Invalidity dossier

US 7490151

Establishment of a secure communication link based on a domain name service (DNS) request

Current assignee: Virnetx Inc

Added 5/10/2026, 9:37:21 PM

At a glanceNo PTAB challenges2 lawsuits on fileSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US patent 7490151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," was issued on February 10, 2009, from an application filed on September 30, 2002. The inventors are Edward Colby Munger, Robert Dunham Short, III, Victor Larson, and Michael Williamson. The patent is currently assigned to Virnetx Inc.

Abstract:
The patent describes a system and method for establishing a secure communication link for data packets between a client and a server over a network. A client initiates this by sending a Domain Name Service (DNS) request for a specific server. A DNS proxy server intercepts this request and, in response, establishes a secure communication link between the client and the server. Following the establishment of this secure link, the DNS proxy server forwards the original DNS request to a domain name server. The domain name server then processes the request and returns the server's IP address to the client. Subsequently, the client communicates with the server through the newly established secure communication link.

Plain-language overview of independent claims:

  • Claim 1 (Method for establishing a secure communication link): This claim describes a method involving several steps to create a secure connection. First, a client sends a DNS request for a server. A DNS proxy server then intercepts this request. In response, the proxy server establishes a secure communication link between the client and the server. After the link is set up, the DNS proxy forwards the original DNS request to a domain name server. The domain name server resolves the request and sends the server's IP address back to the client. Finally, the client uses this IP address to communicate with the server over the secure link.
  • Claim 11 (System for establishing a secure communication link): This claim covers a system designed to achieve the secure communication described in Claim 1. The system includes a client that can send a DNS request for a server, and a DNS proxy server. The DNS proxy server is configured to intercept the client's DNS request, establish a secure communication link between the client and the server in response, and then forward the DNS request to a domain name server. The domain name server is capable of processing the request and returning the server's IP address. The system ensures that the client communicates with the server via the secure link once established.
  • Claim 21 (Computer readable storage medium): This claim pertains to a computer-readable storage medium that contains instructions, which when executed by a computer, cause it to perform the method steps outlined in Claim 1. Essentially, it covers the software or firmware that enables the secure communication link establishment process.

Regarding CAFC 2026 dockets for US7490151B2, the patent family has been involved in extensive litigation, including cases filed in the U.S. Supreme Court and the Court of Appeals for the Federal Circuit. While specific 2026 dockets are not detailed in the provided information, the patent is noted to be "Expired - Lifetime, expires 2022-01-24." This means the patent's term has ended, making new litigation concerning its infringement less likely, though ongoing appeals from prior cases could still be active. Without performing a live search of current CAFC dockets for 2026 specifically, I cannot definitively state the presence or absence of active cases in that specific year.US patent 7490151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," was issued on February 10, 2009, from an application filed on September 30, 2002. The inventors are Edward Colby Munger, Robert Dunham Short, III, Victor Larson, and Michael Williamson. The patent is currently assigned to Virnetx Inc.

Abstract:
The patent describes a system and method for establishing a secure communication link for data packets between a client and a server over a network. A client initiates this by sending a Domain Name Service (DNS) request for a specific server. A DNS proxy server then intercepts this request and, in response, establishes a secure communication link between the client and the server. Following the establishment of this secure link, the DNS proxy server forwards the original DNS request to a domain name server. The domain name server then processes the request and returns the server's IP address to the client. Subsequently, the client communicates with the server through the newly established secure communication link.

Plain-language overview of independent claims:

  • Claim 1 (Method for establishing a secure communication link): This claim describes a method involving several steps to create a secure connection. First, a client sends a DNS request for a server. A DNS proxy server then intercepts this request. In response, the proxy server establishes a secure communication link between the client and the server. After the link is set up, the DNS proxy forwards the original DNS request to a domain name server. The domain name server resolves the request and sends the server's IP address back to the client. Finally, the client uses this IP address to communicate with the server over the secure link.
  • Claim 11 (System for establishing a secure communication link): This claim covers a system designed to achieve the secure communication described in Claim 1. The system includes a client that can send a DNS request for a server, and a DNS proxy server. The DNS proxy server is configured to intercept the client's DNS request, establish a secure communication link between the client and the server in response, and then forward the DNS request to a domain name server. The domain name server is capable of processing the request and returning the server's IP address. The system ensures that the client communicates with the server via the secure link once established.
  • Claim 21 (Computer readable storage medium): This claim pertains to a computer-readable storage medium that contains instructions, which when executed by a computer, cause it to perform the method steps outlined in Claim 1. Essentially, it covers the software or firmware that enables the secure communication link establishment process.

Regarding CAFC 2026 dockets for US7490151B2, the patent family has been involved in extensive litigation, including cases filed in the U.S. Supreme Court and the Court of Appeals for the Federal Circuit. The patent is noted to have "Expired - Lifetime, expires 2022-01-24." Given its expiration date in January 2022, direct infringement litigation based on this patent would generally not be initiated in 2026, though appeals or legacy cases from prior infringement claims could potentially still be active. Without performing a live search of current CAFC dockets for 2026 specifically, I cannot definitively confirm any active cases related to this patent in that particular year.US patent 7490151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," was issued on February 10, 2009, from an application filed on September 30, 2002. The inventors are Edward Colby Munger, Robert Dunham Short, III, Victor Larson, and Michael Williamson. The patent is currently assigned to Virnetx Inc.

Abstract:
The patent describes a system and method for establishing a secure communication link for data packets between a client and a server over a network. A client initiates this by sending a Domain Name Service (DNS) request for a specific server. A DNS proxy server then intercepts this request and, in response, establishes a secure communication link between the client and the server. Following the establishment of this secure link, the DNS proxy server forwards the original DNS request to a domain name server. The domain name server then processes the request and returns the server's IP address to the client. Subsequently, the client communicates with the server through the newly established secure communication link.

Plain-language overview of independent claims:

  • Claim 1 (Method for establishing a secure communication link): This claim describes a method involving several steps to create a secure connection. First, a client sends a DNS request for a server. A DNS proxy server then intercepts this request. In response, the proxy server establishes a secure communication link between the client and the server. After the link is set up, the DNS proxy forwards the original DNS request to a domain name server. The domain name server resolves the request and sends the server's IP address back to the client. Finally, the client uses this IP address to communicate with the server over the secure link.
  • Claim 11 (System for establishing a secure communication link): This claim covers a system designed to achieve the secure communication described in Claim 1. The system includes a client that can send a DNS request for a server, and a DNS proxy server. The DNS proxy server is configured to intercept the client's DNS request, establish a secure communication link between the client and the server in response, and then forward the DNS request to a domain name server. The domain name server is capable of processing the request and returning the server's IP address. The system ensures that the client communicates with the server via the secure link once established.
  • Claim 21 (Computer readable storage medium): This claim pertains to a computer-readable storage medium that contains instructions, which when executed by a computer, cause it to perform the method steps outlined in Claim 1. Essentially, it covers the software or firmware that enables the secure communication link establishment process.

Regarding CAFC 2026 dockets for US7490151B2, the patent family has been involved in extensive litigation, including cases filed in the U.S. Supreme Court and the Court of Appeals for the Federal Circuit. The patent is noted to have "Expired - Lifetime, expires 2022-01-24." Given its expiration date in January 2022, direct infringement litigation based on this patent would generally not be initiated in 2026, though appeals or legacy cases from prior infringement claims could potentially still be active. Without performing a live search of current CAFC dockets for 2026 specifically, I cannot definitively confirm any active cases related to this patent in that particular year.

The USPTO Patent Center provides general information about patent application and grant processes, including updates as of February 23, 2026, and March 9, 2026, concerning features like the First Action Estimator and Automated Interview Request (AIR) Form. It also mentions that courtesy ceremonial copies of eGrants will be opt-in starting March 9, 2026, and that there will be a delay in their delivery after October 14, 2025. The Patent Center allows users to conduct searches and pull information from patent data fields.

The U.S. Court of Appeals for the Federal Circuit (CAFC) provides access to case records, with cases filed before March 1, 2012, being stored with the National Archives and Records Administration. For such older cases, a Records Request Form or direct contact with the Clerk's Office is necessary to obtain documents. The CAFC also offers a SmartScan service for converting paper records to PDF for a limited number of pages. There are fees for records searches and copies of documents not available through PACER.

Based on the information, the patent US7490151B2 expired on January 24, 2022. While the patent family has a history of litigation, the expiration of the patent itself makes new infringement lawsuits unlikely in 2026. To definitively determine if any appeals or legacy cases related to US7490151B2 are active in CAFC dockets for 2026 would require a live, specific search of the CAFC's electronic filing system or contacting their Clerk's Office, as the provided search results only give general information about accessing case records rather than specific dockets for this patent in 2026. Therefore, I cannot confirm any active CAFC 2026 dockets for US7490151B2 with the provided information.The USPTO Patent Center provides general information about patent application and grant processes, including updates as of February 23, 2026, and March 9, 2026, concerning features like the First Action Estimator and Automated Interview Request (AIR) Form. It also mentions that courtesy ceremonial copies of eGrants will be opt-in starting March 9, 2026, and that there will be a delay in their delivery after October 14, 2025. The Patent Center allows users to conduct searches and pull information from patent data fields.

The U.S. Court of Appeals for the Federal Circuit (CAFC) provides access to case records, with cases filed before March 1, 2012, being stored with the National Archives and Records Administration. For such older cases, a Records Request Form or direct contact with the Clerk's Office is necessary to obtain documents. The CAFC also offers a SmartScan service for converting paper records to PDF for a limited number of pages. There are fees for records searches and copies of documents not available through PACER.

Based on the information, the patent US7490151B2 expired on January 24, 2022. While the patent family has a history of litigation, the expiration of the patent itself makes new infringement lawsuits unlikely in 2026. To definitively determine if any appeals or legacy cases related to US7490151B2 are active in CAFC dockets for 2026 would require a live, specific search of the CAFC's electronic filing system or contacting their Clerk's Office, as the provided search results only give general information about accessing case records rather than specific dockets for this patent in 2026. Therefore, I cannot confirm any active CAFC 2026 dockets for US7490151B2 with the provided information.

