IP Library Granted Patent US 9,860,342
Granted Patent B2
US 9,860,342 · App. 15/237,271 · Granted Jan 2, 2018

Systems and methods for protecting an identity in network communications

Inventor: Barbara M. Hunt (McLean, VA)
Assignee: Cutting Edge Consulting Associates, Inc.
H04L67/34G06F9/5038H04L29/08981H04L45/22H04L45/586H04L63/0407H04L67/10H04L49/70H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,860,342
App. No.
15/237,271
Granted
Jan 2, 2018
Kind
B2
Abstract

In some embodiments, a method includes sending a first data unit, received from a source device, to a destination device via a first data unit path. The first data unit path includes (1) a first virtual machine and a second virtual machine that are included in a first network, and (2) a third virtual machine that is included in a second network. Furthermore, the first data unit path includes the first virtual machine, the second virtual machine, and the third virtual machine in a first order. The method includes sending a second data unit, received from the source device, to the destination device via a second data unit path from the source device to the destination device. The second data unit path includes each of the first virtual machine, the second virtual machine, and the third virtual machine in a second order different from the first order.

Claims (32)

1. A non-transitory processor readable medium storing code representing instructions configured to be executed by a processor, the code comprising code to cause the processor to:

define a first virtual network that is configured to be operatively coupled to a source device and that includes a first virtual machine and a second virtual machine instantiated in a first cloud;

define a second virtual network that is configured to be operatively coupled to a destination device and that includes a third virtual machine and a fourth virtual machine instantiated in a second cloud;

route a first data unit from the source device to the destination device via the first virtual machine and the third virtual machine; and

route a second data unit from the source device to the destination device via the second virtual machine and the fourth virtual machine.

2. The non-transitory processor readable medium of claim 1 , wherein the first cloud includes a first plurality of servers and the second cloud includes a second plurality of servers mutually exclusive from the first plurality of servers.

3. The non-transitory processor readable medium of claim 1 , wherein the first cloud includes a first plurality of servers and the second cloud includes a second plurality of servers, at least one server from the first plurality of servers being included within the second plurality of servers.

4. The non-transitory processor readable medium of claim 1 , wherein the source device is communicatively coupled to the first cloud via an open systems interconnection (OSI) layer 3 connection.

5. The non-transitory processor readable medium of claim 1 , wherein the source device is communicatively coupled to the first cloud via an open systems interconnection (OSI) layer 2 connection.

6. The non-transitory processor readable medium of claim 1 , wherein the first virtual machine is communicatively coupled to the third virtual machine via an open systems interconnection (OSI) layer 2 connection tunneled within an OSI layer 3 connection.

7. The non-transitory processor readable medium of claim 1 , the code further comprising code to cause the processor to route the first data unit from the source device to the first virtual machine via a fifth virtual machine.

8. The non-transitory processor readable medium of claim 1 , the code further comprising code to cause the processor to route the first data unit from the source device to the first virtual machine via a fifth virtual machine instantiated in the first cloud.

9. The non-transitory processor readable medium of claim 1 , the code further comprising code to cause the processor to route the first data unit from the first virtual machine to the third virtual machine via an internal internet protocol (IP) address assigned by at least one of the first cloud or the second cloud.

10. A non-transitory processor readable medium storing code representing instructions configured to be executed by a processor, the code comprising code to cause the processor to:

define, at a first time, a first data unit path from a source device to a destination device, the first data unit path including a first virtual machine and a second virtual machine, the first virtual machine instantiated on at least one server of a first cloud, the second virtual machine instantiated on at least one server of a second cloud that is physically mutually exclusive from the first cloud; and

define, at a second time, a second data unit path from the source device to the destination device, the second data unit path including a third virtual machine and at least one of the first virtual machine or the second virtual machine, the second data unit path being different from the first data unit path.

11. The non-transitory processor readable medium of claim 10 , the code further comprising code to cause the processor to:

route a first data unit via the first data unit path; and

route a second data unit via the second data unit path.

12. The non-transitory processor readable medium of claim 10 , the code further comprising code to cause the processor to dynamically select one of the first data unit path or the second data unit path for a data unit based on a schedule.

13. The non-transitory processor readable medium of claim 10 , the code further comprising code to cause the processor to randomly or pseudo-randomly select one of the first data unit path or the second data unit path for a data unit.

14. The non-transitory processor-readable medium of claim 10 , the code further comprising code to:

detect an attempt to identify the source device at a third time after the first time and before the second time, the second data unit path defined in response to detecting the attempt to identify the source device.

15. A non-transitory processor readable medium storing code representing instructions configured to be executed by a processor, the code comprising code to cause the processor to:

send a first data unit received from a source device to a destination device via a first data unit path that traverses a first network via at least one first network virtual machine and a second network via at least one second network virtual machine; and

send a second data unit received from the source device to the destination device via a second data unit path different from the first data unit path, the second data unit path traversing the first network via the at least one first network virtual machine and the second network via the at least one second network virtual machine.

16. The non-transitory processor readable medium of claim 15 , wherein the second data unit path includes at least one of the first virtual machine or the second virtual machine.

17. The non-transitory processor readable medium of claim 15 , the code further comprising code to cause the processor to:

define first data unit path; and

define the second data unit path in response to a scheduled event.

18. The non-transitory processor readable medium of claim 15 , the code further comprising code to cause the processor to send the first data unit from the first virtual machine to the second virtual machine using a routing table.

19. The non-transitory processor readable medium of claim 15 , wherein the code further comprising code to cause the processor to send the first data unit from the first virtual machine to the second virtual machine using an internal internet protocol (IP) address.

Assignments (6)
SECURITY INTEREST Recorded Oct 31, 2024
From: CONCEAL, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 069092/0485 →
SECURITY INTEREST Recorded Feb 16, 2023
From: CONCEAL, INC.
To: SIGNATURE BANK
Reel/Frame 062721/0242 →
CHANGE OF NAME Recorded Nov 1, 2022
From: NETABSTRACTION, INC.
To: CONCEAL, INC.
Reel/Frame 061828/0373 →
SECURITY INTEREST Recorded Sep 3, 2021
From: NETABSTRACTION, INC.
To: SIGNATURE BANK
Reel/Frame 057381/0019 →
CHANGE OF NAME Recorded Jun 14, 2018
From: CUTTING EDGE CONSULTING ASSOCIATES, INC.
To: NETABSTRACTION, INC.
Reel/Frame 046363/0967 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2017
From: HUNT, BARBARA M.
To: CUTTING EDGE CONSULTING ASSOCIATES, INC.
Reel/Frame 043325/0511 →
Continuity (3)
Continuation 13961379 · Aug 7, 2013
Provisional Application 61732664 · Dec 3, 2012
Related Publication 20170006136A1 · Jan 5, 2017