IP Library Granted Patent US 11,652,798
Granted Patent B2
US 11,652,798 · App. 17/314,796 · Granted May 16, 2023

Dynamic, user-configurable virtual private network

Inventor: Ira A. Hunt, IV (Chantilly, VA)
Assignee: Conceal, Inc.
H04L63/0272H04L12/4641H04L45/22H04L63/0414H04L63/06H04L63/083H04L63/0823H04L12/4633H04L45/54H04L49/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,798
App. No.
17/314,796
Granted
May 16, 2023
Kind
B2
Abstract

Some embodiments described herein relate managing communications between an origin and a destination using end-user and/or administrator configurable virtual private network(s) (VPN(s)). A first VPN that defines a first data path between an origin and a destination can be defined at a first time. A second VPN that defines a second, different data path between the origin and the destination can defined at a second time. Each packet sent across the first VPN and each packet sent across the second VPN can follow the same data path for that VPN, such each packet can be sent across the first VPN or the second VPN in the order it was received, and the transition between the first VPN and the second VPN can be “seamless,” and communications between the origin and the destination are not disrupted between the first time period and the second time period.

Claims (50)

1. A non-transitory processor-readable medium storing code to be executed by a processor, the code comprising code representing instructions to:

define a first virtual private network (VPN) having a first route that includes a first plurality of logical switches, a first logical switch from the first plurality of logical switches instantiated in a first commercial cloud and a second logical switch from the first plurality of logical switches instantiated in a second commercial cloud at least partially physically distinct from the first commercial cloud;

receive a first packet from an origin at a first time, the first packet being from a continuous stream of packets;

send the first packet to a destination via the first VPN;

receive a second packet from the continuous stream of packets at a second time;

define a second VPN having a second route that includes a second plurality of logical switches, the second plurality of logical switches at least partially different from the first plurality of logical switches; and

send the second packet to the destination via the second VPN without interrupting the continuous stream of packets traveling from the origin to the destination.

2. The non-transitory processor-readable medium of claim 1 , further comprising code representing instructions to encrypt the first packet to produce a first encrypted packet before sending the send the first packet via the first VPN.

3. The non-transitory processor-readable medium of claim 1 , further comprising code to cause the processor to:

define a plurality of decryption keys;

send a decryption key from the plurality of decryption keys to each logical switch from the first plurality of logical switches such that each logical switch from the first plurality of logical switches is uniquely associated with a different decryption key from the plurality of decryption keys; and

apply a plurality of layers of encryption on the first packet using a plurality of encryption keys associated with the plurality of decryption keys to encrypt the first packet before sending the first packet via the first VPN.

4. The non-transitory processor-readable medium of claim 1 , further comprising code representing instructions to:

define a first plurality of decryption keys;

send a decryption key from the first plurality of decryption keys to each logical switch from the first plurality of logical switches such that each logical switch from the first plurality of logical switches is uniquely associated with a different decryption key from the first plurality of decryption keys;

apply a first plurality of layers of encryption on the first packet using a first plurality of encryption keys associated with the first plurality of decryption keys to encrypt the first packet before sending the first packet via the first VPN;

define a second plurality of decryption keys;

send a decryption key from the second plurality of decryption keys to each logical switch from the second plurality of logical switches such that each logical switch from the second plurality of logical switches is uniquely associated with a different decryption key from the second plurality of decryption keys; and

apply a second plurality of layers of encryption on the second packet using a second plurality of encryption keys associated with the second plurality of decryption keys to encrypt the second packet before sending the second packet via the second VPN.

5. The non-transitory processor-readable medium of claim 1 , wherein the first plurality of logical switches do not broadcast encryption keys, decryption keys, or their membership in the first VPN.

6. The non-transitory process-readable medium of claim 1 , wherein the first VPN is defined based on at least one of an instruction from the origin or an instruction from an administrator associated with the processor.

7. The non-transitory processor-readable medium of claim 1 , wherein at least two logical switches from the second plurality of logical switches are implemented on different commercial clouds.

8. The non-transitory processor-readable medium of claim 1 , further comprising code representing instructions to send a signal to cause the first plurality of logical switches to be instantiated.

9. The non-transitory processor-readable medium of claim 1 , wherein the first packet is received directly from the origin.

10. The non-transitory processor-readable medium of claim 1 , wherein the first packet is received indirectly from the origin.

11. The non-transitory processor-readable medium of claim 1 , further comprising code representing instructions to:

receive, from the origin, a certificate authenticating an origin device, the first route defined based on the certificate.

