IP Library › Granted Patent US 10,129,074
Granted Patent B2
US 10,129,074 · App. 15/912,843 · Granted Nov 13, 2018

Techniques for accessing logical networks via a virtualized gateway

Inventor: Ahmed Fuad Siddiqui (Everett, WA)
Assignee: Amazon Technologies, Inc.
H04L41/04H04L12/4633H04L12/4641H04L29/06H04L41/0896H04L41/5054H04L63/0272H04L63/08H04L63/10H04L67/02H04L67/08H04L67/10H04L67/1008H04L67/141H04L69/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,129,074
App. No.
15/912,843
Granted
Nov 13, 2018
Kind
B2
Abstract

Disclosed are various embodiments for receiving, via a network, a request from a client to establish a network tunnel over the network. A credential is received from the client in order to establish the network tunnel. The client is authenticated based upon the credential. The client negotiates, via the network, to establish the network tunnel.

Claims (28)

1. A system comprising:

a computing device comprising a processor and a memory; and

machine readable instructions stored in the memory that, when executed by the processor of the computing device, cause the computing device to at least:

create a virtual network comprising a virtual network gateway in response to receipt of a service call from a client device;

transmit a virtual network address to the client device in response to establishment of a connection between the virtual network gateway and the client device; and

allocate an available second computing resource to the virtual network gateway to augment a first computing resource assigned to the virtual network gateway in response to usage of the first computing resource exceeding a threshold.

2. The system of claim 1 , wherein the machine readable instructions further cause the computing device to identify a permission associated with the client device, the permission specifying a limitation of the client device on access to a portion of the virtual network.

3. The system of claim 2 , wherein the machine readable instructions further cause the computing device to limit access of the client device to the portion of the virtual network specified in the permission.

4. The system of claim 3 , wherein the machine readable instructions that cause the computing device to limit access of the client device to the portion of the virtual network specified in the permission further cause the computing device to limit the access of the client device from a virtual network address.

5. The system of claim 1 , wherein the machine readable instructions further cause the computing device to at least terminate the connection between the virtual network gateway and the client device in response to receipt of a command to terminate the connection.

6. The system of claim 1 , wherein the machine readable instructions further cause the computing device to at least encrypt the connection between the virtual network gateway and the client device.

7. The system of claim 1 , wherein the machine readable instructions further cause the computing device to at least:

receive authentication credentials from the client device;

determine that the authentication credentials are valid; and

allocate the virtual network address for the client device in response to determining that the authentication credentials are valid.

8. A computer-implemented method, comprising:

creating, in response to receiving a service call in at least one computing device, a virtual network comprising a virtual network gateway;

transmitting, in response to the service call to the at least one computing device, a virtual network address to a client device establishing a connection with the virtual network gateway;

allocating, in the at least one computing device, an available second computing resource to the virtual network gateway to augment a first computing resource assigned to the virtual network gateway when usage of the first computing resource meets a predefined allocation threshold; and

identifying a permission associated with the client device, the permission specifying a limitation of the client device on access to a portion of the virtual network.

9. The computer-implemented method of claim 8 , further comprising encrypting the connection of the client device with the virtual network gateway.

10. The computer-implemented method of claim 8 , further comprising limiting access of the client device to the portion of the virtual network specified in the permission.

11. The computer-implemented method of claim 10 , wherein limiting access of the client device to the portion of the virtual network specified in the permission further comprises limiting the access of the client device from a virtual network address.

12. The computer-implemented method of claim 8 , further comprising terminating the connection between the client device and the virtual network gateway in response to receiving a notification to terminate the connection.

13. The computer-implemented method of claim 8 , further comprising:

receiving authentication credentials from the client device;

determining that the authentication credentials are valid; and

assigning the virtual network address to the client device in response to determining that the authentication credentials are valid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2018
From: SIDDIQUI, AHMED FUAD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 045430/0838 →
Continuity (3)
Continuation 15426225 · Feb 7, 2017
Continuation 13683658 · Nov 21, 2012
Related Publication 20180198675A1 · Jul 12, 2018