IP Library Granted Patent US 10,912,053
Granted Patent B2
US 10,912,053 · App. 16/741,934 · Granted Feb 2, 2021

Enforcing geographic restrictions for multitenant overlay networks

Inventors: David Robinson Bild (Chicago, IL); Mario Frank DeRango (Cary, IL)
Assignee: Xaptum, Inc.
H04W60/005H04W8/04H04W8/082H04W40/246H04W40/28H04W64/003H04W88/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,912,053
App. No.
16/741,934
Granted
Feb 2, 2021
Kind
B2
Abstract

A method includes receiving, via a core network in accordance with a regional data routing plan, an affiliation request from a data source device based on a first level regional affiliation of the data source device and a first computing entity. The method further includes determining whether a second level regional affiliation is substantially equal to the first level regional affiliation. When the second level regional affiliation is not substantially equal to the first level regional affiliation, the method further includes identifying a second computing entity based on the second level regional affiliation and sending a notification message to the second computing entity regarding the data source device being affiliated with the second computing entity. The method further includes broadcasting a gateway message to the core network to change the regional data routing plan such that data from the data source device is routed to the second computing entity.

Claims (96)

1. A method comprises:

receiving, by a first computing entity via a core network in accordance with a regional data routing plan, an affiliation request from a data source device based on a first level regional affiliation of the data source device and the first computing entity;

determining, by the first computing entity, whether a second level regional affiliation of the data source device and the first computing entity is substantially equal to the first level regional affiliation; and

when the second level regional affiliation is not substantially equal to the first level regional affiliation:

identifying, by the first computing entity, a second computing entity based on the second level regional affiliation;

sending, by the first computing entity, a notification message to the second computing entity regarding the data source device being affiliated with the second computing entity; and

broadcasting, by the second computing entity, a gateway message to the core network, wherein the gateway message changes the regional data routing plan such that data from the data source device is routed to the second computing entity.

2. The method of claim 1 further comprises:

when the second level regional affiliation is substantially equal to the first level regional affiliation:

broadcasting, by the first computing entity, a second gateway message to the core network, wherein the second gateway message changes the regional data routing plan such that the data from the data source device is routed to the first computing entity.

3. The method of claim 1 further comprises:

when the second level regional affiliation is not substantially equal to the first level regional affiliation:

receiving, by the second computing entity via the core network, the data from the data source device; and

transferring, by the second computing entity, the data from the data source device to a user computing device in accordance with the second level regional affiliation.

4. The method of claim 1 , wherein the determining whether the second level regional affiliation of the data source device and the first computing entity is substantially equal to the first level regional affiliation comprises one or more of:

determining the second level regional affiliation based on one or more of:

a geographic location of the data source device;

a home geographic region of the data source device;

a geographic region of the first computing entity;

a geographic region of the second computing entity;

a data storage restriction of a data type of the data from the data source device;

another data storage restriction of the data from the data source device; and

a data group associated with the data source device and a computing entity associated with the data group;

indicating that the second level regional affiliation of the data source device and the first computing entity is not substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the second computing entity; and

indicating that the second level regional affiliation of the data source device and the first computing entity is substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the first computing entity.

5. The method of claim 1 , wherein the identifying the second computing entity based on the second level regional affiliation comprises one or more of:

identifying a user computing device to receive the data from the data source device, wherein the user computing device is associated with the second computing entity; and

performing an edge computing device table lookup to identify an entry that associates the second computing entity with the second level regional affiliation.

6. The method of claim 1 , wherein the broadcasting the gateway message to the core network comprises:

generating the gateway message in accordance with a border gateway protocol based to advertise an address associated with a user computing device to receive the data from the data source device, wherein the user computing device is associated with the second computing entity in accordance with the second level regional affiliation; and

sending the gateway message to a border router of the core network.

7. A computing entity comprises:

an interface;

a local memory; and

a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:

receive, via the interface from a core network in accordance with a regional data routing plan, an affiliation request from a data source device based on a first level regional affiliation of the data source device and the computing entity;

determine whether a second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation; and

when the second level regional affiliation is not substantially equal to the first level regional affiliation:

identify a second computing entity based on the second level regional affiliation; and

send, via the interface, a notification message to the second computing entity regarding the data source device being affiliated with the second computing entity, wherein the second computing entity broadcasts a gateway message to the core network in response to receiving the notification message, wherein the gateway message changes the regional data routing plan such that data from the data source device is routed to the second computing entity.

8. The computing entity of claim 7 , wherein the processing module further functions to:

when the second level regional affiliation is substantially equal to the first level regional affiliation:

broadcast, via the interface, a second gateway message to the core network, wherein the second gateway message changes the regional data routing plan such that the data from the data source device is routed to the computing entity.

9. The computing entity of claim 7 , wherein the processing module functions to send the notification message to the second computing entity regarding the data source device being affiliated with the second computing entity by:

generating the notification message to indicate that the data source device is affiliated with the second computing entity; and

transmitting, via the interface, the notification message to the second computing entity, wherein the second computing entity receives, via the core network, the data from the data source device and transfers the data to a user computing device in accordance with the second level regional affiliation.

