IP Library Granted Patent US 8,997,206
Granted Patent B2
US 8,997,206 · App. 11/759,061 · Granted Mar 31, 2015

Peer-to-peer network over a virtual private network

Inventors: Joseph Curcio (Toms River, NJ); Mahalingam Mani (Cupertino, CA)
Assignee: Avaya Inc.
H04L67/104H04L63/0227H04L63/0272H04L67/1057H04L69/161H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,997,206
App. No.
11/759,061
Granted
Mar 31, 2015
Kind
B2
Abstract

The present invention provides a new network topology. More specifically, a peer-to-peer network is defined on a virtual private network. The peer-to-peer network comprises a set of specified users within a virtual private network that are allowed to communicate according to predetermined rules enforced by the peer-to-peer network itself. This affords secure communication between the specified users of the peer-to-peer network independent of the virtual private network.

Claims (46)

1. A method, comprising:

providing a Virtual Private Network (VPN) overlay network for a first set of communication devices; and

defining a first and second peer-to-peer network over the VPN, the first peer-to-peer network being defined for a second set of communication devices over the VPN overlay network and the second peer-to-peer network being defined for at least one of a third set of communication devices and third set of users over the VPN overlay network, wherein the at least one of a second set of communication devices and second set of users are in at least one of a first set of communication devices and first set of users, wherein the at least one of a third set of communication devices and third set of users are in the at least one of a first set of communication devices and first set of users.

2. The method of claim 1 , wherein the first set of communication devices comprises all of the communication devices in the second and third set of communication devices and wherein the second and third set of communication devices do not comprise all of the communication devices in the first set of communication devices.

3. The method of claim 1 , further comprising:

defining communication policies for the second set of communication devices;

defining communication polices for the third set of communication devices, the communication policies for the third set of communication devices being different from the communication policies for the second set of communication devices; and

enforcing the communication policies for the second and third sets of communication devices in the peer-to-peer network and from the peer-to-peer network to the rest of the communication devices in the first set of communication devices.

4. The method of claim 3 , wherein communication policies for the second and third communication devices comprise at least one of security policies, permissions, routing policies, permissible applications, and encryption policies.

5. The method of claim 3 , further comprising:

determining at least one of a name and variety for each communication device in the peer-to-peer network;

assigning a key to each communication device in the peer-to-peer network; a receiving communication device belonging to the peer-to-peer network receiving a key from a sending communication device;

determining, by the receiving communication device, that the received key corresponds to at least one of a name and variety for a communication device in the peer-to-peer network; and

permitting a communication session between the receiving communication device and the sending communication device in accordance with the communication policies.

6. The method of claim 3 , further comprising:

determining at least one of an identifier and key;

assigning the at least one of an identifier and key to each communication device in the peer-to-peer network;

a receiving communication device belonging to the peer-to-peer network receiving at least one of an identifier and key from a sending communication device;

determining, by the receiving communication device, that the received at least one of an identifier and key corresponds to the assigned at least one of an identifier and key; and

permitting a communication session between the receiving communication device and the sending communication device in accordance with the communication policies.

7. The method of claim 1 , further comprising:

determining that a communication device in the peer-to-peer network wants to establish communications with a communication device not in the peer-to-peer network;

the communication device in the peer-to-peer network generating a message for transmission to the communication device not in the peer-to-peer network; and

transmitting the message to the communication device not in the peer-to-peer network by routing the message through a predetermined communication device belonging to the peer-to-peer network.

8. The method of claim 1 , further comprising the second set of communication devices utilizing packets comprising at least an outer IP tunnel header, an IPsec header, and an inner IP header.

9. In an overlay network established on top of a public communication network, the overlay network having a first set of users capable of communicating with one another, an apparatus, comprising:

a management console adapted to define a plurality of peer-to-peer networks over the overlay network, wherein each peer-to-peer network in the plurality of peer-to-peer networks defined over the overlay network comprise different user groups and different communication policies associated therewith, and wherein users in each peer-to-peer network defined over the overlay network are also in the first set of users.

