IP Library Granted Patent US 11,870,797
Granted Patent B2
US 11,870,797 · App. 17/962,799 · Granted Jan 9, 2024

Isolating internet-of-things (IoT) devices using a secure overlay network

Inventors: Derek Chamorro (Austin, TX); Molly Rose Cinnamon (Sherman Oaks, CA); Tom Paseka (San Francisco, CA); Nicholas Wondra (Savoy, IL)
Assignee: CLOUDFLARE, INC.
H04L63/1425H04L63/029H04L63/0236H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,870,797
App. No.
17/962,799
Granted
Jan 9, 2024
Kind
B2
Abstract

A server of a distributed cloud computing network receives, over a tunnel established between a customer-premises equipment and the compute server, traffic from an Internet-of-Things (IoT) device that is connected to the CPE. The server enforces an egress traffic policy to determine whether the traffic is permitted to be transmitted to the destination. If the traffic is not permitted to be transmitted to the destination, the server drops the traffic. If the traffic is permitted to be transmitted to the destination, the server transmits the traffic to the destination.

Claims (52)

1. A method, comprising:

receiving at a compute server of a distributed cloud computing network, over a tunnel established between a customer-premises equipment (CPE) and the compute server, first traffic from an Internet-of-Things (IoT) device that is connected to the CPE, wherein the first traffic is destined to a first destination;

enforcing an egress traffic policy to determine whether the first traffic is permitted to be transmitted to the first destination, wherein the egress traffic policy specifies that traffic is only allowed to be transmitted to a destination associated with a service of the IoT device, wherein the destination associated with the service of the IoT device is external to the distributed cloud computing network;

determining, based on the enforcing of the egress traffic policy, that the first traffic is permitted to be transmitted to the first destination because the first destination corresponds to the destination associated with the service of the IoT device, and responsive to this determination, transmitting the first traffic to the first destination;

receiving, at the compute server, second traffic that is destined to the IoT device;

enforcing an ingress traffic policy to determine whether the second traffic is permitted to be transmitted to the IoT device;

determining, based on the enforcing of the ingress traffic policy, that the second traffic is not permitted to be transmitted to the IoT device, and responsive to this determination, dropping the second traffic;

receiving at the compute server over the tunnel, third traffic from the IoT device that is connected to the CPE, wherein the third traffic is destined to a second destination;

enforcing the egress traffic policy to determine whether the third traffic is permitted to be transmitted to the second destination; and

determining, based on the enforcing of the egress traffic policy, that the third traffic is not permitted to be transmitted to the second destination because the second destination does not correspond to the destination associated with the service of the IoT device, and responsive to this determination, dropping the third traffic.

2. The method of claim 1 , wherein the tunnel is a generic routing encapsulation (GRE) tunnel.

3. The method of claim 2 , wherein a GRE endpoint at the compute server is an anycast IP address that is shared among a plurality of compute servers such that each of the plurality of compute servers can terminate the GRE tunnel.

4. The method of claim 1 , wherein the tunnel is an IPSec tunnel.

5. The method of claim 4 , wherein an endpoint of the IPSec tunnel at the compute server is an anycast IP address that is shared among a plurality of compute servers, wherein stateful information that allows encryption and decryption of the traffic over the IPSec tunnel is stored in a database that is available to each of the plurality of compute servers.

6. The method of claim 1 , further comprising:

wherein the first traffic has a source IP address that is a private IP address; and

prior to transmitting the first traffic to the first destination, translating the private IP address to a public IP address for transmitting the first traffic to the first destination.

7. The method of claim 1 , wherein the egress traffic policy specifies that the first destination is one of one or more predefined destinations to which traffic from the IoT device is allowed to be transmitted.

8. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations comprising:

receiving at a compute server of a distributed cloud computing network, over a tunnel established between a customer-premises equipment (CPE) and the compute server, first traffic from an Internet-of-Things (IoT) device that is connected to the CPE, wherein the first traffic is destined to a first destination;

enforcing an egress traffic policy to determine whether the first traffic is permitted to be transmitted to the first destination, wherein the egress traffic policy specifies that traffic is only allowed to be transmitted to a destination associated with a service of the IoT device, wherein the destination associated with the service of the IoT device is external to the distributed cloud computing network;

determining, based on the enforcing of the egress traffic policy, that the first traffic is permitted to be transmitted to the first destination because the first destination corresponds to the destination associated with the service of the IoT device, and responsive to this determination, transmitting the first traffic to the first destination;

receiving, at the compute server, second traffic that is destined to the IoT device;

enforcing an ingress traffic policy to determine whether the second traffic is permitted to be transmitted to the IoT device;

determining, based on the enforcing of the ingress traffic policy, that the second traffic is not permitted to be transmitted to the IoT device, and responsive to this determination, dropping the second traffic;

receiving at the compute server over the tunnel, third traffic from the IoT device that is connected to the CPE, wherein the third traffic is destined to a second destination;

enforcing the egress traffic policy to determine whether the third traffic is permitted to be transmitted to the second destination; and

determining, based on the enforcing of the egress traffic policy, that the third traffic is not permitted to be transmitted to the second destination because the second destination does not correspond to the destination associated with the service of the IoT device, and responsive to this determination, dropping the third traffic.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the tunnel is a generic routing encapsulation (GRE) tunnel.

