WO2014172769A1 - Procédé, serveur et système pour diriger un trafic de réseau - Google Patents
Procédé, serveur et système pour diriger un trafic de réseau Download PDFInfo
- Publication number
- WO2014172769A1 WO2014172769A1 PCT/CA2013/000403 CA2013000403W WO2014172769A1 WO 2014172769 A1 WO2014172769 A1 WO 2014172769A1 CA 2013000403 W CA2013000403 W CA 2013000403W WO 2014172769 A1 WO2014172769 A1 WO 2014172769A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- computing device
- server
- destination
- originating computing
- originating
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0407—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
Definitions
- the processor may be further configured to identify the originating computing device.
- the routing operation may involve blocking traffic between the originating computing device and the destination computing device.
- the routing operation may involve anonymizing the originating computing device.
- a non-transitory computer readable medium encoded with codes.
- the codes are for directing a processor to receive a profile record for an originating computing device.
- the codes are for further directing a processor to receive a destination identifier from the originating computing device.
- the destination identifier is associated with a destination computing device.
- the codes are for directing a processor to determine if the destination identifier is associated with the profile record.
- the codes are for directing a processor to return an assigned query result to the originating computing device when the destination identifier is associated with the profile record.
- the codes are also for directing a processor to return a default query result to the originating computing device when the destination identifier is not associated with the profile record.
- Figure 4 is a flow chart of a method for directing network traffic in accordance with an embodiment
- the memory storage unit 158 can be of any type such as non-volatile memory (e.g. Electrically Erasable Programmable Read Only Memory (EEPROM), Flash Memory, hard disk, floppy disk, optical disk, solid state drive, or tape drive) or volatile memory (e.g. random access memory (RAM)).
- non-volatile memory e.g. Electrically Erasable Programmable Read Only Memory (EEPROM), Flash Memory, hard disk, floppy disk, optical disk, solid state drive, or tape drive
- volatile memory e.g. random access memory (RAM)
- RAM random access memory
- the memory storage unit 158 is generally a type of non-volatile memory because of the robust nature of non-volatile memory, some embodiments can use volatile memory in situations where high access speed is desired.
- the memory storage unit 158 is a non-volatile memory unit storing a routing database 255 having routing information for carrying out a routing operation.
- the routing database routes network traffic form the originating computing device to the destination computing device 58.
- Table IV contents of Table IV are for illustrative purposes, and that the routing database 255a can include fewer or more profile records. However, the example contents of Table IV will be referred to hereafter to further explanation of the present description.
- method 700 will lead to further understanding of the system 50a and its various components.
- system 50a and/or the method 700 can be varied, and need not work exactly as discussed herein in conjunction with each other, and that such variations are within the scope of the present invention.
- method 700 need not be performed in the exact sequence as shown and that various blocks can be performed in parallel rather than in sequence; hence the elements of the method 700 are referred to herein as "blocks" rather than "steps”.
- FIG 10 a schematic representation of another non-limiting example of a system for directing network traffic is generally shown at 50b.
- the system 50b includes a plurality of originating computing devices 54b-1 , 54b-2, and 54b-3, a plurality of destination computing devices 58b-1 , 58b-2, 58b- 3, and 58b-4, a name server 62b, and a plurality of intermediation servers 66b-1 , 66b-2, 66b-3, 66b-4, and 66b-5 interconnected by a network 70b.
- each of the originating computing devices 54b-1 , 54b-2, and 54b- 3 can be any type of computing device configured to communicate over the network 70b for sending and receiving data including the types discussed above in connection with the originating computing device 54.
- the plurality of originating computing devices 54b-1 , 54b-2, and 54b-3 are not limited to the same type of computing device and can include a combination of various types of computing devices.
- each of the originating computing devices 54c-1 , 54c-2, and 54c- 3 can be any type of computing device configured to communicate over the network 70c for sending and receiving data including the types discussed above in connection with the originating computing device 54.
