processing application would transfer the data corresponding to the document to the presentation layer <b>54</b>, which would in turn transfer the data to the session layer <b>56</b>, and so on, until the data is transferred to the physical layer <b>64</b>, i.e., the actual physical medium, such as cables and wires, used to transfer data. The receiving computer would receive the data at the physical layer <b>64</b> and transfer the data up through the OSI reference model <b>50</b> layers until the data exists as a document in the word processing application on the receiving computer.
[0047] The data link layer <b>62</b> provides network and protocol characteristics for the transmission of data across a physical network link. Specifications for the data link layer <b>62</b> may define physical addressing, network topology, error notification, flow control and other network and protocol characteristics. The data link layer <b>62</b> may also manage access to the physical medium through the physical layer. The network layer <b>60</b> provides functions such as routing that enable multiple links to be combined into a network.
[0048] The application layer <b>52</b>, presentation layer <b>54</b> and session layer <b>56</b> are sometimes referred to as the upper layers and are usually implemented only in software. The transport layer <b>58</b>, network layer <b>60</b>, data link layer <b>62</b> and physical layer <b>64</b> are sometimes referred to as the lower layers and are typically implemented in hardware and software.
[0049] A suite of communication protocols widely in use today for transmitting information over networks such as the Internet is commonly referred to as Transmission Control Protocol/Internet Protocol (TCP/IP). A simplified TCP/IP protocol stack <b>70</b> is shown in FIG. 4B. TCP/IP is well-known in the art and will not be described here. The simplified TCP/IP protocol stack <b>70</b> shown in FIG. 4B has four layers—an application layer <b>72</b>, a transport layer <b>74</b>, an Internet layer <b>76</b> and a network interface layer <b>78</b>. Various aspects of a TCP/IP protocol stack <b>70</b> may roughly be mapped to the OSI reference model <b>50</b>. In particular, the Internet layer <b>76</b>, or the Internet Protocol (IP) layer of the TCP/IP protocol stack <b>70</b>, may provide functions that are roughly similar to the OSI reference model <b>50</b> network layer <b>60</b>. Accordingly, the terms “network layer” and “IP layer” may be used interchangeably throughout this application.
[0050] Referring back to FIG. 3, data may be encrypted at a data link layer <b>40</b>A of a first computer <b>10</b> and transmitted via a modem or other transmission mechanism to a first interface device <b>16</b>. At the first interface device <b>16</b>, the data is packetized according to standard TCP/IP protocols and further encrypted at the network or IP layer <b>42</b>A. Encryption at the data link layer <b>40</b>A may be effected using any data link layer encryption mechanism, including, without limitation, devices implementing data link layer encryption techniques currently available on the market such as the Mykotronx PALLADIUM or KIV-7 or the Cylink LINK ENCRYPTOR. Encryption at the network or IP layer <b>42</b>A may be effected using any IP layer encryption technique, such as, for example, an Internet Protocol (IP) packet encryption method such as IPSec. Algorithms that may be used to encrypt data at both the data link and IP layers include, without limitation, the DATA ENCRYPTION STANDARD (DES), TRIPLE DES, the ADVANCED ENCRYPTION STANDARD (AES), SKIPJACK and BLOWFISH.
[0051] Once data has been packetized and encrypted at the IP layer, it may be sent out over a packet switching network <b>22</b>, such as, for example, the Internet, where it is retrieved by a second interface device <b>24</b> that decrypts the data at the IP layer <b>42</b>B using an IP layer decrypting algorithm that is the reverse of the encrypting algorithm used by the first interface device <b>16</b> to encrypt the data. The data, which at this stage of the transmission is no longer IP layer encrypted but only data link layer encrypted, is then reconstructed, or depacketized, and then transmitted to a second computer <b>32</b> where it is decrypted at the data link layer <b>40</b>B using a data link layer decrypting algorithm that is the reverse of the encrypting algorithm used by the first computer <b>10</b> to encrypt the data. At this stage, the data is no longer encrypted and is available for use by a user.
[0052] A flow chart showing a general method for securely transmitting data according to embodiments of the present invention is shown in FIG. 5. Data that requires secure transmission may be encrypted at the data link layer at step <b>80</b>. Subsequently, the data link-encrypted data may be packetized at step <b>82</b> such that it is suitable for transmission over a packet switching network, such as, for example, the Internet. Next, the packetized data may be IP layer encrypted at step <b>84</b>, and then transmitted over the Internet or other packet switched network at step <b>86</b>.