10. The non-transitory machine-readable storage medium of claim 9 , wherein a GRE endpoint at the compute server is an anycast IP address that is shared among a plurality of compute servers such that each of the plurality of compute servers can terminate the GRE tunnel.

11. The non-transitory machine-readable storage medium of claim 8 , wherein the tunnel is an IPSec tunnel.

12. The non-transitory machine-readable storage medium of claim 11 , wherein an endpoint of the IPSec tunnel at the compute server is an anycast IP address that is shared among a plurality of compute servers, wherein stateful information that allows encryption and decryption of traffic over the IPSec tunnel is stored in a database that is available to each of the plurality of compute servers.

13. The non-transitory machine-readable storage medium of claim 8 , wherein the first traffic has a source IP address that is a private IP address, and wherein prior to transmitting the first traffic to the first destination, translating the private IP address to a public IP address for transmitting the first traffic to the first destination.

14. The non-transitory machine-readable storage medium of claim 8 , wherein the egress traffic policy specifies that the first destination is one of one or more predefined destinations to which traffic from the IoT device is allowed to be transmitted.

15. A compute server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the compute server to perform operations comprising,

receiving at the compute server of a distributed cloud computing network, over a tunnel established between a customer-premises equipment (CPE) and the compute server, first traffic from an Internet-of-Things (IoT) device that is connected to the CPE, wherein the first traffic is destined to a first destination,

enforcing an egress traffic policy to determine whether the first traffic is permitted to be transmitted to the first destination, wherein the egress traffic policy specifies that traffic is only allowed to be transmitted to a destination associated with a service of the IoT device, wherein the destination associated with the service of the IoT device is external to the distributed cloud computing network,

determining, based on the enforcing of the egress traffic policy, that the first traffic is permitted to be transmitted to the first destination because the first destination corresponds to the destination associated with the service of the IoT device, and responsive to this determination, transmitting the first traffic to the first destination,

receiving, at the compute server, second traffic that is destined to the IoT device;

enforcing an ingress traffic policy to determine whether the second traffic is permitted to be transmitted to the IoT device,

determining, based on the enforcing of the ingress traffic policy, that the second traffic is not permitted to be transmitted to the IoT device, and responsive to this determination, dropping the second traffic,

receiving at the compute server over the tunnel, third traffic from the IoT device that is connected to the CPE, wherein the third traffic is destined to a second destination,

enforcing the egress traffic policy to determine whether the third traffic is permitted to be transmitted to the second destination, and

determining, based on the enforcing of the egress traffic policy, that the third traffic is not permitted to be transmitted to the second destination because the second destination does not correspond to the destination associated with the service of the IoT device, and responsive to this determination, dropping the third traffic.

16. The compute server of claim 15 , wherein the tunnel is a generic routing encapsulation (GRE) tunnel.

17. The compute server of claim 16 , wherein a GRE endpoint at the compute server is an anycast IP address that is shared among a plurality of compute servers such that each of the plurality of compute servers can terminate the GRE tunnel.

18. The compute server of claim 15 , wherein the tunnel is an IPSec tunnel.

19. The compute server of claim 18 , wherein an endpoint of the IPSec tunnel at the compute server is an anycast IP address that is shared among a plurality of compute servers, wherein stateful information that allows encryption and decryption of the traffic over the IPSec tunnel is stored in a database that is available to each of the plurality of compute servers.

20. The compute server of claim 15 , wherein the first traffic has a source IP address that is a private IP address, and wherein prior to transmitting the first traffic to the first destination, translating the private IP address to a public IP address for transmitting the first traffic to the first destination.

21. The compute server of claim 15 , wherein the egress traffic policy specifies that the first destination is one of one or more predefined destinations to which traffic from the IoT device is allowed to be transmitted.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2022
From: CHAMORRO, DEREK; CINNAMON, MOLLY ROSE; PASEKA, TOM; WONDRA, NICHOLAS
To: CLOUDFLARE, INC.
Reel/Frame 061365/0960 →
Continuity (2)
Continuation 17698836 · Mar 18, 2022
Related Publication 20230300158A1 · Sep 21, 2023
Cited By (1)
US 12,598,162