IP Library Granted Patent US 12,284,245
Granted Patent B2
US 12,284,245 · App. 18/608,202 · Granted Apr 22, 2025

Methods and devices for network censorship circumvention

Inventor: Serene Han (New York, NY)
Assignee: SNOWSTORM NETWORKS LLC
H04L67/104H04L61/2517H04L61/4535H04L63/0457H04L63/107H04L69/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,245
App. No.
18/608,202
Granted
Apr 22, 2025
Kind
B2
Abstract

Methods, non-transitory computer readable media, and peer devices are disclosed that facilitate network censorship circumvention. A censored peer sends to a rendezvous peer censored peer location information. A connection with a volunteer peer is then established using volunteer peer location information received from the rendezvous peer for a matched volunteer peer. First network traffic is then sent to the volunteer peer in accordance with a first network protocol using a second network protocol associated with the connection. The first network traffic is directed to a network host restricted with respect to the censored peer and the second network protocol is a peer-to-peer network protocol. Second network traffic responsive to the first network traffic is then extracted from network message(s) to thereby obtain access to the restricted network host via the volunteer peer. The first network messages are in accordance with the second network protocol and received via the connection.

Claims (33)

1. A censored peer device, comprising memory having instructions stored thereon and one or more processors coupled to the memory and configured to execute the instructions to:

establish a connection with a volunteer peer device using volunteer peer location information received from a rendezvous peer device and corresponding to the volunteer peer device;

send to the volunteer peer device first network traffic in accordance with a first network protocol using a second network protocol associated with the established connection, wherein the first network traffic is directed to a network host restricted with respect to the censored peer device and the second network protocol is a peer-to-peer network protocol; and

extract second network traffic responsive to the first network traffic from one or more first network messages to obtain access to the restricted network host via the volunteer peer device, wherein the one or more first network messages are in accordance with the second network protocol and received via the established connection.

2. The censored peer device of claim 1 , wherein the first network protocol is hypertext transfer protocol (HTTP), the second network protocol is web real-time communication (WebRTC), and the one or more processors are further configured to execute the instructions to:

send to the rendezvous peer device censored peer location information, wherein the censored peer location information comprises an Internet protocol (IP) address and a port number of a first endpoint held open by the censored peer device after the censored peer location information is sent to the rendezvous peer device; and

establish the connection via a second endpoint at the volunteer peer device using the volunteer peer location information.

3. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to obtain at least a portion of the censored peer location information from a server device disposed on an opposite side of a network address translation (NAT) device as the censored peer device.

4. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to send a session description protocol (SDP) offer in a body of a hypertext transfer protocol (HTTP) message to the rendezvous peer device, wherein the SDP offer comprises the censored peer location information.

5. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

encapsulate the first network traffic in one or more second network messages in a format in accordance with the second network protocol; and

send the second network messages via a local socket secure (SOCKS) proxy server interface corresponding to an endpoint of the established connection at the censored peer device.

6. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to poll the rendezvous peer device until the volunteer peer location information is received from the rendezvous peer device.

7. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to send to the rendezvous peer device negotiation metadata before establishing the connection to facilitate matching of the censored peer device to the volunteer peer device.

8. The censored peer device of claim 1 , wherein the one or more processors are further configured to execute the instructions to encrypt the first network traffic before sending the first network traffic within one or more second network messages via the established connection.

9. A rendezvous peer device, comprising memory having instructions stored thereon and one or more processors coupled to the memory and configured to execute the stored instructions to:

obtain a first offer message from a censored peer device and a second offer message from a volunteer peer device, wherein the first offer message comprises censored peer location information and first negotiation metadata and the second offer message comprises volunteer peer location information and second negotiation metadata;

determine that the volunteer peer device is a match for the censored peer device based on a score generated from the first negotiation metadata and the second negotiation metadata, wherein the first negotiation metadata and the second negotiation metadata comprise a network topology associated with the censored peer device and the volunteer peer device, respectively; and

send a first answer message to the censored peer device and a second answer message to the volunteer peer device, wherein the first answer message comprises the volunteer peer location information and the second answer message comprises the censored peer location information, the censored peer location information comprises a first Internet protocol (IP) address of the censored peer device and a first port number held open by the censored peer device, and the first answer message and the second answer message facilitate establishment of a peer connection between the volunteer peer device and the censored peer device via the first IP address and the first port number.

10. The rendezvous peer device of claim 9 , wherein the first offer message and the second offer message comprise session description protocol (SDP) offers, the first answer message and the second answer message comprise SDP answers, and the SDP offers and answers are included in the body of respective hypertext transfer protocol (HTTP) messages.

11. The rendezvous peer device of claim 9 , wherein one or more of the first or second negotiation metadata further comprises network address translation (NAT) information, a bridge fingerprint, a signal strength, a geolocation, an indication of a current load, or another indication of a current bandwidth.