[0053] A flow chart showing a more detailed method for securely transmitting and receiving data according to embodiments of the present invention is shown in FIG. 6. At step <b>90</b>, data to be securely transmitted is obtained. The data may be obtained by a first computer or computer system. Once obtained, the data is encrypted at a data link layer at step <b>92</b>. The data may be encrypted using any encryption algorithm according to the needs of a user. For example, algorithms that are typically used for encryption at a data link layer include, but are not limited to, DES, TRIPLE DES, AES, SKIPJACK and BLOWFISH.
[0054] Once the data has been encrypted at a data link layer, the data may be transmitted to a first interface device over a transmission medium at step <b>94</b>. The data link encrypted data may be transmitted using a modem over a dedicated line, such as, for example, lines used in a conventional telephone system. The data link encrypted data may then be received by the first interface device using a modem at step <b>96</b>.
[0055] Once the data link encrypted data has been received by the first interface device, it may be wrapped, i.e., it may be packetized at step <b>98</b> and encrypted again at an IP layer at step <b>100</b>. Subsequently, wrapped data, or, in other words, the packetized, twice encrypted data, may be transmitted to a second interface device over a packet switching network, such as the Internet at step <b>102</b>. In this way, embodiments of the present invention may implement VPNs to transmit data.
[0056] Once transmitted, the packetized, twice encrypted data may be received by the second interface device connected to the packet switched network at step <b>104</b> and the process may be reversed, or unwrapped. At step <b>106</b>, the packetized, twice encrypted data is IP decrypted. The packets are then reconstructed at step <b>108</b>, then transmitted over a dedicated line at step <b>110</b>. The second interface device may transmit the reconstructed, once decrypted data using a modem. It is understood that the data at this point may also be referred to again as once encrypted data, since decrypting a first time data that has been encrypted twice results in data that is again encrypted only once. However, for consistency, twice encrypted data that has been decrypted once will be referred to once decrypted data.
[0057] Subsequently, the reconstructed, once decrypted data is received by a second computer or computer system at step <b>112</b>. The second computer or computer system may also use a modem for receiving the reconstructed, once decrypted data. The second computer or computer system then decrypts the reconstructed, once decrypted data at step <b>114</b>, making it available in an unencrypted form for a user.
[0058] The nature of the data according to embodiments of the present invention as data is prepared for transmission over a packet switched network may be seen in FIG. 7. Unencrypted, continuous data <b>120</b> is encrypted a first time to become once encrypted, continuous data <b>122</b>. After the first encryption, the once encrypted, continuous data is divided into portions, or is packetized, such that it becomes once encrypted, packetized data <b>124</b> suitable for transmission over a packet switching network. The packetized data may then be appended and prepended with a trailer and header <b>126</b>, respectively, consistent with TCP/IP, such that it may be suitable for transmission over the Internet. The once encrypted, packetized data is then encrypted again such that it becomes twice encrypted, packetized data <b>128</b>. The second encryption process may utilize IPSec protocols, which may prepend to each packet an IP header and, for example, an Encapsulated Secure Payload (ESP) header and append to each packet a standard ESP trailer as well as an ESP authentication trailer. The packetized, twice encrypted data may then be distributed over a packet switched network such as, for example, the Internet.
[0059] A block diagram of a system according to an embodiment of the present invention implementing multiple users and a remote access server (RAS server) may be seen in FIG. 8. Any number of users <b>130</b>, <b>132</b> as well as email servers <b>134</b>, network servers <b>136</b> and the like may be connected to a LAN <b>138</b>. The LAN <b>138</b> may also have a connection to a RAS server <b>140</b> to allow users at a remote location to interface with devices on the LAN <b>138</b>. The RAS server <b>140</b> may contain any number of modems <b>142</b> or other devices allowing for a point-to-point or dedicated connection. The individual modems <b>142</b> in the RAS server <b>140</b> may be merged or concentrated into a modem concentrator <b>144</b>. The modem concentrator <b>144</b> administrates the transmission of data from multiple modems. The modem concentrator <b>144</b> may interface to a dedicated communication link <b>146</b> such as, for example, PSTN lines, ISDN lines, DSL lines or T-1 lines.
