Enabling secure network mobile device communications

US9912663B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9912663-B2
Application numberUS-201715427167-A
CountryUS
Kind codeB2
Filing dateFeb 8, 2017
Priority dateJan 31, 2005
Publication dateMar 6, 2018
Grant dateMar 6, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems of communicating with secure endpoints included within a secured network from a mobile device external to the secured network is disclosed. The method includes initiating a VPN-based secure connection to a VPN appliance, and initializing a stealth-based service on the mobile device. The method further includes transmitting user credential information from the mobile device to a VDR broker via the VPN appliance, and receiving status information from the VDR broker identifying a VDR associated with the mobile device and providing a connected status. The method also includes communicating with one or more secure endpoints within the secured network via a VPN connection to the VDR via the VPN appliance and through the VDR to the one or more secure endpoints within a community of interest based on the user credential information transmitted to the VDR broker.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of enabling communication between a mobile device and one or more secure endpoints included within a secured network, the method comprising: receiving user credentials from the mobile device at a virtual data relay (VDR) broker within a gateway; allocating a virtual data relay (VDR) at the gateway; retrieving a wrapping key associated with the VDR; transmitting a tuples request to an authentication server from the VDR broker, the tuples request including the user credentials; receiving from the authentication server, one or more communities of interest (COIs) wrapped with the wrapping key associated with the VDR, the one or more COIs based on the user credentials; and providing configuration information to the VDR. 2. The method of claim 1 , further comprising the VDR opening a license tunnel to a home stealth appliance. 3. The method of claim 1 , further comprising receiving status information from the VDR at the VDR broker. 4. The method of claim 1 , wherein the wrapping key is provided to the VDR broker by the VDR. 5. The method of claim 1 , further comprising returning status information regarding the VDR to the mobile device. 6. The method of claim 1 , further comprising establishing a secured connection between the mobile device and the gateway. 7. The method of claim 6 , wherein the secured connection between the mobile connection and the gateway comprises a virtual private network (VPN) connection established via a VPN appliance. 8. The method of claim 1 , further comprising receiving a tuples XML file from the authentication server in response to the tuples request. 9. A gateway comprising: a programmable circuit; a memory operatively connected to the programmable circuit and storing instructions which, when executed by the programmable circuit, cause the gateway to perform: receiving user credentials from the mobile device at a virtual data relay (VDR) broker within the gateway; allocating a virtual data relay (VDR) at the gateway; retrieving a wrapping key associated with the VDR; transmitting a tuples request to an authentication server from the VDR broker, the tuples request including the user credentials; receiving from the authentication server, one or more communities of interest (COIs) wrapped with the wrapping key associated with the VDR, the one or more COIs based on the user credentials; and providing configuration information to the VDR. 10. The gateway according to claim 9 , wherein the wrapping key is provided to the VDR broker by the VDR. 11. The gateway according to claim 9 , wherein the gateway further receives a tuples XML file from the authentication server in response to the tuples request. 12. The gateway according to claim 9 , wherein the VDR broker includes an authentication manager, a VPN manager, a VDR manager, a client application manager, an event manager, and a license manager. 13. The gateway according to claim 12 , wherein the event manager comprises a VDR table. 14. The gateway according to claim 12 , wherein the VDR manager is configured to manage a pool of available VDRs. 15. The gateway according to claim 12 , wherein the VPN manager is configured to receive client tunnel connection indications from a VPN server. 16. The gateway according to claim 12 , wherein the authentication manager is configured to authenticate the user credentials as being associated with the one or more COIs. 17. The gateway according to claim 12 , wherein the license manager is configured to manage a license tunnel connection to a license gateway. 18. A communication network comprising: the gateway according to claim 9 ; one or more mobile devices communicatively connected to the gateway; and a secure enterprise network comprising a plurality of computing devices, the plurality of computing devices being associated with the one or more communities of interest.

Assignees

Inventors

Classifications

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

  • Wireless resource allocation · CPC title

  • Grouping of entities · CPC title

  • Gateway arrangements · CPC title

  • Virtual private networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9912663B2 cover?
Methods and systems of communicating with secure endpoints included within a secured network from a mobile device external to the secured network is disclosed. The method includes initiating a VPN-based secure connection to a VPN appliance, and initializing a stealth-based service on the mobile device. The method further includes transmitting user credential information from the mobile device t…
Who is the assignee on this patent?
Johnson Robert A, Trocki James, Vallevand Mark K, and 3 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0884. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 06 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).