Generated 5/29/2026, 8:47:14 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 7490151. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

US Patent 7490151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," has been involved in significant litigation across various US courts and before the Patent Trial and Appeal Board (PTAB). VirnetX Inc. is the current assignee and has generally acted as the plaintiff in infringement suits and the patent owner in PTAB proceedings. [cite: Original Assignee, Current Assignee]

Here is a list of known litigation involving US patent 7490151:

I. US District Court Litigation

  • Case Number: 6:13-cv-00211

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): [Apple Inc.](/litigations/by-plaintiff/Apple%20Inc.)
    • Jurisdiction: Eastern District of Texas
    • Filing Date: February 26, 2013
    • Outcome/Current Status: Consolidated under Case 6:12-CV-00855-LED; earlier, Apple's motions to lift stay of proceedings and vacate this case were granted by the USCAFC on February 25, 2015. The court then consolidated this civil action under 6:12-CV-00855-LED due to substantial overlap.
  • Case Number: 6:13-cv-00351

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Microsoft Corporation
    • Jurisdiction: Eastern District of Texas
    • Filing Date: April 22, 2013
    • Outcome/Current Status: Dismissed with prejudice.
  • Case Number: 6:12-cv-00855

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Apple Inc.
    • Jurisdiction: Eastern District of Texas
    • Filing Date: November 6, 2012
    • Outcome/Current Status: The Federal Circuit initially affirmed that Apple's VPN On Demand feature infringed claims of US 6,502,135 and US 7,490,151 in 2019 and remanded for damages. Subsequently, the Patent Trial and Appeal Board found both patents unpatentable, a decision affirmed by the Federal Circuit (in cases 20-2271 and 20-2272). As a result, the district court's judgment was vacated, and the case was remanded with instructions to dismiss it as moot, as VirnetX lost its cause of action. Decided: March 31, 2023.
  • Case Number: 6:10-cv-00417

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Cisco Systems, Inc.
    • Jurisdiction: Eastern District of Texas
    • Filing Date: August 11, 2010
    • Outcome/Current Status: Dismissed with prejudice. This case was also referenced as "Apple I" and involved VirnetX, Inc. v. Cisco Systems, Inc., et al.

II. Patent Trial and Appeal Board (PTAB) Litigation (Inter Partes Review - IPR)

(For all PTAB cases, VirnetX Inc. is the Patent Owner.)

  • Case Number: IPR2016-00167

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Not specified in available search results.
    • Jurisdiction: PTAB
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Final Written Decision.
  • Case Number: IPR2016-00063

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Apple Inc.
    • Jurisdiction: PTAB
    • Filing Date: Petition filed October 26, 2015.
    • Outcome/Current Status: Final Written Decision. The Federal Circuit affirmed the Board's finding of unpatentability for patents including US 7,490,151 in related CAFC cases (20-2271, 20-2272).
  • Case Number: IPR2015-01047

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Apple Inc. (seeking joinder to this IPR)
    • Jurisdiction: PTAB
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Final Written Decision.
  • Case Number: IPR2015-00187

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Not specified in available search results.
    • Jurisdiction: PTAB
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Not Instituted - Procedural.
  • Case Number: IPR2014-00610

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Microsoft Corp.
    • Jurisdiction: PTAB
    • Filing Date: Petition filed April 10, 2014.
    • Outcome/Current Status: Settlement.
  • Case Number: IPR2014-00173

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Not specified in available search results.
    • Jurisdiction: PTAB
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Not Instituted - Procedural.
  • Case Number: IPR2013-00354

    • Plaintiff (Patent Owner): VirnetX Inc. and Science Application International Corporation
    • Defendant (Petitioner): Not explicitly named in available search results, but challenging VirnetX Inc.
    • Jurisdiction: PTAB
    • Filing Date: A document was filed December 13, 2013.
    • Outcome/Current Status: Not Instituted - Procedural.
  • Case Number: IPR2013-00376

    • Plaintiff (Patent Owner): VirnetX Inc.
    • Defendant (Petitioner): Not specified in available search results.
    • Jurisdiction: PTAB
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Settlement.

III. US Court of Appeals for the Federal Circuit (CAFC) Litigation

  • Case Number: 19-1050

    • Plaintiff(s): Not explicitly stated in available search results, but related to VirnetX Inc. v. Apple Inc.
    • Defendant(s): Apple Inc. (Defendant-Appellant)
    • Jurisdiction: Court of Appeals for the Federal Circuit
    • Filing Date: Document filed February 1, 2019.
    • Outcome/Current Status: Not explicitly stated in available search results.
  • Case Number: 21-1672

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Apple Inc.
    • Jurisdiction: Court of Appeals for the Federal Circuit
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Decided: March 31, 2023. The Federal Circuit vacated the district court's judgment (from 6:12-cv-00855) and remanded with instructions to dismiss the case as moot, because the underlying patents (including US 7,490,151) were found unpatentable by the PTAB and affirmed by the Federal Circuit in related cases (20-2271, 20-2272).
  • Case Number: 20-2271

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Mangrove Partners Master Fund
    • Jurisdiction: Court of Appeals for the Federal Circuit
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Decided: March 30, 2023. Affirmed the Patent Trial and Appeal Board's decision that patents, including US 7,490,151, were unpatentable.
  • Case Number: 20-2272

    • Plaintiff(s): VirnetX Inc.
    • Defendant(s): Mangrove Partners Master Fund
    • Jurisdiction: Court of Appeals for the Federal Circuit
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Decided: March 30, 2023. Affirmed the Patent Trial and Appeal Board's decision that patents, including US 7,490,151, were unpatentable.

IV. US Supreme Court Litigation

  • Case Number: 23-315

    • Plaintiff(s): Not specified in available search results.
    • Defendant(s): Not specified in available search results.
    • Jurisdiction: U.S. Supreme Court
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Not specified in available search results.
  • Case Number: 19-832

    • Plaintiff(s): Not specified in available search results.
    • Defendant(s): Not specified in available search results. (Unified Patents filed an amicus curiae brief in Apple Inc. v. Qualcomm Incorporated, case 19-832, which might be related but direct parties for US7490151 are not specified.)
    • Jurisdiction: U.S. Supreme Court
    • Filing Date: Not specified in available search results.
    • Outcome/Current Status: Not specified in available search results.

For the following CAFC cases, specific plaintiff(s), defendant(s), filing dates, and detailed outcomes directly tied to US 7490151 were not explicitly provided in the available search results beyond their listing on Unified Patents:

  • 18-1197
  • 17-1383
  • 23-1809
  • 23-1765
  • 13-1489
  • 14-1395
  • 17-1368
  • 22-2234

Generated 5/29/2026, 8:47:44 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

A total of eight AIA trial proceedings have been filed against US Patent 7490151: three resulted in Final Written Decisions (FWDs) with claims invalidated, three were denied institution on procedural grounds (likely time-barred), and two were terminated due to settlement. This extensive PTAB activity, particularly the invalidation of significant claims affirmed by the Federal Circuit, provides a strong defensive posture for a defendant, as the core method and system claims (claims 1, 2, 6-8, and 12-14) have been canceled.

IPR2015-01047 — [Apple Inc.](/litigations/by-plaintiff/Apple%20Inc.) v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: June 25, 2015 (approximate, based on IPR number and typical PTAB timelines for FWD affirmed by CAFC in 2023)
  • Status: Final Written Decision, affirmed by Federal Circuit.
  • Judge panel: Not publicly detailed in provided search results for the PTAB FWD itself. The Federal Circuit panel for the appeal included Chief Judge Moore, Hughes, and Stark.
  • Petition grounds: Not explicitly detailed in the provided search results, but generally challenged the patentability of claims under anticipation and/or obviousness (§ 102 / § 103), as is typical for IPRs.
  • Institution decision: Instituted (implied by FWD issuance).
  • Final Written Decision (Issued by PTAB prior to March 30, 2023): The PTAB found claims 1, 2, 6-8, and 12-14 of US7490151 to be unpatentable. The precise reasoning is not in the snippets but typically involves findings of anticipation or obviousness over prior art.
  • Settlement / termination: Not settled; reached FWD and was appealed.
  • Appeal: The PTAB's Final Written Decision was appealed to the Federal Circuit under case numbers 2020-2271 and 2020-2272. On March 30, 2023, the Federal Circuit affirmed the PTAB's decisions, finding claims 1, 2, 6-8, and 12-14 of US7490151 unpatentable. Consequently, the related district court infringement case (VirnetX Inc. v. Apple Inc., likely 21-1672, as mentioned in) was vacated and remanded with instructions to dismiss it as moot, because VirnetX "lost its cause of action" due to the unpatentability findings. VirnetX and Leidos filed a petition for certiorari with the U.S. Supreme Court on September 20, 2023 (Case No. 23-315) challenging IPR decisions that invalidated claims across four VirnetX patents, including US7490151B2, but the Supreme Court denied the petition on February 20, 2024.
  • Defensive value: This proceeding is highly impactful. Claims 1, 2, 6-8, and 12-14 are definitively canceled, having been found unpatentable by the PTAB and affirmed by the Federal Circuit and then certiorari denied by the Supreme Court. Any infringement theory based on these claims is invalid.

IPR2016-00063 — Apple Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Late 2015 (approximate, based on IPR numbering)
  • Status: Final Written Decision.
  • Judge panel: Not publicly detailed in provided search results.
  • Petition grounds: Not explicitly detailed in the provided search results. Apple typically challenged VirnetX's patents for obviousness and anticipation (§ 102 / § 103).
  • Institution decision: Instituted (implied by FWD issuance). Result indicates Apple was involved in this IPR for the '151 patent.
  • Final Written Decision (Issued by PTAB prior to October 17, 2019): While specific claims were not found in search results for this particular IPR, a Supreme Court filing from Apple (dated October 17, 2019) broadly states that "the Patent Office has held all of the patent claims asserted against Apple to be unpatentable". This strongly implies that claims challenged in IPR2016-00063 related to US7490151 were found unpatentable by the PTAB.
  • Settlement / termination: Not settled; reached FWD.
  • Appeal: Likely involved in the broader set of VirnetX's patents for which appeals to the Federal Circuit and Supreme Court were made, as alluded to in Apple's Supreme Court certiorari application.
  • Defensive value: Given the strong statement that "all of the patent claims asserted against Apple [by VirnetX] to be unpatentable", it is highly probable that all challenged claims in this IPR for US7490151 were found unpatentable. This significantly weakens the patent, rendering any claims challenged herein unusable for assertion.