[0060] The dedicated communication link may interface to a VPN server <b>148</b>. The VPN server <b>148</b> may then wrap the data, i.e., packetize and IP encrypt the data, received from the RAS server <b>140</b> and transmit the data over a packet switched network <b>22</b> such as, for example, the Internet. The wrapped data may then be received from the packet switched network <b>22</b> by a second VPN server <b>152</b>. The second VPN server <b>152</b> may then “unwrap” the data and transmit it via a dedicated line <b>154</b> using a modem <b>156</b> or other mechanism to a remote client <b>158</b>.
[0061] The remote client <b>158</b> may be a portable computer or other portable computing device and may contain a modem <b>160</b> for receiving the unwrapped data from the second VPN server <b>152</b>. The remote client <b>158</b> may then data link decrypt the data such that the data is then completely unencrypted and available for use. Alternatively, if there are several remote clients, the second VPN server <b>152</b> may transmit data to a second modem concentrator and then to individual modems in the remote client computers.
[0062] A block diagram according to another embodiment of the present invention is shown in FIG. 9. Any number of users <b>170</b>, <b>172</b> as well as email servers <b>174</b>, network servers <b>176</b> and the like may be connected to a LAN <b>178</b>. The LAN <b>178</b> may also have a connection to RAS server <b>180</b> to allow a user or users at a remote location to interface with devices on the LAN <b>178</b>. The RAS server <b>180</b> may contain any number of modems <b>182</b> or other devices allowing for a point-to-point or dedicated connection. The individual modems <b>182</b> in the RAS server <b>180</b> may be merged or concentrated into a modem concentrator <b>184</b>. The modem concentrator <b>184</b> may interface to a dedicated communication link <b>186</b> such as, for example, PSTN lines, ISDN lines, DSL lines or T-1 lines. The dedicated communication link may interface to a server <b>187</b> which in turn interfaces to a RAS client <b>188</b>. The RAS client <b>188</b> may be a laptop or other portable computing device.
[0063] A flowchart detailing a method of operation for an embodiment of the present invention shown in FIG. 9 is shown in FIG. 10. Data for secure transmission is obtained at step <b>190</b>. Such data may be generated by a user or may be the result of email server, network server or other operations within the LAN. The data is then encrypted at an IP layer by the RAS server at step <b>192</b> using any encryption algorithm suitable to a user, such as, for example, DES, TRIPLE DES, AES, SKIPJACK and BLOWFISH. Alternatively, the data may be encrypted at an IP layer by a network client or a VPN server. Subsequent to IP encryption, the data is then encrypted again at a data link layer by the RAS server at step <b>194</b>, again using any encryption algorithm suitable to a user, which may be the same as or different than the algorithm used for encryption at the IP layer.
[0064] Once the data has been encrypted at the data link layer, the data may be transmitted from the RAS server via a modem or other transmission mechanism to a modem concentrator at step <b>196</b>. The modem concentrator may then transmit the twice encrypted data over a dedicated communication link at step <b>198</b>. The twice encrypted data may be received by a RAS client using a modem at step <b>200</b>.
[0065] Once received by the RAS client, the data is first decrypted at the data link layer at step <b>202</b>, then decrypted again at the IP layer at step <b>204</b>. After decryption at the IP layer, the data is available for use by the remote user.
[0066] Embodiments of the present invention may also utilize tokens, keys, certificates or other authenticating mechanism to implement secure transmissions. For example, a user according to the embodiment of FIG. 9 may be required to enter an authenticating mechanism before being allowed access to the system. The authenticating mechanism may be used to verify that the user is the person that the user claims to be. Such authenticating mechanisms are used frequently in the art, especially in relation to the Internet. For example, a protocol known as Internet Security Association and Key Management Protocol/Oakley (ISAKMP/Oakley) allows a server to obtain a public key to authenticate a user using digital certificates.
[0067] A block diagram according to an embodiment of the present invention using a network model may be seen in FIG. 11. In this embodiment, data may be first encrypted at a data link layer <b>210</b> in a system. Subsequently, the data link encrypted data may be routed back into the computer system where it may then be packetized and encrypted at the IP layer <b>212</b>.
[0068] Subsequent to packetizing and IP encryption, the packetized, twice encrypted data may be transmitted over a packet switched network. Such data may be received by a user over the packet switched network and the foregoing process may be reversed such that the data is available for use.
[0069] While particular embodiments of the present invention have been shown and described, it will be obvious to those skilled in the art that the invention is not limited to the particular embodiments shown and described and that changes and modifications may be made without departing from the spirit and scope of the appended claims.
