IP Library Granted Patent US 12,457,196
Granted Patent B2
US 12,457,196 · App. 18/521,351 · Granted Oct 28, 2025

Secure private traffic exchange in a unified network service

Inventor: Nicholas Alexander Wondra (Savoy, IL)
Assignee: CLOUDFLARE, INC.
H04L63/0236H04L12/4633H04L63/0272H04L63/029H04L63/0485H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,196
App. No.
18/521,351
Granted
Oct 28, 2025
Kind
B2
Abstract

Traffic is received at an interface of a compute server. Identity information associated with the traffic is determined including an identifier of a customer to which the traffic is attributable. An egress policy configured for the first customer is used to determine whether the traffic is allowed to be transmitted to a destination where that destination is a resource of a second customer. If the traffic is allowed to be transmitted, the traffic and identity information is transmitted over a cross-customer GRE tunnel to a namespace of the second costumer on the compute server. An ingress policy configured for the second customer is used to determine whether the traffic is allowed to be transmitted to the destination, and if it is, then the traffic is transmitted.

Claims (56)

1. A method, comprising:

receiving traffic at a traffic interface of a compute server, wherein the traffic interface is one of a Generic Routing Encapsulation (GRE) tunnel interface, an encrypted tunnel interface, a Virtual Private Network (VPN) server interface, and an Internet Protocol Security (IPsec) tunnel interface;

determining identity information associated with the traffic, wherein the identity information includes at least an identifier of a first customer to which the traffic is attributable, the first customer having a first isolated network stack at the compute server;

determining, using one or more egress policies configured for the first customer and the identity information, whether the traffic is allowed to be transmitted to a target destination of the traffic, wherein the target destination of the traffic is a resource of a second customer having a second isolated network stack at the compute server;

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic and the identity information to the second isolated network stack;

receiving the traffic at the second isolated network stack at the compute server;

determining, using one or more ingress policies configured for the second customer and the identity information, whether the traffic is allowed to be transmitted to the target destination of the traffic; and

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic to the target destination.

2. The method of claim 1 , wherein the traffic interface is the VPN server interface, wherein the traffic is received over a VPN tunnel from a VPN client executing on a client device at the VPN server interface, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying a user of the client device, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether the user is allowed to access the resource of the second customer.

3. The method of claim 1 , wherein the traffic interface is the GRE tunnel interface, wherein the traffic is received over a GRE tunnel from a router of an office network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the GRE tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the GRE tunnel from the router of the office network of the first customer is allowed to access the resource of the second customer.

4. The method of claim 3 , wherein the GRE tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

5. The method of claim 1 , wherein the traffic interface is the IPsec tunnel interface, wherein the traffic is received over an IPsec tunnel from a router of a private network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the IPsec tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the IPSec tunnel from the router of the private network of the first customer is allowed to access the resource of the second customer.

6. The method of claim 5 , wherein the IPsec tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

7. The method of claim 1 , wherein the egress policies configured for the first customer and the ingress policies configured for the second customer define users associated with the first customer allowed to access the resource of the second customer.

8. The method of claim 1 , wherein transmitting the traffic to the second isolated network stack comprises:

sending the traffic and the identity information to a routing service;

determining that the target destination is located in the second isolated network stack; and

determining that a tunnel connecting the first isolated network stack and the second network isolated stack is an outgoing traffic interface for sending the traffic to the second isolated network stack.

9. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations including:

receiving traffic at a traffic interface of a compute server, wherein the traffic interface is one of a Generic Routing Encapsulation (GRE) tunnel interface, an encrypted tunnel interface, a Virtual Private Network (VPN) server interface, and an Internet Protocol Security (IPsec) tunnel interface;

determining identity information associated with the traffic, wherein the identity information includes at least an identifier of a first customer to which the traffic is attributable, the first customer having a first isolated network stack at the compute server;

determining, using one or more egress policies configured for the first customer and the identity information, whether the traffic is allowed to be transmitted to a target destination of the traffic, wherein the target destination of the traffic is a resource of a second customer having a second isolated network stack at the compute server;

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic and the identity information to the second isolated network stack;

receiving the traffic at the second isolated network stack at the compute server;

determining, using one or more ingress policies configured for the second customer and the identity information, whether the traffic is allowed to be transmitted to the target destination of the traffic; and

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic to the target destination.