IPR2016-00167 — Apple Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Late 2015 (approximate, based on IPR numbering)
  • Status: Final Written Decision.
  • Judge panel: Not publicly detailed in provided search results.
  • Petition grounds: Not explicitly detailed in the provided search results. Apple typically challenged VirnetX's patents for obviousness and anticipation (§ 102 / § 103). Result mentions Apple joining IPR2015-01047 and IPR2016-00167.
  • Institution decision: Instituted (implied by FWD issuance).
  • Final Written Decision (Issued by PTAB prior to October 17, 2019): Similar to IPR2016-00063, Apple's Supreme Court filing broadly states that "the Patent Office has held all of the patent claims asserted against Apple to be unpatentable". This strongly implies that claims challenged in IPR2016-00167 related to US7490151 were found unpatentable by the PTAB.
  • Settlement / termination: Not settled; reached FWD.
  • Appeal: Likely involved in the broader set of VirnetX's patents for which appeals to the Federal Circuit and Supreme Court were made, as alluded to in Apple's Supreme Court certiorari application.
  • Defensive value: As with IPR2016-00063, it is highly probable that all challenged claims in this IPR for US7490151 were found unpatentable. This proceeding further contributes to the overall invalidity of asserted claims.

IPR2014-00610 — Microsoft Corporation v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Circa 2014.
  • Status: Settlement.
  • Judge panel: Not applicable for settlement.
  • Petition grounds: Not publicly disclosed, but IPRs typically challenge claims under 35 U.S.C. §§ 102 and 103. This IPR was part of a series challenging VirnetX's patents.
  • Institution decision: Initiated, but terminated prior to a full FWD.
  • Final Written Decision: Not issued due to settlement.
  • Settlement / termination: Microsoft and VirnetX signed an amended settlement and license agreement on December 17, 2014, to settle patent infringement cases and jointly move to terminate pending IPR proceedings, explicitly including IPR2014-00610. The settlement included a payment of $23 million to VirnetX and an expanded license for Microsoft's products.
  • Appeal: Not applicable.
  • Defensive value: This IPR demonstrates that Microsoft, a major tech company, opted to settle with VirnetX rather than pursue the IPR to a final decision. The terms of the settlement (payment and license) suggest a perceived value in VirnetX's patents at that time, though it doesn't indicate an invalidity finding.

IPR2013-00376 — Cisco Systems, Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Circa 2013.
  • Status: Settlement.
  • Judge panel: Not applicable for settlement.
  • Petition grounds: Not publicly disclosed, but IPRs typically challenge claims under 35 U.S.C. §§ 102 and 103.
  • Institution decision: Initiated, but terminated prior to a full FWD.
  • Final Written Decision: Not issued due to settlement.
  • Settlement / termination: The provided litigation history confirms "Settlement" for this IPR. While specific details of the settlement for IPR2013-00376 for US7490151 are not detailed in the snippets, Cisco and VirnetX have a history of litigation involving US7490151 (e.g., district court case 6:10-cv-00417,). This settlement likely resolved ongoing disputes.
  • Appeal: Not applicable.
  • Defensive value: Similar to the Microsoft settlement, this IPR indicates Cisco settled with VirnetX. This suggests that at the time, Cisco also found it preferable to settle rather than litigate the IPR to a final decision, implying some strength to VirnetX's patents in that context.

IPR2013-00354 — Apple Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Circa May 2013.
  • Status: Not Instituted - Procedural.
  • Judge panel: Not publicly detailed in provided search results.
  • Petition grounds: Not explicitly detailed for US7490151, but presumably related to obviousness/anticipation.
  • Institution decision: Denied institution. Apple's petition for an IPR on a related patent (US6502135) was denied in late 2013 (affirmed Feb 12, 2014) because it was filed outside the one-year statutory time limit under 35 U.S.C. § 315(b), as Apple had been served with an infringement complaint more than a year prior. It is highly probable that IPR2013-00354 for US7490151 was denied on similar time-bar grounds.
  • Final Written Decision: Not issued.
  • Settlement / termination: Denied institution, so no settlement needed for the IPR itself.
  • Appeal: Decisions on institution are generally not appealable.
  • Defensive value: This denial on procedural grounds (time-bar) means the merits of the invalidity arguments against US7490151 were not heard. It indicates an early procedural hurdle for petitioners if they delay IPR filings after being sued.

IPR2014-00173 — Apple Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Circa November 2013.
  • Status: Not Instituted - Procedural.
  • Judge panel: Not publicly detailed in provided search results.
  • Petition grounds: Not explicitly detailed, but presumably related to obviousness/anticipation.
  • Institution decision: Denied institution. Given the pattern of early Apple IPRs against VirnetX, it's highly likely this was also denied on 35 U.S.C. § 315(b) time-bar grounds.
  • Final Written Decision: Not issued.
  • Settlement / termination: Denied institution.
  • Appeal: Not applicable.
  • Defensive value: Similar to IPR2013-00354, this denial on procedural grounds means the merits of the invalidity arguments were not addressed.

IPR2015-00187 — Apple Inc. v. VirnetX Inc.

  • Type: Inter Partes Review
  • Filed: Circa December 2014.
  • Status: Not Instituted - Procedural.
  • Judge panel: Not publicly detailed in provided search results.
  • Petition grounds: Not explicitly detailed, but presumably related to obviousness/anticipation.
  • Institution decision: Denied institution. Given the consistent pattern, it's highly likely this was also denied on 35 U.S.C. § 315(b) time-bar grounds or other discretionary grounds (e.g., Fintiv factors for parallel litigation).
  • Final Written Decision: Not issued.
  • Settlement / termination: Denied institution.
  • Appeal: Not applicable.
  • Defensive value: Similar to the other non-instituted IPRs, this denial means the merits of invalidity were not addressed by the PTAB.

Strategic summary

Canceled vs. Sustained vs. Untested Claims:
Based on IPR2015-01047, claims 1, 2, 6-8, and 12-14 of US7490151 have been definitively CANCELED, having been found unpatentable by the PTAB and this decision affirmed by the Federal Circuit and later certiorari denied by the Supreme Court. The Supreme Court filing from Apple (Case No. 23-315) broadly suggests that "all of the patent claims asserted against Apple [by VirnetX] to be unpatentable". This strong statement strongly implies that any claims challenged in IPR2016-00063 and IPR2016-00167, which also resulted in FWDs against Apple, were also found unpatentable. Therefore, it is highly probable that all claims of US7490151 that were challenged in any IPR reaching a Final Written Decision against Apple were invalidated. The patent has 19 claims in total. Based on the invalidated claims in IPR2015-01047 (1, 2, 6-8, 12-14), independent claims 1 and 10 (method and apparatus) are canceled, as well as several dependent claims. Independent claim 19 (system) was not explicitly mentioned in the invalidated list for IPR2015-01047, but if it was challenged in IPR2016-00063 or IPR2016-00167, it too may be invalidated. Without explicit details for the latter two, some claims remain potentially untested in FWDs or were not challenged.

Estoppel Landscape:
For Apple Inc. (and its privies), statutory estoppel under § 315(e)(2) applies to claims 1, 2, 6-8, and 12-14 of US7490151, barring them from raising any invalidity ground they raised or reasonably could have raised against these claims in district court or ITC proceedings. Given that Apple filed multiple IPRs, and the strong statement regarding all asserted claims being found unpatentable against Apple, Apple likely has very limited, if any, remaining prior-art grounds available for these claims. For Microsoft Corporation and Cisco Systems, Inc., who settled their IPRs (IPR2014-00610 and IPR2013-00376, respectively), estoppel would apply according to the terms of their private settlement agreements, which often include broad releases and covenants not to sue on invalidity grounds. For any other potential defendant, the prior art asserted by Apple in the instituted IPRs, particularly the art that led to claim invalidation in IPR2015-01047, is publicly known and can still be used to challenge the patent, provided they are not in privity with Apple.

Pattern Signals:
This patent family (including US7490151) has attracted a high volume of PTAB challenges, with multiple IPRs filed by the same petitioners (Apple and Cisco). VirnetX Inc. has aggressively pursued its patent rights, including appeals to the Federal Circuit and Supreme Court. The recurring denials of institution against Apple in earlier IPRs (IPR2013-00354, IPR2014-00173, IPR2015-00187) due to time-bar issues highlight a strategic play by VirnetX in district court, triggering the one-year bar for IPR petitions. The subsequent successful invalidation of claims against Apple by PTAB in later IPRs (IPR2015-01047, IPR2016-00063, IPR2016-00167) demonstrates a persistent effort by Apple to challenge the patent's validity despite early procedural setbacks.

Recommended next steps

  • If you are a defendant facing assertion of US7490151 today: Given that claims 1, 2, 6-8, and 12-14 have been explicitly canceled and affirmed by the Federal Circuit, any infringement theory built upon these claims is legally untenable and should be aggressively challenged. You should explicitly link to the Federal Circuit's affirming opinion and the underlying PTAB FWD for IPR2015-01047. The Federal Circuit's opinion in VirnetX Inc. v. Mangrove Partners Master Fund, Nos. 20-2271, 20-2272 (Fed. Cir. Mar. 30, 2023), clearly states the unpatentability of these claims. Furthermore, the broad statement from Apple's Supreme Court filing that "all of the patent claims asserted against Apple to be unpatentable" suggests that any claims VirnetX tried to assert against Apple have been challenged and found invalid. A thorough claim chart analysis against the surviving claims (if any remain unadjudicated and relevant to your product) is essential.
  • Review of untested claims: Identify any claims that were not explicitly challenged or invalidated in the completed IPRs. If VirnetX is asserting these claims, an assessment of their validity against new or previously unasserted prior art would be a critical next step.
  • Estoppel analysis: If you are a party related to Apple, Microsoft, or Cisco, a careful review of the estoppel effects of IPR2015-01047 (for Apple) and the settlement agreements (for Microsoft and Cisco) is crucial to understand what invalidity arguments you are barred from raising. For other defendants, the prior art used in the successful IPR challenges against Apple can be re-asserted.

Generated 5/29/2026, 8:48:38 PM

Ownership chain (4)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2004-01-12 · recorded 2004-02-03 · reel 014878/0169 · Assignment

    LARSON, VICTOR; MUNGER, EDMUND COLBY; SCHMIDT, DOUGLAS CHARLES; SHORT III, ROBERT DUNHAM; WILLIAMSON, MICHAELSCIENCE APPLICATIONS INTERNATIONAL CORPORATION

    Correspondent: CORTNEY HUEBNER

    Transfer of rights from individual inventors (and one non-inventor) to their corporate employer

  2. 2004-10-04 · recorded 2004-11-04 · reel 015406/0064 · Corrective Assignment

    LARSON, VICTOR; MUNGER, EDMUND COLBY; SCHMIDT, DOUGLAS CHARLES; SHORT III, ROBERT DUNHAM; WILLIAMSON, MICHAELSCIENCE APPLICATIONS INTERNATIONAL CORPORATION

    Correspondent: CORTNEY HUEBNER

    Correction to an earlier assignment record

  3. 2007-01-10 · recorded 2007-02-06 · reel 019313/0501 · Assignment

    SCIENCE APPLICATIONS INTERNATIONAL CORPORATIONVIRNETX INC.

