IP Library Granted Patent US 10,972,587
Granted Patent B1
US 10,972,587 · App. 16/560,105 · Granted Apr 6, 2021

Systems and methods for altering the character of network traffic

Inventors: Christopher Edward Delaney (Front Royal, VA); Chava Louis Jurado (Leesburg, VA); Jeremiah MacDonald (Greenville, SC); Carl Bailey Jacobs (Fredericksburg, VA)
Assignee: Berryville Holdings, LLC
H04L69/326H04L12/4641H04L47/36
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,972,587
App. No.
16/560,105
Granted
Apr 6, 2021
Kind
B1
Abstract

Systems and methods for altering the character of data originating from a Virtual Private Network (VPN) are provided. First data is received from the VPN by a first network interface. The first data comprises a first plurality of packets. A message is generated by combining the first plurality of packets. Second data is generated by segmenting the message into a second plurality of packets. A third plurality of packets in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet and the last packet in the second plurality of packets is less than the network maximum transfer unit allowed by the Internet. The second data is forwarded to the second network interface. The second network interface sends the data to a web server.

Claims (56)

1. A system for altering the character of data originating from a Virtual Private Network (VPN), the system comprising:

a first network interface device configured to receive first data from the VPN;

a second network interface device configured to send second data to a webserver;

a data processor coupled to the first network interface device and the second network interface device having memory storing instructions, which when executed result in operations comprising:

receiving the first data from the first network interface device, the first data comprising a first plurality of packets;

generating a message by combining the first plurality of packets;

generating the second data by segmenting the message into a second plurality of packets, wherein a third plurality of packets in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet and the last packet in the second plurality of packets is less than the network maximum transfer unit allowed by the Internet; and

forwarding the second data to the second network interface device;

wherein each packet in the first plurality of packets is smaller than a network maximum transfer unit allowed by the Internet due to the VPN removing VPN headers from third data originating from a user computing device in communication over the Internet with the VPN.

2. The system of claim 1 , the operations further comprising:

determining an external IP address not restricted by the webserver;

sending the second data over the second network interface device using the external IP address as a source address.

3. The system of claim 1 , wherein the first data indicates a desire by the user computing device to perform at least one of the following activities: web browsing, file transfers, media streaming, and domain name server (DNS) lookups.

4. The system of claim 1 , wherein a type of the first network interface device is selected from the group comprising: an Ethernet port, an integrated WiFi adapter, a USB WiFi adaptor, a mobile communications adapter, or a USB-tethered cellular device.

5. The system of claim 1 , wherein the data processor resides on one of the following: a Raspberry Pi, a laptop, a desktop, or a server-grade machine.

6. The system of claim 1 , the operations further comprising:

registering an internal IP address with a VPN service in the VPN, the internal IP address corresponding to a point of presence for accessing the Internet; and

establishing a connection between the first network interface device and the VPN using the internal IP address.

7. The system of claim 1 , wherein all but the last packet in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet.

8. The system of claim 1 , the operations further comprising:

performing network address translation (NAT) on the second data prior to forwarding the second data to the second network interface device.

9. A method for altering the character of data originating from a Virtual Private Network (VPN), the method comprising:

receiving first data from the VPN;

receiving the first data from a first network interface device forming part of a cloaking device, the first data comprising a first plurality of packets;

generating a message by combining the first plurality of packets;

generating second data by segmenting the message into a second plurality of packets, wherein a third plurality of packets in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet and the last packet in the second plurality of packets is less than the network maximum transfer unit allowed by the Internet;

forwarding the second data to a second network interface device forming part of the cloaking device; and

sending, by the second network interface device, second data to a remote computing device;

wherein each packet in the first plurality of packets is smaller than a network maximum transfer unit allowed by the Internet due to the VPN removing VPN headers from third data originating from a user computing device in communication over the Internet with the VPN.

10. The method of claim 9 , wherein the remote computing device is a webserver, and the method further comprises:

determining an external IP address not restricted by the webserver;

sending the second data over the second network interface device using the external IP address as a source address.

11. The method of claim 9 , wherein the first data indicates a user's desire to perform at least one of the following activities: web browsing, file transfers, media streaming, and DNS lookups.

12. The method of claim 9 , wherein a type of the first network interface device is selected from the group comprising: an Ethernet port, an integrated WiFi adapter, a USB WiFi adaptor, a mobile communications adapter, or a USB-tethered cellular device.

13. The method of claim 9 , wherein the data processor resides on one of the following: a Raspberry Pi, a laptop, a desktop, or a server-grade machine.

14. The method of claim 9 , the operations further comprising:

registering an internal IP address with a VPN service in the VPN, the internal IP address corresponding to a point of presence for accessing the Internet; and

establishing a connection between the first network interface device and the VPN using the internal IP address.

15. The method of claim 9 , wherein all but the last packet in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet.

16. The method of claim 9 further comprising:

performing network address translation (NAT) on the second data prior to forwarding the second data to the second network interface.

17. A non-transitory computer readable storage medium for altering the character of data originating from a Virtual Private Network (VPN), the non-transitory computer readable storage medium storing instructions, which when executed by one or more data processors, result in operations comprising:

receiving first data from the VPN;

receiving the first data from a first network interface device, the first data comprising a first plurality of packets;

generating a message by combining the first plurality of packets;

generating second data by segmenting the message into a second plurality of packets, wherein a third plurality of packets in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet and the last packet in the second plurality of packets is less than the network maximum transfer unit allowed by the Internet;

forwarding the second data to a second network interface device forming part of the cloaking device; and

sending, by the second network interface, second data to a remote computing device;

wherein each packet in the first plurality of packets is smaller than a network maximum transfer unit allowed by the Internet due to the VPN removing VPN headers from third data originating from a user computing device in communication over the Internet with the VPN.

18. The non-transitory computer readable storage medium of claim 17 , wherein all but the last packet in the second plurality of packets is equal to the network maximum transfer unit allowed by the Internet.

19. The non-transitory computer readable storage medium of claim 17 , wherein the remote computing device is a webserver and the operations further comprise:

determining an external IP address not restricted by the webserver;

sending the second data over the second network interface device using the external IP address as a source address.

20. The non-transitory computer readable storage medium of claim 17 , wherein the operations further comprise:

registering an internal IP address with a VPN service in the VPN, the internal IP address corresponding to a point of presence for accessing the Internet; and

establishing a connection between the first network interface device and the VPN using the internal IP address.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2022
From: BERRYVILLE HOLDINGS, LLC
To: CYBER IP HOLDINGS, LLC
Reel/Frame 059797/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2020
From: DELANEY, CHRISTOPHER EDWARD; JURADO, CHAVA LOUIS; MACDONALD, JEREMIAH; JACOBS, CARL BAILEY
To: BERRYVILLE HOLDINGS, LLC
Reel/Frame 051547/0862 →
Continuity (1)
Provisional Application 62732691 · Sep 18, 2018
Cited By (2)
US 12,278,712 US 12,407,725