Secure network protocol and transit system to protect communications deliverability and attribution
Abstract
A network protocol and transit system that together provide data tunneling designed for anonymous and hidden delivery. The approach protects communications deliverability and attribution for users on any device and in any location, irrespective of the underlying operating environment. The solution provides for a fully “cloaked network” comprising zero-trust nodes, an onion routing-based bi-directional protocol with modular multi-layered encryption, evasive multi-pathing that leverages randomized ephemeral virtual circuit generation, and virtual rendezvous for person-to-person communications. The approach may be implemented “as-a-service,” in a hybrid/bridged network, on-premises, or otherwise.
Claims
exact text as granted — not AI-modifiedWhat is claimed is as follows:
1 . A method of secure communication operative at a first endpoint in association with a network of nodes configured as a mesh, wherein a node is a computing entity, and at least some of the nodes in the network are configured with a discovery service, comprising:
receiving from the discovery service a list of nodes in the network; responsive to receipt of the list of nodes, establishing a virtual circuit to a gateway node identified from the list and requesting that the gateway node establish a connection to a protected network distinct from the network of nodes and to which the gateway node is coupled; and responsive to receipt from the gateway node of given information, the given information confirming that the gateway node has established a connection to the protected network, communicating information to an entity in the protected network via the virtual circuit and the gateway node.
2 . The method as described in claim 1 wherein the given information also confirms that a user associated with the first endpoint has an authorization to connect to the protected network.
3 . The method as described in claim 1 wherein the protected network is a virtual private network (VPN).
4 . The method as described in claim 1 wherein the virtual circuit has at least three (3) node hops comprising first, second and third nodes, and wherein the second node only sees the first and third nodes but not the first endpoint or the gateway node.
5 . A method of secure communication operative at a first endpoint in association with a network of nodes configured as a mesh, wherein a node is a computing entity, and wherein individual endpoints announce their presence on the network anonymously by registering presence records in a data structure shared across the nodes, comprising:
establishing a virtual circuit to first node to look up a second endpoint presence record, and building a second virtual circuit to a second node; building a third virtual circuit to a third node identified in the second endpoint presence record to request a connection between the first endpoint and the second endpoint via the second node; communicating with the second endpoint in response to the second endpoint accepting the connection request and establishing a separate virtual circuit from the second endpoint to the second node.
6 . A method of secure communication operative at a first endpoint in association with a network of nodes configured as a mesh, wherein a node is a computing entity, and wherein individual endpoints announce their presence on the network anonymously by registering presence records in a data structure shared across a first subset of nodes, the nodes in the first subset being onion nodes, comprising:
receiving from a discovery service a list of nodes in the network, the list of nodes having been agreed upon via consensus by a second subset of nodes, the nodes in the second subset being discovery nodes; responsive to receipt of the list, building a first virtual circuit to a node designated in the list and issuing a connection request to a second endpoint; building a second virtual circuit to a rendezvous node; and communicating with the second endpoint in response to the second endpoint accepting the connection request and establishing a separate virtual circuit from the second endpoint to the rendezvous node.Join the waitlist — get patent alerts
Track US2022255903A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.