IP Library Granted Patent US 12,445,351
Granted Patent B2
US 12,445,351 · App. 18/669,017 · Granted Oct 14, 2025

Fabric-based virtual air gap provisioning, system and methods

Inventors: Thomas M. Wittenschlaeger (Flowery Branch, GA); Nicholas James Witchey (Laguna Hills, CA)
Assignee: Nant Holdings IP, LLC
H04L41/0806H04L12/12H04L45/04H04L63/10H04L63/20H04L43/0817H04L43/10Y02D30/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,351
App. No.
18/669,017
Granted
Oct 14, 2025
Kind
B2
Abstract

A device configured to or programmed to instantiate an isolated sub-fabric is presented. A network configuration device uses a virtual air gap policy to instantiate a sub-fabric from a fabric of networking nodes. The sub-fabric is configured with an internal routing policy that respects the nature of the defined isolation. Further, the fabric is provisioned with a virtual air gap that ensures the external networking nodes respect the isolation of the sub fabric.

Claims (44)

1. A network configuration device for configuring a fabric of interconnected networking nodes, the network configuration device comprising:

at least one computer readable non-transitory memory configured to store at least an air gap policy comprising fabric isolation criteria defined with respect to a multi-dimensional fabric configuration space; and

at least one processor coupled with the at least one computer readable non-transitory memory, wherein the at least one processor is configured to execute instructions stored in the at least one computer readable non-transitory memory to:

identify, based on the fabric isolation criteria of the air gap policy, a subset of the interconnected networking nodes for constructing a sub-fabric within the fabric;

cause a transmission of at least one configuration instruction to at least one of the interconnected networking nodes in the subset of interconnected networking nodes, the at least one configuration instruction indicating an internal routing policy for the sub-fabric;

provision, at least in part based on the air gap policy, the fabric with an air gap to isolate the subset of the interconnected networking nodes of the sub-fabric from external nodes of the fabric;

cause a state change of interconnects between the interconnected networking nodes, when the fabric is provisioned with the air gap;

monitor for transmission of a heart-beat protocol packet between the interconnected networking nodes of the sub-fabric and the external nodes of the fabric;

prohibit the interconnected networking nodes of the sub-fabric from rejoining the external nodes of the fabric for a specified time period after provisioning the fabric with the air gap; and

allow the interconnected networking nodes of the sub-fabric to rejoin the external nodes of the fabric subsequent to the specified time period.

2. The network configuration device of claim 1 , wherein monitoring for transmission of the heart-beat protocol packet includes transmitting the heart-beat protocol packet from the interconnected networking nodes of the sub-fabric to the external nodes of the fabric.

3. The network configuration device of claim 2 , wherein transmitting the heart-beat protocol packet includes transmitting the heart-beat protocol packet on a regular periodic basis.

4. The network configuration device of claim 3 , wherein the regular periodic basis includes at least one of a once per second frequency, a once per minute frequency, a daily frequency, or a monthly frequency.

5. The network configuration device of claim 2 , wherein transmitting the heart-beat protocol packet includes transmitting the heart-beat protocol packet on an irregular, non-periodic basis.

6. The network configuration device of claim 5 , wherein the irregular, non-periodic basis is established based on at least one of a key, a secret token, or a pseudo-random number generator, used to synchronize transmission and reception of the heart-beat protocol packet from the interconnected networking nodes of the sub-fabric to the external nodes of the fabric.

7. The network configuration device of claim 1 , wherein monitoring for transmission of the heart-beat protocol packet includes transmitting the heart-beat protocol packet from the external nodes of the fabric to the interconnected networking nodes of the sub-fabric.

8. The network configuration device of claim 7 , wherein transmitting the heart-beat protocol packet includes transmitting the heart-beat protocol packet on a regular periodic basis.

9. The network configuration device of claim 8 , wherein the regular periodic basis includes at least one of a once per second frequency, a once per minute frequency, a daily frequency, or a monthly frequency.

10. The network configuration device of claim 7 , wherein transmitting the heart-beat protocol packet includes transmitting the heart-beat protocol packet on an irregular, non-periodic basis.

