IP Library Granted Patent US 11,881,964
Granted Patent B2
US 11,881,964 · App. 17/589,753 · Granted Jan 23, 2024

System and method for a global virtual network

Inventors: Joseph E. Rubenstein (Beijing, CN); Jørn Allan Dose Knutsen (Oslo, NO); Thibaud August Bernard Jean Saint-Martin (Aubignan, FR); Carlos Eduardo Oré (Saint-Herblain, FR); Fred Broussard (Indianapolis, IN)
Assignee: UMBRA TECHNOLOGIES LTD.
H04L12/4633H04L45/12H04L45/64H04L61/4511H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,881,964
App. No.
17/589,753
Granted
Jan 23, 2024
Kind
B2
Abstract

Systems and methods for connecting devices via a virtual global network are disclosed. In one embodiment the network system may comprise a first device in communication with a first endpoint device and a second device in communication with a second endpoint device. The first and second devices may be connected with a communication path. The communication path may comprise one or more intermediate tunnels connecting each endpoint device to one or more intermediate access point servers and one or more control servers.

Claims (33)

1. A method comprising:

identifying, by one or more processors, a plurality of candidate communication paths between a first network node and a second network node;

determining, by the one or more processors, a plurality of security ratings corresponding to the plurality of candidate communication paths, wherein the plurality of security ratings indicate a level of security risk for each of the plurality of candidate communication paths;

storing, by the one or more processors, an identification of the plurality of candidate communication paths and the plurality of security ratings in a route performance table that is used to make real-time routing decisions; and

accessing, by the one or more processors, the route performance table to select a communication path from the plurality of candidate communication paths based on the plurality of security ratings, wherein the selected communication path is used to communicate data between the first network node and the second network node.

2. The method of claim 1 , wherein selecting the communication path comprises comparing each of the plurality of security ratings to at least one of a first value associated with a secure resource and a second value associated with a compromised resource.

3. The method of claim 2 , wherein each of the plurality of security ratings are normalized such that the first value is 1.0, the second value is 0.0, or both the first value is 1.0 and the second value is 0.0.

4. The method of claim 1 , wherein each of the plurality of security ratings is based on at least one of a security test or a performance log.

5. The method of claim 1 , wherein the first network node is configured to perform a Domain Name System lookup to locate a device associated with the second network node.

6. The method of claim 1 , wherein the selected communication path comprises at least one intermediate network node configured to cache the data communicated between the first network node and the second network node.

7. The method of claim 1 , wherein the plurality of security ratings are one of a plurality of factors associated with the plurality of candidate communication paths, and wherein the communication path is selected based on the plurality of factors.

8. The method of claim 7 , wherein the plurality of factors further comprise at least one of bandwidth, latency, number of hops, or packet loss.

9. The method of claim 7 , wherein the plurality of factors further comprise at least one of real-time statistics or historical statistics.

10. The method of claim 1 , wherein the first network node is configured to perform firewall services.

11. A system comprising:

a non-transitory memory; and

one or more processors configured to read instructions from the non-transitory memory that, when executed, cause the one or more hardware processors to perform operations comprising:

identifying a plurality of candidate communication paths between a first network node and a second network node;

determining a plurality of security ratings corresponding to the plurality of candidate communication paths, wherein the plurality of security ratings indicate a level of security risk for each of the plurality of candidate communication paths;

storing an identification of the plurality of candidate communication paths and the plurality of security ratings in a route performance table that is used to make real-time routing decisions; and

accessing the route performance table to select a communication path from the plurality of candidate communication paths based on the plurality of security ratings, wherein the selected communication path is used to communicate data between the first network node and the second network node.

12. The system of claim 11 , wherein selecting the communication path comprises comparing each of the plurality of security ratings to at least one of a first value associated with a secure resource and a second value associated with a compromised resource.

13. The system of claim 12 , wherein each of the plurality of security ratings are normalized such that the first value is 1.0, the second value is 0.0, or both the first value is 1.0 and the second value is 0.0.

14. The system of claim 11 , wherein each of the plurality of security ratings is based on at least one of a security test or a performance log.

15. The system of claim 11 , wherein the first network node is configured to perform a Domain Name System lookup to locate a device associated with the second network node.

16. The system of claim 11 , wherein the selected communication path comprises at least one intermediate network node configured to cache the data communicated between the first network node and the second network node.

17. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising: identifying a plurality of candidate communication paths between a first network node and a second network node;

determining a plurality of security ratings corresponding to the plurality of candidate communication paths, wherein the plurality of security ratings indicate a level of security risk for each of the plurality of candidate communication paths;

storing an identification of the plurality of candidate communication paths and the plurality of security ratings in a route performance table that is used to make real-time routing decisions; and

accessing the route performance table to select a communication path from the plurality of candidate communication paths based on the plurality of security ratings, wherein the selected communication path is used to communicate data between the first network node and the second network node.

18. The non-transitory computer-readable medium of claim 17 , wherein selecting the communication path comprises comparing each of the plurality of security ratings to at least one of a first value associated with a secure resource and a second value associated with a compromised resource.

19. The non-transitory computer-readable medium of claim 18 , wherein each of the plurality of security ratings are normalized such that the first value is 1.0, the second value is 0.0, or both.

20. The non-transitory computer-readable medium of claim 17 , wherein each of the plurality of security ratings is based on at least one of a security test or a performance log.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY LISTED AS UMBRA TECHNOLOGY LTD. AS PREVIOUSLY RECORDED ON REEL 063610 FRAME 0614. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 3, 2023
From: RUBENSTEIN, JOSEPH E; KNUTSEN, JORN ALLAN DOSE; ORE, CARLOS EDUARDO; BROUSSARD, FRED; SAINT-MARTIN, THIBAUD AUGUSTE BERNARD JEAN
To: UMBRA TECHNOLOGIES LTD.
Reel/Frame 065654/0170 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2023
From: RUBENSTEIN, JOSEPH E; KNUTSEN, JORN ALLAN DOSE; ORE, CARLOS EDUARDO; BROUSSARD, FRED; SAINT-MARTIN, THIBAUD AUGUSTE BERNARD JEAN
To: UMBRA TECHNOLOGY LTD.
Reel/Frame 063610/0614 →
Cited By (2)
US 12,289,183 US 12,665,833