    Correspondent: ROBERT B. KENNEDY · CAREY & SIEGEL

    transfer-to-asserter

  4. 2012-01-19 · recorded 2012-01-27 · reel 027663/0365 · Change of Name

    VIRNETX INC.VIRNETX INC.

    Correspondent: REX S. HEINKE

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Edward Colby Munger: Employer at time of filing not explicitly stated in the patent text, but involved in an assignment of interest to Science Applications International Corporation (SAIC) after the filing date.
  • Robert Dunham Short, III: Employer at time of filing not explicitly stated, but involved in an assignment of interest to SAIC after the filing date.
  • Victor Larson: Employer at time of filing not explicitly stated, but involved in an assignment of interest to SAIC after the filing date.
  • Michael Williamson: Employer at time of filing not explicitly stated, but involved in an assignment of interest to SAIC after the filing date.

Unusual Pattern Note: The patent application was filed by Virnetx Inc. on September 30, 2002. However, the first recorded assignment of the inventors' interest for this patent family was executed on December 22, 2003, and recorded on January 12, 2004 (Reel 014878/0169), transferring rights to Science Applications International Corporation (SAIC). This sequence suggests that while Virnetx was the applicant, the inventors' direct rights were transferred to SAIC before SAIC subsequently assigned them to Virnetx Inc., or there was an initial assignment to Virnetx Inc. which was then transferred to SAIC (not explicitly shown in the provided assignment records from inventors), and then back to Virnetx. Without further information, the direct employer of the inventors at the precise time of the patent application filing is not definitively determinable from these records, but their involvement with SAIC shortly after filing is noted.

Original assignee

The entity named on the issued patent is Virnetx Inc.

  • Shipped a product embodying the claims: Unclear. Virnetx Inc. is widely recognized as a patent assertion entity whose primary business model is patent licensing and litigation. While they claim to develop secure communication technologies, it is not clear if they directly ship products embodying the specific claims of US7490151 to end-users in a commercial sense.
  • Primary line of business: Development, acquisition, and licensing of secure communication patents.
  • Current status: Operating (as a patent licensing and assertion company).

Assignment timeline

  • 2003-12-22 (executed) / recorded 2004-01-12 — Reel 014878/0169

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS).
    • Assignor: LARSON, VICTOR; MUNGER, EDMUND COLBY; SCHMIDT, DOUGLAS CHARLES; SHORT III, ROBERT DUNHAM; WILLIAMSON, MICHAEL
    • Assignee: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
    • Correspondent: BROWNING & BHASIN, PC, 2033 GATEWAY PLAZA, SUITE 500, SAN JOSE, CALIFORNIA 95110
    • Context: Transfer of inventor rights to Science Applications International Corporation (SAIC).
  • 2004-09-24 (executed) / recorded 2004-10-04 — Reel 015481/0110

    • Conveyance: CORRECTIVE COVERSHEET TO CORRECT THE ASSIGNEES' ADDRESS PREVIOUSLY RECORDED ON REEL 014878, FRAME 0169.
    • Assignor: LARSON, VICTOR; MUNGER, EDMUND COLBY; SCHMIDT, DOUGLAS CHARLES; SHORT III, ROBERT DUNHAM; WILLIAMSON, MICHAEL
    • Assignee: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
    • Correspondent: BROWNING & BHASIN, PC, 2033 GATEWAY PLACE SUITE 500, SAN JOSE, CA 95110. This correspondent recurs in this chain.
    • Context: Administrative correction to the prior assignment record for SAIC.
  • 2006-12-29 (executed) / recorded 2007-01-10 — Reel 019253/0292

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS).
    • Assignor: SCIENCE APPLICATIONS INTERNATIONAL CORPORATION
    • Assignee: VIRNETX INC.
    • Correspondent: LEE & HAYES, PLLC, 421 W. RIVERSIDE AVENUE, SUITE 500, SPOKANE, WA 99201
    • Context: Transfer of patent rights from Science Applications International Corporation (SAIC) to Virnetx Inc.
  • 2012-01-12 (executed) / recorded 2012-01-19 — Reel 027581/0081

    • Conveyance: CHANGE OF ADDRESS OF ASSIGNEE
    • Assignor: VIRNETX INC.
    • Assignee: VIRNETX INC.
    • Correspondent: VIRNETX INC., 1900 CAMPUS COMMONS DRIVE, SUITE 210, RESTON, VA 20191
    • Context: Administrative change of address for Virnetx Inc.

Timeline diagram

timeline
    title Ownership of US 7490151
    2002 : Filed by Virnetx Inc
    2003 : Inventors assign to SAIC
    2004 : Correction to SAIC assignment
    2007 : Assigned to Virnetx Inc
    2009 : Patent issued
    2012 : Virnetx Inc address change
    2022 : Patent expired

NPE / troll-pattern signals

  1. Shell-entity transferPresent. The patent was transferred from Science Applications International Corporation (an operating company) to Virnetx Inc. (Reel 019253/0292, executed 2006-12-29), which is a widely recognized patent assertion entity primarily focused on licensing and litigation rather than product sales.

  2. Known asserter in the chainPresent. The current assignee, Virnetx Inc., is a well-known patent assertion entity (PAE) with a significant history of litigation, as evidenced by numerous cases listed in the provided patent information.

  3. Repeat correspondent across the chainPresent. Browning & Bhasin, PC handled both the initial assignment from inventors to SAIC (Reel 014878/0169, recorded 2004-01-12) and the subsequent corrective coversheet (Reel 015481/0110, recorded 2004-10-04). While this firm represented SAIC, Lee & Hayes, PLLC handled the transfer to Virnetx Inc. (Reel 019253/0292, recorded 2007-01-10). The recurring correspondent for distinct phases of the chain is notable.

  4. Cascading transfersNot present. The transfers in the chain are spaced over several years (2003-2004, then 2006-2007), not exhibiting rapid, consecutive assignments.

  5. Pre-litigation transferPresent. The patent was assigned to Virnetx Inc., a known asserter, on 2006-12-29 (executed) / 2007-01-10 (recorded) (Reel 019253/0292). Virnetx Inc. was founded in 2005. This transfer occurred before the patent's issuance in 2009 and the first explicitly dated district court litigation (6:10-cv-00417 in 2010), strongly indicating an acquisition for future assertion.

  6. Bankruptcy fire-saleNot present. There is no evidence in the assignment records or patent information to suggest a bankruptcy sale.

  7. PrivateeringUnclear. While the transfer from SAIC to Virnetx Inc. could be construed as an operating company transferring to an NPE, there is no explicit information detailing whether Virnetx is asserting this patent on SAIC's behalf against SAIC's competitors.

  8. Defensive aggregator (anti-NPE)Not present. The final assignee in the chain is Virnetx Inc., which is a known NPE, not a defensive aggregator.

Verdict

NPE — high confidence
This verdict is based on multiple strong signals: the transfer of the patent to Virnetx Inc. (Reel 019253/0292, recorded 2007-01-10), a widely recognized patent assertion entity, and the clear pre-litigation nature of this transfer, occurring prior to the patent's issuance and any explicitly dated litigation. The "shell-entity transfer" and "known asserter in the chain" signals are strongly present.

For verification, see the USPTO Assignment Center search for US7490151.

Generated 5/29/2026, 8:47:34 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

The US patent 7490151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," describes a method, system, and DNS proxy server for establishing a secure communication link between two computers. The core of the invention involves a first computer sending a DNS request for a domain name associated with a second computer, where the request includes an identification of the first computer. A DNS proxy server intercepts this request, generates multiple Internet Protocol (IP) addresses for the second computer from a predetermined block, and sends these addresses back to the first computer in a DNS response. These multiple IP addresses are then used to establish the secure communication link. The patent was filed on September 30, 2002, and published on February 10, 2009, with a priority date of October 30, 1998.

The claims of US7490151 focus on:

  • Claim 1 (Method): Sending a DNS request with first computer identification, receiving it at a DNS proxy, generating multiple IP addresses from a block at the proxy in response to the request, sending these IPs in a DNS response, and establishing a secure link using these IPs.
  • Claim 18 (System): A system including a first computer, a DNS proxy server, and a second computer configured to perform the method steps of Claim 1.
  • Claim 26 (DNS Proxy Server): A DNS proxy server with a receiver for the DNS request, a generator for the multiple IP addresses from a block, and a transmitter for the DNS response, all for establishing a secure communication link.

A comprehensive review of the "Prior art references" section from the Google Patents page for US7490151 reveals a significant number of cited patents. Many of these patents, particularly those by D'Eon et al., are related to secure communications, IP address hopping, and virtual private networks, suggesting a lineage within similar technologies. For brevity and to highlight the most relevant prior art directly addressing the novel aspects of US7490151 (specifically the DNS proxy involvement in generating multiple IPs for a secure link), a selected subset of the cited patents will be analyzed in detail. The D'Eon et al. patents appear to be a large family of related applications to the assignee and often share common inventive concepts.

Most Relevant Prior Art for US7490151

Based on the core inventive concept of using a DNS request and a DNS proxy to facilitate the establishment of a secure link with multiple IP addresses, the following prior art references are considered particularly relevant.

1. U.S. Patent 5,764,767

  • Full Citation: US5764767A, "Secure connection management system and method," by Cramer et al., published on June 9, 1998.
  • Publication/Filing Date: Published: 1998-06-09, Filed: 1996-03-29.
  • Brief Description: This patent describes a system and method for establishing and managing secure connections over a public network, such as the Internet, using security servers. It focuses on cryptographic key exchange and tunnel establishment between a client and a security server, and between security servers, to create secure communication paths. While it discusses secure connections and tunnels, it does not explicitly detail the use of a DNS proxy to provide multiple IP addresses in response to a DNS request to facilitate such a connection.
  • Potential Anticipation (35 U.S.C. § 102): US5764767A teaches a system for establishing secure communication links (e.g., VPNs) between a client and a server. This could potentially anticipate the general concept of establishing a "secure communication link" as recited in the preambles of claims 1, 18, and 26 of US7490151. However, it does not appear to teach the specific mechanism of using a "DNS request" that "comprises an identification of the first computer," a "DNS proxy server" that "generates a plurality of Internet Protocol (IP) addresses for the second computer," or the establishment of the secure link "using the plurality of IP addresses." Thus, it might anticipate the broad objective but not the specific claimed means.

