IP Library Granted Patent US 11,916,885
Granted Patent B1
US 11,916,885 · App. 18/094,858 · Granted Feb 27, 2024

Tunnelling with support for dynamic naming resolution

Inventors: Carlos Ulderico Cirello Filho (Burlingame, CA); Philip D. Hassey (Rye, CO)
Assignee: strongDM, Inc.
H04L63/029H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,885
App. No.
18/094,858
Granted
Feb 27, 2024
Kind
B1
Abstract

Mesh agents for an overlay network may be provided such that each mesh agent may be hosted on network computers in the overlay network. In response to a network interface providing raw datagrams to a mesh agent in the overlay network further actions may be performed, including: determining a payload protocol based on the raw datagrams; determining payload datagrams included in the raw datagrams based on the payload protocol; determining a request from a client based on the payload datagrams and the payload protocol; or the like. In response to an infrastructure security computer determining validation information that validates the request further actions may be performed, including: modifying the payload datagrams based on the payload protocol and the validation information; modifying the raw datagrams to include the modified payload datagrams; forwarding the modified raw datagrams to a next mesh agent identified with the validation information; or the like.

Claims (117)

1. A method for managing access to network resources in a network using one or more processors to execute instructions that are configured to cause actions, wherein the execution of the instructions enables performance of actions, comprising:

providing a plurality of mesh agents for an overlay network, wherein each mesh agent is hosted on one or more network computers in the overlay network; and

in response to a network interface providing one or more raw datagrams to a mesh agent in the overlay network, performing further actions, including:

determining a payload protocol based on one or more payloads for the one or more raw datagrams;

determining one or more payload datagrams included in the one or more raw datagrams based on the payload protocol; and

determining a request from a client based on the one or more payload datagrams and the payload protocol; and

in response to an infrastructure security computer determining validation information that validates the request, performing further actions, including:

modifying the one or more payload datagrams to conform to one or more overlay network policies of the infrastructure security computer;

updating the one or more modified payload datagrams to include one or more updated-payloads based on the payload protocol and the validation information;

generating one or more new raw datagrams that include the one or more updated payload datagrams; and

forwarding the one or more new raw datagram to a next mesh agent identified with the validation information, wherein the one or more new raw datagrams are configured to bypass communication management by a kernel level of an operating system and to directly communicate over a network interface with the next mesh agent.

2. The method of claim 1 , further comprising:

providing a name service that associates a plurality of network addresses with a plurality of name values, wherein the associations are provided to the name service by the infrastructure security computer;

determining one or more name values associated with the request based on the payload protocol; and

providing another request to the name service based on the one or more name values, wherein a response from the name service includes one or more network addresses associated with the one or more name values.

3. The method of claim 1 , further comprising:

providing a payload protocol status based on the payload protocol and the one or more payload datagrams, wherein the payload protocol status corresponds to the request; and

modifying the payload protocol status based on the one or more modified payload datagrams.

4. The method of claim 1 , further comprising:

providing the one or more raw datagrams to the network interface, wherein the network interface is managed by an operating system that hosts the mesh agent; and

forwarding the one or more raw datagrams from the network interface to the mesh agent absent modification or interference by the operating system.

5. The method of claim 1 , further comprising:

determining a network address in the overlay network based on the infrastructure security computer, wherein one or more portions of the network address include one or more values that the payload protocol reserves for use with processes associated with privileged users; and

assigning the network address to the mesh agent, wherein the mesh agent is associated with one or more non-privileged users.

6. The method of claim 1 , further comprising:

modifying the overlay network based on one or more updates to the infrastructure security computer, wherein the one or more updates to the infrastructure security computer include associating one or more network addresses with a portion of the plurality of mesh agents; and

in response to the association of the one or more network addresses with the portion of the plurality of mesh agents, updating a name service to associate the one or more network addresses with name information that corresponds to each mesh agent included in the portion of the plurality of mesh agents.

