IP Library Granted Patent US 11,165,825
Granted Patent B2
US 11,165,825 · App. 15/932,254 · Granted Nov 2, 2021

System and method for creating encrypted virtual private network hotspot

Inventors: Jesse Aaron Adams (Seattle, WA); Christopher Joseph O'Connell (Tucson, AZ); Jennifer Marie Catanduanes McEwen (Seattle, WA)
Assignee: Emerald Cactus Ventures, Inc.
H04L63/18H04L12/4675H04W12/03H04W12/06H04W12/08H04W48/16H04L63/0272H04L63/0428H04W12/086H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,825
App. No.
15/932,254
Granted
Nov 2, 2021
Kind
B2
Abstract

System and method for extending zones of control through a hotspot for communications to and from computing devices based on specific criteria corresponding to zones of control. An encrypted virtual private network (VPN) for a browsing session may be established at a first computing device and remote server computers matching the parameters of the established zone. Then, a user of the first computing device may further establish a wireless hotspot network suited to allow additional remote computing devices to piggy-back on the one or more established encrypted virtual private networks. Thus, other connected devices using the hotspot connection to reach a broader computer network (e.g., the Internet) are then also taking advantage of the encrypted VPN being provided by the host of the hotspot. Each connected computing device may then also have various communications isolated through zonal control from the hotspot device.

Claims (38)

1. A computing device, comprising:

a processor configured to execute instructions stored in a memory;

a software-based browser module stored in the memory and configured to be executed by the processor and configured to establish first and second encrypted communication links with respective first and second external computing devices;

a software-based zone control module stored configured to be executed by the processor in the memory and controlled by the browser module, the zone control module further configured to:

establish a first zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the first zone of control, the first zone of control isolating communications coordinated by the browser module based on a first user-generated customized criteria that identifies a first geographic region corresponding exclusively to a first physical location of at least a first one of the one or more external computing devices such that communications that originate outside of the first zone of control are restricted from accessing data generated by the communications within the first zone of control without impacting communications coordinated by the communication module; and

establish a second zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the second zone of control, the second zone of control isolating communications coordinated by the browser module based on second user-generated customized criteria that identifies a second geographic region that is mutually exclusive of the first geographic region, the second geographic region corresponding exclusively to a second physical location of at least a second one of the one or more external computing devices such that communications that originate outside of the second zone of control are restricted from accessing data generated by the communications within the second zone of control without impacting communications coordinated by the communication module, the second permission rules based on the second geographic region wherein at least one file type does not have permission to be communication to the browser modules within the second zone of control;

a hardware-based communication module coupled to the processor and configured to communicate with the one or more external computing devices through a computer network using the communication link through the browser module wherein communications are isolated in the first zone of control, the communication module further configured to establish a local hotspot network wherein communications through the local hotspot network are isolated in the first zone of control; and

a cache memory exclusively associated with the first zone of control and configured to store data associated with communications within the first zone of control such that access to the cache memory from any other communication link outside of the first zone of control is prevented.

2. The computing device of claim 1 , wherein the communication link comprises a virtual private network communication link.

3. The computing device of claim 1 , wherein the local hotspot network comprises a Wi-Fi network.

4. The computing device of claim 1 , wherein communications through the local hotspot network comprise encrypted communications.

5. The computing device of claim 1 , further comprising a second browser module configured to facilitate communications in the local hotspot network outside of the first zone of control.

6. The computing device in claim 1 , where the browser module is isolated within the computing device when the hotspot establishment is initiated from the one or more external computing devices.

7. A computing system, comprising:

a server computing device configured to communicate data through a computer network;

a first local computing device configured to communicate with the server computing device through the computer network, the first local computing device further comprising:

a processor configured to execute instructions stored in a memory;

a software-based browser module stored in the memory and configured to be executed by the processor and configured to establish first and second encrypted communication links with respective first and second external computing devices;

a software-based zone control module stored configured to be executed by the processor in the memory and controlled by the browser module, the zone control module further configured to:

establish a first zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the first zone of control, the first zone of control isolating communications coordinated by the browser module based on a first user-generated customized criteria that identifies a first geographic region corresponding exclusively to a first physical location of at least a first one of the one or more external computing devices such that communications that originate outside of the first zone of control are restricted from accessing data generated by the communications within the first zone of control without impacting communications coordinated by the communication module; and

establish a second zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the second zone of control, the second zone of control isolating communications coordinated by the browser module based on second user-generated customized criteria that identifies a second geographic region that is mutually exclusive of the first geographic region, the second geographic region corresponding exclusively to a second physical location of at least a second one of the one or more external computing devices such that communications that originate outside of the second zone of control are restricted from accessing data generated by the communications within the second zone of control without impacting communications coordinated by the communication module, the second permission rules based on the second geographic region wherein at least one file type does not have permission to be communication to the browser modules within the second zone of control; and

a hardware-based communication module coupled to the processor and configured to communicate with the one or more external computing devices through a computer network using the communication link through the browser module wherein communications are isolated in the first zone of control, the communication module further configured to establish a local hotspot network wherein communications through the local hotspot network are isolated in the first zone of control; and

a cache memory exclusively associated with the first zone of control and configured to store data associated with communications within the first zone of control such that access to the cache memory from any other communication link outside of the first zone of control is prevented; and

a second local computing device configured to connect to the local hotspot network and configured to communicate data through the second zone of control.

