IP Library Granted Patent US 12,101,295
Granted Patent B2
US 12,101,295 · App. 17/977,391 · Granted Sep 24, 2024

Internet protocol security (IPSec) tunnel using anycast at a distributed cloud computing network

Inventors: Michael John Vanderwater (Champaign, IL); Adam Simon Chalmers (Austin, TX); Nuno Miguel Lourenço Diegues (Lisbon, PT); Arég Harutyunyan (San Francisco, CA); Erich Alfred Heine (Champaign, IL); Nicholas Alexander Wondra (Savoy, IL)
Assignee: CLOUDFLARE, INC.
H04L63/0236H04L12/4633H04L63/0272H04L63/029H04L63/0485H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,101,295
App. No.
17/977,391
Granted
Sep 24, 2024
Kind
B2
Abstract

An IPSec tunnel request for establishing an IPSec tunnel from a customer router to an anycast IP address of a distributed cloud computing network is received. The same anycast IP address is shared among compute servers of the distributed cloud computing network. A handshake is performed with the customer router from a first compute server including generating security associations for encrypting and decrypting IPSec traffic. The security associations are propagated to each compute server and are used for encrypting and decrypting traffic.

Claims (72)

1. A method, comprising:

receiving an IPSec tunnel request for establishing an IPSec tunnel from a customer router to an anycast IP address of a distributed cloud computing network, wherein a same anycast IP address is shared among a plurality of compute servers of the distributed cloud computing network;

performing a handshake with the customer router from a first one of the compute servers of the distributed cloud computing network, wherein performing the handshake includes generating a set of one or more security associations for encrypting and decrypting IPSec traffic;

propagating the generated set of security associations to each of the other plurality of compute servers of the distributed cloud computing network;

receiving a first packet destined to the customer router at a second one of the compute servers of the distributed cloud computing network, wherein the first packet is received at a first traffic interface of the second compute server, and wherein the first traffic interface is a layer 2 or layer 3 tunnel interface connected with a different customer router;

encrypting the first packet at the second one of the compute servers using the propagated generated set of security associations; and

transmitting the encrypted first packet from the second one of the compute servers to the customer router.

2. The method of claim 1 , further comprising:

receiving a second packet destined to the customer router at the second one of the compute servers of the distributed cloud computing network, wherein the second packet is received at a second traffic interface of the second compute server, wherein the second traffic interface is one of a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface;

encrypting the second packet at the second one of the compute servers using the propagated generated set of security associations, wherein encrypting the second packet is performed at an IPSec tunnel interface of the second compute server; and

transmitting the encrypted second packet from the second one of the compute servers to the customer router.

3. The method of claim 1 , further comprising:

determining identity information associated with the first packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable; and

prior to transmitting the encrypted first packet to the customer router, determining, using one or more policies configured for the customer and the determined identity information, that the first packet is allowed to be transmitted to the customer router.

4. The method of claim 1 , further comprising:

receiving a second encrypted packet from the customer router at a third one of the compute servers of the distributed cloud computing network;

decrypting the second encrypted packet at the third one of the compute servers using the propagated generated set of security associations; and

processing the decrypted second packet at the third one of the compute servers.

5. The method of claim 4 , wherein processing the decrypted second packet at the third one of the compute servers includes transmitting the decrypted second packet to a destination specified in the decrypted second packet.

6. The method of claim 5 , wherein the second encrypted packet is received at an IPSec tunnel interface of the third compute server and decrypted at the IPSec tunnel interface, and wherein transmitting the decrypted second packet to the destination specified in the decrypted second packet is performed at a traffic interface of the third compute server that is one of a layer 2 or layer 3 tunnel interface connected with a different customer router, a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface.

7. The method of claim 6 , further comprising:

determining identity information associated with the decrypted second packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable;

prior to transmitting the decrypted second packet to the destination specified in the decrypted second packet, determining, using one or more policies configured for the customer and the determined identity information, that the decrypted second packet is allowed to be transmitted to the customer router.

8. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to carry out operations including:

receiving an IPSec tunnel request for establishing an IPSec tunnel from a customer router to an anycast IP address of a distributed cloud computing network, wherein a same anycast IP address is shared among a plurality of compute servers of the distributed cloud computing network;

performing a handshake with the customer router from a first one of the compute servers of the distributed cloud computing network, wherein performing the handshake includes generating a set of one or more security associations for encrypting and decrypting IPSec traffic;

propagating the generated set of security associations to each of the other plurality of compute servers of the distributed cloud computing network;

receiving a first packet destined to the customer router at a second one of the compute servers of the distributed cloud computing network, wherein the first packet is received at a first traffic interface of the second compute server, and wherein the first traffic interface is a layer 2 or layer 3 tunnel interface connected with a different customer router;

encrypting the first packet at the second one of the compute servers using the propagated generated set of security associations; and

transmitting the encrypted first packet from the second one of the compute servers to the customer router.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the operations further include:

receiving a second packet destined to the customer router at the second one of the compute servers of the distributed cloud computing network, wherein the second packet is received at a second traffic interface of the second compute server, wherein the second traffic interface is one of a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface;

encrypting the second packet at the second one of the compute servers using the propagated generated set of security associations, wherein encrypting the second packet is performed at an IPSec tunnel interface of the second compute server; and

transmitting the encrypted second packet from the second one of the compute servers to the customer router.

