IP Library Granted Patent US 8,528,070
Granted Patent B2
US 8,528,070 · App. 11/899,288 · Granted Sep 3, 2013

System and method for secure service delivery

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,528,070
App. No.
11/899,288
Granted
Sep 3, 2013
Kind
B2
Abstract

A secure service delivery network, including a service delivery compartment connected to deliver services to a plurality of client networks. The secure service delivery network includes a first firewall connecting the service delivery compartment to a first virtual local area network. The secure service delivery network includes a plurality of firewalls each connecting one of the plurality of client networks to the first virtual local area network, whereby no communications between the plurality of client networks can be made over the first virtual local area network. A related method is also described.

Claims (27)

1. A secure service delivery data processing system, comprising:

a computer for receiving requests for services from a plurality of client networks;

a service delivery compartment application, at a computer system, connected to deliver services to a plurality of client networks using a secure service delivery network wherein said services comprise secure access to leveraged compute resources;

a first virtual firewall, at said computer system, connecting the service delivery compartment to a first virtual local area network;

a plurality of firewalls, at said computer system, each connecting one of the plurality of client networks to the first virtual local area network, whereby no communications between the plurality of client networks can be made over the first virtual local area network;

a leveraged services compartment application connected to provide compute resources, the leveraged services compartment application connected to communicate with the first virtual local area network, wherein the leveraged services compartment application is connected to communicate with the first virtual local area network via the first virtual firewall;

a plurality of virtual routing and forwarding (VRF) nodes connected between the plurality of firewalls and the first virtual local area network; and

a plurality of virtual local area networks each associated with one of the plurality of client networks and connected between the plurality of firewalls and the plurality of VRF nodes, wherein none of the plurality of client networks can detect another of the plurality of client networks.

2. The secure service delivery data processing system of claim 1 , wherein at least one of the plurality of firewalls is a virtual firewall.

3. The secure service delivery data processing system of claim 1 , further comprising a secure network access gateway computer connected to communicate with the first virtual local area network.

4. The secure service delivery data processing system of claim 1 , wherein at least some of the plurality of VRF nodes communicate using Enhanced Interior Gateway Routing Protocol.

5. The secure service delivery data processing system of claim 1 , further comprising at least one network address translation (NAT) remediation rail connected to a VRF node.

6. The secure service delivery data processing system of claim 1 , further comprising a virtual private network connected to a VRF node.

7. The secure service delivery data processing system of claim 1 , further comprising a backup and restore rail associated with one of the plurality of client networks.

8. The secure service delivery data processing system of claim 7 , further comprising a firewall connected between the backup and restore rail and the first virtual local area network.

9. The secure service delivery data processing system of claim 1 , wherein each of the plurality of client networks can communicate with a secure delivery compartment.

10. A computer-implemented method of delivering services to a plurality of client networks, comprising:

receiving requests for services from a plurality of client networks, by a computer system, wherein said services comprise secure access to leveraged compute resources;

delivering the services to the plurality of client networks using a secure service delivery network, by said computer system; and

wherein the secure service delivery network includes a service delivery compartment application connected to deliver the services to the plurality of client networks, a first virtual firewall connecting the service delivery compartment to a first virtual local area network, and a plurality of firewalls each connecting one of the plurality of client networks to the first virtual local area network,

wherein no communications between the plurality of client networks can be made over the first virtual local area network,

wherein a leveraged services compartment application is connected to provide compute resources, the leveraged services compartment application is connected to communicate with the first virtual local area network and the leveraged services compartment application is connected to communicate with the first virtual local area network via the first virtual firewall,

wherein a plurality of virtual routing and forwarding (VRF) nodes are connected between the plurality of firewalls and the first virtual local area network,

wherein a plurality of virtual local area networks each associated with one of a plurality of client networks and connected between the plurality of firewalls and the plurality of VRF nodes, and

wherein none of the plurality of client networks can detect another of the plurality of client networks.

11. The computer-implemented method of claim 10 , wherein at least one of the plurality of firewalls is a virtual firewall.

12. The computer-implemented method of claim 10 , wherein the secure service delivery network also includes a secure network access gateway computer connected to communicate with the first virtual local area network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2009
From: ELECTRONIC DATA SYSTEMS, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 022449/0267 →
CHANGE OF NAME Recorded Mar 24, 2009
From: ELECTRONIC DATA SYSTEMS CORPORATION
To: ELECTRONIC DATA SYSTEMS, LLC
Reel/Frame 022460/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2007
From: STIEKES, BRYAN E.; WILLIAMS, SHAWN A.
To: ELECTRONIC DATA SYSTEMS CORPORATION
Reel/Frame 019851/0968 →