10. The non-transitory machine-readable storage medium of claim 9 , wherein the traffic interface is the VPN server interface, wherein the traffic is received over a VPN tunnel from a VPN client executing on a client device at the VPN server interface, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying a user of the client device, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether the user is allowed to access the resource of the second customer.

11. The non-transitory machine-readable storage medium of claim 9 , wherein the traffic interface is the GRE tunnel interface, wherein the traffic is received over a GRE tunnel from a router of an office network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the GRE tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the GRE tunnel from the router of the office network of the first customer is allowed to access the resource of the second customer.

12. The non-transitory machine-readable storage medium of claim 11 , wherein the GRE tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

13. The non-transitory machine-readable storage medium of claim 9 , wherein the traffic interface is the IPsec tunnel interface, wherein the traffic is received over an IPsec tunnel from a router of a private network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the IPsec tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the IPSec tunnel from the router of the private network of the first customer is allowed to access the resource of the second customer.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the IPsec tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

15. The non-transitory machine-readable storage medium of claim 9 , wherein the egress policies configured for the first customer and the ingress policies configured for the second customer define users associated with the first customer allowed to access the resource of the second customer.

16. The non-transitory machine-readable storage medium of claim 9 , wherein transmitting the traffic to the second isolated network stack comprises:

sending the traffic and the identity information to a routing service;

determining that the target destination is located in the second isolated network stack; and

determining that a tunnel connecting the first isolated network stack and the second network isolated stack is an outgoing traffic interface for sending the traffic to the second isolated network stack.

17. A compute server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the server to perform operations including:

receiving traffic at a traffic interface of the compute server, wherein the traffic interface is one of a Generic Routing Encapsulation (GRE) tunnel interface, an encrypted tunnel interface, a Virtual Private Network (VPN) server interface, and an Internet Protocol Security (IPsec) tunnel interface;

determining identity information associated with the traffic, wherein the identity information includes at least an identifier of a first customer to which the traffic is attributable, the first customer having a first isolated network stack at the compute server;

determining, using one or more egress policies configured for the first customer and the identity information, whether the traffic is allowed to be transmitted to a target destination of the traffic, wherein the target destination of the traffic is a resource of a second customer having a second isolated network stack at the compute server;

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic and the identity information to the second isolated network stack;

receiving the traffic at the second isolated network stack at the compute server;

determining, using one or more ingress policies configured for the second customer and the identity information, whether the traffic is allowed to be transmitted to the target destination of the traffic; and

responsive to determining that the traffic is allowed to be transmitted to the target destination, transmitting the traffic to the target destination.

18. The server of claim 17 , wherein the traffic interface is the VPN server interface, wherein the traffic is received over a VPN tunnel from a VPN client executing on a client device at the VPN server interface, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying a user of the client device, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether the user is allowed to access the resource of the second customer.

19. The server of claim 17 , wherein the traffic interface is the GRE tunnel interface, wherein the traffic is received over a GRE tunnel from a router of an office network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the GRE tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the GRE tunnel from the router of the office network of the first customer is allowed to access the resource of the second customer.

20. The server of claim 19 , wherein the GRE tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

21. The server of claim 19 , wherein the traffic interface is the IPsec tunnel interface, wherein the traffic is received over an IPsec tunnel from a router of a private network of the first customer, wherein the traffic has a destination IP address that is associated with an IP address of the target destination, wherein the identity information includes information identifying the first customer based on the IPsec tunnel being associated with an account of the first customer, and wherein determining, using the one or more egress policies configured for the first customer includes determining whether traffic received over the IPSec tunnel from the router of the private network of the first customer is allowed to access the resource of the second customer.

22. The server of claim 21 , wherein the IPsec tunnel interface is assigned an IP address that is an anycast IP address that is shared among a plurality of compute servers of a distributed cloud computing network.

23. The server of claim 21 , wherein the egress policies configured for the first customer and the ingress policies configured for the second customer define users associated with the first customer allowed to access the resource of the second customer.

24. The server of claim 19 , wherein transmitting the traffic to the second isolated network stack comprises:

sending the traffic and the identity information to a routing service;

determining that the target destination is located in the second isolated network stack; and

determining that a tunnel connecting the first isolated network stack and the second network isolated stack is an outgoing traffic interface for sending the traffic to the second isolated network stack.