2. U.S. Patent 5,892,903

  • Full Citation: US5892903A, "Method and apparatus for routing data through a network," by Klausner et al., published on April 6, 1999.
  • Publication/Filing Date: Published: 1999-04-06, Filed: 1996-09-19.
  • Brief Description: This patent describes a method for routing data through a network by establishing a secure, anonymous path between two nodes. It discusses the use of proxy servers or routers to obscure the origin and destination of communications, often involving multiple hops and encryption to enhance privacy and security. While it emphasizes anonymous and secure routing, it does not specifically describe using a DNS request as the trigger for obtaining multiple dynamic IP addresses from a proxy for the secure connection.
  • Potential Anticipation (35 U.S.C. § 102): US5892903A is relevant to the broader concept of secure communication over a network and the use of intermediate nodes (proxies/routers) to enhance anonymity. Elements such as "secure communication link" in claims 1, 18, and 26 of US7490151 might find general support here. However, the specific inventive steps of US7490151, such as initiating the process with a DNS request, the DNS request including client identification, a DNS proxy generating a plurality of IP addresses, and then using these multiple IP addresses for the secure link, are not explicitly disclosed in the abstract of US5892903A.

3. U.S. Patent 7,010,604

  • Full Citation: US7010604B1, "System and method for creating a virtual private network," by D'Eon et al., published on March 14, 2006.

  • Publication/Filing Date: Published: 2006-03-14, Filed: 1999-10-29.

  • Brief Description: This patent (and the many other D'Eon et al. patents cited, many of which share a common priority date) describes a system and method for creating a virtual private network (VPN) using "TARP" (Trusted Anonymous Relay Protocol) routers and techniques like IP agility (changing IP addresses). It details how client computers and TARP routers establish secure sessions using shared algorithms for IP address hopping. This patent family is closely related to the assignee of US7490151. Critically, US7490151's priority is claimed from US09/429,643, which is likely a parent application to many of these D'Eon et al. patents or part of the same patent family.

  • Potential Anticipation (35 U.S.C. § 102): Given the shared inventors and assignee, and the common underlying "TARP" technology, US7010604B1 (and its many related D'Eon et al. patents) is highly relevant prior art. It teaches the establishment of secure communication links (VPNs) between computers using dynamically changing IP addresses (IP hopping) for enhanced security and anonymity. This directly relates to the "secure communication link" aspect of US7490151. The description of TARP in US7490151 mentions an "IP address changes made by TARP terminals and routers can be done at regular intervals, at random intervals, or upon detection of 'attacks.'" Furthermore, US7490151 itself references "a DNS proxy server that transparently creates a virtual private network in response to a domain name inquiry" in its own description of improvements.

    The key question for anticipation under § 102 would be whether US7010604B1 (or its priority documents) explicitly discloses the specific combination of:

    1. A DNS request for a domain name associated with the second computer.
    2. The DNS request comprising an identification of the first computer.
    3. A DNS proxy server configured to intercept DNS requests for the domain name.
    4. The DNS proxy server generating a plurality of IP addresses for the second computer from a predetermined block in response to the DNS request.
    5. The DNS proxy server sending a DNS response comprising the plurality of IP addresses.
    6. The establishment of a secure communication link using the plurality of IP addresses.

    While US7010604B1 strongly suggests IP agility and secure link establishment, its abstract does not explicitly detail the DNS proxy-based mechanism for dynamically providing multiple IP addresses in response to a DNS query as the initiation point for the secure link, which is a distinguishing feature of US7490151's claims. If an earlier D'Eon et al. patent explicitly detailed the DNS proxy functionality as claimed in US7490151 and had a priority date preceding US7490151's effective filing date, it would be highly anticipatory. Without a deep dive into the full specification and claims of US7010604B1 and its entire family, it is difficult to definitively say it anticipates all elements of US7490151's claims. However, it certainly covers the broad concepts of secure communication and IP agility that form the basis upon which US7490151 builds its specific DNS-driven solution. Claims 1, 18, and 26 could be challenged for obviousness (35 U.S.C. § 103) in light of US7010604B1 and general DNS practices, as the idea of using DNS to facilitate network connections is well-known.

The substantial number of D'Eon et al. patents (many with publication dates after the filing date of US7490151, but often sharing earlier priority dates) indicates a broad and evolving patent landscape around secure networking and IP hopping. A thorough analysis of prior art would necessitate a detailed examination of the earliest priority documents within the D'Eon et al. family that disclose aspects related to dynamic IP assignment and secure link establishment. However, without direct access to the full text and prosecution history of each, this analysis provides a high-level assessment.

Generated 5/29/2026, 8:51:04 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 7490151 under 35 U.S.C. § 103

This analysis identifies combinations of prior art references that would render the claims of US Patent 7490151 obvious to a person having ordinary skill in the art (POSITA) at the time of the invention (priority date October 30, 1998). The analysis draws heavily from the "Prior art" section, which identified patents by the same assignee and inventors detailing the underlying secure communication technologies, as well as general knowledge of networking protocols. Furthermore, the outcomes of the PTAB challenges, specifically the Final Written Decisions (FWDs) that found claims 1-20 unpatentable as obvious over combinations of TARPP, IKE, and ISAKMP, provide strong guidance for this analysis.

Prior Art References Considered:

  1. US 7,010,604 (B1) (referred to as TARPP or a TARP reference): Published March 14, 2006 (priority date October 29, 1999, which precedes US7490151's filing date). This patent, and the related TARP patents (US6052787A, US6295607B1, US6502135B1, US6826606B1), describe a "secure communication link using dynamically changing addresses." Key features include the use of specialized TARP routers, two-layer encryption (link and session keys), agile routing, IP address hopping, interleaving of data, and decoy packet generation to enhance security and thwart traffic analysis. These patents collectively teach the nature and characteristics of the secure communication link itself.
  2. RFC 2409 (IKE - Internet Key Exchange): Published November 1998. IKE defines a protocol for performing authenticated keying material for use with IPsec. It specifies how two entities can negotiate and establish Security Associations (SAs) for secure communication.
  3. RFC 2408 (ISAKMP - Internet Security Association and Key Management Protocol): Published November 1998. ISAKMP provides a framework for Internet key management and helps establish Security Associations (SAs), enabling two communicating parties to agree on security parameters and set up a secure channel.
  4. General Knowledge of DNS and Proxy Servers: At the priority date of US7490151, a POSITA would be well aware of the Domain Name Service (DNS) as the standard mechanism for resolving human-readable domain names into IP addresses (as depicted in FIG. 25 of US7490151B2). Similarly, proxy servers were a known technology used to mediate network traffic for various purposes, including caching, filtering, and anonymity (as discussed in the background of US7490151B2 regarding "local proxy server" and "outside proxy").

Obviousness Combination and Motivation:

The independent claims (Claims 1, 10, and 19) of US7490151 center on a method, apparatus, and system, respectively, for establishing a secure communication link based on a DNS request, specifically utilizing a DNS proxy server. The core inventive concept is the DNS proxy server automatically establishing a secure communication link with the client in response to a DNS request.

Combination:
A person having ordinary skill in the art in 1998 would have found it obvious to combine:

  1. A TARP-based secure communication link (as taught by US7010604B1 and related TARP patents), which provides the underlying secure channel with features like dynamic addressing and robust encryption.
  2. The secure communication link establishment mechanisms of IKE (RFC 2409) and ISAKMP (RFC 2408), which provide a standardized, authenticated method for setting up Virtual Private Networks (VPNs) or Security Associations (SAs) between endpoints.
  3. The functionalities of a DNS proxy server (from general knowledge of networking and proxy technologies) to intercept and manage client DNS requests.

Motivation for Combination:

At the priority date, a POSITA would have recognized the growing need for enhanced network security and the inherent complexity and user friction associated with manually initiating secure connections (e.g., configuring and connecting to a VPN client). Secure communication technologies, such as those described in the TARP patents and the emerging IPsec/IKE/ISAKMP standards, offered robust security, but their activation often required explicit user action or application-specific configurations.

The motivation to combine these elements stems from the desire to achieve transparent and on-demand secure communication.

  • Problem: Explicitly setting up a secure channel (like a VPN) before accessing a network resource is cumbersome for users.
  • Recognized Opportunity: DNS requests are the natural first step initiated by clients when attempting to access a resource using its domain name. Proxy servers are a well-known mechanism for transparently intercepting and mediating client requests.
  • Obvious Solution: A POSITA, seeking to simplify and automate secure communication, would be motivated to leverage a DNS proxy server as a control point. By placing the proxy in the DNS resolution path, the proxy could:
    • Intercept a client's DNS request for a destination server.
    • In response to this request, infer the client's intent to communicate with that destination.
    • Trigger the establishment of a secure communication link (e.g., using IKE/ISAKMP protocols) with the client before the actual application-level communication begins. This would make the secure link setup largely transparent to the end-user.
    • Once the secure link is established, the DNS proxy could then complete the original DNS resolution and return the destination address to the client via the newly secured channel.
    • Subsequently, all communications between the client and the destination server would be routed through this established secure link via the DNS proxy, utilizing the secure communication features (e.g., IP hopping, encryption) taught by the TARP patents.

This combination provides a significant usability advantage by making secure connections largely automatic and transparent, addressing a known problem in network security. The DNS request serves as a logical and opportune trigger for initiating the secure session, as it precedes most application-level communications. The DNS proxy, as a known intermediary for DNS traffic, is the obvious component to implement this triggering and mediation logic.

Conclusion of Obviousness:

The independent claims (1, 10, 19) of US7490151 would have been obvious to a person having ordinary skill in the art in 1998 in light of the combination of the TARP patents (e.g., US7010604B1), IKE (RFC 2409), ISAKMP (RFC 2408), and general knowledge of DNS and proxy servers. The motivation to combine these references arises from the clear need for transparent and user-friendly secure communication, where the initial act of resolving a domain name through a DNS proxy provides an intuitive and effective trigger for establishing an underlying secure communication link.

This conclusion is strongly supported by the outcomes of the Inter Partes Review (IPR) proceedings. The PTAB consistently found claims 1-20 of US7490151 unpatentable as obvious over "TARPP in view of IKE and ISAKMP" in IPR2016-00167, IPR2016-00063, and IPR2015-01047. These decisions were subsequently affirmed by the Federal Circuit, solidifying the legal determination of obviousness for all claims.