12. The rendezvous peer device of claim 9 , further comprising a plurality of communication interfaces each comprising an antenna and associated with a different network protocol and one or more different capabilities selected from power, range, or bandwidth.

13. The rendezvous peer device of claim 12 , wherein the first offer message and the second offer message are received on a different one of the communication interfaces.

14. The rendezvous peer device of claim 9 , wherein the volunteer peer location information comprises a second Internet protocol (IP) address of the volunteer peer device and a second port number and the first answer message and the second answer message facilitate establishment of a peer connection between the volunteer peer device and the censored peer device via the second IP address and the second port number.

15. A method implemented by a rendezvous peer device, the method comprising:

obtaining a first offer message from a censored peer device and a second offer message from a volunteer peer device, wherein the first offer message comprises censored peer location information and first negotiation metadata and the second offer message comprises volunteer peer location information and second negotiation metadata;

determining that the volunteer peer device is a match for the censored peer device based on a score generated from the first negotiation metadata and the second negotiation metadata; and

sending a first answer message to the censored peer device and a second answer message to the volunteer peer device, wherein the first answer message comprises the volunteer peer location information and the second answer message comprises the censored peer location information, the censored peer location information comprises a first Internet protocol (IP) address of the censored peer device and a first port number held open by the censored peer device, and the first answer message and the second answer message facilitate establishment of a peer connection between the volunteer peer device and the censored peer device.

16. The method of claim 15 , wherein the first negotiation metadata and the second negotiation metadata comprise a network topology associated with the censored peer device and the volunteer peer device, respectively.

17. The method of claim 15 , wherein the first offer message and the second offer message comprise session description protocol (SDP) offers, the first answer message and the second answer message comprise SDP answers, and the SDP offers and answers are included in the body of respective hypertext transfer protocol (HTTP) messages.

18. The method of claim 15 , wherein one or more of the first or second negotiation metadata further comprises network address translation (NAT) information, a bridge fingerprint, a signal strength, a geolocation, an indication of a current load, or another indication of a current bandwidth.

19. The method of claim 15 , further comprising receiving the first offer message and the second offer message on different ones of a plurality of communication interfaces each comprising an antenna and associated with a different network protocol and one or more different capabilities selected from power, range, or bandwidth.

20. The method of claim 15 , wherein the volunteer peer location information comprises a second Internet protocol (IP) address of the volunteer peer device and a second port number and the first answer message and the second answer message facilitate establishment of a peer connection between the volunteer peer device and the censored peer device via the second IP address and the second port number.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: HAN, SERENE
To: SNOWSTORM INC.
Reel/Frame 070259/0428 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: SNOWSTORM INC.
To: SNOWSTORM NETWORKS LLC
Reel/Frame 070259/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2025
From: HAN, SERENE
To: SNOWSTORM NETWORKS LLC
Reel/Frame 070170/0691 →
Continuity (3)
Continuation 18378092 · Oct 9, 2023
Provisional Application 63378683 · Oct 7, 2022
Related Publication 20240267425A1 · Aug 8, 2024
References Cited (17)
US 9621659B1 · Ghazanfari · 2017 [cited by examiner]
US 9775015B1 · Mishra · 2017 [cited by examiner]
US 11652697B1 · Kozlovski · 2023 [cited by applicant]
US 20110216753A1 · Kneckt et al. · 2011 [cited by applicant]
US 20150195365A1 · Choi · 2015 [cited by applicant]
US 20180248891A1 · Tamma · 2018 [cited by examiner]
US 20190116154A1 · Auge Pujadas et al. · 2019 [cited by applicant]
US 20190207819A1 · Sathya · 2019 [cited by examiner]
US 20190356701A1 · Prabhu · 2019 [cited by applicant]
US 20200036801A1 · Lu et al. · 2020 [cited by applicant]
US 20200329334A1 · Kurian · 2020 [cited by examiner]
US 20220103525A1 · Shribman et al. · 2022 [cited by applicant]
US 20230412701A1 · Pilkauskas · 2023 [cited by examiner]
International Search Report and Written Opinion mailed Feb. 2, 2024 in corresponding International Patent Application No. PCT/US2023/034759. [cited by applicant]
Cao et al., “SkyF2F: Censorship Resistant via Skype Overlay Network.” Information Engineering, 2009. ICIE '09 WASE International Conference on Information Engineering, IEEE, Jul. 10, 2009, pp. 350-354, XP031516820. [cited by applicant]
Barradas et al., “Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTC.” Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data M… [cited by applicant]
Extended European Search Report mailed Mar. 4, 2025 in corresponding European Patent Application No. 23866617.6. [cited by applicant]