IP Library › Granted Patent US 11,743,101
Granted Patent B2
US 11,743,101 · App. 18/086,013 · Granted Aug 29, 2023

Techniques for accessing logical networks via a virtualized gateway

Inventor: Ahmed Fuad Siddiqui (Everett, WA)
Assignee: AMAZON TECHNOLOGIES, INC.
H04L41/04H04L9/40H04L12/4633H04L12/4641H04L41/0896H04L41/5054H04L63/0272H04L63/08H04L63/10H04L67/02H04L67/08H04L67/10H04L67/1008H04L67/141H04L69/24H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,101
App. No.
18/086,013
Granted
Aug 29, 2023
Kind
B2
Abstract

Disclosed are various embodiments for receiving, via a network, a request from a client to establish a network tunnel over the network. A credential is received from the client in order to establish the network tunnel. The client is authenticated based upon the credential. The client negotiates, via the network, to establish the network tunnel.

Claims (41)

1. A system, comprising:

a computing device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

create, in response to receiving a service call, a virtual network comprising a virtual network gateway;

transmit, in response to the service call, a virtual network address to a client device establishing a connection with the virtual network gateway;

allocate, in response to a usage of a first computing resource assigned to the virtual network gateway having met a predefined allocation threshold, an available second computing resource to the virtual network gateway to augment the first computing resource; and

identify, in response to allocating the available second computing resource, a permission associated with the client device, the permission specifying a limitation of the client device on access to a portion of the virtual network.

2. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least encrypt the connection between the client device and the virtual network gateway.

3. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least limit access of the client device to the portion of the virtual network specified in the permission.

4. The system of claim 3 , wherein the machine-readable instructions that limit access of the client device to the portion of the virtual network specified in the permission, when executed by the processor, further cause the computing device to at least limit the access of the client device from a virtual network address.

5. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least terminate, in response to receiving a notification to terminate the connection, the connection between the client device and the virtual network gateway.

6. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive authentication credentials from the client device; and

assign the virtual network address to the client device in response to determining that the authentication credentials are valid.

7. The system of claim 1 , wherein the permission is a first permission and the machine-readable instructions, when executed by the processor, further cause the computing device to at least identify a second permission associated with the client, the second permission specifying a limitation of the client device on use of an encrypted network tunnel.

8. A computer-implemented method, comprising:

monitoring, by a computing device, usage of a first computing resource assigned to a logical network gateway for a logical network, the first computing resource facilitating the operation of a plurality of logical network tunnels maintained by the logical network gateway between the logical network and a plurality of respective clients; and

allocating, by the computing device in response to a determination that usage of the first computing resource exceeds a threshold, a second computing resource to the logical network gateway to augment the first computing resource.

9. The computer-implemented method of claim 8 , further comprising receiving, by the computing device, a request from a client to connect to the logical network gateway; and wherein the determination that the usage of the first computing resource exceeds the threshold occurs in response to receiving the request from the client to connect to the logical network gateway.

10. The computer-implemented method of claim 9 , further comprising establishing, by the computing device, a logical network tunnel between the client and the logical network in response to allocating the second computing resource.

11. The computer-implemented method of claim 10 , wherein the logical network tunnel is an encrypted connection.

12. The computer-implemented method of claim 10 , wherein establishing the logical network tunnel between the client and the logical network gateway further comprises assigning, by the computing device, a logical network address to the client.

13. The computer-implemented method of claim 9 , further comprising authenticating, by the computing device in response to the request to connect to the logical network gateway, the client; and wherein the determination that the usage of the first computing resource exceeds the threshold further occurs in response to authenticating the client.

14. The computer-implemented method of claim 8 , wherein at least one of the first computing resource or the second computing resource comprises a virtual machine.

15. A computer-implemented method, comprising:

receiving, by a computing device, a request from a client to establish an encrypted network tunnel to a logical network;

receiving, by the computing device, a credential over the network from the client, the client executing on a client device;

authenticating, by the computing device, the client based upon the credential;

establishing, by the computing device, the encrypted network tunnel in response to authentication of the client;

allocating, by the computing device, a first computing resource to the encrypted network tunnel;

monitoring, by the computing device, usage of the first computing resource to determine that consumption of the first computing resource exceeds a predefined threshold; and

allocating, by the computing device and in response to a determination that consumption of the first computing resource exceeds the predefined threshold, an available second computing resource to the encrypted network tunnel to augment the first computing resource assigned to the encrypted network tunnel.

16. The computer-implemented method of claim 15 , further comprising identifying, by the computing device, a permission associated with the client, the permission specifying a limitation of the client device on use of the encrypted network tunnel.

17. The computer-implemented method of claim 16 , wherein identifying the permission further comprises:

sending, by the computing device, the credential to an authentication service; and

receiving, by the computing device, the permission from the authentication service.

18. The computer-implemented method of claim 16 , further comprising limiting, by the computing device, usage of the encrypted network tunnel by the client device to a permitted usage specified in the permission.

19. The computer-implemented method of claim 15 , wherein authenticating the client further comprises:

sending, by the computing device, the credential to an authentication service; and

receiving, by the computing device, a response from the authentication service, the response indicating that the client is authenticated.

20. The computer-implemented method of claim 15 , wherein the logical network comprises at least one virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2023
From: SIDDIQUI, AHMED FUAD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 062940/0525 →
Continuity (7)
Continuation 17484917 · Sep 24, 2021
Continuation 16692327 · Nov 22, 2019
Continuation 16179198 · Nov 2, 2018
Continuation 15912843 · Mar 6, 2018
Continuation 15426225 · Feb 7, 2017
Continuation 13683658 · Nov 21, 2012
Related Publication 20230130682A1 · Apr 27, 2023
Cited By (1)
US 12,395,396