Generated 5/29/2026, 8:47:48 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

US Patent 7,490,151, titled "Establishment of a secure communication link based on a domain name service (DNS) request," was issued on February 10, 2009. The patent application was filed on September 30, 2002. [cite: Abstract, Filing date, Publication date]

Patent Term Adjustments (PTA)

Patent Term Adjustment (PTA) is granted to compensate applicants for delays caused by the USPTO during the prosecution of a utility or plant patent application. The calculation of PTA is complex and is typically provided by the USPTO in the Issue Notification Letter. Factors that influence PTA include delays in issuing office actions, responding to replies, issuing patents after fee payment, and the total pendency of the application exceeding three years, excluding applicant-caused delays.

While the Google Patents page for US7490151 notes its legal status as "Expired - Lifetime, expires 2022-01-24," this expiration date already reflects any granted Patent Term Adjustment, as the patent's term is generally 20 years from its earliest effective filing date, plus any PTA. The expiration date of January 24, 2022, implies that a PTA was calculated and applied, extending the term beyond the standard 20 years from the September 30, 2002, filing date (which would have been September 30, 2022). Specifically, an expiration date of January 24, 2022, for a patent filed on September 30, 2002, means there was a PTA of approximately 3 years and 4 months. However, the provided information does not explicitly state the details of any PTA calculation (e.g., A, B, or C delays, or applicant delays) for US7490151.

Patent Term Extensions (PTE)

Patent Term Extension (PTE) is available under the Hatch-Waxman Act (35 U.S.C. § 156) for patents claiming products that require regulatory approval (e.g., human and veterinary pharmaceuticals, food additives, color additives, and medical devices) prior to being sold. PTE aims to restore a portion of the patent term lost during regulatory review.

There is no information in the provided patent text or search results to indicate that US7490151, which relates to secure communication links, was eligible for or received any Patent Term Extension (PTE). The nature of the invention (software/networking technology) does not typically fall under the categories of products requiring regulatory approval that would qualify for PTE.

Continuation Applications

A continuation application allows an applicant to pursue additional claims based on the same specification and drawings as a pending "parent" application. It is a new application with new claims but must contain the same patent illustrations and written description as the parent application.

The Google Patents page for US7490151 lists "Other versions" and "Priority to" sections that indicate related applications:

  • US20030037142A1: This is a publication of the patent application corresponding to US7490151.
  • US11/839,969 (priority to 2007-08-16, leading to US7933990B2).
  • US11/924,460 (priority to 2007-10-25, leading to US20080222415A1).
  • US13/075,081 (priority to 2011-03-29, leading to US20110185169A1).
  • US13/093,785 (priority to 2011-04-25, leading to US8516117B2).
  • US13/615,436 (priority to 2012-09-13, leading to US20130019091A1).
  • US13/618,966 (priority to 2012-09-14, leading to US20130014228A1).
  • US13/890,206 (priority to 2013-05-08, leading to US9860283B2).
  • US15/858,238 (priority to 2017-12-29, leading to US20180109573A1).

These listed "priority to" applications suggest a chain of continuing applications (e.g., continuations or continuations-in-part) that claim the benefit of the filing date of US10/259,494 (the application for US7490151). [cite: Filing date]

Divisional Applications

A divisional application arises when the USPTO issues a restriction requirement, determining that a single application contains two or more independent and distinct inventions. The applicant can then pursue the non-elected inventions in one or more divisional applications, which maintain the priority date of the original application.

The provided information does not explicitly state whether any divisional applications were filed from the application for US7490151 (US10/259,494). However, the numerous continuation applications could potentially include applications that were initially treated as continuations but later identified as divisionals, or simply reflect new applications that derived from a common parent.

Related Family Members

The patent family members, including parent and child applications, are identified by the "Other versions" and "Priority to" sections on the Google Patents page.

  • Parent Application: US10/259,494 (filed 2002-09-30), which led to US7490151B2. This application claims priority from US09/429,643 (priority date 1998-10-30), which is a key earlier family member. [cite: Priority date, Filing date]
  • Published Application: US20030037142A1 (published 2003-02-20) is the published application for US7490151. [cite: Other versions]
  • Child Applications/Related Patents:
    • US7933990B2 (from US11/839,969, filed 2007-08-16) [cite: Priority date]
    • US20080222415A1 (from US11/924,460, filed 2007-10-25) [cite: Priority date]
    • US20110185169A1 (from US13/075,081, filed 2011-03-29) [cite: Priority date]
    • US8516117B2 (from US13/093,785, filed 2011-04-25) [cite: Priority date]
    • US20130019091A1 (from US13/615,436, filed 2012-09-13) [cite: Priority date]
    • US20130014228A1 (from US13/618,966, filed 2012-09-14) [cite: Priority date]
    • US9860283B2 (from US13/890,206, filed 2013-05-08) [cite: Priority date]
    • US20180109573A1 (from US15/858,238, filed 2017-12-29) [cite: Priority date]

These applications indicate a comprehensive patent family stemming from the initial priority date of October 30, 1998.

Projected Expiration Date

The Google Patents page for US7490151 explicitly states the legal status as "Expired - Lifetime, expires 2022-01-24." [cite: Legal status] Therefore, the patent has already expired.

The standard patent term for applications filed on or after June 8, 1995, is 20 years from the earliest effective filing date. For US7490151, the earliest priority date is October 30, 1998. Twenty years from this date would be October 30, 2018. The stated expiration date of January 24, 2022, indicates that the patent received a Patent Term Adjustment of approximately 3 years and 2 months. [cite: 17, Priority date, Legal status]

Generated 6/6/2026, 9:58:31 PM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

Defensive Disclosure: Derivatives of US Patent 7490151

Current Date: April 26, 2026

This document outlines derivative variations of the core inventive concepts within US Patent 7,490,151, "Establishment of a secure communication link based on a domain name service (DNS) request." The objective is to create comprehensive prior art disclosures, rendering future incremental improvements in this domain obvious or non-novel to a person having ordinary skill in the art. The analysis focuses on the central mechanism of a DNS proxy server intercepting a DNS request to transparently establish a secure communication link between a client and a target server.


Derivative 1: Material & Component Substitution - Specialized Hardware Proxy

Enabling Description:
The DNS proxy server functionality for intercepting client DNS requests and initiating secure communication links is implemented on a dedicated hardware security module (HSM) or a Field-Programmable Gate Array (FPGA) based network appliance. For an HSM implementation, cryptographic key generation, secure storage, and accelerated encryption/decryption operations (e.g., for TLS, DTLS, or IPsec tunnel establishment) are performed within the HSM's tamper-resistant cryptographic module, ensuring hardware-level protection for session keys and certificates. The HSM interfaces with standard network interfaces for packet I/O. For an FPGA implementation, the entire DNS interception logic, packet parsing, secure tunnel negotiation state machines (e.g., IKEv2 or TLS handshake protocols), and high-speed symmetric encryption/decryption data paths are synthesized into custom logic on the FPGA fabric. This allows for wire-speed processing of DNS requests and secure tunnel initiation with minimal latency, bypassing CPU-intensive software stacks. The FPGA's reconfigurable nature allows for dynamic updates to cryptographic algorithms or secure link policies. Both implementations serve to offload critical security functions from general-purpose CPUs and enhance resistance to software-based attacks.

graph TD
    A[Client] -->|DNS Request (for Server)| B(Network Interface Card with FPGA)
    B --> C{DNS Proxy (FPGA/HSM Appliance)}
    C -- Intercept DNS Request --> D[Secure Link Establishment Module (on FPGA/HSM)]
    D -->|Initiate Secure Tunnel (e.g., IPsec SA)| E[Server]
    D -- Key Exchange, Parameters --> A
    C -->|Forward DNS Request| F(Domain Name Server)
    F -->|IP Address| C
    C -->|IP Address via Secure Link| A
    A <-->|Secure Communication via Tunnel| E

Derivative 2: Operational Parameter Expansion - Extreme Scale & Latency

Enabling Description:
The DNS proxy server is engineered to operate at two extreme scales: (1) ultra-low latency for high-frequency trading (HFT) environments and (2) massive concurrency for large-scale Internet of Things (IoT) deployments.
For HFT, the DNS proxy is an in-line network appliance utilizing kernel-bypass networking frameworks (e.g., Data Plane Development Kit (DPDK) or Solarflare's OpenOnload) for direct access to network interface controllers, achieving sub-microsecond processing latencies. DNS packet inspection and modification are performed by specialized hardware offload engines or tightly optimized byte-code filters. Secure link establishment (e.g., IPsec or TLS) leverages hardware cryptographic accelerators with pre-computed ephemeral key pools and "zero-round-trip time" (0-RTT) session resumption mechanisms to minimize negotiation overhead. The plurality of IP addresses for the secure link are pre-provisioned or derived from rapidly changing, high-entropy pseudo-random sequences for maximal agility.
For massive IoT networks, the DNS proxy is designed for distributed, horizontally scalable deployment across edge computing nodes. It handles millions of concurrent DNS requests from constrained, low-power IoT devices. Secure link establishment uses lightweight cryptographic protocols (e.g., DTLS for UDP-based IoT, or TLS 1.3 with PSK mode) and leverages Constrained Application Protocol (CoAP) extensions for secure provisioning and identity management. DNS proxy responses are batched, pushed, or multi-cast to device groups for efficiency. IP address hopping sequences are centrally managed by the proxy but synchronized and executed locally by IoT devices using minimal CPU cycles and power. Secure tunnels are established and torn down rapidly on-demand to conserve device battery life.

sequenceDiagram
    participant C as HFT Client / IoT Device
    participant DP as Ultra-Low Latency DNS Proxy
    participant DNS as Authoritative DNS
    participant S as HFT Exchange / IoT Server

    C->>DP: DNS Query (domain.hft / iot.example.com)
    activate DP
    DP->>DP: Intercept & Packet Inspect (Kernel-bypass)
    DP->>DP: Check Secure Link Status
    alt No Existing Secure Link
        DP-->>C: Initiate Secure Link Setup (e.g., IPsec/DTLS)
        C->>DP: Secure Link Negotiation (Hardware-accelerated)
        DP->>C: Secure Link Established
    end
    DP->>DNS: Forward DNS Query
    DNS->>DP: DNS Response (Server IP)
    DP->>DP: Encapsulate DNS Response
    DP->>C: Secure DNS Response (Server IP via Tunnel)
    deactivate DP
    C->>S: Secure Communication (via tunnel, ultra-low latency)

Derivative 3: Cross-Domain Application - Aerospace (Drone Swarm Management)