11. The network configuration device of claim 10 , wherein the irregular, non-periodic basis is established based on at least one of a key, a secret token, or a pseudo-random number generator, used to synchronize transmission and reception of the heart-beat protocol packet from external nodes of the fabric to the interconnected networking nodes of the sub-fabric.

12. The network configuration device of claim 1 , wherein the at least one processor is configured to execute a wipe clean policy to delete at least a portion of data stored in the interconnected networking nodes of the sub-fabric, prior to the interconnected networking nodes of the sub-fabric rejoining the external nodes of the fabric.

13. The network configuration device of claim 12 , wherein the wipe clean policy includes at least one of:

overwriting existing configuration files in memories of the interconnected networking nodes of the sub-fabric with NULL files; or

wiping each of the interconnected networking nodes clean of all configuration information including firmware files.

14. The network configuration device of claim 13 , wherein each of the interconnected networking nodes of the sub-fabric are configured with a count-down timer to simultaneously conduct a wipe clean operation.

15. The network configuration device of claim 1 , wherein the interconnected networking nodes of the sub-fabric are distributed across a geographically significant distance.

16. The network configuration device of claim 15 , wherein the geographically significant distance includes nodes interconnected networking nodes of the sub-fabric distributed across at least one of a city, a continent or the world.

17. A method of configuring a fabric of interconnected networking nodes, the method comprising:

identifying, based on fabric isolation criteria of an air gap policy, a subset of the interconnected networking nodes for constructing a sub-fabric within the fabric, wherein the fabric isolation criteria are defined with respect to a multi-dimensional fabric configuration space;

causing a transmission of at least one configuration instruction to at least one of the interconnected networking nodes in the subset of interconnected networking nodes, the at least one configuration instruction indicating an internal routing policy for the sub-fabric;

provisioning, at least in part based on the air gap policy, the fabric with an air gap to isolate the subset of the interconnected networking nodes of the sub-fabric from external nodes of the fabric;

causing a state change of interconnects between the interconnected networking nodes, when the fabric is provisioned with the air gap; and

monitoring for transmission of a heart-beat protocol packet between the interconnected networking nodes of the sub-fabric and the external nodes of the fabric, including transmitting the heart-beat protocol packet from the interconnected networking nodes of the sub-fabric to the external nodes of the fabric on an irregular, non-periodic basis,

wherein the irregular, non-periodic basis is established based on at least one of a key, a secret token, or a pseudo-random number generator, used to synchronize transmission and reception of the heart-beat protocol packet from the interconnected networking nodes of the sub-fabric to the external nodes of the fabric.

18. The method of claim 17 , wherein:

the sub-fabric is a top secret sub-fabric; and

the method includes prohibiting the interconnected networking nodes of the sub-fabric from rejoining the external nodes of the fabric.

19. A non-transitory computer-readable storage medium including program code which, when executed by at least one processor, causes operations comprising:

identifying, within a fabric of interconnected networking nodes, a subset of interconnected networking nodes for constructing a sub-fabric within the fabric, wherein identifying the subset is based on fabric isolation criteria of an air gap policy, and the fabric isolation criteria are defined with respect to a multi-dimensional fabric configuration space;

causing a transmission of at least one configuration instruction to at least one of the interconnected networking nodes in the subset of interconnected networking nodes, the at least one configuration instruction indicating an internal routing policy for the sub-fabric;

provisioning, at least in part based on the air gap policy, the fabric with an air gap to isolate the subset of the interconnected networking nodes of the sub-fabric from external nodes of the fabric;

causing a state change of interconnects between the interconnected networking nodes, when the fabric is provisioned with the air gap; and

monitoring for transmission of a heart-beat protocol packet between the interconnected networking nodes of the sub-fabric and the external nodes of the fabric, including transmitting the heart-beat protocol packet from the external nodes of the fabric to the interconnected networking nodes of the sub-fabric on an irregular, non-periodic basis,

