Patents Assigned to Tempered Networks, Inc.
  • Patent number: 11831514
    Abstract: Embodiments are directed to managing communication over networks. A gateway identifier (GID), a network address, source nodes, relays, or the like, may be determined based on an overlay network. Two or more relays may be ranked based on metrics associated with each relay such that a top ranked relay is designated as a preferred relay.
    Type: Grant
    Filed: April 30, 2021
    Date of Patent: November 28, 2023
    Assignee: Tempered Networks, Inc.
    Inventors: Jeffrey Michael Ahrenholz, Dustin Orion Lundquist
  • Patent number: 11824901
    Abstract: Embodiments are directed to managing communication. Credentials of a user may be provided to an authorization service such that the authorization service authenticates the user as a member of authorization groups and such that the user may be associated with a gateway on an overlay network. The authorization groups may be compared with user groups to associate the user with one or more user group. The gateway may be associated with one or more resource group based on the user groups. Policy information may be generated for the gateway based on each resource group. The policy information may be provided to the gateway to define policies associated with resources in the overlay network. The policy information may be enforced against source nodes providing overlay traffic directed to target nodes in the overlay network.
    Type: Grant
    Filed: July 16, 2021
    Date of Patent: November 21, 2023
    Assignee: Tempered Networks, Inc.
    Inventors: Nicholas Anthony Marrone, Bryan David Skene
  • Patent number: 11729152
    Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.
    Type: Grant
    Filed: February 1, 2021
    Date of Patent: August 15, 2023
    Assignee: Tempered Networks, Inc.
    Inventors: Ludwin Fuchs, Dustin Orion Lundquist
  • Patent number: 11582129
    Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.
    Type: Grant
    Filed: December 14, 2018
    Date of Patent: February 14, 2023
    Assignee: Tempered Networks, Inc.
    Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
  • Patent number: 11509559
    Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.
    Type: Grant
    Filed: September 5, 2019
    Date of Patent: November 22, 2022
    Assignee: Tempered Networks, Inc.
    Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
  • Patent number: 11070594
    Abstract: Embodiments are directed to managing communication. Credentials of a user may be provided to an authorization service such that the authorization service authenticates the user as a member of authorization groups and such that the user may be associated with a gateway on an overlay network. The authorization groups may be compared with user groups to associate the user with one or more user group. The gateway may be associated with one or more resource group based on the user groups. Policy information may be generated for the gateway based on each resource group. The policy information may be provided to the gateway to define policies associated with resources in the overlay network. The policy information may be enforced against source nodes providing overlay traffic directed to target nodes in the overlay network.
    Type: Grant
    Filed: October 29, 2020
    Date of Patent: July 20, 2021
    Assignee: Tempered Networks, Inc.
    Inventors: Nicholas Anthony Marrone, Bryan David Skene
  • Patent number: 10999154
    Abstract: Embodiments are directed to managing communication over networks. A gateway identifier (GID), a network address, source nodes, relays, or the like, may be determined based on an overlay network. Two or more relays may be ranked based on metrics associated with each relay such that a top ranked relay is designated as a preferred relay.
    Type: Grant
    Filed: October 23, 2020
    Date of Patent: May 4, 2021
    Assignee: Tempered Networks, Inc.
    Inventors: Jeffrey Michael Ahrenholz, Dustin Orion Lundquist
  • Patent number: 10911418
    Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.
    Type: Grant
    Filed: June 26, 2020
    Date of Patent: February 2, 2021
    Assignee: Tempered Networks, Inc.
    Inventors: Ludwin Fuchs, Dustin Orion Lundquist
  • Patent number: 10797979
    Abstract: Embodiments are directed to managing communication networks. One or more links associated with a gateway computer may be monitored. Each link may be associated with a network addresses, and the gateway computer is associated with a gateway identifier (GID). Metrics associated with the monitored links may be provided. Scores may be associated with the links based on the metrics. The scores may be modified based on policy information. The links may be compared based on the scores and the policy information. A comparison may be employed to activate a portion of the links such that the activated links may be employed to communicate over the networks with other gateway computers. The links may be compared based on updated metrics. The comparison of the updated metrics may be used to activate another portion of the links that are associated with the GID.
    Type: Grant
    Filed: October 26, 2018
    Date of Patent: October 6, 2020
    Assignee: Tempered Networks, Inc.
    Inventors: Ludwin Fuchs, Paul David Lambros Bartell, Bryan David Skene, Jeffrey Michael Ahrenholz, Konstantin Tsoy
  • Patent number: 10797993
    Abstract: Embodiments are directed to a relay that receives packets from a source gateway associated with a source gateway identifier (GID) and a target GID associated with a target gateway where each GID is separate from a network address or a hostname of the source gateway or the target gateway. The relay determines a connection route based on an association between the connection route and an ingress identifier obtained from the packets. The relay provides the connection route based on the source GID and the target GID. The relay determines network address information associated with the target gateway based on the connection route. And, the relay forwards the packets provided by the source gateway to the target gateway based on the network address information.