7. A system for managing access to network resources, comprising:

a network computer, comprising:

a memory that stores at least instructions; and

one or more hardware processors that execute instructions that are configured to cause performance of actions, including:

providing a plurality of mesh agents for an overlay network, wherein each mesh agent is hosted on one or more network computers in the overlay network; and

in response to a network interface providing one or more raw datagrams to a mesh agent in the overlay network, performing further actions, including:

determining a payload protocol based on one or more payloads for the one or more raw datagrams;

determining one or more payload datagrams included in the one or more raw datagrams based on the payload protocol; and

determining a request from a client based on the one or more payload datagrams and the payload protocol; and

in response to an infrastructure security computer determining validation information that validates the request, performing further actions, including:

modifying the one or more payload datagrams to conform to one or more overlay network policies of the infrastructure security computer:

updating the one or more modified payload datagrams to include one or more updated-payloads based on the payload protocol and the validation information;

generating one or more new raw datagrams that include the one or more updated payload datagrams; and

forwarding the one or more new raw datagram to a next mesh agent identified with the validation information, wherein the one or more new raw datagrams are configured to bypass communication management by a kernel level of an operating system and to directly communicate over a network interface with the next mesh agent; and

a client computer, comprising:

a memory that stores at least instructions; and

one or more hardware processors that execute instructions that are configured to cause performance of actions, including:

providing the request.

8. The system of claim 7 , wherein the one or more network computer processors execute instructions that perform actions further comprising:

providing a name service that associates a plurality of network addresses with a plurality of name values, wherein the associations are provided to the name service by the infrastructure security computer;

determining one or more name values associated with the request based on the payload protocol; and

providing another request to the name service based on the one or more name values, wherein a response from the name service includes one or more network addresses associated with the one or more name values.

9. The system of claim 7 , wherein the one or more network computer processors execute instructions that perform actions further comprising:

providing a payload protocol status based on the payload protocol and the one or more payload datagrams, wherein the payload protocol status corresponds to the request; and

modifying the payload protocol status based on the one or more modified payload datagrams.

10. The system of claim 7 , wherein the one or more network computer processors execute instructions that perform actions further comprising:

providing the one or more raw datagrams to the network interface, wherein the network interface is managed by an operating system that hosts the mesh agent; and

forwarding the one or more raw datagrams from the network interface to the mesh agent absent modification or interference by the operating system.

11. The system of claim 7 , wherein the one or more network computer processors execute instructions that perform actions further comprising:

determining a network address in the overlay network based on the infrastructure security computer, wherein one or more portions of the network address include one or more values that the payload protocol reserves for use with processes associated with privileged users; and

assigning the network address to the mesh agent, wherein the mesh agent is associated with one or more non-privileged users.

12. The system of claim 7 , wherein the one or more network computer processors execute instructions that perform actions further comprising:

modifying the overlay network based on one or more updates to the infrastructure security computer, wherein the one or more updates to the infrastructure security computer include associating one or more network addresses with a portion of the plurality of mesh agents; and

in response to the association of the one or more network addresses with the portion of the plurality of mesh agents, updating a name service to associate the one or more network addresses with name information that corresponds to each mesh agent included in the portion of the plurality of mesh agents.

13. A processor readable non-transitory storage media that includes instructions for managing access to network resources over a network, wherein execution of the instructions by one or more hardware processors on one or more network computers performs actions, comprising:

providing a plurality of mesh agents for an overlay network, wherein each mesh agent is hosted on one or more network computers in the overlay network; and

in response to a network interface providing one or more raw datagrams to a mesh agent in the overlay network, performing further actions, including:

determining a payload protocol based on one or more payloads for the one or more raw datagrams;

determining one or more payload datagrams included in the one or more raw datagrams based on the payload protocol; and

determining a request from a client based on the one or more payload datagrams and the payload protocol; and

in response to an infrastructure security computer determining validation information that validates the request, performing further actions, including:

modifying the one or more payload datagrams to conform to one or more overlay network policies of the infrastructure security computer;

updating the one or more modified payload datagrams to include one or more updated-payloads based on the payload protocol and the validation information;

generating one or more new raw datagrams that include the one or more updated payload datagrams; and

forwarding the one or more new raw datagram to a next mesh agent identified with the validation information, wherein the one or more new raw datagrams are configured to bypass communication management by a kernel level of an operating system and to directly communicate over a network interface with the next mesh agent.

14. The media of claim 13 , further comprising:

providing a name service that associates a plurality of network addresses with a plurality of name values, wherein the associations are provided to the name service by the infrastructure security computer;

determining one or more name values associated with the request based on the payload protocol; and

providing another request to the name service based on the one or more name values, wherein a response from the name service includes one or more network addresses associated with the one or more name values.

15. The media of claim 13 , further comprising:

providing a payload protocol status based on the payload protocol and the one or more payload datagrams, wherein the payload protocol status corresponds to the request; and

modifying the payload protocol status based on the one or more modified payload datagrams.