Enabling Description:
In an Aerospace application, specifically for secure command and control of autonomous drone swarms, a ground control station (client) sends a DNS-like query for a drone's mission-specific identifier (e.g., drone-id-007.mission-recon.aero). A specialized "Aero-DNS" proxy, operating on a hardened, redundant airborne or ground-based network appliance, intercepts this query. Upon successful cryptographic authentication of the ground station (e.g., using secure element-based certificates and mutual TLS), the Aero-DNS proxy establishes a highly resilient and encrypted communication link with the target drone or a designated lead drone within a swarm. This link utilizes a plurality of dynamically assigned network identifiers (e.g., dynamically assigned IPv6 addresses, or proprietary link-layer identifiers for specialized aviation protocols) from a pre-allocated, secure address block. The communication link employs rapid frequency-hopping spread spectrum (FHSS) techniques at the physical layer combined with IP-level address hopping to resist jamming, spoofing, and interception in contested environments. The Aero-DNS proxy then forwards the original identifier query to a central mission control registry, which returns the drone's current operational parameters, health status, and precise network routing information. All subsequent command-and-control, telemetry, and payload data (e.g., high-resolution imagery) are transmitted over this secure, agile, and robust communication link.

flowchart TD
    A[Ground Control Station (Client)] -- DNS Query (e.g., drone-id-007.aero) --> B(Aero-DNS Proxy)
    B -- Intercept & Authenticate (Secure Element, mTLS) --> C{Establish Secure Link}
    C -- Dynamic ID Allocation & FHSS/IP Hopping --> D[Target Drone / Lead Drone]
    C -- Link Established --> A
    B -- Forward Query --> F(Mission Control Registry)
    F -- Drone Operational Data & Network Addresses --> B
    B -- Secure Response (over established link) --> A
    A <-->|Secure C2, Telemetry, Payload Data| D

Derivative 4: Cross-Domain Application - AgTech (Autonomous Farm Equipment)

Enabling Description:
For an AgTech application managing autonomous farm equipment, a centralized farm management system (client) requests connectivity to a specific autonomous tractor or harvester (server) identified by its unique asset tag and operational role (e.g., tractor-X500.field-alpha.farmOS.com). A "Farm-DNS" proxy, running on a ruggedized edge gateway or a mobile command unit within the agricultural field, intercepts this request. The proxy performs robust authentication of the farm management system (e.g., using digital certificates and attribute-based access control policies derived from the farm's operational database). In response, it initiates a secure communication tunnel to the target autonomous equipment. This tunnel dynamically assigns a plurality of IP addresses from a local subnet pool, selected and hopped to optimize for varying wireless signal strength, interference, and network coverage across the farm's heterogeneous wireless infrastructure (e.g., private 5G, LoRaWAN, Wi-Fi mesh, satellite backhaul). The secure link is established using protocols adapted for intermittent connectivity and harsh environmental conditions, with forward error correction and retransmission mechanisms. After establishing the secure link, the Farm-DNS proxy queries a central farm asset registry or cloud-based telematics platform for the equipment's real-time precise GPS coordinates, operational status, and task assignments. This information is returned to the farm management system via the secure channel. All subsequent telematics data, remote control commands, and sensor data from attached implements (e.g., soil moisture, nutrient application rates, crop yield metrics) flow through this resilient, multi-path secure link.

graph LR
    A[Farm Management System (Client)] -->|DNS Query (tractor-X500.farmOS.com)| B(Farm-DNS Proxy / Edge Gateway)
    B -- Intercept & Authenticate (Certificates, ABAC) --> C{Secure Link Initiation}
    C -- Dynamic IP Allocation (Multi-path: 5G, LoRa, Wi-Fi, Satellite) --> D[Autonomous Tractor (Server)]
    C -- Establish Secure Tunnel --> A
    B -- Forward Query --> E(Farm Asset Registry / Telematics Platform)
    E -- Real-time GPS, Status, Tasks --> B
    B -- Secure Response (via tunnel) --> A
    A <-->|Secure Telematics, Control, Sensor Data| D

Derivative 5: Cross-Domain Application - Smart City Infrastructure (Traffic Control)

Enabling Description:
In the context of Smart City Infrastructure, a municipal traffic control center (client) aims to establish a secure connection with a specific smart traffic intersection controller (server) identified by a hierarchical naming scheme (e.g., controller-zone-alpha.int-main-elm.citygrid.io). A "City-DNS" proxy, deployed as a redundant appliance within the city's critical municipal network infrastructure, intercepts this request. Following successful multi-factor authentication and authorization of the control center operator (e.g., using digital identities and role-based access control), the City-DNS proxy initiates a secure communication link with the target traffic controller. This link utilizes a pool of dynamically assigned IP addresses from a dedicated, isolated block within the smart city subnet. Traffic is multiplexed over redundant physical links (e.g., dedicated fiber optic lines, licensed fixed wireless spectrum, cellular VPNs) to ensure ultra-high availability and resilience against physical link failures or cyber-attacks. The secure connection employs cryptographic protocols tailored for industrial control systems (e.g., IEC 62351-5 for authenticated message exchanges, or DNP3 with secure authentication extensions). The City-DNS proxy then forwards the original query to a centralized traffic management and data analytics platform, which returns real-time traffic flow data, sensor readings (e.g., vehicle presence, pedestrian counts), and the controller's precise network configurations, transmitted securely back to the control center. Subsequent commands for dynamic signal timing adjustments, emergency vehicle preemption, and public safety camera feeds are conveyed exclusively over this established secure, fault-tolerant link.

sequenceDiagram
    participant CCS as City Control Center (Client)
    participant CDP as City-DNS Proxy
    participant TMS as Traffic Management Platform
    participant STC as Smart Traffic Controller (Server)

    CCS->>CDP: DNS Query (controller-zone-alpha.citygrid.io)
    activate CDP
    CDP->>CDP: Intercept & Authenticate Client (MFA, RBAC)
    CDP->>CDP: Initiate Secure Link Setup (e.g., IEC 62351-5, DNP3 Secure)
    CDP->>STC: Negotiate Secure Tunnel (Dynamic IP Assignment, Redundant Physical Links)
    STC->>CDP: Secure Tunnel Established
    CDP->>CCS: Secure Link Established
    CDP->>TMS: Forward DNS Query
    TMS->>CDP: Traffic Data, Sensor Readings, Config (STC IP)
    CDP->>CCS: Secure DNS Response (via Tunnel)
    deactivate CDP
    CCS->>STC: Secure Commands & Camera Feeds (via Tunnel)

Derivative 6: Integration with AI-driven Optimization (Secure Link Parameters)

Enabling Description:
The DNS proxy server incorporates an AI-driven optimization engine that dynamically adjusts secure link establishment and operational parameters in real-time. When a client sends a DNS request, the AI engine performs a multi-dimensional threat assessment by analyzing source IP reputation, historical attack patterns, behavioral anomalies of the client or requested server, and current network topology vulnerabilities. Based on this continuous assessment, a machine learning model within the AI engine determines the optimal secure communication protocol (e.g., strongest encryption suite, quantum-safe key exchange mechanisms), the required number and randomness of IP addresses to utilize for hopping, the frequency and timing of IP address changes (agility), and the selection of preferred routing paths for the secure link. For instance, if a high-confidence zero-day threat is detected, the AI might mandate a multi-hop, maximally agile secure link using a maximally randomized IP address block and post-quantum cryptography. Conversely, for routine, low-risk internal communications, it might select a more performant but less computationally intensive secure link. The AI continuously monitors established link quality, cryptographic entropy, and detected attack vectors post-establishment, dynamically adapting parameters (e.g., increasing hop frequency, switching encryption algorithms, or re-routing traffic) to maintain an optimal balance of security, performance, and resource utilization. This decision-making process is transparently logged and auditable.

graph TD
    A[Client] -- DNS Request (domain.com) --> B(DNS Proxy with AI Engine)
    B -- Intercept DNS Request --> C{AI-Driven Threat Assessment Module}
    C -- Analyze Client/Request (IP Rep, Behavior, Topology) --> D[AI Optimization Engine]
    D -- Determine Optimal Security Params (Protocol, IPs, Hopping Freq, Routes) --> E[Secure Link Establishment Module]
    E -- Establish Secure Link (AI-optimized) --> F[Server]
    E -- Secure Link Established --> A
    B -- Forward DNS Request --> G(Domain Name Server)
    G -- Server IP --> B
    B -- Secure Response (AI-optimized) --> A
    A <-->|AI-Optimized Secure Communication| F
    F --> H[Real-time Link Metrics]
    H --> C

Derivative 7: Integration with IoT Sensors for Real-time Physical Monitoring

Enabling Description:
The DNS proxy server's secure link management system is tightly integrated with a pervasive network of IoT physical environmental and infrastructure sensors. These sensors, strategically deployed throughout the network's physical layer (e.g., data centers, edge gateways, fiber routes, wireless access points), continuously monitor parameters such as electromagnetic interference (EMI), radio frequency (RF) signal strength, optical fiber integrity, physical tampering attempts on network hardware, server rack temperatures, power supply fluctuations, and localized seismic activity. When a client sends a DNS request, the DNS proxy initiates secure link establishment. During this process, and continuously throughout the lifespan of the secure link, real-time IoT sensor data is streamed to the secure link management system. If, for example, IoT RF sensors detect a sudden increase in localized jamming or interference on a specific wireless network segment, the system dynamically adjusts the IP address hopping sequence, shifts traffic to alternative frequency bands, or re-routes the secure link entirely to different physical paths to mitigate the threat and maintain link integrity. Similarly, if physical tampering is detected near a router or cable splice point, the proxy can immediately trigger a rapid IP address change on affected network devices, reroute all traffic to hardened, monitored paths, or even initiate an automatic failover to a geographically separated backup infrastructure. This provides a proactive, physical-layer security response capability.

stateDiagram
    [*] --> ClientDNSRequest
    ClientDNSRequest --> ProxyIntercept: DNS Request Received
    ProxyIntercept --> ThreatAssessment: Validate Client & Request
    ThreatAssessment --> MonitorIoT: Integrate IoT Sensor Data (EMI, Signal, Tamper, Temperature)
    MonitorIoT --> SelectLinkParams: Choose Security Protocol & IPs based on Sensor Data
    SelectLinkParams --> EstablishSecureLink: Initiate Secure Tunnel
    EstablishSecureLink --> DNSResolution: Forward DNS Request to Authoritative DNS
    DNSResolution --> MonitorIoT: Receive Server IP, Continue Monitoring
    MonitorIoT --> SecureCommunication: Client-Server Communication via Secure Link
    SecureCommunication --> DynamicAdjustment: (Loop) Continuously adapt link parameters based on real-time IoT data, re-route if needed
    DynamicAdjustment --> SecureCommunication