10. The non-transitory machine-readable storage medium of claim 8 , wherein the operations further comprise:

determining identity information associated with the first packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable; and

prior to transmitting the encrypted first packet to the customer router, determining, using one or more policies configured for the customer and the determined identity information, that the first packet is allowed to be transmitted to the customer router.

11. The non-transitory machine-readable storage medium of claim 8 , wherein the operations further comprise:

receiving a second encrypted packet from the customer router at a third one of the compute servers of the distributed cloud computing network;

decrypting the second encrypted packet at the third one of the compute servers using the propagated generated set of security associations; and

processing the decrypted second packet at the third one of the compute servers.

12. The non-transitory machine-readable storage medium of claim 11 , wherein processing the decrypted second packet at the third one of the compute servers includes transmitting the decrypted second packet to a destination specified in the decrypted second packet.

13. The non-transitory machine-readable storage medium of claim 12 , wherein the second encrypted packet is received at an IPSec tunnel interface of the third compute server and decrypted at the IPSec tunnel interface, and wherein transmitting the decrypted second packet to the destination specified in the decrypted second packet is performed at a traffic interface of the third compute server that is one of a layer 2 or layer 3 tunnel interface connected with a different customer router, a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the operations further comprise:

determining identity information associated with the decrypted second packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable;

prior to transmitting the decrypted second packet to the destination specified in the decrypted second packet, determining, using one or more policies configured for the customer and the determined identity information, that the decrypted second packet is allowed to be transmitted to the customer router.

15. A system, comprising:

a first compute server of a distributed cloud computing network, the first compute server including a first processor, and a first non-transitory machine-readable storage medium that provides instructions that, if executed by the first processor, will cause the first compute server to perform first operations including:

receiving an IPSec tunnel request for establishing an IPSec tunnel from a customer router to an anycast IP address of a distributed cloud computing network, wherein a same anycast IP address is shared among the first compute server and a plurality of other compute servers of the distributed cloud computing network;

performing a handshake with the customer router from the first compute server of the distributed cloud computing network, wherein performing the handshake includes generating a set of one or more security associations for encrypting and decrypting IPSec traffic;

propagating the generated set of security associations to each of the other plurality of compute servers of the distributed cloud computing network;

a second compute server of the distributed cloud computing network, the second compute server including a second processor, and a second non-transitory machine-readable storage medium that provides instructions that, if executed by the second processor, will cause the second compute server to perform second operations including:

receiving a first packet destined to the customer router, wherein the first packet is received at a first traffic interface of the second compute server, and wherein the first traffic interface is a layer 2 or layer 3 tunnel interface connected with a different customer router;

encrypting the first packet using the propagated generated set of security associations; and

transmitting the encrypted first packet to the customer router.

16. The system of claim 15 , wherein the second operations further include:

receiving a second packet destined to the customer router, wherein the second packet is received at a second traffic interface of the second compute server, wherein the second traffic interface is one of a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface;

encrypting the second packet using the propagated generated set of security associations, wherein encrypting the second packet is performed at an IPSec tunnel interface of the second compute server; and

transmitting the encrypted second packet to the customer router.

17. The system of claim 15 , wherein the second operations further comprise:

determining identity information associated with the first packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable; and

prior to transmitting the encrypted first packet to the customer router, determining, using one or more policies configured for the customer and the determined identity information, that the first packet is allowed to be transmitted to the customer router.

18. The system of claim 15 , further comprising:

a third compute server of the distributed cloud computing network, the third compute server including a third processor, and a third non-transitory machine-readable storage medium that provides instructions that, if executed by the third processor, will cause the third compute serve to perform third operations including:

receiving a second encrypted packet from the customer router;

decrypting the second encrypted packet using the propagated generated set of security associations; and

processing the decrypted second packet.

19. The system of claim 18 , wherein processing the decrypted second packet includes transmitting the decrypted second packet to a destination specified in the decrypted second packet.

20. The system of claim 19 , wherein the second encrypted packet is received at an IPSec tunnel interface of the third compute server and decrypted at the IPSec tunnel interface, and wherein transmitting the decrypted second packet to the destination specified in the decrypted second packet is performed at a traffic interface of the third compute server that is one of a layer 2 or layer 3 tunnel interface connected with a different customer router, a virtual private network (VPN) server interface connected with a VPN client, a tunnel interface connected with a tunnel client executing on an origin server of the customer, and a web server interface.

21. The system of claim 20 , wherein the third operations further comprise:

determining identity information associated with the decrypted second packet, wherein the identity information includes at least an identifier of a customer to which the traffic is attributable;

prior to transmitting the decrypted second packet to the destination specified in the decrypted second packet, determining, using one or more policies configured for the customer and the determined identity information, that the decrypted second packet is allowed to be transmitted to the customer router.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2024
From: VANDERWATER, MICHAEL JOHN; CHALMERS, ADAM SIMON; DIEGUES, NUNO MIGUEL LOURENÇO; HARUTYUNYAN, ARÉG; HEINE, ERICH ALFRED; WONDRA, NICHOLAS ALEXANDER
To: CLOUDFLARE, INC.
Reel/Frame 068226/0984 →
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (5)
Division 17700058 · Mar 21, 2022
Provisional Application 63321757 · Mar 20, 2022
Provisional Application 63286520 · Dec 6, 2021
Provisional Application 63164492 · Mar 22, 2021
Related Publication 20230074300A1 · Mar 9, 2023