Contents5
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7594113B2 | Cited by | United States of America | Applicant |
| US6826616B2 | Cited by | United States of America | Search report |
| US9516002B2 | Cited by | United States of America | Search report |
| US8645681B1 | Cited by | United States of America | Search report |
| US2003154286A1 | Cited by | United States of America | Pre-grant |
| US2010067696A1 | Cited by | United States of America | Pre-grant |
| US10511573B2 | Cited by | United States of America | Applicant |
| US10015052B2 | Cited by | United States of America | Search report |
| US7626977B2 | Cited by | United States of America | Search report |
| US2005134155A1 | Cited by | United States of America | Pre-grant |
| US12124563B2 | Cited by | United States of America | Applicant |
| US2008034201A1 | Cited by | United States of America | Pre-grant |
| US2009327695A1 | Cited by | United States of America | Pre-grant |
| US8209750B2 | Cited by | United States of America | Applicant |
| US2002080756A1 | Cited by | United States of America | Pre-grant |
| US6839759B2 | Cited by | United States of America | Search report |
| US7418504B2 | Cited by | United States of America | Applicant |
| US2008216168A1 | Cited by | United States of America | Pre-grant |
| US2017238172A1 | Cited by | United States of America | Search report |
| US7983419B2 | Cited by | United States of America | Search report |
| US2006123134A1 | Cited by | United States of America | Pre-grant |
| US8792626B2 | Cited by | United States of America | Search report |
| US10237730B2 | Cited by | United States of America | Search report |
| US2008005792A1 | Cited by | United States of America | Pre-grant |
| US2009313469A1 | Cited by | United States of America | Pre-grant |
| WO2005020496A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2008301406A1 | Cited by | United States of America | Pre-grant |
| US2010202615A1 | Cited by | United States of America | Pre-grant |
| US2008040791A1 | Cited by | United States of America | Pre-grant |
| US9525666B2 | Cited by | United States of America | Search report |
| US2007165602A1 | Cited by | United States of America | Pre-grant |
| WO2005020496A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9219709B2 | Cited by | United States of America | Search report |
| CN109391609A | Cited by | China | Search report |
| US2016080171A1 | Cited by | United States of America | Pre-grant |
| US8631450B1 | Cited by | United States of America | Search report |
| US7577835B2 | Cited by | United States of America | Applicant |
| US2003031320A1 | Cited by | United States of America | Pre-grant |
| US2005044358A1 | Cited by | United States of America | Pre-grant |
| US7945777B2 | Cited by | United States of America | Applicant |
| US2012084838A1 | Cited by | United States of America | Pre-grant |
| US9860283B2 | Cited by | United States of America | Applicant |
| US2005021949A1 | Cited by | United States of America | Pre-grant |
| US2005058122A1 | Cited by | United States of America | Pre-grant |
| US2009077375A1 | Cited by | United States of America | Pre-grant |
| US7216226B2 | Cited by | United States of America | Search report |
| US2008040783A1 | Cited by | United States of America | Pre-grant |
| US10187387B2 | Cited by | United States of America | Applicant |
| WO2017140759A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2007177578A1 | Cited by | United States of America | Pre-grant |
| US2011238993A1 | Cited by | United States of America | Pre-grant |
| US2009322556A1 | Cited by | United States of America | Pre-grant |
| US2011185053A1 | Cited by | United States of America | Pre-grant |
| US8745373B2 | Cited by | United States of America | Search report |
| US2014304503A1 | Cited by | United States of America | Pre-grant |
| US8295273B2 | Cited by | United States of America | Applicant |
| US2004107286A1 | Cited by | United States of America | Pre-grant |
| US2008222415A1 | Cited by | United States of America | Pre-grant |
| US7707407B2 | Cited by | United States of America | Applicant |
| US7480722B2 | Cited by | United States of America | Search report |
| US9514310B2 | Cited by | United States of America | Applicant |
| US8958416B2 | Cited by | United States of America | Applicant |
| US2003188161A1 | Cited by | United States of America | Pre-grant |
| US2011185169A1 | Cited by | United States of America | Pre-grant |
| US9565469B2 | Cited by | United States of America | Applicant |
| US8090941B2 | Cited by | United States of America | Applicant |
| US9967240B2 | Cited by | United States of America | Applicant |
