IP Library Granted Patent US 11,729,187
Granted Patent B2
US 11,729,187 · App. 16/798,756 · Granted Aug 15, 2023

Encrypted overlay network for physical attack resiliency

Inventors: Gerardo Diaz-Cuellar (Woodinville, WA); Venkata Subrahmanyam Raman (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/1416H04L63/0272H04L63/0478H04L63/0485H04L63/061H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,187
App. No.
16/798,756
Granted
Aug 15, 2023
Kind
B2
Abstract

Devices and methods for protecting server devices from physical attacks use an encrypted overlay network to securely communicate between a trusted network and one or more host computer devices in communication with the trusted network. The devices and methods may generate VPN tunnels to communicate directly with individual host computer devices. The devices and methods may securely transmit data packets between the trusted network and the host computer devices using the VPN tunnels.

Claims (48)

1. A method, comprising: establishing, at a virtual private network (VPN) server on a trusted network, a first trusted internet protocol (IP) address for a first host computer device of a plurality of host computer devices on a network rack in communication with the trusted network, wherein the first trusted IP address is associated with a physical IP address of the first host computer device; using the first trusted IP address to establish a first VPN tunnel directly between the first host computer device and the VPN server over the physical IP address of the first host computer device; securely transmitting data packets between the first host computer device and the VPN sever using the first VPN tunnel; and establishing a second trusted IP address for a second host computer device of the plurality of host computer devices on the network rack in communication with the trusted network, wherein the second trusted IP address is associated with a physical IP address of the second host computer device, wherein establishing the first trusted IP address and the second trusted IP address further comprises exchanging using a common key received in a broadcast message with a packet encrypted with the common key sent to the physical IP address associated with the first host computer device and to the physical IP address of the second host computer device.

2. The method of claim 1 , further comprising:

using the second trusted IP address to generate a second VPN tunnel directly between the second host computer device and the VPN server over the physical IP address of the second host computer device; and

securely transmitting the data packets between the second host computer device and the VPN server using the second VPN tunnel.

3. The method of claim 1 , further comprising:

using the first trusted IP address and the second trusted IP address to communicate the first VPN tunnel between the first host computer device and the second host computer device over the physical IP address of the first host computer and the physical IP address of the second host computer device;

securely transmitting the data packets between the first host computer device and the VPN sever using the first VPN tunnel; and

securely transmitting the data packets between the second host computer device and the VPN server using the first VPN tunnel.

4. The method of claim 1 , further comprising:

establishing an encrypted communication channel between a first network interface card (NIC) of the first host computer device and a second network interface card (NIC) of the second host computer device using the first trusted IP address and the second trusted IP address; and

securely transmitting the data packets between the first host computer device and the second host computer device using the encrypted communication channel.

5. The method of claim 1 , wherein establishing the first trusted IP address and the second trusted IP address further comprises:

exchanging the common key between the first host computer device, the second host computer device, and the VPN server; or

sending the broadcast message with the encrypted packet with the common key to the physical IP address associated with the first host computer device and the physical address associated with the second host computer device; and

receiving a response to the broadcast message from the first host computer device and the second host computer device.

6. The method of claim 5 , further comprising:

using the common key to encrypt the data packets transmitted via the first VPN tunnel and a second VPN tunnel.

7. The method of claim 5 , further comprising:

using the responses to build a table with an association between the physical IP address of the plurality of host computer devices and a trusted IP address for each of the plurality of host computer devices.

8. The method of claim 1 , further comprising:

receiving a request from a customer to access one of the plurality of host computer devices; and

using a nonencrypted communication channel to communicate between one host computer device of the plurality of host computer devices and the customer.

9. The method of claim 1 , further comprising:

receiving a request from a customer to access one of the plurality of host computer devices; and

using an encrypted communication channel to communicate between one host computer device of the plurality of host computer devices and the customer.

