WO2014172769A1 - Procédé, serveur et système pour diriger un trafic de réseau - Google Patents

Procédé, serveur et système pour diriger un trafic de réseau Download PDF

Info

Publication number
WO2014172769A1
WO2014172769A1 PCT/CA2013/000403 CA2013000403W WO2014172769A1 WO 2014172769 A1 WO2014172769 A1 WO 2014172769A1 CA 2013000403 W CA2013000403 W CA 2013000403W WO 2014172769 A1 WO2014172769 A1 WO 2014172769A1
Authority
WO
WIPO (PCT)
Prior art keywords
computing device
server
destination
originating computing
originating
Prior art date
Application number
PCT/CA2013/000403
Other languages
English (en)
Inventor
Leonid PECHERSKY
Original Assignee
Selectivevpn Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Selectivevpn Inc. filed Critical Selectivevpn Inc.
Priority to PCT/CA2013/000403 priority Critical patent/WO2014172769A1/fr
Publication of WO2014172769A1 publication Critical patent/WO2014172769A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0407Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4505Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
    • H04L61/4511Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]

Definitions

  • the processor may be further configured to identify the originating computing device.
  • the routing operation may involve blocking traffic between the originating computing device and the destination computing device.
  • the routing operation may involve anonymizing the originating computing device.
  • a non-transitory computer readable medium encoded with codes.
  • the codes are for directing a processor to receive a profile record for an originating computing device.
  • the codes are for further directing a processor to receive a destination identifier from the originating computing device.
  • the destination identifier is associated with a destination computing device.
  • the codes are for directing a processor to determine if the destination identifier is associated with the profile record.
  • the codes are for directing a processor to return an assigned query result to the originating computing device when the destination identifier is associated with the profile record.
  • the codes are also for directing a processor to return a default query result to the originating computing device when the destination identifier is not associated with the profile record.
  • Figure 4 is a flow chart of a method for directing network traffic in accordance with an embodiment
  • the memory storage unit 158 can be of any type such as non-volatile memory (e.g. Electrically Erasable Programmable Read Only Memory (EEPROM), Flash Memory, hard disk, floppy disk, optical disk, solid state drive, or tape drive) or volatile memory (e.g. random access memory (RAM)).
  • non-volatile memory e.g. Electrically Erasable Programmable Read Only Memory (EEPROM), Flash Memory, hard disk, floppy disk, optical disk, solid state drive, or tape drive
  • volatile memory e.g. random access memory (RAM)
  • RAM random access memory
  • the memory storage unit 158 is generally a type of non-volatile memory because of the robust nature of non-volatile memory, some embodiments can use volatile memory in situations where high access speed is desired.
  • the memory storage unit 158 is a non-volatile memory unit storing a routing database 255 having routing information for carrying out a routing operation.
  • the routing database routes network traffic form the originating computing device to the destination computing device 58.
  • Table IV contents of Table IV are for illustrative purposes, and that the routing database 255a can include fewer or more profile records. However, the example contents of Table IV will be referred to hereafter to further explanation of the present description.
  • method 700 will lead to further understanding of the system 50a and its various components.
  • system 50a and/or the method 700 can be varied, and need not work exactly as discussed herein in conjunction with each other, and that such variations are within the scope of the present invention.
  • method 700 need not be performed in the exact sequence as shown and that various blocks can be performed in parallel rather than in sequence; hence the elements of the method 700 are referred to herein as "blocks" rather than "steps”.
  • FIG 10 a schematic representation of another non-limiting example of a system for directing network traffic is generally shown at 50b.
  • the system 50b includes a plurality of originating computing devices 54b-1 , 54b-2, and 54b-3, a plurality of destination computing devices 58b-1 , 58b-2, 58b- 3, and 58b-4, a name server 62b, and a plurality of intermediation servers 66b-1 , 66b-2, 66b-3, 66b-4, and 66b-5 interconnected by a network 70b.
  • each of the originating computing devices 54b-1 , 54b-2, and 54b- 3 can be any type of computing device configured to communicate over the network 70b for sending and receiving data including the types discussed above in connection with the originating computing device 54.
  • the plurality of originating computing devices 54b-1 , 54b-2, and 54b-3 are not limited to the same type of computing device and can include a combination of various types of computing devices.
  • each of the originating computing devices 54c-1 , 54c-2, and 54c- 3 can be any type of computing device configured to communicate over the network 70c for sending and receiving data including the types discussed above in connection with the originating computing device 54.
  • the plurality of originating computing devices 54c-1 , 54c-2, and 54c-3 are not limited to the same type of computing device and can include a combination of various types of computing devices.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer And Data Communications (AREA)