- the plurality of originating computing devices 54c-1 , 54c-2, and 54c-3 are not limited to the same type of computing device and can include a combination of various types of computing devices.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer And Data Communications (AREA)
Abstract
L'invention concerne un serveur de nom, un serveur d'intermédiation, un système et un procédé permettant de diriger un trafic de réseau. Le serveur de nom et le serveur d'intermédiation comprennent chacun une interface de réseau conçue pour communiquer avec un réseau, une mémoire conçue pour stocker un enregistrement de profil, et un processeur en communication avec la mémoire et l'interface de réseau. Le serveur de nom sert à renvoyer un résultat de requête attribuée vers un dispositif informatique d'origine lorsqu'un identifiant de destination est associé à l'enregistrement de profil, lequel serveur de nom est en outre conçu pour demander le résultat de requête attribuée depuis un serveur d'intermédiation. Le serveur d'intermédiation sert à effectuer une opération de routage en fonction d'une demande, laquelle opération de routage consiste à anonymiser le dispositif informatique d'origine. Le système comprend un dispositif informatique d'origine, un dispositif informatique de destination, un serveur de nom et un serveur d'intermédiation qui sont tous connectés à un réseau. Le procédé consiste à recevoir un enregistrement de profil et un identifiant de destination, à déterminer une association entre l'enregistrement de profil et l'identifiant, et à effectuer un retour avec un résultat de demande attribuée ou un résultat de demande par défaut.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/CA2013/000403 WO2014172769A1 (fr) | 2013-04-24 | 2013-04-24 | Procédé, serveur et système pour diriger un trafic de réseau |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/CA2013/000403 WO2014172769A1 (fr) | 2013-04-24 | 2013-04-24 | Procédé, serveur et système pour diriger un trafic de réseau |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2014172769A1 true WO2014172769A1 (fr) | 2014-10-30 |
Family
ID=51790930
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CA2013/000403 WO2014172769A1 (fr) | 2013-04-24 | 2013-04-24 | Procédé, serveur et système pour diriger un trafic de réseau |
Country Status (1)
Country | Link |
---|---|
WO (1) | WO2014172769A1 (fr) |
Citations (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CA2291393A1 (fr) * | 1998-12-31 | 2000-06-30 | Lucent Technologies Inc. | Methode de communication anonyme des donnees afferentes l'utilisateur d'un site web |
US20010034709A1 (en) * | 2000-02-29 | 2001-10-25 | Stoifo Salvatore J. | Anonymous and private browsing of web-sites through private portals |
WO2001092997A2 (fr) * | 2000-04-26 | 2001-12-06 | Science Applications International Corporation | Ameliorations apportees a un protocole de reseau agile pour securiser les communications a disponibilite de systeme assuree |
US20040098485A1 (en) * | 1998-10-30 | 2004-05-20 | Science Applications International Corporation | Agile network protocol for secure communications using secure domain names |
US20040143738A1 (en) * | 1999-12-02 | 2004-07-22 | Colin Savage | System for providing session-based network privacy, private, persistent storage, and discretionary access control for sharing private data |
US20050033659A1 (en) * | 1996-01-17 | 2005-02-10 | Privacy Infrastructure, Inc. | Third party privacy system |
US20060023646A1 (en) * | 2004-07-30 | 2006-02-02 | George David A | Method and apparatus for anonymous data transfers |
US20090171982A1 (en) * | 1999-12-21 | 2009-07-02 | Thomas Hagan | Privacy and Security Method and System for a World-Wide-Web Site |
US20090228708A1 (en) * | 2008-03-05 | 2009-09-10 | Trostle Jonathan T | System and Method of Encrypting Network Address for Anonymity and Preventing Data Exfiltration |
US20110110568A1 (en) * | 2005-04-08 | 2011-05-12 | Gregory Vesper | Web enabled medical image repository |
US20110283017A1 (en) * | 2010-05-14 | 2011-11-17 | Microsoft Corporation | Interconnecting Members of a Virtual Network |
CA2788573A1 (fr) * | 2012-09-06 | 2012-11-01 | Guest Tek Interactive Entertainment Ltd. | Capacite de l'hote d'un etablissement d'accueil d'utiliser les dispositifs multiples destines aux hotes pour acceder au service reseau |
