IP Library Granted Patent US 11,799,960
Granted Patent B2
US 11,799,960 · App. 17/189,082 · Granted Oct 24, 2023

Distributed network security system providing isolation of customer data

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L67/1097G06F9/45533G06F9/45558H04L12/4641H04L63/0209H04L63/20H04L67/10H04L67/52G06F2009/4557G06F2009/45579G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,960
App. No.
17/189,082
Granted
Oct 24, 2023
Kind
B2
Abstract

Techniques for delivering a distributed network security service providing isolation of customer data are described. One example method includes assigning a first node in a distributed network to a first customer; assigning a second node in the distributed network to a second customer; configuring the assigned first node to process network traffic only from the first customer; configuring the assigned second node to process network traffic only from the second customer; processing, by the assigned first node, network traffic associated with the first customer; and processing, by the assigned second node, network traffic associated with the second customer, wherein the network traffic of the first customer is isolated from the network traffic of the second customer, wherein the network traffic of the customers is kept isolated from one another.

Claims (43)

1. A computer-implemented method executed by one or more processors comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client networks, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client network and sources outside the distributed network, and to examine i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the associated client network;

wherein traffic associated with one client network is inaccessible to node containers associated with other client networks;

wherein some of the nodes executing in a plurality of the node containers are copies of the same virtual machine;

wherein a first node of a first client network is an instance of a particular virtual machine, and is executing on local hardware that is part of the first client network; and

wherein a second node of a second client network also is an instance of the particular virtual machine, and is executing on remote hardware that is not a part of the first client network or the second client network.

2. The method of claim 1 , wherein a third node of the first client network is an instance of the same particular virtual machine and is executing on remote hardware that is not a part of the first client network or the second client network.

3. The method of claim 2 , wherein the particular virtual machine is configured to access a security policy of a node container's associated client network and to apply the security policy to the i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources.

4. The method of claim 3 , wherein, to access a security policy of a node container's associated client network, the virtual machine is configured to request the security policy from another node executing in the same node container.

5. The method of claim 2 , wherein a fourth node of the first client network is a physical machine with functionality different than the virtual machine.

6. The method of claim 5 , wherein the fourth node is housed on the remote hardware.

7. The method of claim 5 , wherein the fourth node is housed on the first client network.

8. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client networks, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client network and sources outside the distributed network, and to examine i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the associated client network;

wherein traffic associated with one client network is inaccessible to node containers associated with other client networks;

wherein some of the nodes executing in a plurality of the node containers are copies of the same virtual machine;

wherein a first node of a first client network is an instance of a particular virtual machine, and is executing on local hardware that is part of the first client network; and

wherein a second node of a second client network also is an instance of the particular virtual machine, and is executing on remote hardware that is not a part of the first client network or the second client network.

9. The non-transitory, computer-readable medium of claim 8 , wherein a third node of the first client network is an instance of the same particular virtual machine and is executing on remote hardware that is not a part of the first client network or the second client network.

10. The non-transitory, computer-readable medium of claim 9 , wherein the particular virtual machine is configured to access a security policy of a node container's associated client network and to apply the security policy to the i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources.

11. The non-transitory, computer-readable medium of claim 10 , wherein, to access a security policy of a node container's associated client network, the virtual machine is configured to request the security policy from another node executing in the same node container.

12. The non-transitory, computer-readable medium of claim 9 , wherein a fourth node of the first client network is a physical machine with functionality different than the virtual machine.

13. The non-transitory, computer-readable medium of claim 12 , wherein the fourth node is housed on the remote hardware.

14. The non-transitory, computer-readable medium of claim 12 , wherein the fourth node is housed on the first client network.

15. A system comprising:

one or more processors; and

computer memory storing instructions operable when executed by the processors to cause the processors to perform operations comprising:

maintaining a distributed network security service, the security service configured to perform operations comprising:

generating, for each of a plurality of client networks, an associated node container;

executing, in each node container, one or more nodes that are each configured to act as an intermediary between clients of the associated client network and sources outside the distributed network, and to examine i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources outside the distributed network and originating from the associated client network;

wherein traffic associated with one client network is inaccessible to node containers associated with other client networks;

wherein some of the nodes executing in a plurality of the node containers are copies of the same virtual machine;

wherein a first node of a first client network is an instance of a particular virtual machine and is executing on local hardware that is part of the first client network; and

wherein a second node of a second client network also is an instance of the particular virtual machine and is executing on remote hardware that is not a part of the first client network or the second client network.

16. The system of claim 15 , wherein a third node of the first client network is an instance of the same particular virtual machine and is executing on remote hardware that is not a part of the first client network or the second client network.

17. The system of claim 16 , wherein the particular virtual machine is configured to access a security policy of a node container's associated client network and to apply the security policy to the i) traffic addressed to the associated client network and originating from sources outside the distributed network; and ii) traffic addressed to the sources.

18. The system of claim 17 , wherein, to access a security policy of a node container's associated client network, the virtual machine is configured to request the security policy from another node executing in the same node container.

19. The system of claim 16 , wherein a fourth node of the first client network is a physical machine with functionality different than the virtual machine.

20. The system of claim 19 , wherein the fourth node is housed on the remote hardware.

Assignments (5)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
FIRST AMENDMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Sep 10, 2021
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057566/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 056357/0491 →
Continuity (3)
Continuation 16666296 · Oct 28, 2019
Continuation 15233894 · Aug 10, 2016
Related Publication 20210258381A1 · Aug 19, 2021