Abstract

L'invention concerne un serveur de nom, un serveur d'intermédiation, un système et un procédé permettant de diriger un trafic de réseau. Le serveur de nom et le serveur d'intermédiation comprennent chacun une interface de réseau conçue pour communiquer avec un réseau, une mémoire conçue pour stocker un enregistrement de profil, et un processeur en communication avec la mémoire et l'interface de réseau. Le serveur de nom sert à renvoyer un résultat de requête attribuée vers un dispositif informatique d'origine lorsqu'un identifiant de destination est associé à l'enregistrement de profil, lequel serveur de nom est en outre conçu pour demander le résultat de requête attribuée depuis un serveur d'intermédiation. Le serveur d'intermédiation sert à effectuer une opération de routage en fonction d'une demande, laquelle opération de routage consiste à anonymiser le dispositif informatique d'origine. Le système comprend un dispositif informatique d'origine, un dispositif informatique de destination, un serveur de nom et un serveur d'intermédiation qui sont tous connectés à un réseau. Le procédé consiste à recevoir un enregistrement de profil et un identifiant de destination, à déterminer une association entre l'enregistrement de profil et l'identifiant, et à effectuer un retour avec un résultat de demande attribuée ou un résultat de demande par défaut.
PCT/CA2013/000403 2013-04-24 2013-04-24 Procédé, serveur et système pour diriger un trafic de réseau WO2014172769A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CA2013/000403 WO2014172769A1 (fr) 2013-04-24 2013-04-24 Procédé, serveur et système pour diriger un trafic de réseau

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CA2013/000403 WO2014172769A1 (fr) 2013-04-24 2013-04-24 Procédé, serveur et système pour diriger un trafic de réseau

Publications (1)

Publication Number Publication Date
WO2014172769A1 true WO2014172769A1 (fr) 2014-10-30

Family

ID=51790930

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CA2013/000403 WO2014172769A1 (fr) 2013-04-24 2013-04-24 Procédé, serveur et système pour diriger un trafic de réseau

Country Status (1)

Country Link
WO (1) WO2014172769A1 (fr)

Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2291393A1 (fr) * 1998-12-31 2000-06-30 Lucent Technologies Inc. Methode de communication anonyme des donnees afferentes l'utilisateur d'un site web
US20010034709A1 (en) * 2000-02-29 2001-10-25 Stoifo Salvatore J. Anonymous and private browsing of web-sites through private portals
WO2001092997A2 (fr) * 2000-04-26 2001-12-06 Science Applications International Corporation Ameliorations apportees a un protocole de reseau agile pour securiser les communications a disponibilite de systeme assuree
US20040098485A1 (en) * 1998-10-30 2004-05-20 Science Applications International Corporation Agile network protocol for secure communications using secure domain names
US20040143738A1 (en) * 1999-12-02 2004-07-22 Colin Savage System for providing session-based network privacy, private, persistent storage, and discretionary access control for sharing private data
US20050033659A1 (en) * 1996-01-17 2005-02-10 Privacy Infrastructure, Inc. Third party privacy system
US20060023646A1 (en) * 2004-07-30 2006-02-02 George David A Method and apparatus for anonymous data transfers
US20090171982A1 (en) * 1999-12-21 2009-07-02 Thomas Hagan Privacy and Security Method and System for a World-Wide-Web Site
US20090228708A1 (en) * 2008-03-05 2009-09-10 Trostle Jonathan T System and Method of Encrypting Network Address for Anonymity and Preventing Data Exfiltration
US20110110568A1 (en) * 2005-04-08 2011-05-12 Gregory Vesper Web enabled medical image repository
US20110283017A1 (en) * 2010-05-14 2011-11-17 Microsoft Corporation Interconnecting Members of a Virtual Network
CA2788573A1 (fr) * 2012-09-06 2012-11-01 Guest Tek Interactive Entertainment Ltd. Capacite de l'hote d'un etablissement d'accueil d'utiliser les dispositifs multiples destines aux hotes pour acceder au service reseau