-
2013
- 2013-04-24 WO PCT/CA2013/000403 patent/WO2014172769A1/fr active Application Filing
Patent Citations (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20050033659A1 (en) * | 1996-01-17 | 2005-02-10 | Privacy Infrastructure, Inc. | Third party privacy system |
US20040098485A1 (en) * | 1998-10-30 | 2004-05-20 | Science Applications International Corporation | Agile network protocol for secure communications using secure domain names |
CA2291393A1 (fr) * | 1998-12-31 | 2000-06-30 | Lucent Technologies Inc. | Methode de communication anonyme des donnees afferentes l'utilisateur d'un site web |
US20040143738A1 (en) * | 1999-12-02 | 2004-07-22 | Colin Savage | System for providing session-based network privacy, private, persistent storage, and discretionary access control for sharing private data |
US20090171982A1 (en) * | 1999-12-21 | 2009-07-02 | Thomas Hagan | Privacy and Security Method and System for a World-Wide-Web Site |
US20010034709A1 (en) * | 2000-02-29 | 2001-10-25 | Stoifo Salvatore J. | Anonymous and private browsing of web-sites through private portals |
WO2001092997A2 (fr) * | 2000-04-26 | 2001-12-06 | Science Applications International Corporation | Ameliorations apportees a un protocole de reseau agile pour securiser les communications a disponibilite de systeme assuree |
US20060023646A1 (en) * | 2004-07-30 | 2006-02-02 | George David A | Method and apparatus for anonymous data transfers |
US20110110568A1 (en) * | 2005-04-08 | 2011-05-12 | Gregory Vesper | Web enabled medical image repository |
US20090228708A1 (en) * | 2008-03-05 | 2009-09-10 | Trostle Jonathan T | System and Method of Encrypting Network Address for Anonymity and Preventing Data Exfiltration |
US20110283017A1 (en) * | 2010-05-14 | 2011-11-17 | Microsoft Corporation | Interconnecting Members of a Virtual Network |
CA2788573A1 (fr) * | 2012-09-06 | 2012-11-01 | Guest Tek Interactive Entertainment Ltd. | Capacite de l'hote d'un etablissement d'accueil d'utiliser les dispositifs multiples destines aux hotes pour acceder au service reseau |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11023378B2 (en) | Distributed cloud-based dynamic name server surrogation systems and methods | |
JP7165653B2 (ja) | 特定の識別情報を開示することのない識別子間のリンクの確立 | |
US10142291B2 (en) | System for providing DNS-based policies for devices | |
KR102595830B1 (ko) | 통제된 액세스 자원들에 대한 위치―기반 액세스 | |
US9602472B2 (en) | Methods and systems for privacy protection of network end users including profile slicing | |
US9712422B2 (en) | Selection of service nodes for provision of services | |
US8909792B2 (en) | Method, system, and computer program product for identifying and tracking social identities | |
US8914510B2 (en) | Methods, systems, and computer program products for enhancing internet security for network subscribers | |
US20140223575A1 (en) | Privacy protection in recommendation services | |
US20140115715A1 (en) | System and method for controlling, obfuscating and anonymizing data and services when using provider services | |
KR20110055392A (ko) | 사용자 기반의 dns 서버 접근 제어 | |
JP5337240B2 (ja) | 広告転送用記憶および検索ネットワーク | |
EP3123696B1 (fr) | Ressources approuvées de service | |
Buchanan et al. | A privacy preserving method using privacy enhancing techniques for location based services | |
US20150339720A1 (en) | System and method for targeting users for content delivery | |
US20230121519A1 (en) | Trusted system for providing customized content to internet service provider subscribers | |
US11290472B2 (en) | Threat intelligence information access via a DNS protocol | |
US9634935B2 (en) | Method, name server, and system for directing network traffic utilizing profile records | |
CN115699706A (zh) | 用于以注重隐私的方式在不同域之间传播数据的方法和系统 | |
WO2014172769A1 (fr) | Procédé, serveur et système pour diriger un trafic de réseau | |
CN111865976A (zh) | 一种访问控制方法、装置及网关 | |
US10958580B2 (en) | System and method of performing load balancing over an overlay network | |
US11611623B2 (en) | Trusted system for providing customized content to internet service provider subscribers | |
JP2023505207A (ja) | 複数管理者オプト・アウト・システム及び方法 | |
Weber et al. | Technical Foundations: Computer Networks |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13883198 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 13883198 Country of ref document: EP Kind code of ref document: A1 |