10. The apparatus of claim 9 , wherein at least some users in the first set of users are not in a peer-to-peer network.

11. The apparatus of claim 9 , wherein the management console is further adapted to define the communication policies for each of the peer-to-peer networks, wherein the communication policies for users in the peer-to-peer networks differ from policies for the first set of users that are not in a peer-to-peer network, and wherein the management console is further adapted to control communications between users in the peer-to-peer network and users not in the peer-to-peer network.

12. The apparatus of claim 11 , wherein the communication policies for each of the peer-to-peer networks comprise one of restrictions and permissions related to at least one of TCP/IP application layer protocols, transport layer protocols, and network layer protocols.

13. The apparatus of claim 9 , wherein at least one peer-to-peer network defined over the overlay network comprises a mesh topology.

14. The apparatus of claim 9 , wherein the overlay network comprises at least one of an IPsec, an L2, and an L3 VPN overlay network configured in at least one of a mesh and hub-and-spoke topology.

15. The apparatus of claim 9 , wherein each user in the first set of users is associated with at least one communication device and wherein each communication device in a first peer-to-peer network is adapted to establish communications with one another using a predetermined TCP/IP application layer protocol.

16. The apparatus of claim 9 , wherein the management console is further adapted to determine and assign a key to each user in a first peer-to-peer network defined over the overlay network such that the use of the assigned key in communications indicates that the user providing the assigned key belongs to the first peer-to-peer network defined over the overlay network.

17. The apparatus of claim 16 , wherein the key assigned to each user in the first peer-to-peer network comprises a common key.

18. The apparatus of claim 16 , wherein each user in the first peer-to-peer network is assigned a unique key.

19. The apparatus of claim 16 , wherein the key comprises at least one of an authentication key, an encryption key, and an identifier.

20. The apparatus of claim 16 , wherein users in the first peer-to-peer network communicate with one another using packets comprising an outer IP tunnel header, an IPsec header, and an inner IP header, a TCP/UDP header, an application specific header, and data payload.

21. A communication device, comprising:

a management console adapted to define a plurality of peer-to-peer networks of users over an overlay network and a set of policies for controlling communication capabilities between the users in each peer-to-peer network, wherein each peer-to-peer network in the plurality of peer-to-peer networks defined over the overlay network comprise different user groups and different communication policies associated therewith.

22. The device of claim 21 , wherein the management console resides on a communication device associated with a user belonging to a peer-to-peer network defined over the overlay network.

23. The device of claim 21 , wherein the management console resides on a server adapted to at least partially facilitate the overlay network.

24. The device of claim 21 , wherein the overlay network comprises at least one of an IPsec, an L2, and an L3 VPN overlay network, and wherein at least one peer-to-peer network defined over the overlay network is configured in a mesh topology.

25. A non-transitory computer readable medium having stored thereon instructions that cause a computing system to execute a method, the instructions comprising:

instructions configured to provide a Virtual Private Network (VPN) overlay network for a first set of communication devices and first set of users; and

instructions configured to define a first and second peer-to-peer network over the VPN, the first peer-to-peer network being defined for a second set of communication devices over the VPN overlay network and the second peer-to-peer network being defined for at least one of a third set of communication devices and third set of users over the VPN overlay network, wherein at least one of a second set of communication devices and second set of users are in at least one of a first set of communication devices and first set of users, wherein the at least one of a third set of communication devices and third set of users are in the at least one of a first set of communication devices and first set of users.

Assignments (25)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
BANKRUPTCY COURT ORDER RELEASING THE SECURITY INTEREST RECORDED AT REEL/FRAME 020156/0149 Recorded Jul 25, 2022
From: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
To: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES
Reel/Frame 060953/0412 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.; AVAYA TECHNOLOGY, LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
Reel/Frame 045032/0213 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
REASSIGNMENT Recorded Jun 26, 2008
From: AVAYA TECHNOLOGY LLC
To: AVAYA INC
Reel/Frame 021156/0734 →
SECURITY AGREEMENT Recorded Nov 28, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 020166/0705 →
SECURITY AGREEMENT Recorded Nov 27, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 020156/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2007
From: CURCIO, JOSEPH; MANI, MAHALINGAM
To: AVAYA TECHNOLOGY LLC
Reel/Frame 019391/0674 →
Continuity (1)
Related Publication 20080307519A1 · Dec 11, 2008