IP Library › Granted Patent US 11,575,661
Granted Patent B2
US 11,575,661 · App. 16/936,076 · Granted Feb 7, 2023

Centralized management of private networks

Inventors: David F. Carney (Toronto, CA); Avery Pennarun (Montreal, CA); David J. Crawshaw (New York, NY)
Assignee: Tailscale Inc.
H04L63/0442H04L61/5007H04L63/083H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,661
App. No.
16/936,076
Granted
Feb 7, 2023
Kind
B2
Abstract

Described herein are systems, methods, and software to manage private networks for computing elements. In one example, a computing element may obtain credential information associated with a user and generate a public-private key pair for the computing element. The computing element may further communicate the public key from the pair with metadata to a coordination service to register the computing element at the coordination service. Once registered, the computing element may receive communication information associated with one or more other computing elements that permit the computing element to communicate with the other computing elements.

Claims (44)

1. A method of operating a computing element to join a private network, the method comprising:

obtaining credential information associated with a user of the computing element;

generating a public key and a private key associated with the computing element and the user;

communicating the public key with computing element metadata to a coordination service, wherein the computing element metadata comprises at least a portion of the credential information;

receiving, from the coordination service, communication information associated with one or more other computing elements for the user and the private network, wherein the communication information comprises at least a public key associated with each computing element of the one or more other computing elements and internet protocol (IP) addressing for each computing element of the one or more other computing elements, and wherein the IP addressing for each computing element of the one or more computing elements comprises at least an IP address allocated by the coordination service; and

generating a packet for communication with a second computing element of the one or more other computing elements using the received communication information.

2. The method of claim 1 , wherein the computing element comprises a physical computing device or a virtual machine.

3. The method of claim 1 , wherein obtaining the credential information associated with the user comprises receiving a username and password associated with the user, and wherein the method further comprises communicating the username and password to an authentication service to obtain a token for the user.

4. The method of claim 3 , wherein the computing element metadata comprises the token.

5. The method of claim 1 further comprising:

generating a second public key and a second private key; and

communicating the second public key to the coordination service to replace the public key, wherein the communication demonstrates possession of the private key by the computing element.

6. The method of claim 1 , wherein the computing element metadata comprises one or more IP addresses associated with the computing element.

7. A computing apparatus comprising:

a storage system;

a processing system operatively coupled to the storage system; and

program instructions stored on the storage system to operate a computing element to join a private network that, when executed by the processing system, direct the computing apparatus to:

obtain credential information associated with a user of the computing element;

generate a public key and a private key associated with the computing element and the user;

communicate the public key with computing element metadata to a coordination service, wherein the computing element metadata comprises at least a portion of the credential information;

receive, from the coordination service, communication information associated with one or more other computing elements for the user and the private network, wherein the communication information comprises at least a public key associated with each computing element of the one or more other computing elements and internet protocol (IP) addressing for each computing element of the one or more other computing elements, and wherein the IP addressing for each computing element of the one or more computing elements comprises at least an IP address allocated by the coordination service; and

generate a packet for communication with a second computing element of the one or more other computing elements using the received communication information.

8. The computing apparatus of claim 7 , wherein the computing element comprises a physical computing device or a virtual machine.

9. The computing apparatus of claim 7 , wherein obtaining the credential information associated with the user comprises receiving a username and password associated with the user, and wherein the program instructions further direct the computing apparatus to communicate the username and password to an authentication service to obtain a token for the user.

10. The computing apparatus of claim 9 , wherein the computing element metadata comprises the token.

11. The computing apparatus of claim 7 , wherein the program instructions further direct the computing apparatus to:

generate a second public key and a second private key; and

communicate the second public key to the coordination service to replace the public key, wherein the communication demonstrates possession of the private key by the computing element.

12. The computing apparatus of claim 7 , wherein the computing element metadata comprises one or more IP addresses associated with the computing element.

13. An apparatus comprising:

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media to operate a computing element to join a private network that, when executed by a processing system, direct the processing system to:

obtain credential information associated with a user of the computing element;

generate a public key and a private key associated with the computing element and the user;

communicate the public key with computing element metadata to a coordination service, wherein the computing element metadata comprises at least a portion of the credential information;

receive, from the coordination service, communication information associated with one or more other computing elements for the user and the private network, wherein the communication information comprises at least a public key associated with each computing element of the one or more other computing elements and internet protocol (IP) addressing for each computing element of the one or more other computing elements, and wherein the IP addressing for each computing element of the one or more computing elements comprises at least an IP address allocated by the coordination service; and

generate a packet for communication with a second computing element of the one or more other computing elements using the received communication information.

14. The apparatus of claim 13 , wherein the computing element comprises a physical computing device or a virtual machine.

15. The apparatus of claim 13 , wherein obtaining the credential information associated with the user comprises receiving a username and password associated with the user, and wherein the program instructions further direct the computing apparatus to communicate the username and password to an authentication service to obtain a token for the user.

16. The apparatus of claim 15 , wherein the computing element metadata comprises the token.

17. The apparatus of claim 13 , wherein the program instructions further direct the processing system to:

generate a second public key and a second private key; and

communicate the second public key to the coordination service to replace the public key, wherein the communication demonstrates possession of the private key by the computing element.

18. The apparatus of claim 13 , wherein the computing element metadata comprises one or more IP addresses associated with the computing element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2020
From: CARNEY, DAVID F.; PENNARUN, AVERY; CRAWSHAW, DAVID J.
To: TAILSCALE INC.
Reel/Frame 053284/0086 →
Continuity (1)
Related Publication 20220029973A1 · Jan 27, 2022