IP Library › Granted Patent US 12,120,028
Granted Patent B1
US 12,120,028 · App. 18/194,413 · Granted Oct 15, 2024

Secure data routing with channel resiliency

Inventors: John G. Andrews (Cleveland Heights, OH); Mikel Youssef Awad (Tampa, FL); Matthew William Carpenter (Aurora, OH); John P. Keyerleber (Richmond Heights, OH)
Assignee: SCATR, Corp
H04L45/74H04L45/24H04L45/245H04L63/0435H04L67/1019H04L67/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,028
App. No.
18/194,413
Granted
Oct 15, 2024
Kind
B1
Abstract

A secure data routing method and system are disclosed. Logical communication channels are established that each associate an IP address and a protocol port associated with a first computer system to an IP address and a protocol port associated with a second or third computer system. Some logical communication channels associated with the second computer system and some logical communication channels associated with the third computer system are associated with the same IP address and protocol port associated with the first computer system. Data packets are received and parsed to find tokens embedded in the headers. A first data packet embedding a first token is associated to a first source and is decrypted using a first decryption key associated with the first source. A second data packet embedding a second token is associated to a second source and is decrypted using a second decryption key associated with the second source.

Claims (35)

1. A method of secure data routing, comprising:

establishing a first plurality of logical communication channels by a scattering application executing on a first computer system, wherein each of the first plurality of logical communication channels associates an Internet protocol (IP) address and a protocol port associated with the first computer system to an IP address and a protocol port associated with a second computer system;

establishing a second plurality of logical communication channels by the scattering application, wherein each of the second plurality of logical communication channels associates an IP address and a protocol port associated with the first computer system to an IP address and a protocol port associated with a third computer system and wherein at least some of the second plurality of logical communication channels are associated with the same IP address and protocol port associated with the first computer system that some of the first plurality of logical communication channels are associated with;

receiving a plurality of data packets by the scattering application via an IP address and a protocol port of the first computer system that is associated with one of the first plurality of logical communication channels and also associated with one of the second plurality of logical communication channels;

parsing the data packets by the scattering application to find identification tokens embedded in the headers of the data packets;

associating a first data packet embedding a first identification token to a first data packet source;

decrypting the first data packet using a first decryption key associated with the first data packet source;

associating a second data packet embedding a second identification token to a second data packet source;

decrypting the second data packet using a second decryption key associated with the second data packet source;

storing a plurality of decrypted data packets by the scattering application in a data structure, wherein each stored decrypted data packet is associated with a sequence number;

maintaining a next expected packet sequence number by the scattering application;

when a decrypted data packet stored in the data structure is associated with the next expected packet sequence number, transmitting the decrypted data packet and a decrypted data packet stored in the data structure that has a sequence number next in order by the scattering application to a communication user device; and

when a time-to-live value of a decrypted data packet stored in the data structure is due to expire, transmitting the decrypted data packet stored in the data structure having a time-to-live value due to expire to the communication user device.

2. The method of claim 1 , wherein the first computer system is a virtual server.

3. The method of claim 1 , wherein the first computer system is a plurality of virtual servers in a cloud computing environment.

4. The method of claim 1 , wherein the first computer system is a server computer.

5. The method of claim 1 , wherein the first data packet source is associated with a first plurality of different decryption keys and the first decryption key is one of the first plurality of decryption keys and wherein the second data packet source is associated with a second plurality of different decryption keys and the second decryption key is one of the second plurality of decryption keys.

6. The method of claim 1 , wherein the data structure is a doubly linked list data structure.

7. A computer system for secure data routing, comprising:

at least one non-transitory memory;

at least one processor; and

a scattering application stored in the at least one non-transitory memory that, when executed by the at least one processor:

establish a first plurality of logical communication channels, wherein each of the first plurality of logical communication channels associates an Internet protocol (IP) address and a protocol port associated with the computer system to an IP address and a protocol port associated with a second computer system,

establish a second plurality of logical communication channels, wherein each of the second plurality of logical communication channels associates an IP address and a protocol port associated with the first computer system to an IP address and a protocol port associated with a third computer system and wherein at least some of the second plurality of logical communication channels are associated with the same IP address and protocol port associated with the first computer system that some of the first plurality of logical communication channels are associated with,

receive a plurality of data packets via an IP address and a protocol port of the computer system that is associated with one of the first plurality of logical communication channels and also associated with one of the second plurality of logical communication channels,

parse the data packets to find identification tokens embedded in the headers of the data packets, wherein a first data packet embedding a first identification token is associated to a first data packet source and a second data packet embedding a second identification token is associated to a second data packet source, and wherein the first data packet is decrypted using a first decryption key associated with the first data packet source and the second data packet is decrypted using a second decryption key associated with the second data packet source,

stores a plurality of decrypted data packets in a data structure, wherein each

stored decrypted data packet is associated with a sequence number, maintains a next expected packet sequence number,

when a decrypted data packet stored in the data structure is associated with the next expected packet sequence number, transmits the decrypted data packet and a decrypted data packet stored in the data structure that has a sequence number next in order to a communication user device, and

when a time-to-live value of a decrypted data packet stored in the data structure is due to expire, transmits the decrypted data packet stored in the data structure having a time-to-live value due to expire to the communication user device.

8. The computer system of claim 7 , wherein the computer system is a virtual server.

9. The computer system of claim 7 , wherein the computer system is a plurality of virtual servers in a cloud computing environment.

10. The computer system of claim 7 , wherein the computer system is a server computer.

11. The computer system of claim 7 , wherein the first data packet source is associated with a first plurality of different decryption keys and the first decryption key is one of the first plurality of decryption keys and wherein the second data packet source is associated with a second plurality of different decryption keys and the second decryption key is one of the second plurality of decryption keys.

12. The computer system of claim 7 , wherein the data structure is a doubly linked list data structure.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: SCATR, LLC
To: SCATR, CORP
Reel/Frame 068117/0434 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2024
From: ANDREWS, JOHN G.; KEYERLEBER, JOHN P.; AWAD, MIKEL YOUSSEF; CARPENTER, MATTHEW WILLIAM
To: SCATR LLC
Reel/Frame 067446/0107 →
Cited By (9)
US 12,335,160 US 12,432,042 US 12,519,631 US 12,519,755 US 12,567,966 US 12,615,284 US 12,689,910 US 12,701,101 US 12,739,648