System and method for automatically initiating and dynamically establishing secure internet connections between a fire-walled server and a fire-walled client

a technology of automatic initiation and dynamic establishment, applied in the field of computer networking and network security, can solve the problems of ipv4 not providing sufficient unique addresses for the current expansion of the internet, the practical limit is much lower, and the number of scalability problems of the internet network, so as to avoid performance and security problems and achieve unprecedented ease of use.

Inactive Publication Date: 2005-10-27
SIMTONE CORP (US)
View PDF56 Cites 94 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Benefits of technology

[0010] In accordance with an embodiment of the present invention, the method and system automatically and dynamically initiates and establishes connections, preferably secured connections, between a server and a fire-walled client device (Client), both connected to an untrusted network (such as the Internet) through a Network Address Translator or Translation (NAT) router or a firewall. The secure connections of present invention are initiated and established without requiring any user configuration on the Client and without accepting any explicit connection request and/or packets from the Client by the Server, thereby advantageously allowing the Server firewall to always remain closed to all inbound traffic.
[0011] The present invention enables the creation of dynamically instantiated virtual point to point network connections over the Internet to securely connect Servers and Clients on demand, thereby advantag

Problems solved by technology

This rapid expansion has increased radically the need for protecting computers from unauthorized access and has already started causing a number of scalability problems for the Internet network itself.
The practical limit however, is much lower, due to inefficiencies in how IP addresses are allocated and routed.
As such, IPv4 does not provide sufficient unique addresses for the current expansion of the Internet.
However, this is a problem for applications that require Servers to securely connect to Clients, through incoming connections going through their NAT routers, such as file sharing, games applications, video conferencing, voice-over-IP internet telephony or for secure access to computer servers that do not allow clients to directly connect to them from the internet.
When one of these computers is behind a NAT ro

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • System and method for automatically initiating and dynamically establishing secure internet connections between a fire-walled server and a fire-walled client
  • System and method for automatically initiating and dynamically establishing secure internet connections between a fire-walled server and a fire-walled client
  • System and method for automatically initiating and dynamically establishing secure internet connections between a fire-walled server and a fire-walled client

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0021] In accordance with an embodiment of the present invention, the system and method automatically and dynamically initiates and establishes connections, preferably secure connections, between a server and a fire-walled client device. Turning now to FIG. 1, there is illustrated a Server 1100 and a client device (Client 1200), both connected to an untrusted network 1000 (such as the Internet) through a Network Address Translator or Translation (NAT) router or a firewall 1300. The connections between the Server and the Client are initiated and established without requiring any user configuration on the Client 1200 and without accepting any explicit connection request and / or packets from the Client 1200 by the Server 1100, thereby allowing the Server firewall 1300 to always remain closed to all inbound traffic.

[0022] In accordance with an embodiment, the present invention utilizes a third computer 1400, e.g., a trusted party such as a session control server (“SCS”), with a public I...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

A system and method for automatically and dynamically initiating and establishing secure connections between a Server and a Client using a session control server (SCS). Both the Server and the Client are connected to an untrusted network (such as the Internet) through a Network Address Translator or Translation (NAT) router or a firewall. The SCS, independently trusted by both the Server and the Client, brokers the required connection parameters to establish a secure connection between the Server and the Client. The system and method does not require any user configuration on the Client and eliminates the need for the Server to accept explicit connection requests or packets from the Client, thereby allowing the Server firewall to always remain closed to all inbound traffic.

Description

RELATED APPLICATION [0001] This application claims priority to U.S. Provisional patent application No. 60 / 561,806 filed Apr. 12, 2004 which is incorporated herein by reference in its entirety.FIELD OF THE INVENTION [0002] The present invention relates to the field of computer networking and network security. More specifically it relates to a method automatically and dynamically initiating and establishing secure connections between a computer (i.e., Server) and a plurality of computers (i.e., clients), each of which is behind a Network Address Translator router and / or firewall. BACKGROUND OF THE INVENTION [0003] The Internet continues undergoing rapid expansion in the numbers of connected computers and it is estimated that the trend towards widely available wireless connectivity and portable computing devices will increase exponentially the number of new computers that connect each day. This rapid expansion has increased radically the need for protecting computers from unauthorized ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): H04L12/28H04L29/06H04L29/08H04L29/12
CPCH04L29/12509H04L61/2567H04L63/0236H04L67/14H04L63/10H04L63/166H04L63/029H04L12/22
Inventor GILLESPIE, BRIANSALMEN, HELMUTTRACEY, DAVID
Owner SIMTONE CORP (US)
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products