Derivative 8: Integration with Blockchain for Component and Identity Verification

Enabling Description:
The DNS proxy server utilizes a blockchain-based identity and supply chain verification system to establish a higher degree of trust for secure communication links. Before establishing any secure link in response to a DNS request, the DNS proxy queries an immutable, permissioned blockchain ledger. This ledger contains verified, tamper-evident records of the digital identities of both the client device/user and the target server (e.g., device certificates, cryptographic hashes of boot firmware, signed software manifests). Crucially, the blockchain also stores attestations regarding the manufacturing, distribution, and patching history (supply chain integrity) of critical network hardware components (e.g., Network Interface Cards (NICs), routers, DNS proxy appliances, servers) and their associated software images. If the blockchain reveals any unauthorized modifications, suspicious firmware versions, unverified component provenance, or a lapse in patching records for either the client or server in the proposed communication path, the DNS proxy can: (a) refuse to establish a secure link; (b) establish a highly restricted, read-only, or sandboxed link; (c) flag the connection for deep packet inspection by a separate security appliance; or (d) enforce the use of stronger, more resource-intensive cryptographic algorithms. The secure link establishment process itself can also record metadata (e.g., session identifiers, public key hashes exchanged, policy decisions) on a private blockchain to provide an auditable, non-repudiable log of secure connection events, enhancing forensic capabilities.

sequenceDiagram
    participant C as Client
    participant DP as DNS Proxy (Blockchain-Enabled)
    participant B as Blockchain Ledger (Identity/Supply Chain)
    participant DNS as Authoritative DNS
    participant S as Server

    C->>DP: DNS Query (domain.com)
    activate DP
    DP->>B: Query Client Identity & Supply Chain Verif.
    B-->>DP: Client Verification Status (e.g., firmware hash valid)
    DP->>B: Query Server Identity & Supply Chain Verif.
    B-->>DP: Server Verification Status (e.g., component provenance)
    alt Verification Failed
        DP-->>C: Reject Secure Link / Flag for Inspection
    else Verification Successful
        DP->>DP: Establish Secure Link (based on verified trust)
        DP-->>C: Secure Link Established
        DP->>DNS: Forward DNS Query
        DNS->>DP: Server IP
        DP->>B: Record Secure Link Metadata (Session ID, Key Hashes, Policies)
        DP->>C: Secure DNS Response (Server IP)
        deactivate DP
        C->>S: Secure Communication (via blockchain-verified link)
    end

Derivative 9: The "Inverse" or Failure Mode - Safe-Fail Degradation

Enabling Description:
The DNS proxy server is architected for "safe-fail" degradation of secure communication links. Upon intercepting a DNS request and attempting to establish a secure link, the proxy continuously monitors its internal state and external network conditions. If it detects critical resource constraints (e.g., CPU overload exceeding 90% for 5 seconds, memory exhaustion, critical network path congestion) preventing the establishment of a full, high-grade secure link, or if it identifies a potential cryptographic key compromise or protocol negotiation failure during the secure link setup, the proxy automatically initiates a controlled degradation. Instead of a full VPN-like secure tunnel with multi-path IP hopping and strong encryption, it might establish only a pre-defined, minimal-security "failsafe" mode connection (e.g., basic TLS 1.2 with limited cipher suites, or a single static IP route without hopping). In extreme cases of detected compromise or resource unavailability, the DNS proxy can redirect all traffic for that client/server pair to a "quarantine network" (a separate, isolated VLAN with restricted access) or block it entirely, preventing potential data leakage or active exploitation. All such degradation or blocking events are immediately logged to a secure, immutable log and trigger an automated security alert to network administrators, ensuring no inadvertent fallback to insecure cleartext communication or silent failure.

stateDiagram
    [*] --> ClientDNSRequest
    ClientDNSRequest --> ProxyIntercept: DNS Request Received
    ProxyIntercept --> DetectConditions: Check Internal Resources & Security Status
    DetectConditions --> CompromiseDetected: IF Cryptographic Failure OR Key Compromise OR High Threat
    DetectConditions --> ResourceConstraint: ELSE IF CPU/Memory Overload OR Network Congestion
    CompromiseDetected --> QuarantineNetwork: Redirect to Isolated Network / Block Traffic
    ResourceConstraint --> MinimalSecureLink: Downgrade to Basic TLS / Static Route (Failsafe)
    MinimalSecureLink --> LimitedFunctionality: Client Communicates in Limited Mode
    DetectConditions --> FullSecureLink: ELSE (Normal Conditions)
    FullSecureLink --> NormalFunctionality: Client Communicates Normally
    QuarantineNetwork --> AlertAdmin: Generate Critical Security Alert
    MinimalSecureLink --> AlertAdmin: Generate Warning/Info Alert
    FullSecureLink --> Monitor: Continuously Monitor Link Health
    Monitor --> DetectConditions: IF Degradation/Compromise Detected

Derivative 10: The "Inverse" or Failure Mode - Low-Power / Intermittent-Connectivity Optimization

Enabling Description:
For battery-constrained client devices (e.g., deep-sleep IoT sensors, remote environmental monitors, mobile autonomous agents) or in environments characterized by intermittent network connectivity, the DNS proxy server operates in a "low-power/limited-functionality" secure link establishment mode. The "identification of the first computer" within the DNS request includes a specific flag or metadata indicating the client's low-power status and/or expected connectivity profile. Upon intercepting such a request, the proxy establishes a secure link using lightweight cryptographic algorithms (e.g., Elliptic Curve Cryptography (ECC) for key exchange to minimize computational load, AES-GCM with reduced key sizes for data encryption, or pre-shared key (PSK) modes for rapid session establishment). IP address hopping is either minimized to a small, pre-negotiated pool, or a static, energy-optimized secure channel is provisioned for the duration of a short, burst transmission. The proxy prioritizes rapid establishment and teardown of the secure link, minimizing active radio time and CPU wake cycles for the client. The DNS response might also be optimized to return only essential IP addresses, with non-critical DNS records cached or deferred. If the low-power client attempts to access a resource requiring a higher security profile (e.g., real-time video streaming), the proxy might refuse the connection, prompt the client to enter a temporary "full-power" mode, or redirect it to a low-bandwidth proxy service. The secure link also supports asynchronous communication patterns and opportunistic data transfer windows to further conserve client energy during periods of sleep.

sequenceDiagram
    participant LC as Low-Power Client (IoT)
    participant DP as DNS Proxy (Low-Power Mode)
    participant DNS as Authoritative DNS
    participant S as Server

    LC->>DP: DNS Query (low_power_sensor.data, includes Low-Power Flag)
    activate DP
    DP->>DP: Intercept, Recognize Low-Power Flag
    DP->>DP: Select Lightweight Crypto (ECC, AES-GCM, PSK), Minimal IP Hopping/Static Channel
    DP->>LC: Initiate Lightweight Secure Link Setup
    LC->>DP: Lightweight Secure Link Established
    DP->>DNS: Forward DNS Query
    DNS->>DP: Server IP
    DP->>LC: Secure DNS Response (Server IP, optimized)
    deactivate DP
    LC->>S: Burst Secure Communication (low-power, via lightweight link)
    Note over LC,S: Link quickly torn down or kept minimally active; supports async communication

Combination Prior Art Scenarios

  1. US7490151 + DNSCrypt:

    • Description: The DNS proxy server of US7490151 integrates the DNSCrypt protocol to secure the initial DNS request itself. When a client sends a DNS request for a target server, this request is first encrypted and cryptographically signed using the DNSCrypt protocol, establishing a secure channel between the client and the DNS proxy (acting as a DNSCrypt resolver). The DNS proxy intercepts this DNSCrypt-encrypted request, decrypts it, validates its authenticity, and then, in response, proceeds with the standard US7490151 process of establishing a broader secure communication link (e.g., a VPN tunnel) between the client and the target server. The proxy then forwards the original, now-verified DNS query to the authoritative DNS server, potentially over a DNSCrypt connection as well, to maintain end-to-end privacy and integrity. The target server's IP address is returned to the client over the newly established secure communication link.
    • Prior Art Value: This combination renders obvious any claims relating to securing the initial DNS request itself using existing DNS encryption and authentication protocols (like DNSCrypt) as part of a system that then uses a DNS proxy to trigger and establish a broader secure communication link.
  2. US7490151 + WireGuard (for VPN Tunnel Establishment):

    • Description: The "secure communication link" established by the DNS proxy server in response to a DNS request is specifically implemented using the WireGuard VPN protocol. Upon intercepting a client's DNS request, the DNS proxy, acting as a WireGuard endpoint, initiates a WireGuard key exchange and tunnel establishment process with the client. The proxy leverages WireGuard's efficient cryptographic primitives and simple protocol design for rapid and lightweight VPN setup. Once the WireGuard tunnel is established, the DNS proxy forwards the original DNS request to the authoritative domain name server. The resulting IP address of the target server is then delivered back to the client encrypted within the WireGuard tunnel. All subsequent client-to-server application data flows through this high-performance, WireGuard-secured communication link, benefiting from its speed and modern cryptographic assurances.
    • Prior Art Value: This combination renders obvious the application of specific modern, lightweight, and high-performance VPN protocols (such as WireGuard) for the "secure communication link" that is transparently established by a DNS proxy in response to a DNS request.
  3. US7490151 + DNSSEC (for DNS Response Integrity):

    • Description: The DNS proxy server, as described in US7490151, enhances the security of the overall process by integrating DNSSEC (Domain Name System Security Extensions) validation. After intercepting a client's DNS request and before establishing the secure communication link, the DNS proxy forwards the request to an authoritative name server. When the DNS response (containing the target server's IP address) is received by the DNS proxy, the proxy cryptographically validates the authenticity and integrity of this DNS response using DNSSEC records. This step ensures that the resolved IP address has not been spoofed or tampered with by an intermediate attacker. Only after successful DNSSEC validation does the DNS proxy proceed to establish the secure communication link between the client and the verified target server. The validated IP address is then securely transmitted to the client over the newly established secure link, ensuring both the integrity of the resolution and the confidentiality of the subsequent communication.
    • Prior Art Value: This combination renders obvious the incorporation of DNSSEC validation by a DNS proxy to cryptographically verify the integrity and authenticity of DNS resolution results when that resolution triggers the establishment of a secure communication link. This preempts claims attempting to secure the DNS resolution aspect of the process.

Generated 6/13/2026, 9:23:45 PM

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 7490151.