Patent Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050033659A1 (en) * 1996-01-17 2005-02-10 Privacy Infrastructure, Inc. Third party privacy system
US20040098485A1 (en) * 1998-10-30 2004-05-20 Science Applications International Corporation Agile network protocol for secure communications using secure domain names
CA2291393A1 (fr) * 1998-12-31 2000-06-30 Lucent Technologies Inc. Methode de communication anonyme des donnees afferentes l'utilisateur d'un site web
US20040143738A1 (en) * 1999-12-02 2004-07-22 Colin Savage System for providing session-based network privacy, private, persistent storage, and discretionary access control for sharing private data
US20090171982A1 (en) * 1999-12-21 2009-07-02 Thomas Hagan Privacy and Security Method and System for a World-Wide-Web Site
US20010034709A1 (en) * 2000-02-29 2001-10-25 Stoifo Salvatore J. Anonymous and private browsing of web-sites through private portals
WO2001092997A2 (fr) * 2000-04-26 2001-12-06 Science Applications International Corporation Ameliorations apportees a un protocole de reseau agile pour securiser les communications a disponibilite de systeme assuree
US20060023646A1 (en) * 2004-07-30 2006-02-02 George David A Method and apparatus for anonymous data transfers
US20110110568A1 (en) * 2005-04-08 2011-05-12 Gregory Vesper Web enabled medical image repository
US20090228708A1 (en) * 2008-03-05 2009-09-10 Trostle Jonathan T System and Method of Encrypting Network Address for Anonymity and Preventing Data Exfiltration
US20110283017A1 (en) * 2010-05-14 2011-11-17 Microsoft Corporation Interconnecting Members of a Virtual Network
CA2788573A1 (fr) * 2012-09-06 2012-11-01 Guest Tek Interactive Entertainment Ltd. Capacite de l'hote d'un etablissement d'accueil d'utiliser les dispositifs multiples destines aux hotes pour acceder au service reseau

Similar Documents

Publication Publication Date Title
US11023378B2 (en) Distributed cloud-based dynamic name server surrogation systems and methods
JP7165653B2 (ja) 特定の識別情報を開示することのない識別子間のリンクの確立
US10142291B2 (en) System for providing DNS-based policies for devices
KR102595830B1 (ko) 통제된 액세스 자원들에 대한 위치―기반 액세스
US9602472B2 (en) Methods and systems for privacy protection of network end users including profile slicing
US9712422B2 (en) Selection of service nodes for provision of services
US8909792B2 (en) Method, system, and computer program product for identifying and tracking social identities
US8914510B2 (en) Methods, systems, and computer program products for enhancing internet security for network subscribers
US20140223575A1 (en) Privacy protection in recommendation services
US20140115715A1 (en) System and method for controlling, obfuscating and anonymizing data and services when using provider services
KR20110055392A (ko) 사용자 기반의 dns 서버 접근 제어
JP5337240B2 (ja) 広告転送用記憶および検索ネットワーク
EP3123696B1 (fr) Ressources approuvées de service
Buchanan et al. A privacy preserving method using privacy enhancing techniques for location based services
US20150339720A1 (en) System and method for targeting users for content delivery
US20230121519A1 (en) Trusted system for providing customized content to internet service provider subscribers
US11290472B2 (en) Threat intelligence information access via a DNS protocol
US9634935B2 (en) Method, name server, and system for directing network traffic utilizing profile records
CN115699706A (zh) 用于以注重隐私的方式在不同域之间传播数据的方法和系统
WO2014172769A1 (fr) Procédé, serveur et système pour diriger un trafic de réseau
CN111865976A (zh) 一种访问控制方法、装置及网关
US10958580B2 (en) System and method of performing load balancing over an overlay network
US11611623B2 (en) Trusted system for providing customized content to internet service provider subscribers
JP2023505207A (ja) 複数管理者オプト・アウト・システム及び方法
Weber et al. Technical Foundations: Computer Networks

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13883198

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13883198

Country of ref document: EP

Kind code of ref document: A1