16. The media of claim 13 , further comprising:

providing the one or more raw datagrams to the network interface, wherein the network interface is managed by an operating system that hosts the mesh agent; and

forwarding the one or more raw datagrams from the network interface to the mesh agent absent modification or interference by the operating system.

17. The media of claim 13 , further comprising:

determining a network address in the overlay network based on the infrastructure security computer, wherein one or more portions of the network address include one or more values that the payload protocol reserves for use with processes associated with privileged users; and

assigning the network address to the mesh agent, wherein the mesh agent is associated with one or more non-privileged users.

18. The media of claim 13 , further comprising:

modifying the overlay network based on one or more updates to the infrastructure security computer, wherein the one or more updates to the infrastructure security computer include associating one or more network addresses with a portion of the plurality of mesh agents; and

in response to the association of the one or more network addresses with the portion of the plurality of mesh agents, updating a name service to associate the one or more network addresses with name information that corresponds to each mesh agent included in the portion of the plurality of mesh agents.

19. A network computer for managing access to network resources, comprising:

a memory that stores at least instructions; and

one or more hardware processors that execute instructions that are configured to cause performance of actions, including:

providing a plurality of mesh agents for an overlay network, wherein each mesh agent is hosted on one or more network computers in the overlay network; and

in response to a network interface providing one or more raw datagrams to a mesh agent in the overlay network, performing further actions, including:

determining a payload protocol based on one or more payloads for the one or more raw datagrams;

determining one or more payload datagrams included in the one or more raw datagrams based on the payload protocol; and

determining a request from a client based on the one or more payload datagrams and the payload protocol; and

in response to an infrastructure security computer determining validation information that validates the request, performing further actions, including:

modifying the one or more payload datagrams to conform to one or more overlay network policies of the infrastructure security computer:

updating the one or more modified payload datagrams to include one or more updated-payloads based on the payload protocol and the validation information;

generating one or more new raw datagrams that include the one or more updated payload datagrams; and

forwarding the one or more new raw datagram to a next mesh agent identified with the validation information, wherein the one or more new raw datagrams are configured to bypass communication management by a kernel level of an operating system and to directly communicate over a network interface with the next mesh agent.

20. The network computer of claim 19 , wherein the one or more processors execute instructions that perform actions further comprising:

providing a name service that associates a plurality of network addresses with a plurality of name values, wherein the associations are provided to the name service by the infrastructure security computer;

determining one or more name values associated with the request based on the payload protocol; and

providing another request to the name service based on the one or more name values, wherein a response from the name service includes one or more network addresses associated with the one or more name values.

21. The network computer of claim 19 , wherein the one or more processors execute instructions that perform actions further comprising:

providing a payload protocol status based on the payload protocol and the one or more payload datagrams, wherein the payload protocol status corresponds to the request; and

modifying the payload protocol status based on the one or more modified payload datagrams.

22. The network computer of claim 19 , wherein the one or more processors execute instructions that perform actions further comprising:

providing the one or more raw datagrams to the network interface, wherein the network interface is managed by an operating system that hosts the mesh agent; and

forwarding the one or more raw datagrams from the network interface to the mesh agent absent modification or interference by the operating system.

23. The network computer of claim 19 , wherein the one or more processors execute instructions that perform actions further comprising:

determining a network address in the overlay network based on the infrastructure security computer, wherein one or more portions of the network address include one or more values that the payload protocol reserves for use with processes associated with privileged users; and

assigning the network address to the mesh agent, wherein the mesh agent is associated with one or more non-privileged users.

24. The network computer of claim 19 , wherein the one or more processors execute instructions that perform actions further comprising:

modifying the overlay network based on one or more updates to the infrastructure security computer, wherein the one or more updates to the infrastructure security computer include associating one or more network addresses with a portion of the plurality of mesh agents; and

in response to the association of the one or more network addresses with the portion of the plurality of mesh agents, updating a name service to associate the one or more network addresses with name information that corresponds to each mesh agent included in the portion of the plurality of mesh agents.

Assignments (2)
MERGER Recorded May 26, 2026
From: STRONGDM, INC.
To: DELINEA INC.
Reel/Frame 074757/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2023
From: CIRELLO FILHO, CARLOS ULDERICO; HASSEY, PHILIP D.
To: STRONGDM, INC.
Reel/Frame 062317/0908 →
Cited By (9)
US 12,242,599 US 12,284,224 US 12,348,519 US 12,355,770 US 12,423,418 US 12,432,242 US 12,603,921 US 12,670,246 US 12,695,793