12. The non-transitory processor-readable medium of claim 1 , further comprising representing instructions to:

receive, from the origin, a first certificate, the first route defined based on the first certificate; and

receive, from the origin, a second certificate, the second route defined based on the second certificate.

13. The non-transitory processor-readable medium of claim 1 , wherein the first route includes at least three logical switches.

14. The non-transitory processor-readable medium of claim 1 , wherein an administrator of the first VPN is not an administrator of physical hardware of the first commercial cloud or the second commercial cloud.

15. The non-transitory processor-readable medium of claim 1 , wherein the first plurality of logical switches are only accessible to packets sent from the origin.

16. The non-transitory processor-readable medium of claim 1 , wherein sending the first packet to the destination via the first VPN includes sending the first packet to the destination without any identifiers associated with the origin or any logical switch from the first plurality of logical switches.

17. The non-transitory processor-readable medium of claim 1 , further comprising code representing instructions to:

define a routing table for the first VPN that identifies each logical switch from the first plurality of logical switches by a private internal internet protocol (IP) address and a public IP address;

propagate at least a portion of the routing table to each logical switch from the first plurality of logical switches; and

address the first packet using the private internal IP address.

18. The non-transitory processor-readable medium of claim 1 , wherein the second VPN is an altered version of the first VPN.

19. A method, comprising:

sending a decryption key from a plurality of decryption keys to a plurality of logical switches such that each logical switch from the plurality of logical switches is uniquely associated with a different decryption key from the plurality of decryption keys, at least one logical switch from the plurality of logical switches implemented in each of at least two commercial clouds;

sending, at a first time, a first encrypted packet from a continuous stream of packets to a first ingress node of a virtual private network (VPN) that includes at least a first subset of the plurality of logical switches such that the first encrypted packet travels a first data path to a destination device and such that the first ingress node applies a decryption key uniquely associated with the first ingress node to reveal an address of an intermediate logical switch from the plurality of logical switches, the decryption key uniquely associated with the first ingress node from the plurality of decryption keys; and

sending, at a second time, a second encrypted packet from the continuous stream of packets to a second ingress node of the VPN such that the second encrypted packet traverses a second data path to the destination device without being fully decrypted before reaching the destination device, the second data path different from the first data path and including at least a second subset of logical switches from the plurality of logical switches.

20. The method of claim 19 , wherein the first ingress node and the second ingress node are the same ingress node.

21. The method of claim 19 , wherein the first ingress node and the second ingress node are different ingress nodes.

22. The method of claim 19 , further comprising:

applying a plurality of layers of encryption on a first data packet to form the first encrypted packet, each layer of encryption from the plurality of layers of encryption applied using an encryption key associated with a decryption key from the plurality of decryption keys, that decryption key being associated with a logical switch from the first subset of logical switches.

23. The method of claim 19 , further comprising:

applying a first plurality of layers of encryption on a first data packet to form the first encrypted packet, each layer of encryption from the first plurality of layers of encryption applied using an encryption key associated with a decryption key from the plurality of decryption keys, that decryption key being associated with a logical switch from the first subset of logical switches; and

applying a second plurality of layers of encryption on a second data packet to form the second encrypted packet, each layer of encryption from the second plurality of layers of encryption applied using an encryption key associated with a decryption key from the plurality of decryption keys, that decryption key being associated with a logical switch from the second subset of logical switches.

Assignments (6)
SECURITY INTEREST Recorded Oct 31, 2024
From: CONCEAL, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 069092/0485 →
SECURITY INTEREST Recorded Feb 16, 2023
From: CONCEAL, INC.
To: SIGNATURE BANK
Reel/Frame 062721/0242 →
CHANGE OF NAME Recorded Dec 13, 2022
From: NETABSTRACTION, INC.
To: CONCEAL, INC.
Reel/Frame 062116/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2022
From: HUNT, IRA A., IV
To: CUTTING EDGE CONSULTING ASSOCIATES, INC.
Reel/Frame 059062/0530 →
CHANGE OF NAME Recorded Feb 22, 2022
From: CUTTING EDGE CONSULTING ASSOCIATES, INC.
To: NETABSTRACTION, INC.
Reel/Frame 059216/0970 →
SECURITY INTEREST Recorded Sep 3, 2021
From: NETABSTRACTION, INC.
To: SIGNATURE BANK
Reel/Frame 057381/0019 →
Continuity (4)
Continuation 16721445 · Dec 19, 2019
Division 15864781 · Jan 8, 2018
Provisional Application 62558204 · Sep 13, 2017
Related Publication 20220078164A1 · Mar 10, 2022