IP Library › Granted Patent US 10,505,784
Granted Patent B2
US 10,505,784 · App. 16/179,198 · Granted Dec 10, 2019

Techniques for accessing logical networks via a virtualized gateway

Inventor: Ahmed Fuad Siddiqui (Everett, WA)
Assignee: Amazon Technologies, Inc.
H04L41/04H04L12/4633H04L12/4641H04L29/06H04L41/0896H04L41/5054H04L63/0272H04L63/08H04L63/10H04L67/02H04L67/08H04L67/10H04L67/1008H04L67/141H04L69/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,784
App. No.
16/179,198
Granted
Dec 10, 2019
Kind
B2
Abstract

Disclosed are various embodiments for receiving, via a network, a request from a client to establish a network tunnel over the network. A credential is received from the client in order to establish the network tunnel. The client is authenticated based upon the credential. The client negotiates, via the network, to establish the network tunnel.

Claims (55)

1. A system comprising:

a computing device comprising a processor and a memory; and

machine readable instructions stored in the memory that, when executed by the processor of the computing device, cause the computing device to at least:

receive a first request from a client device to create a logical network, the first request comprising authentication credentials for the client device;

determine that the authentication credentials in the first request are valid;

create the logical network, the logical network comprising a logical network gateway;

receive a second request from the client device to connect to a logical network, the second request comprising the authentication credentials for the client device;

determine that the authentication credentials in the second request are valid;

establish an encrypted connection between the logical network gateway and the client device;

assign a logical network address to the client device; and

allocate an available second computing resource to the logical network gateway to augment a first computing resource assigned to the logical network gateway in response to usage of the first computing resource exceeding a threshold.

2. The system of claim 1 , wherein the machine readable instructions further cause the computing device to identify a permission associated with the client device, the permission specifying a limitation of the client device on access to a portion of the logical network.

3. The system of claim 2 , wherein the machine readable instructions further cause the computing device to limit access of the client device to the portion of the logical network specified in the permission.

4. The system of claim 3 , wherein the machine readable instructions that cause the computing device to limit access of the client device to the portion of the logical network specified in the permission further cause the computing device to limit the access of the client device from the logical network address.

5. The system of claim 1 , wherein the machine readable instructions further cause the computing device to at least terminate the connection between the logical network gateway and the client device in response to receipt of a command to terminate the connection.

6. The system of claim 1 , wherein the machine readable instructions that cause the computing device to determine that the authentication credentials in the first request are valid or the machine readable instructions that cause the computing device to determine that the authentication credentials in the second request are valid further cause the computing device to at least:

send an authentication request to an authentication server, the authentication request comprising the authentication credentials; and

receive a response from the authentication server, the response including an indication that the authentication credentials are valid.

7. The system of claim 1 , wherein the first request to create the logical network further comprises a range of network addresses to assign to computing devices connected to the logical network and the logical network address assigned to the client device is from the range of network addresses.

8. A computer-implemented method, comprising:

receiving, via a computing device, a first request from a client device to create a logical network, the first request comprising authentication credentials for the client device;

determining, via a computing device, that the authentication credentials in the first request are valid;

creating, via a computing device, the logical network, the logical network comprising a logical network gateway;

receiving, via a computing device, a second request from the client device to connect to a logical network, the second request comprising the authentication credentials for the client device;

determining, via a computing device, that the authentication credentials in the second request are valid;

establishing, via the computing device, an encrypted connection between the logical network gateway and the client device;

assigning, via the computing device, a logical network address to the client device; and

allocating, via the computing device, an available second computing resource to the logical network gateway to augment a first computing resource assigned to the logical network gateway in response to usage of the first computing resource exceeding a threshold.

9. The computer-implemented method of claim 8 , wherein determining that the authentication credentials in the first request or determining that the authentication credentials in the second request are valid further comprises:

sending, via the computing device, an authentication request to an authentication server, the authentication request comprising the authentication credentials; and

receiving, via the computing device, a response from the authentication server, the respond including an indication that the authentication credentials are valid.

10. The computer-implemented method of claim 8 , further comprising identifying, via the computing device, a permission associated with the client device, the permission specifying a limitation of the client device on access to a portion of the logical network.

11. The computer-implemented method of claim 10 , further comprising limiting, via the computing device, access of the client device to the portion of the logical network specified in the permission.

12. The computer-implemented method of claim 11 , wherein limiting access of the client device to the portion of the logical network specified in the permission further comprises limiting, via the computing device, the access of the client device from the logical network address.

13. The computer-implemented method of claim 8 , further comprising terminating, via the computing device, the connection between the client device and the logical network gateway in response to receiving a notification to terminate the connection.

14. The computer-implemented method of claim 8 , wherein the first request to create the logical network further comprises a range of network addresses to assign to computing devices connected to the logical network and the logical network address assigned to the client device is from the range of network addresses.

15. A system, comprising:

a computing device comprising a processor and a memory; and

machine readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

receive a request from a client to establish an encrypted network tunnel to a logical network;

receive a credential over the network from the client;

authenticate the client based upon the credential;

establish the encrypted network tunnel in response to authentication of the client;

allocate a first computing resource to the encrypted network tunnel;

monitor usage of the first computing resource to determine that consumption of the first computing resource exceeds a predefined threshold; and

allocate an available second computing resource to the encrypted network tunnel to augment the first computing resource assigned to the encrypted network tunnel in response to a determination that consumption of the first computing resource exceeds the predefined threshold.

16. The system of claim 15 , wherein the machine readable instructions further cause the computing device to identify a permission associated with the client, the permission specifying a limitation of the client device on use of the encrypted network tunnel.

17. The system of claim 16 , wherein the machine readable instructions that cause the computing device to identify the permission further cause the computing device to at least:

send the credential to an authentication service; and

receive the permission from the authentication service.

18. The system of claim 16 , wherein the machine readable instructions further cause the computing device to limit usage of the encrypted network tunnel by the client device to a permitted usage specified in the permission.

19. The system of claim 15 , wherein the machine readable instructions that cause the computing device to authenticate the client based upon the credential further cause the computing device to:

send the credential to an authentication service; and

receive a response from the authentication service, the response indicating that the client is authenticated.

20. The system of claim 15 , wherein the logical network comprises at least one virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2019
From: SIDDIQUI, AHMED FUAD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 048272/0633 →
Continuity (4)
Continuation 15912843 · Mar 6, 2018
Continuation 15426225 · Feb 7, 2017
Continuation 13683658 · Nov 21, 2012
Related Publication 20190158346A1 · May 23, 2019