US2022263800A1PendingUtilityA1

Secure on-premise to cloud communication

Assignee: OROCK TECH INCPriority: Jun 15, 2018Filed: Dec 23, 2021Published: Aug 18, 2022
Est. expiryJun 15, 2038(~11.9 yrs left)· nominal 20-yr term from priority
Inventors:John Leon
H04L 63/0245H04L 63/0272H04L 63/0876H04L 63/0209H04L 63/18
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A plurality of system nodes coupled via a dedicated private network is described herein. The nodes offer an end-to-end solution for protecting against network-based attacks. The nodes can include network gateways that allow remote systems, such as servers located at an entity's place of operation or a data center accessible by the entity, to securely transmit data between the nodes and the remote systems. For example, the network gateways can transmit split data into different portions, and transmit each portion over a different path through a public network to mitigate the effects of man-in-the-middle attacks. Once data reaches a node, transmission of the data from one node to another can pass through multiple intermediary nodes via the dedicated private network. The nodes and/or remote systems may also include cross-domain guard devices that control whether data can pass from one security domain to another.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for securely communicating data, the system comprising:
 a computing system comprising one or more computing devices, the computing system configured to operate as a cross-domain guard, the computing system located in a data center that has an internal network with a first security domain, the computing system configured with computer-executable instructions that, when executed, cause the computing system to:
 determine that a first data packet can be transmitted from the first security domain to a second security domain based on an analysis of content of the first data packet; and 
 prevent transmission of a second data packet from the first security domain to the second security domain based on an analysis of content of the second data packet; 
   a source network gateway in communication with the computing system and located in the data center, the source network gateway comprising a hardware processor, the source network gateway configured with second computer-executable instructions that, when executed, cause the source network gateway to obtain and split the first data packet into a third data packet and a fourth data packet that is not a duplicate of the third data packet; and   a remote system located at a location remote from the data center, the remote system having a second internal network with the second security domain, the remote system further comprising a remote network gateway,   wherein the remote network gateway is configured with third computer-executable instructions that, when executed, cause the remote network gateway to:
 obtain the third data packet from the source network gateway via a first path through the network; 
 obtain the fourth data packet from the source network gateway via a second path through the network; and 
 assemble the third data packet and the fourth data packet to form a reassembled version of the first data packet.

Join the waitlist — get patent alerts

Track US2022263800A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.