8. The computer system of claim 7 , further comprising a third local computing device configured to connect to the local hotspot network and configured to communicate data through the first zone of control.

9. The computer system of claim 7 , further comprising a third local computing device configured to connect to the local hotspot network and configured to communicate data through the local hotspot network and isolated from other communications within the first zone of control.

10. The computer system of claim 7 , further comprising a third local computing device configured to connect to the local hotspot network and configured to communicate data through the local hotspot network that is isolated from other communications within the first zone of control.

11. The computer system of claim 7 , further comprising a second server computing device configured to communicate data through the computer network to the first local computing device that is isolated from other communications within the first zone of control.

12. The computer system of claim 7 , further comprising proxy server computing device coupled between the server computing device and the first local computing device configured to facilitate communications within the first zone of control.

13. A computer-based method, comprising:

instantiating a browser having a private encrypted communication channel at a first local computing device;

establishing a first zone of control associated with received data from at least one external computing device, the first zone of control associated with the instantiated browser and associated with a first isolated cache memory, the first zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the first zone of control, the first zone of control isolating communications coordinated by the browser module based on a first user-generated customized criteria that identifies a first geographic region corresponding exclusively to a first physical location of at least a first one of the one or more external computing devices such that communications that originate outside of the first zone of control are restricted from accessing data generated by the communications within the first zone of control without impacting communications coordinated by the communication module;

establishing a first zone of control associated with received data from at least one external computing device, the first zone of control associated with the instantiated browser and associated with a first isolated cache memory, the second zone of control having permission rules based on specific server locations wherein only certain types of files or sites are allowed to load from the second zone of control, the second zone of control isolating communications coordinated by the browser module based on second user-generated customized criteria that identifies a second geographic region that is mutually exclusive of the first geographic region, the second geographic region corresponding exclusively to a second physical location of at least a second one of the one or more external computing devices such that communications that originate outside of the second zone of control are restricted from accessing data generated by the communications within the second zone of control without impacting communications coordinated by the communication module, the second permission rules based on the second geographic region wherein at least one file type does not have permission to be communication to the browser modules within the second zone of control;

isolating communications coordinated by the instantiated browser that occur outside of the first and second zones of control from communications that occur within the first and second zones of control via encryption and isolating communications between the first and second zones such that access by a communication within the second zone of control to data stored in the first cache memory is prevented and such that access by a communication within the first zone of control to data stored in the second cache memory is prevented; and

facilitating communication of the isolated communications within the zone of control with a second local computing device through a local hotspot network.

14. The method of claim 13 , further comprising disallowing communications to and from the second local computing device outside of the first zone of control.

15. The method of claim 13 , further comprising instantiating a second browser to coordinate communication outside of the second zone of control.

16. The method of claim 13 , further comprising restricting the data coordinated by the instantiated browser within the first zone of control from access by communication or computation occurring outside of the first zone of control without impacting communications outside of the first zone of control.

Assignments (6)
MERGER Recorded Feb 24, 2023
From: AVAST SOFTWARE, INC.
To: GEN DIGITAL INC.
Reel/Frame 062799/0677 →
MERGER Recorded Oct 22, 2021
From: EMERALD CACTUS VENTURES, INC.
To: AVAST SOFTWARE, INC.
Reel/Frame 057877/0404 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2018
From: EMERALD CACTUS VENTURES, LLC
To: EMERALD CACTUS VENTURES, INC.
Reel/Frame 047676/0335 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TITLE PREVIOUSLY RECORDED ON REEL 046475 FRAME 0200. ASSIGNOR(S) HEREBY CONFIRMS THE SYSTEM AND METHOD FOR CREATING ENCRYPTED VIRTUAL PRIVATE NETWORK HOTSPOT. Recorded Aug 3, 2018
From: TENTA, LLC
To: EMERALD CACTUS VENTURES, LLC
Reel/Frame 047446/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2018
From: TENTA, LLC
To: EMERALD CACTUS VENTURES, LLC
Reel/Frame 046475/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2018
From: ADAMS, JESSE A; O'CONNELL, CHRISTOPHER J; MCEWEN, JENNIFER C
To: TENTA, LLC
Reel/Frame 045602/0775 →
Continuity (2)
Provisional Application 62459903 · Feb 16, 2017
Related Publication 20180234456A1 · Aug 16, 2018