IP Library Granted Patent US 11,502,993
Granted Patent B2
US 11,502,993 · App. 16/988,777 · Granted Nov 15, 2022

Scalable and on-demand multi-tenant and multi region secure network

Inventors: Amit Bareket (Tel-Aviv, IL); Sagi Gidali (Rishon-LeZion, IL)
Assignee: Perimeter 81 LTD
H04L63/0236H04L12/66H04L45/04H04L61/5007H04L63/029H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,502,993
App. No.
16/988,777
Granted
Nov 15, 2022
Kind
B2
Abstract

Provided herein are systems and methods for configuring a segmented cloud based network based on separate Internet Protocol (IP) segments, comprising receiving instructions to create one or more additional private virtual networks as respective additional segments in a multi-tenant multi-regional cloud based network segmented to a plurality of segments each mapped by a respective IP address range, calculating one or more non-conflicting new IP address range based on analysis of the IP address range of each of the segments, allocating a respective new IP address range to each additional segment, and deploying automatically one or more gateways. The gateways are configured to connect one or more client devices to the additional segments) by assigning each client device an IP address in the respective new IP address range and routing network packets between the client devices and the respective additional segment according to mapping of the respective new IP address range.

Claims (27)

1. A system for configuring a segmented cloud based network based on separate Internet Protocol (IP) segments, comprising:

at least one processor configured to:

receive instructions to create at least one additional private virtual network in at least one multi-tenant multi-regional cloud based network segmented to a plurality of segments by adding a respective additional segment to the plurality of segments, each of the plurality of segments is mapped by a respective IP address range which is non-conflicting with the IP address range of any other of the plurality of segments;

calculate a new IP address range which is non-conflicting with the IP address range of any of the plurality of segments based on analysis of the IP address range of each of the plurality of segments;

allocate the new IP address range to map the respective additional segment; and

deploy automatically at least one gateway configured to connect at least one of a plurality of client devices to the respective additional segment by assigning the at least one client device an IP address in the new IP address range and routing network packets between the at least one client device and the respective additional segment according to mapping of the new IP address range.

2. The system of claim 1 , wherein the at least one gateway is configured to apply Layer 2 (L2) routing to route the network packets between the at least one client device and the respective additional segment.

3. The system of claim 1 , wherein the at least one gateway is configured to apply Layer 3 (L3) routing to route the network packets between the at least one client device and the respective additional segment.

4. The system of claim 1 , wherein at least one of the plurality of segments is further segmented to a plurality of subnets using Classless Inter-Domain Routing (CIDR).

5. The system of claim 1 , wherein at least one of the plurality of segments is further segmented to a plurality of subnets using at least one firewall configured to route network traffic within the at least one segment according to at least one routing table.

6. The system of claim 1 , wherein a plurality of gateways are deployed to provide connectivity to at least one of the plurality of segments for a plurality of client devices located at a plurality of geographical regions.

7. The system of claim 6 , wherein each of the plurality of gateways is deployed in at least one respective edge server connected at an edge of the network in a respective one of the plurality of geographical regions in close network proximity to a respective access point providing network connectivity to the client devices located in the respective geographical region.

8. The system of claim 7 , wherein the plurality of gateways providing connectivity to the at least one segment for client devices located in the plurality of geographical regions are interconnected via at least one site to site secure connection.

9. The system of claim 1 , wherein the at least one processor is further configured to deploy automatically at least one additional gateway according to at least one predefined rule in response to a request received from at least one additional client device to connect to at least one of the plurality of segments.

10. The system of claim 9 , wherein the at least one additional gateway is configured to connect the at least one additional client device to the at least one segment by assigning the at least one additional client device an IP address in the IP address range of the at least one segment and routing network packets between the at least one additional client device and the at least one segment according to the mapping of the IP address range allocated to the at least one segment.

11. The system of claim 9 , wherein the at least one additional gateway is deployed in at least one of a plurality of geographical regions supported by the at least one cloud based network in which the at least one additional client device is located.

12. A computer implemented method of configuring a segmented cloud based network based on separate Internet Protocol (IP) segments, comprising:

using at least one processor configured for:

receiving instructions to create at least one additional private virtual network in at least one multi-tenant multi-regional cloud based network segmented to a plurality of segments by adding a respective additional segment to the plurality of segments, each of the plurality of segments is mapped by a respective IP address range which is non-conflicting with the IP address range of any other of the plurality of segments;

calculating a new IP address range which is non-conflicting with the IP address range of any of the plurality of segments based on analysis of the IP address range of each of the plurality of segments;

allocating the new IP address range to map the respective additional segment; and

deploying automatically at least one gateway configured to connect at least one of a plurality of client devices to the respective additional segment by assigning the at least one client device an IP address in the new IP address range and routing network packets between the at least one client device and the respective additional segment according to mapping of the new IP address range.

13. A computer program with a program code for configuring a segmented cloud based network based on separate Internet Protocol (IP) segments, comprising a non-transitory medium storing thereon computer program instructions which, when executed by at least one hardware processor, cause the at least one hardware processor to:

receive instructions to create at least one additional private virtual network in at least one multi-tenant multi-regional cloud based network segmented to a plurality of segments by adding a respective additional segment to the plurality of segments, each of the plurality of segments is mapped by a respective IP address range which is non-conflicting with the IP address range of any other of the plurality of segments;

calculate a new IP address range which is non-conflicting with the IP address range of any of the plurality of segments based on analysis of the IP address range of each of the plurality of segments;

allocate the new IP address range to map the respective additional segment; and

deploy automatically at least one gateway configured to connect at least one of a plurality of client devices to the respective additional segment by assigning the at least one client device an IP address in the new IP address range and routing network packets between the at least one client device and the respective additional segment according to mapping of the new IP address range.

Assignments (3)
MERGER Recorded Sep 11, 2024
From: CHECK POINT SSE SOLUTIONS LTD
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 068549/0582 →
CHANGE OF NAME Recorded Oct 26, 2023
From: PERIMETER 81 LTD
To: CHECK POINT SSE SOLUTIONS LTD
Reel/Frame 065360/0520 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2020
From: BAREKET, AMIT; GIDALI, SAGI
To: PERIMETER 81 LTD
Reel/Frame 053569/0514 →
Continuity (1)
Related Publication 20220045985A1 · Feb 10, 2022