wherein the irregular, non-periodic basis is established based on at least one of a key, a secret token, or a pseudo-random number generator, used to synchronize transmission and reception of the heart-beat protocol packet from external nodes of the fabric to the interconnected networking nodes of the sub-fabric.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2024
From: WITTENSCHLAEGER, THOMAS
To: NANTWORKS, LLC
Reel/Frame 067478/0903 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2024
From: NANTWORKS, LLC
To: NANT HOLDINGS IP, LLC
Reel/Frame 067478/0974 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2024
From: WITCHEY, NICHOLAS J.
To: NANTWORKS, LLC
Reel/Frame 067479/0043 →
Continuity (5)
Continuation 17533939 · Nov 23, 2021
Continuation 16692879 · Nov 22, 2019
Continuation 14721766 · May 26, 2015
Provisional Application 62002657 · May 23, 2014
Related Publication 20240314029A1 · Sep 19, 2024
References Cited (98)
US 5805924A · Stoevhase · 1998 [cited by examiner]
US 6256295B1 · Callon · 2001 [cited by applicant]
US 7352745B2 · Perera et al. · 2008 [cited by applicant]
US 7548545B1 · Wittenschlaeger · 2009 [cited by applicant]
US 7548556B1 · Wittenschlaeger · 2009 [cited by applicant]
US 7599314B2 · Wittenschlaeger · 2009 [cited by applicant]
US 7603428B2 · Wittenschlaeger · 2009 [cited by applicant]
US 7644317B1 · Sajassi · 2010 [cited by examiner]
US 7673011B2 · Archer et al. · 2010 [cited by applicant]
US 7742445B2 · Stewart et al. · 2010 [cited by applicant]
US 7904602B2 · Wittenschlaeger · 2011 [cited by applicant]
US 8001280B2 · Blumrich et al. · 2011 [cited by applicant]
US 8468244B2 · Redlich · 2013 [cited by examiner]
US 8745734B1 · Brandwine · 2014 [cited by examiner]
US 9171178B1 · Banerjee · 2015 [cited by examiner]
US 9369431B1 · Kirby · 2016 [cited by examiner]
US 10491467B2 · Wittenschlaeger et al. · 2019 [cited by applicant]
US 20020053032A1 · Dowling · 2002 [cited by examiner]
US 20020178158A1 · Kanno · 2002 [cited by examiner]
US 20030163728A1 · Shaw · 2003 [cited by examiner]
US 20050055418A1 · Blanc · 2005 [cited by examiner]
US 20050152305A1 · Ji · 2005 [cited by examiner]
US 20060235985A1 · Ramkumar · 2006 [cited by examiner]
US 20060291455A1 · Katz et al. · 2006 [cited by applicant]
US 20070091903A1 · Atkinson · 2007 [cited by examiner]
US 20070180226A1 · Schory · 2007 [cited by examiner]
US 20080033845A1 · McBride · 2008 [cited by examiner]
US 20080049643A1 · Arcese · 2008 [cited by examiner]
US 20080137532A1 · Namburi et al. · 2008 [cited by applicant]
US 20080155676A1 · Johnson · 2008 [cited by examiner]
US 20080178278A1 · Grinstein · 2008 [cited by examiner]
US 20080235755A1 · Blaisdell · 2008 [cited by examiner]
US 20090064307A1 · Holar · 2009 [cited by examiner]
US 20090103524A1 · Mantripragada · 2009 [cited by examiner]
US 20090136909A1 · Asukai · 2009 [cited by examiner]
US 20090154454A1 · Wittenschlaeger · 2009 [cited by applicant]
US 20090228575A1 · Thubert et al. · 2009 [cited by applicant]
US 20090274157A1 · Vaidya et al. · 2009 [cited by applicant]
US 20090316619A1 · Wittenschlaeger · 2009 [cited by applicant]
US 20100058334A1 · Mohindra · 2010 [cited by examiner]
US 20100061250A1 · Nugent · 2010 [cited by examiner]
US 20100125662A1 · Ou · 2010 [cited by examiner]
US 20100312913A1 · Wittenschlaeger · 2010 [cited by applicant]
US 20100318785A1 · Ozgit · 2010 [cited by examiner]
US 20110060819A1 · Salkewicz · 2011 [cited by examiner]
US 20110066851A1 · Bello et al. · 2011 [cited by applicant]
US 20110138457A1 · Jolfaei · 2011 [cited by examiner]
US 20120297043A1 · Davis · 2012 [cited by examiner]
US 20120303738A1 · Gilson · 2012 [cited by examiner]
US 20130036236A1 · Morales · 2013 [cited by examiner]
US 20130042115A1 · Sweet · 2013 [cited by examiner]
US 20130078945A1 · Lavi · 2013 [cited by examiner]
US 20130305341A1 · Baker · 2013 [cited by examiner]
US 20130326002A1 · Leuoth · 2013 [cited by examiner]
US 20140073362A1 · Kawata · 2014 [cited by examiner]
US 20140237156A1 · Regula · 2014 [cited by examiner]
US 20140282922A1 · Iwanski · 2014 [cited by examiner]
US 20140297843A1 · Shiga · 2014 [cited by examiner]
US 20140310810A1 · Brueckner · 2014 [cited by examiner]
US 20140328382A1 · Lee · 2014 [cited by examiner]
US 20140359044A1 · Davis · 2014 [cited by examiner]
US 20140362808A1 · Zhong · 2014 [cited by examiner]
US 20150092593A1 · Kompella · 2015 [cited by examiner]
US 20150150113A1 · Robb · 2015 [cited by examiner]
US 20150169893A1 · Desai · 2015 [cited by examiner]
US 20150208318A1 · Mosko · 2015 [cited by examiner]
US 20150220409A1 · Shao · 2015 [cited by examiner]
US 20150222533A1 · Birrittella · 2015 [cited by examiner]
US 20150264014A1 · Budhani · 2015 [cited by examiner]
US 20150301880A1 · Allu · 2015 [cited by examiner]
US 20150312266A1 · Thomas · 2015 [cited by examiner]
US 20150370582A1 · Kinsella · 2015 [cited by examiner]
US 20160134591A1 · Liao · 2016 [cited by examiner]
US 20160162438A1 · Hussain · 2016 [cited by examiner]
US 20160323175A1 · Liu · 2016 [cited by examiner]
US 20170041329A1 · Göbel · 2017 [cited by examiner]
US 20170063920A1 · Thomas · 2017 [cited by examiner]
US 20170139736A1 · Messerli · 2017 [cited by examiner]
US 20170206034A1 · Fetik · 2017 [cited by examiner]
US 20170230412A1 · Thomas · 2017 [cited by examiner]
US 20180115652A1 · Russell · 2018 [cited by examiner]
US 20180343238A1 · Tola · 2018 [cited by examiner]
US 20200259709A1 · Wittenschlaeger et al. · 2020 [cited by applicant]
US 20220086041A1 · Wittenschlaeger et al. · 2022 [cited by applicant]
WO 2010131150A1 · 2010 [cited by applicant]
WO 2012068443A1 · 2012 [cited by applicant]
WO 2012092031A1 · 2012 [cited by applicant]
Office Action from corresponding U.S. Appl. No. 16/692,879 dated May 27, 2021. [cited by applicant]
Capuno, Welcome to Infinera's Blog, Infinera Digital Optical Transport Solutions—Blog, 2011. [cited by applicant]
Infinera, Is Your Network Ready?, Infinera Digital Optical Transport Solutions—Bloq, 2011. [cited by applicant]
Infinera, Inventing the Colorless, Directionless and Contentionless ROADM, Infinera Digital Optical Transport Solutions—Blog, 2011. [cited by applicant]
“Infinera, Nettlix's Price Hike And The Bandwidth Dilema, Infinera Digital Optical Transport Solutions—Bloq, 2011.” [cited by applicant]
physorg.com, New Technique Offers Enhanced Security For Sensitive Data In Cloud Computing, Physorg.com website, Technology/Computer Science, 2011. [cited by applicant]
physorg.com, Physicists Map Spiraling Light To Harness Untapped Data Capacity, Phvsora.com website, Physics/ General Physics, 2011. [cited by applicant]
Showalter, Mark, Introducing The New Infinera DTN-X, Infinera Digital Optical Transport Solutions—Blog, 2011. [cited by applicant]
Office Action from corresponding U.S. Appl. No. 14/721,766 dated Dec. 14, 2018. [cited by applicant]
Office Action from corresponding U.S. Appl. No. 14/721,766 dated Apr. 19, 2018. [cited by applicant]
Office Action from corresponding U.S. Appl. No. 14/721,766 dated Sep. 20, 2017. [cited by applicant]
Cited By (1)
US 12,580,968