10. The computing entity of claim 7 , wherein the processing module functions to determine whether the second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation by one or more of:

determining the second level regional affiliation based on one or more of:

a geographic location of the data source device;

a home geographic region of the data source device;

a geographic region of the computing entity;

a geographic region of the second computing entity;

a data storage restriction of a data type of the data from the data source device;

another data storage restriction of the data from the data source device; and

a data group associated with the data source device and a computing device associated with the data group;

indicating that the second level regional affiliation of the data source device and the computing entity is not substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the second computing entity; and

indicating that the second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the computing entity.

11. The computing entity of claim 7 , wherein the processing module functions to identify the second computing entity based on the second level regional affiliation by one or more of:

identifying a user computing device to receive the data from the data source device, wherein the user computing device is associated with the second computing entity; and

performing an edge computing device table lookup to identify an entry that associates the second computing entity with the second level regional affiliation.

12. The computing entity of claim 7 , wherein the processing module further functions to send the notification message to the second computing entity regarding the data source device being affiliated with the second computing entity by:

generating the notification message to indicate that the data from the data source device is to be routed to the second computing entity; and

transmitting, via the interface, the notification message to the second computing entity, wherein the second computing entity generates the gateway message in accordance with a border gateway protocol based to advertise an address associated with a user computing device to receive the data from the data source device, wherein the second computing entity sends the gateway message to a border router of the core network, and wherein the user computing device is associated with the second computing entity in accordance with the second level regional affiliation.

13. A computer readable memory comprises:

a first memory element that stores operational instructions that, when executed by a processing module, causes the processing module to:

receive, from a core network in accordance with a regional data routing plan, an affiliation request from a data source device based on a first level regional affiliation of the data source device and a computing entity;

a second memory element that stores operational instructions that, when executed by the processing module, causes the processing module to:

determine whether a second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation; and

a third memory element that stores operational instructions that, when executed by the processing module, causes the processing module to:

when the second level regional affiliation is not substantially equal to the first level regional affiliation:

identify a second computing entity based on the second level regional affiliation; and

send a notification message to the second computing entity regarding the data source device being affiliated with the second computing entity, wherein the second computing entity broadcasts a gateway message to the core network in response to receiving the notification message, wherein the gateway message changes the regional data routing plan such that data from the data source device is routed to the second computing entity.

14. The computer readable memory of claim 13 further comprises:

a fourth memory element that stores operational instructions that, when executed by the processing module, causes the processing module to:

when the second level regional affiliation is substantially equal to the first level regional affiliation:

broadcast a second gateway message to the core network, wherein the second gateway message changes the regional data routing plan such that the data from the data source device is routed to the computing entity.

15. The computer readable memory of claim 13 , wherein the processing module functions to execute the operational instructions stored by the third memory element to cause the processing module to send the notification message to the second computing entity regarding the data source device being affiliated with the second computing entity by:

generating the notification message to indicate that the data source device is affiliated with the second computing entity; and

transmitting the notification message to the second computing entity, wherein the second computing entity receives, via the core network, the data from the data source device and transfers the data to a user computing device in accordance with the second level regional affiliation.

16. The computer readable memory of claim 13 , wherein the processing module functions to execute the operational instructions stored by the second memory element to cause the processing module to determine whether the second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation by one or more of:

determining the second level regional affiliation based on one or more of:

a geographic location of the data source device;

a home geographic region of the data source device;

a geographic region of the computing entity;

a geographic region of the second computing entity;

a data storage restriction of a data type of the data from the data source device;

another data storage restriction of the data from the data source device; and

a data group associated with the data source device and a computing device associated with the data group;

indicating that the second level regional affiliation of the data source device and the computing entity is not substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the second computing entity; and

indicating that the second level regional affiliation of the data source device and the computing entity is substantially equal to the first level regional affiliation when the second level regional affiliation indicates that the data from the data source device is to be routed to the computing entity.

17. The computer readable memory of claim 13 , wherein the processing module functions to execute the operational instructions stored by the third memory element to cause the processing module to identify the second computing entity based on the second level regional affiliation by one or more of:

identifying a user computing device to receive the data from the data source device, wherein the user computing device is associated with the second computing entity; and

performing an edge computing device table lookup to identify an entry that associates the second computing entity with the second level regional affiliation.

18. The computer readable memory of claim 13 , wherein the processing module functions to execute the operational instructions stored by the third memory element to further cause the processing module to send the notification message to the second computing entity regarding the data source device being affiliated with the second computing entity by:

generating the notification message to indicate that the data from the data source device is to be routed to the second computing entity; and

transmitting the notification message to the second computing entity, wherein the second computing entity generates the gateway message in accordance with a border gateway protocol based to advertise an address associated with a user computing device to receive the data from the data source device, wherein the second computing entity sends the gateway message to a border router of the core network, and wherein the user computing device is associated with the second computing entity in accordance with the second level regional affiliation.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded May 21, 2024
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 067486/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2024
From: MURRAY LESSINGER AS TRUSTEE-ASSIGNEE FOR THE TRUST FOR THE BENEFIT OF CREDITORS OF XAPTUM, INC; XAPTUM, INC
To: RPX CORPORATION
Reel/Frame 066375/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: BILD, DAVID ROBINSON; DERANGO, MARIO FRANK
To: XAPTUM, INC.
Reel/Frame 051596/0349 →
Continuity (2)
Provisional Application 62799471 · Jan 31, 2019
Related Publication 20200252898A1 · Aug 6, 2020