| US2013340067A1 | Cited by | United States of America | Pre-grant |
| US2011191582A1 | Cited by | United States of America | Pre-grant |
| US7490151B2 | Cited by | United States of America | Applicant |
| US2016156594A9 | Cited by | United States of America | Pre-grant |
| US10257566B2 | Cited by | United States of America | Applicant |
| US7254237B1 | Cited by | United States of America | Applicant |
| US8850179B2 | Cited by | United States of America | Applicant |
| US2004225805A1 | Cited by | United States of America | Pre-grant |
| US9819649B2 | Cited by | United States of America | Applicant |
| US2005060543A1 | Cited by | United States of America | Pre-grant |
| US2004103205A1 | Cited by | United States of America | Pre-grant |
| US2003046402A1 | Cited by | United States of America | Pre-grant |
| US2011167087A1 | Cited by | United States of America | Pre-grant |
| US10362468B2 | Cited by | United States of America | Applicant |
| US2009212971A1 | Cited by | United States of America | Pre-grant |
| US7117280B2 | Cited by | United States of America | Search report |
| US7533259B2 | Cited by | United States of America | Applicant |
| US2005133781A1 | Cited by | United States of America | Pre-grant |
| US2006101273A1 | Cited by | United States of America | Pre-grant |
| US2005060539A1 | Cited by | United States of America | Pre-grant |
| US2003037142A1 | Cited by | United States of America | Pre-grant |
| US2002101989A1 | Cites | United States of America | Pre-grant |
| US5721778A | Cites | United States of America | Pre-grant |
| US6542992B1 | Cites | United States of America | Pre-grant |
| US6697872B1 | Cites | United States of America | Pre-grant |
5 members in 3 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 20157900 | United States of America | P | |
| 20157900 | United States of America | P | |
| 84116801 | United States of America | A | |
| 60201579 | – | – | – |
| US20000201579P | – | – | – |
| US20010841168 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| WO0184797A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU5245201A | Australia | A | |
| US2002004898A1 | United States of America | A1 | |
| WO0184797A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7076651B2 | United States of America | B2 |
48 transactions on the USPTO file
Allowed after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| Payment of Maintenance Fee, 12th Year, Large Entity | |
| Recordation of Patent Grant Mailed | |
| Patent Issue Date Used in PTA CalculationAllowed | |
| Issue Notification MailedAllowed | |
| Dispatch to FDC | |
| Dispatch to FDC | |
| Workflow - Drawings Finished | |
| Application Is Considered Ready for Issue | |
| Issue Fee Payment Verified | |
| Issue Fee Payment Received | |
| Mail Notice of AllowanceAllowed | |
| Mail Examiner's Amendment | |
| Notice of Allowance Data Verification CompletedAllowed | |
| Examiner's Amendment Communication | |
| Date Forwarded to Examiner | |
| Response after Final Action | |
| Request for Extension of Time - Granted | |
| Correspondence Address Change | |
| Change in Power of Attorney (May Include Associate POA) | |
| Correspondence Address Change | |
| Mail Advisory Action (PTOL - 303) | |
| Advisory Action (PTOL-303) | |
| Date Forwarded to Examiner | |
| Response after Final Action | |
| Mail Final Rejection (PTOL - 326)Final rejection | |
| Final RejectionFinal rejection | |
| IFW TSS Processing by Tech Center Complete | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Request for Extension of Time - Granted | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Application Dispatched from OIPE | |
| Application Is Now Complete | |
| Application Is Now Complete | |
| Application Is Now Complete | |
| Oath or Declaration Filed (Including Supplemental) | |
| Notice Mailed--Application Incomplete--Filing Date Assigned | |
| Correspondence Address Change | |
| Correspondence Address Change | |
| IFW Scan & PACR Auto Security Review | |
| Initial Exam Team nn |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Surcharge for late paymentSULP | SULP | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2002004898
- Publication, EPODOC
- US2002004898
- Application
- 9841168
- Application, DOCDB
- 84116801
- Application, EPODOC
- US20010841168
Titles
- English
- System and method for highly secure data communications
Patent term adjustment
- A delay
- +892 daysthe office missed an examination deadline
- Applicant delay
- −183 days
- Net adjustment
- 709 days
Classification
- CPC, 2
- H04L63/0464
- H04L63/0478
- IPC, 1
- H04L29 06
- USPC, 1
- 713151000