Assignments (1)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (6)
Continuation 17977381 · Oct 31, 2022
Division 17700058 · Mar 21, 2022
Provisional Application 63321757 · Mar 20, 2022
Provisional Application 63286520 · Dec 6, 2021
Provisional Application 63164492 · Mar 22, 2021
Related Publication 20240098061A1 · Mar 21, 2024
References Cited (57)
US 7386630B2 · Liong · 2008 [cited by examiner]
US 7526541B2 · Roese et al. · 2009 [cited by applicant]
US 7739372B2 · Roese et al. · 2010 [cited by applicant]
US 9112911B1 · Karhade · 2015 [cited by examiner]
US 9350710B2 · Herle et al. · 2016 [cited by applicant]
US 9571458B1 · Melam et al. · 2017 [cited by applicant]
US 9794107B2 · Gaglianello et al. · 2017 [cited by applicant]
US 9948552B2 · Teng et al. · 2018 [cited by applicant]
US 9948675B2 · Nakamoto · 2018 [cited by examiner]
US 10103892B2 · Grobman · 2018 [cited by examiner]
US 10630725B2 · Nakamoto et al. · 2020 [cited by applicant]
US 10819630B1 · Panchal et al. · 2020 [cited by applicant]
US 10833891B2 · Sung · 2020 [cited by examiner]
US 11128491B2 · Wondra · 2021 [cited by examiner]
US 11360799B2 · Liu et al. · 2022 [cited by applicant]
US 11425216B2 · Branch · 2022 [cited by examiner]
US 11477634B2 · Weniger et al. · 2022 [cited by applicant]
US 11677717B2 · Wondra · 2023 [cited by examiner]
US 11765146B2 · Mestery et al. · 2023 [cited by applicant]
US 11784912B2 · Ehrat · 2023 [cited by examiner]
US 20040010712A1 · Hui · 2004 [cited by examiner]
US 20040103321A1 · Wesinger, Jr. · 2004 [cited by examiner]
US 20080080493A1 · Weintraub · 2008 [cited by examiner]
US 20080165964A1 · Lewis et al. · 2008 [cited by applicant]
US 20090190591A1 · Sankaran · 2009 [cited by applicant]
US 20100325697A1 · Terzis · 2010 [cited by examiner]
US 20110107413A1 · Chawla · 2011 [cited by examiner]
US 20110231907A1 · Smith · 2011 [cited by applicant]
US 20130166709A1 · Doane · 2013 [cited by examiner]
US 20130219486A1 · Work et al. · 2013 [cited by applicant]
US 20130287026A1 · Davie · 2013 [cited by applicant]
US 20140153422A1 · Nambiar et al. · 2014 [cited by applicant]
US 20150082301A1 · Garg · 2015 [cited by examiner]
US 20150350314A1 · Miller · 2015 [cited by examiner]
US 20180063160A1 · Kumar · 2018 [cited by examiner]
US 20180288726A1 · Azgin et al. · 2018 [cited by applicant]
US 20190156054A1 · Lim · 2019 [cited by examiner]
US 20200092194A1 · Tillotson · 2020 [cited by examiner]
US 20200092252A1 · Tillotson · 2020 [cited by examiner]
US 20210058271A1 · Sung et al. · 2021 [cited by applicant]
US 20220070154A1 · Mestery et al. · 2022 [cited by applicant]
US 20220103523A1 · Starr et al. · 2022 [cited by applicant]
US 20240314106A1 · Tuber · 2024 [cited by examiner]
EP 2748991A1 · 2014 [cited by applicant]
KR 1020150023620A · 2015 [cited by applicant]
WO 2013154813A1 · 2013 [cited by applicant]
WO 2020112448A1 · 2020 [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2022/021409, Jun. 30, 2022, 10 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/700,058, Sep. 22, 2022, 12 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/977,391, Oct. 23, 2023, 13 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/326,745, Dec. 8, 2023, 30 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/700,058, Jan. 30, 2023, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/977,381, Jul. 19, 2023, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/977,391, Jan. 24, 2024, 10 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/977,391, May 8, 2024, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/326,745, May 29, 2024, 8 pages. [cited by applicant]
European Search Report and Search Opinion , EP App. No. 22776515.3, Jan. 7, 2025, 7 pages. [cited by applicant]