IP Library Granted Patent US 11,323,454
Granted Patent B1
US 11,323,454 · App. 16/262,275 · Granted May 3, 2022

Systems and methods for securing communications

Inventor: Qing Li (Cupertino, CA)
Assignee: NortonLifeLock Inc.
H04L63/105H04L63/0421H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,323,454
App. No.
16/262,275
Granted
May 3, 2022
Kind
B1
Abstract

The disclosed computer-implemented method for securing communications may include (i) establishing an overlay network within a publicly available on-demand cloud computing platform, the overlay network enabling secure communications between devices by maintaining within the overlay network a services mapping table that defines access rights to at least one of shared data or services, and (ii) transferring data, by the overlay network acting as an intermediary, from a first device that has securely connected to the overlay network to a second device that has securely connected to the overlay network, in accordance with the access rights defined in the services mapping table. Various other methods, systems, and computer-readable media are also disclosed.

Claims (61)

1. A computer-implemented method for securing communications, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

establishing an overlay network within a publicly available on-demand cloud computing platform, the overlay network enabling secure communications between devices by maintaining within the overlay network a services mapping table that defines access rights to at least one of shared data or services; and

transferring data, by the overlay network acting as an intermediary, from a first device that has securely connected to the overlay network to a second device that has securely connected to the overlay network, in accordance with the access rights defined in the services mapping table;

wherein:

the overlay network enables secure communications between devices by further maintaining within the overlay network an access table that maintains a record in part of which target Internet protocol address of the publicly available on-demand cloud computing platform the first device used to connect to the overlay network;

the target Internet protocol address is ephemeral; and

a translation operation is performed to translate an identifier into a corresponding service port or network address to transfer the data.

2. The computer-implemented method of claim 1 , wherein the overlay network comprises a zero trust network.

3. The computer-implemented method of claim 1 , wherein the access table further defines which services a connected user provides to other users.

4. The computer-implemented method of claim 1 , wherein the access table further defines which data a connected user provides to other users.

5. The computer-implemented method of claim 1 , wherein the access table further defines at least one of:

an indication that a connected user is actively connected;

an indication of how the connected user prefers to be notified when other users belonging to a same user group become active;

an indication of when at least one service corresponding to another user becomes active; or

an indication of when at least one shared data item corresponding to another user becomes active.

6. The computer-implemented method of claim 1 , wherein the overlay network permits a user account to publish at least one of:

protected data that the user account can make available to another user account; or

a service that the user account can make available to the another user account.

7. The computer-implemented method of claim 6 , wherein the overlay network permits the user account to publish at least one of the protected data and the service in a location independent manner such that publishing occurs regardless of a current location of a user corresponding to the user account.

8. The computer-implemented method of claim 6 , wherein the overlay network enables multiple devices to access at least one of the protected data and the service such that N-to-N communications are permitted as distinct from being limited to either 1-to-1 or 1-to-N communications.

9. The computer-implemented method of claim 1 , wherein:

transferring data, by the overlay network acting as the intermediary, further includes transferring data from a first party corresponding to the first device to a second party corresponding to the second device; and

at least one of the first party and the second party is anonymous from a perspective of the other party.

10. The computer-implemented method of claim 9 , wherein at least one of the first party and the second party is anonymous from the perspective of the other party such that the anonymous party uses an anonymized user account identifier.

11. The computer-implemented method of claim 1 , wherein the overlay network effectively reduces port exposure at a local network gateway through which the first device connects to the overlay network by enabling a user corresponding to the first device to close a service port of a firewall at the local network gateway and, instead of transferring the data across the service port, transferring the data using the overlay network as the intermediary.

12. The computer-implemented method of claim 1 , wherein transferring the data is performed without data caching inside the overlay network such that the data passes from the first device to the second device in a pass-through manner with respect to the overlay network.

13. The computer-implemented method of claim 1 , wherein the first device and the second device securely connect to the overlay network using network communications conforming to at least one of:

the INTERNET PROTOCOL SECURITY (IPSEC) protocol;

the TRANSPORT LAYER SECURITY protocol;

the SECURE SOCKETS LAYER protocol;

the SECURE SHELL protocol; or

a public key infrastructure.

14. A system for securing communications, the system comprising:

an establishment module, stored in memory, that establishes an overlay network within a publicly available on-demand cloud computing platform, the overlay network enabling secure communications between devices by maintaining within the overlay network a services mapping table that defines access rights to at least one of shared data or services;

a transferring module, stored in memory, that transfers data, as part of the overlay network acting as an intermediary, from a first device that has securely connected to the overlay network to a second device that has securely connected to the overlay network, in accordance with the access rights defined in the services mapping table; and

at least one physical processor configured to execute the establishment module and the transferring module;

wherein:

the overlay network enables secure communications between devices by further maintaining within the overlay network an access table that maintains a record in part of which target Internet protocol address of the publicly available on-demand cloud computing platform the first device used to connect to the overlay network;

the target Internet protocol address is ephemeral; and

the transferring module is configured to perform a translation operation to translate an identifier into a corresponding service port or network address to transfer the data.

15. The system of claim 14 , wherein the overlay network comprises a zero trust network.

16. The system of claim 14 , wherein the access table further defines which services a connected user provides to other users.

17. The system of claim 14 , wherein the access table further defines which data a connected user provides to other users.

18. The system of claim 16 , wherein the access table further defines at least one of:

an indication that a connected user is actively connected;

an indication of how the connected user prefers to be notified when other users belonging to a same user group become active;

an indication of when at least one service corresponding to another user becomes active; or

an indication of when at least one shared data item corresponding to another user becomes active.

19. The system of claim 14 , wherein the first device and the second device securely connect to the overlay network using network communications conforming to at least one of:

the INTERNET PROTOCOL SECURITY (IPSEC) protocol;

the TRANSPORT LAYER SECURITY protocol;

the SECURE SOCKETS LAYER protocol;

the SECURE SHELL protocol; or

a public key infrastructure.

20. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

establish an overlay network within a publicly available on-demand cloud computing platform, the overlay network enabling secure communications between devices by maintaining within the overlay network a services mapping table that defines access rights to at least one of shared data or services; and

transfer data, by the overlay network acting as an intermediary, from a first device that has securely connected to the overlay network to a second device that has securely connected to the overlay network, in accordance with the access rights defined in the services mapping table;

wherein:

the overlay network enables secure communications between devices by further maintaining within the overlay network an access table that maintains a record in part of which target Internet protocol address of the publicly available on-demand cloud computing platform the first device used to connect to the overlay network;

the target Internet protocol address is ephemeral; and

a translation operation is performed to translate an identifier into a corresponding service port or network address to transfer the data.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2019
From: LI, QING
To: SYMANTEC CORPORATION
Reel/Frame 048191/0906 →
Cited By (5)
US 12,411,971 US 12,500,760 US 12,531,886 US 12,652,293 US 12,652,301