×

System, method and apparatus that employ virtual private networks to resist IP QoS denial of service attacks

  • US 9,009,812 B2
  • Filed: 06/24/2013
  • Issued: 04/14/2015
  • Est. Priority Date: 03/20/2001
  • Status: Expired due to Fees
First Claim
Patent Images

1. A system comprising:

  • a Differentiated Services (Diffserv)-enabled Internet Protocol (IP) Virtual Private Network (VPN) network, including at least a first boundary router;

    an IP public network, including at least a second boundary router;

    a plurality of Customer Local Area Networks (LANs), the LANs each including one or more hosts that function as a transmitter and/or receiver of packets communicated over one or both of the Diffserv-enabled VPN network and IP public network;

    a plurality of access networks, each access network coupled, via a Customer Premise Equipment (CPE) edge router and a physical access link, to a respective LAN;

    wherein the access network has a first logical connection to the at least first boundary router in the Diffserv-enabled VPN network and a separate, second logical connection to the at least second boundary router in the IP public network to prevent denial of service attacks on the physical access link originating from sources outside the VPN, the CPE edge router routing only packets with IP address prefixes belonging to the IP VPN via the Diffserv-enabled IP VPN network and routing all other traffic via the IP public network.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×