IP Library › Granted Patent US 12,335,240
Granted Patent B2
US 12,335,240 · App. 17/231,215 · Granted Jun 17, 2025

Centralized management control lists for private networks

Inventors: David F. Carney (Toronto, CA); Avery Pennarun (Montreal, CA); David J. Crawshaw (Berkeley, CA)
Assignee: Tailscale Inc.
H04L63/0428H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,240
App. No.
17/231,215
Granted
Jun 17, 2025
Kind
B2
Abstract

Described herein are systems, methods, and software to manage private networks for computing elements. In one example, a coordination service may obtain a request from a computing element to join a private network. In response to the request, the coordination service may identify communication rules associated with the computing element based on credential and device information in the request and may identify communication information to permit the computing element to communicate with one or more other computing elements in the private network. Once identified, the communication information may be communicated to the computing element.

Claims (45)

1. A method of operating a coordination service for a private communication network of connected computing elements, the method comprising:

receiving a request from a computing element to join the private communication network, wherein the request indicates credential information associated with a user of the computing element and device information associated with the computing element, wherein the device information comprises at least an operating system identifier for an operating system on the computing element;

identifying communication rules associated with the computing element based on the credential information and at least the operating system identifier from the device information, wherein the communication rules define one or more other computing elements of the connected computing elements available to the computing element in the private communication network;

identifying communication information that permits the computing element to communicate with the one or more other computing elements in the private communication network based on the communication rules, wherein the communication information comprises one or more encryption keys and one or more addresses associated with the one or more other computing elements; and

limiting the computing element to communicating with the one or more other computing elements over the private communication network by communicating the communication information to the computing element and communicating second communication information to at least a portion of the one or more other computing elements, wherein the computing element requires additional communication information to communicate with ones of the connected computing elements other than the one or more other computing elements, and wherein the second communication information includes encryption information for packets communicated to the computing element.

2. The method of claim 1 , wherein the device information further comprises services available on the computing element and hardware available on the computing element.

3. The method of claim 1 , wherein the computing element comprises a user computing device, a server, a virtual machine, or a container.

4. The method of claim 1 , wherein the one or more addresses comprises one or more internet protocol (IP) addresses and one or more port numbers associated with the one or more other computing elements.

5. The method of claim 1 further comprising:

receiving the second communication information, wherein the second communication information comprises addressing for the computing element.

6. The method of claim 5 further comprising:

determining the at least a portion of the one or more other computing elements based on the communication rules.

7. The method of claim 1 further comprising:

identifying an update to the communication rules associated with the computing element;

identifying an update to the communication information for the computing element based on the update to the communication rules; and

communicating the update to the communication information to the computing element.

8. The method of claim 7 , wherein the update to the communication rules comprises an addition of a rule, a removal of a rule, or a modification to a rule.

9. A computing apparatus comprising:

a storage system comprising non-transitory computer readable storage media;

a processing system comprising microprocessor circuitry and operatively coupled to the storage system; and

program instructions stored on the storage system that, when executed by the processing system, direct the computing apparatus to:

receive a request from a computing element to join a private communication network of connected computing elements, wherein the request indicates credential information associated with a user of the computing element and device information associated with the computing element, wherein the device information comprises at least an operating system identifier for an operating system on the computing element;

identify communication rules associated with the computing element based on the credential information and at least the operating system identifier from the device information, wherein the communication rules define one or more other computing elements of the connected computing elements available to the computing element in the private communication network;

identify communication information that permits the computing element to communicate with the one or more other computing elements in the private communication network based on the communication rules, wherein the communication information comprises one or more encryption keys and one or more addresses associated with the one or more other computing elements; and

limit the computing element to communicating with the one or more other computing elements over the private communication network by communicating the communication information to the computing element and communicating second communication information to at least a portion of the one or more other computing elements, wherein the computing element requires additional communication information to communicate with ones of the connected computing elements other than the one or more other computing elements, and wherein the second communication information includes encryption information for packets communicated to the computing element.

10. The computing apparatus of claim 9 , wherein the device information further comprises services available on the computing element and hardware available on the computing element.

11. The computing apparatus of claim 9 , wherein the computing element comprises a user computing device, a server, a virtual machine, or a container.

12. The computing apparatus of claim 9 , wherein the one or more addresses comprises one or more internet protocol (IP) addresses and one or more port numbers associated with the one or more other computing elements.

13. The computing apparatus of claim 9 , wherein the program instructions further direct the computing apparatus to:

receive the second communication information, wherein the second communication information comprises addressing for the computing element.

14. The computing apparatus of claim 13 , wherein the program instructions further direct the computing apparatus to:

determine the at least a portion of the one or more other computing elements based on the communication rules.

15. The computing apparatus of claim 9 , wherein the program instructions further direct the computing apparatus to:

identify an update to the communication rules associated with the computing element;

identify an update to the communication information for the computing element based on the update to the communication rules; and

communicate the update to the communication information to the computing element.

16. The computing apparatus of claim 15 , wherein the update to the communication rules comprises an addition of a rule, a removal of a rule, or a modification to a rule.

17. A system comprising:

a plurality of computing elements comprising a plurality of computers connected over a private communication network; and

a coordination service computer configured to:

receive a request from a first computing element of the plurality of computing elements to join a private communication network, wherein the request indicates credential information associated with a user of the first computing element and device information associated with the first computing element, wherein the device information comprises at least an operating system identifier for an operating system on the first computing element;

identify communication rules associated with the first computing element based on the credential information and at least the operating system identifier from the device information, wherein the communication rules define one or more other computing elements of the plurality of computing elements available to the first computing element in the private communication network;

identify communication information that permits the first computing element to communicate with the one or more other computing elements of the plurality of computing elements in the private communication network based on the communication rules, wherein the communication information comprises one or more encryption keys and one or more addresses associated with the one or more other computing elements; and

limit the computing element to communicating with the one or more other computing elements over the private communication network by communicating the communication information to the first computing element and communicating second communication information to at least a portion of the one or more other computing elements, wherein the first computing element requires additional communication information to communicate with ones of the plurality of computing elements other than the one or more other computing elements, and wherein the second communication information includes encryption information for packets communicated to the computing element.

18. The system of claim 17 , wherein the first computing element comprises a user computing device, a server, a virtual machine, or a container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: CARNEY, DAVID F.; PENNARUN, AVERY; CRAWSHAW, DAVID J.
To: TAILSCALE INC.
Reel/Frame 061243/0084 →
Continuity (2)
Provisional Application 63146767 · Feb 8, 2021
Related Publication 20220255905A1 · Aug 11, 2022
References Cited (8)
US 20070019645A1 · Menon · 2007 [cited by examiner]
US 20100122084A1 · Liu · 2010 [cited by examiner]
US 20150012963A1 · Gupta · 2015 [cited by examiner]
US 20190268341A1 · Hugot · 2019 [cited by examiner]
US 20230037386A1 · Scurry · 2023 [cited by examiner]
CN 110113390A · 2019 [cited by examiner]
CN 111988307A · 2020 [cited by examiner]
EP 3091712A1 · 2016 [cited by examiner]