10. A computer device, comprising: at least one memory to store data and instructions; and at least one processor in communication with the at least one memory, wherein the at least one processor is operable to: establish a first trusted internet protocol (IP) address for a first host computer device of a plurality of host computer devices in communication with a trusted network, wherein the first trusted IP address is associated with a physical IP address of the first host computer device; use the first trusted IP address to establish a first VPN tunnel directly between the first host computer device and a VPN server over the physical IP address of the first host computer device; securely transmit data packets between the first host computer device and the VPN sever using the first VPN tunnel; and establish a second trusted IP address for a second host computer device of the plurality of host computer devices in communication with the trusted network, wherein the second trusted IP address is associated with a physical IP address of the second host computer device, wherein establishing the first trusted IP address and the second trusted IP address includes using a common key received in a broadcast message with a packet encrypted with the common key sent to the physical IP address associated with the first host computer device and to the physical IP address of the second host computer device.

11. The computer device of claim 10 , wherein the at least one processor is further operable to:

use the second trusted IP address to generate a second VPN tunnel directly between the second host computer device and the VPN server over the physical IP address of the second host computer device; and

securely transmit the data packets between the second host computer device and the VPN server using the second VPN tunnel.

12. The computer device of claim 10 , wherein the at least one processor is further operable to:

use the first trusted IP address and the second trusted IP address to communicate the first VPN tunnel between the first host computer device and the second host computer device over the physical IP address of the first host computer and the physical IP address of the second host computer device;

securely transmit the data packets between the first host computer device and the VPN sever using the first VPN tunnel; and

securely transmit the data packets between the second host computer device and the VPN server using the first VPN tunnel.

13. The computer device of claim 10 , wherein the at least one processor is further operable to:

establish an encrypted communication channel between a first network interface card (NIC) of the first host computer device and a second network interface card (NIC) of the second host computer device using the first trusted IP address and the second trusted IP address; and

securely transmit the data packets between the first host computer device and the second host computer device using the encrypted communication channel.

14. The computer device of claim 10 , wherein the at least one processor is further operable to establish the first trusted IP address and the second trusted IP address by:

exchanging the common key between the first host computer device, the second host computer device, and the VPN server; or

sending the broadcast message with the encrypted packet with the common key to the physical IP address associated with the first host computer device and the physical address associated with the second host computer device; and

receiving a response to the broadcast message from the first host computer device and the second host computer device.

15. The computer device of claim 14 , wherein the at least one processor is further operable to:

use the common key to encrypt the data packets transmitted via the first VPN tunnel and a second VPN tunnel.

16. The computer device of claim 14 , wherein the at least one processor is further operable to:

use the responses to build a table with an association between the physical IP address of the plurality of host computer devices and a trusted IP address for each of the plurality of host computer devices.

17. The computer device of claim 10 , wherein the at least one processor is further operable to:

receive a request from a customer to access one of the plurality of host computer devices; and

use a nonencrypted or an encrypted communication channel to communicate between one host computer device of the plurality of host computer devices and the customer.

18. A non-transitory computer-readable medium storing instructions executable by a computer device, comprising: at least one instruction for causing the computer device to establish a first trusted internet protocol (IP) address for a first host computer device of a plurality of host computer devices on a network rack in communication with a trusted network, wherein the first trusted IP address is associated with a physical IP address of the first host computer device; at least one instruction for causing the computer device to use the first trusted IP address to establish a first VPN tunnel directly between the first host computer device and a VPN server over the physical IP address of the first host computer device; at least one instruction for causing the computer device to securely transmit data packets between the first host computer device and the VPN sever using the first VPN tunnel; and at least one instruction for causing the computer device to establish a second trusted IP address for a second host computer device of the plurality of host computer devices on the network rack in communication with the trusted network, wherein the second trusted IP address is associated with a physical IP address of the second host computer device, wherein establishing the first trusted IP address and the second trusted IP address includes exchanging using a common key received in a broadcast message with a packet encrypted with the common key sent to the physical IP address associated with the first host computer device and to the physical IP address of the second host computer device.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATES YEAR PREVIOUSLY RECORDED AT REEL: 051900 FRAME: 0953. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 1, 2020
From: DIAZ-CUELLAR, GERARDO; RAMAN, VENKATA SUBRAHMANYAM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 054554/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2020
From: DIAZ-CUELLAR, GERARDO; RAMAN, VENKATA SUBRAHMANYAM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 051900/0953 →
Continuity (1)
Related Publication 20210266336A1 · Aug 26, 2021
Cited By (1)
US 12,531,907