IP Library Granted Patent US 11,030,305
Granted Patent B2
US 11,030,305 · App. 13/664,505 · Granted Jun 8, 2021

Virtual relay device for providing a secure connection to a remote device

Inventors: Ralph Farina (Downington, PA); Ted Hinaman (Malvern, PA); Robert A. Johnson (Pottstown, PA); Steven Rajcan (Glenmore, PA); James Trocki (Whitehall, PA); Mark Vallevand (Lino Lakes, MN)
Assignee: Unisys Corporation
G06F21/53G06F21/606H04L63/0263H04L63/0272H04L63/104G06F9/455
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,305
App. No.
13/664,505
Granted
Jun 8, 2021
Kind
B2
Abstract

Virtual machines in a network may be isolated by encrypting transmissions between the virtual machines with keys possessed only by an intended recipient. Within a network, the virtual machines may be logically organized into a number of community-of-interest (COI) groups. Each COI may use an encryption key to secure communications within the COI, such that only other virtual machines in the COI may decrypt the message. Remote devices may gain access to virtual machines in a network through a virtual device relay. The virtual device relay receives data from the remote device, such as a tablet or cellular phone, and forwards the data to one of the virtual machines, when the virtual device relay shares a COI with the destination virtual machine.

Claims (41)

1. A method of providing a remote device access to a shared network, comprising:

receiving, at a router, an incoming connection request to open an IPsec tunnel to the shared network from the remote device belonging to a community of interest having a unique key;

initiating a virtual device host, wherein the virtual device host executes a virtual device relay for the remote device;

hosting the router and the virtual device relay on a server;

routing, to the virtual device host, data received from the incoming connection;

receiving, at the virtual device relay, data from the remote device, the data being encrypted with the unique key; and

forwarding the data to a second host on the shared network having the same community of interest by the virtual device relay, such that the second host can use the unique key to decrypt the data;

wherein the remote device and the second host can securely communicate through the virtual device relay by use of the unique key.

2. The method of claim 1 , further comprising:

receiving authentication information from the remote device; and

assigning the community-of-interest to the virtual device relay based on the authentication information.

3. The method of claim 2 , further comprising assigning a second community-of-interest to the virtual device relay based on the authentication information.

4. The method of claim 1 , in which the remote device is a mobile device.

5. A computer program product comprising:

a non-transitory computer-readable medium comprising:

code to receive at a router an incoming connection request to open an IPsec tunnel to a shared network from a remote device belonging to a community of interest having a unique key;

code to initiate a virtual device host, wherein the virtual device host executes a virtual device relay for the remote device;

code to host the router and the virtual device relay in a virtualized environment;

code to route, to the virtual device host, data received from the incoming connection;

code to receive, at the virtual device relay, data from a remote device, the data being encrypted with the unique key; and

code to forward the data to a second host on the shared network having the same community of interest by the virtual device relay, such that the second host can use the unique key to decrypt the data;

wherein the remote device and the second host can securely communicate through the virtual relay by use of the unique key.

6. The computer program product of claim 5 , in which the medium comprises:

code to receive authentication information from the remote device; and

code to assign the community-of-interest to the virtual device relay based on the authentication information.

7. The computer program product of claim 6 , in which the medium comprises code to assign a second community-of-interest to the virtual device relay based on the authentication information.

8. An apparatus, comprising:

a memory; and

a processor coupled to the memory, in which the processor is configured:

to receive at a router an incoming connection request to open an IPsec tunnel to a shared network from a remote device belonging to a community of interest having a unique key;

to initiate a first, virtual device host, wherein the first, virtual device host is configured to executes a plurality of virtual device relays for the remote device, each of the virtual device relays being assigned to one or more communities-of-interest of a plurality of communities-of-interest;

to host the router and the virtual device relay in a virtualized environment;

to route to the virtual device host, data received from the incoming connection

to receive, at the virtual device relay, data from the remote device, the data being encrypted with the unique key; and

to forward the data to a second host on the shared network having the same community of interest by the virtual device relay, such that the second host can use the unique key to decrypt the data,

wherein the remote device and the second host can securely communicate through the virtual device relay by use of the unique key.

9. The apparatus of claim 8 , in which the processor is further configured:

to receive authentication information from the remote device; and

to assign the community-of-interest to the virtual device relay based on the authentication information.

10. The apparatus of claim 9 , in which the processor is further configured to assign a second community-of-interest to the virtual device relay based on the authentication information.

11. The apparatus of claim 8 , in which the remote device is a mobile device.

Assignments (6)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
SECURITY INTEREST Recorded Nov 19, 2020
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 054481/0865 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2019
From: FARINA, RALPH; HINAMAN, TED; JOHNSON, ROBERT A; RAJCAN, STEVEN; TROCKI, JAMES; VALLEVAND, MARK K
To: UNISYS CORPORATION
Reel/Frame 049251/0516 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →