IP Library › Granted Patent US 12,395,396
Granted Patent B2
US 12,395,396 · App. 18/349,340 · Granted Aug 19, 2025

Techniques for accessing logical networks via a virtualized gateway

Inventor: Ahmed Fuad Siddiqui (Everett, WA)
Assignee: Amazon Technologies, Inc.
H04L41/045H04L9/40H04L12/4633H04L12/4641H04L41/04H04L41/0896H04L41/0897H04L41/5054H04L63/0272H04L63/08H04L63/10H04L67/02H04L67/08H04L67/10H04L67/1008H04L67/141H04L69/24H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,396
App. No.
18/349,340
Granted
Aug 19, 2025
Kind
B2
Abstract

Disclosed are various embodiments for receiving, via a network, a request from a client to establish a network tunnel over the network. Various embodiments can create a virtual network comprising a virtual network gateway in response to receiving a service call. Various embodiments can further allocate an available computing resource to the virtual network gateway to augment a first computing resource. Allocating the available computing resource can be performed in response to a usage of the first computing resource assigned to the virtual network gateway.

Claims (38)

1. A system, comprising:

a computing device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

create, in response to receiving a service call, a virtual network comprising a virtual network gateway based at least in part on configuration data;

establish an encrypted network tunnel to the virtual network in response to a request from a client to establish the encrypted network tunnel;

allocate, in response to a usage of a first computing resource assigned to the virtual network gateway exceeding a predefined threshold, an available second computing resource to the virtual network gateway to augment the first computing resource, wherein the second computing resource is assigned to the encrypted network tunnel; and

transmit at least the configuration data to a client device.

2. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least limit access of the client device to a portion of the virtual network specified in a permission, the permission being associated with the client device.

3. The system of claim 2 , wherein the machine-readable instructions that limit access of the client device to the portion of the virtual network specified in the permission, when executed by the processor, further cause the computing device to at least limit the access of the client device from a network address.

4. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least terminate a connection between the client device and the virtual network gateway.

5. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive authentication credentials from the client device; and

assign a network address to the client device in response to determining that the authentication credentials are valid.

6. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least identify a permission associated with a client, the permission specifying a limitation of the client device on use of the encrypted network tunnel.

7. A method, comprising:

creating, by a computing device in response to receiving a service call, a virtual network comprising a virtual network gateway based at least in part on configuration data;

establishing an encrypted network tunnel to the virtual network; and

allocating, by the computing device in response to a usage of a first computing resource assigned to the virtual network gateway exceeding a predefined threshold, an available second computing resource to the virtual network gateway to augment the first computing resource.

8. The method of claim 7 , wherein allocating the available second computing resource to the virtual network is in response to determining a capacity threshold has been reached.

9. The method of claim 7 , further comprising limiting, by the computing device, access of the client device to a portion of the virtual network specified in a permission, the permission being associated with the client device.

10. The method of claim 9 , wherein limiting access of the client device to the portion of the virtual network specified in the permission limits the access of the client device from a specified network address.

11. The method of claim 7 , further comprising terminating, by the computing device, a connection between the client device and the virtual network gateway.

12. The method of claim 7 , further comprising: receiving, by the computing device, authentication credentials from the client device; and

assigning, by the computing device, a network address to the client device in response to determining that the authentication credentials are valid.

13. The method of claim 7 , further comprising identifying, by the computing device, a permission associated with a client, the permission specifying a limitation of the client device on use of an encrypted network tunnel.

14. A method, comprising:

establishing, by a computing device, an encrypted network tunnel to a logical network in response to a request from a client to establish the encrypted network tunnel;

allocating, by the computing device, a first computing resource to the encrypted network tunnel;

allocating, by the computing device and in response to a determination that consumption of the first computing resource exceeds a predefined threshold, a second computing resource to the encrypted network tunnel to augment the first computing resource assigned to the encrypted network tunnel.

15. The method of claim 14 , further comprising identifying, by the computing device, a permission associated with the client, the permission specifying a limitation of a client device on use of the encrypted network tunnel.

16. The method of claim 15 , wherein identifying the permission further comprises:

sending, by the computing device, a client credential to an authentication service; and

receiving, by the computing device, the permission from the authentication service.

17. The method of claim 15 , further comprising limiting, by the computing device, usage of the encrypted network tunnel by the client device to a permitted usage specified in the permission.

18. The method of claim 14 , wherein allocating the first computing resource to the encrypted network tunnel is done in response to authenticating a client, authenticating the client comprising:

sending, by the computing device, a client credential to an authentication service; and

receiving, by the computing device, a response from the authentication service, the response indicating that the client is authenticated.

19. The method of claim 14 , wherein the logical network comprises at least one virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2024
From: SIDDIQUI, AHMED FUAD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 066752/0434 →
Continuity (8)
Continuation 18086013 · Dec 21, 2022
Continuation 17484917 · Sep 24, 2021
Continuation 16692327 · Nov 22, 2019
Continuation 16179198 · Nov 2, 2018
Continuation 15912843 · Mar 6, 2018
Continuation 15426225 · Feb 7, 2017
Continuation 13683658 · Nov 21, 2012
Related Publication 20230353444A1 · Nov 2, 2023
References Cited (26)
US 6850497B1 · Sigler · 2005 [cited by examiner]
US 8595378B1 · Cohn · 2013 [cited by examiner]
US 8738745B1 · Brandwine · 2014 [cited by examiner]
US 8843600B1 · Gabrielson · 2014 [cited by examiner]
US 8995301B1 · Miller · 2015 [cited by examiner]
US 9036504B1 · Miller · 2015 [cited by examiner]
US 9203747B1 · Brandwine · 2015 [cited by examiner]
US 9524167B1 · Cohn · 2016 [cited by examiner]
US 9571331B1 · Siddiqui · 2017 [cited by examiner]
US 10938626B2 · Gupta · 2021 [cited by examiner]
US 10938641B1 · Fritz · 2021 [cited by examiner]
US 11570035B2 · Siddiqui · 2023 [cited by examiner]
US 11743101B2 · Siddiqui · 2023 [cited by examiner]
US 20110022721A1 · Diab · 2011 [cited by examiner]
US 20120254353A1 · Baba · 2012 [cited by examiner]
US 20130138816A1 · Kuo · 2013 [cited by examiner]
US 20140032169A1 · McCarthy · 2014 [cited by examiner]
US 20150117179A1 · Sato · 2015 [cited by examiner]
US 20150215414A1 · Kariman · 2015 [cited by examiner]
US 20160197834A1 · Luft · 2016 [cited by examiner]
US 20160197835A1 · Luft · 2016 [cited by examiner]
US 20160198003A1 · Luft · 2016 [cited by examiner]
US 20160218918A1 · Chu · 2016 [cited by examiner]
US 20170180183A1 · Siddiqui · 2017 [cited by examiner]
AU 2013232273A1 · 2014 [cited by examiner]
CA 2836387A1 · 2012 [cited by examiner]