    Type: Grant
    Filed: February 4, 2019
    Date of Patent: October 6, 2020
    Assignee: Tempered Networks, Inc.
    Inventors: Jeffrey Michael Ahrenholz, Orlie Thomas Brewer, Jr., Jeff James Costlow
  • Patent number: 10326799
    Abstract: Embodiments are directed to secure communication over a network. If a source node sends a communication to a target node, a source gateway may forward the communication to the target node. The source gateway may provide a gateway identifier (GID) that may be associated with one or more target gateways associated with the target node. Further, the source gateway may embed marker information that includes at least a portion of the GID in the communication. If the GID is associated with more than one target gateway, a TMD selects one target gateway from the more than one target gateways. Also, the TMD provides a gateway key associated with the selected target gateway that is associated with the communication. And, the TMD may provide the communication to the selected target gateway that provides the communication to the target node.
    Type: Grant
    Filed: August 7, 2017
    Date of Patent: June 18, 2019
    Assignee: Tempered Networks, Inc. Reel/Frame: 043222/0041
    Inventors: Bryan David Skene, Jeff James Costlow, Ludwin Fuchs
  • Patent number: 10200281
    Abstract: Embodiments are directed to a relay that receives packets from a source gateway associated with a source gateway identifier (GID) and a target GID associated with a target gateway where each GID is separate from a network address or a hostname of the source gateway or the target gateway. The relay determines a connection route based on an association between the connection route and an ingress identifier obtained from the packets. The relay provides the connection route based on the source GID and the target GID. The relay determines network address information associated with the target gateway based on the connection route. And, the relay forwards the packets provided by the source gateway to the target gateway based on the network address information.
    Type: Grant
    Filed: August 31, 2018
    Date of Patent: February 5, 2019
    Assignee: Tempered Networks, Inc.
    Inventors: Jeffrey Michael Ahrenholz, Orlie Thomas Brewer, Jr., Jeff James Costlow
  • Patent number: 10178133
    Abstract: Embodiments are directed towards, gateway computers and management platform server computers for managing secure communication over a network. Gateway computer may intercept communications from unauthenticated source node computers directed to target node computers. If the unauthenticated node computer provides its credentials in response to a request for credentials from the gateway computer, the credentials and the intercepted communications may be provided to a management platform server for further processing. The management platform server may authenticate the unauthenticated source node computer based on its credentials and the intercepted communication and the management platform server may determine a target gateway computer that corresponds to the target node computer based on content of the intercepted communication. The management platform server may provide configuration information for generating a secure private network connection between the gateway computer and the target gateway computer.
    Type: Grant
    Filed: August 7, 2017
    Date of Patent: January 8, 2019
    Assignee: Tempered Networks, Inc.
    Inventors: David Mattes, Ludwin Fuchs
  • Patent number: 10158545
    Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.
    Type: Grant
    Filed: May 31, 2018
    Date of Patent: December 18, 2018
    Assignee: Tempered Networks, Inc.
    Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
  • Patent number: 10116539
    Abstract: Embodiments are directed to managing communication networks. One or more links associated with a gateway computer may be monitored. Each link may be associated with a network addresses, and the gateway computer is associated with a gateway identifier (GID). Metrics associated with the monitored links may be provided. Scores may be associated with the links based on the metrics. The scores may be modified based on policy information. The links may be compared based on the scores and the policy information. A comparison may be employed to activate a portion of the links such that the activated links may be employed to communicate over the networks with other gateway computers. The links may be compared based on updated metrics. The comparison of the updated metrics may be used to activate another portion of the links that are associated with the GID.
    Type: Grant
    Filed: May 23, 2018
    Date of Patent: October 30, 2018
    Assignee: Tempered Networks, Inc.
    Inventors: Ludwin Fuchs, Paul David Lambros Bartell, Bryan David Skene, Jeffrey Michael Ahrenholz, Konstantin Tsoy
  • Patent number: 10069726
    Abstract: Embodiments are directed to a relay that receives packets from a source gateway. associated with a source gateway identifier (GID) and a target GID associated with a target gateway where each GID is separate from a network address or a hostname of the source gateway or the target gateway. The relay determines a connection route based on an association between the connection route and an ingress identifier obtained from the packets The relay provides the connection route based on the source GID and the target GID. The relay determines network address information associated with the target gateway based on the connection route. And, the relay forwards the packets provided by the source gateway to the target gateway based on the network address information.
    Type: Grant
    Filed: March 16, 2018
    Date of Patent: September 4, 2018
    Assignee: Tempered Networks, Inc.
    Inventors: Jeffrey Michael Ahrenholz, Orlie Thomas Brewer, Jr., Jeff James Costlow
  • Patent number: 10038725
    Abstract: A private overlay network is introduced into an existing core network infrastructure to control information flow between private secure environments. Such a scheme can be used to connect a factory automation network linking operations devices to a corporate network linking various business units, with enhanced network security. Such a connection can be facilitated by introducing into the existing infrastructure a set of industrial security appliances (ISAs) that work together to create an encrypted tunnel between the two networks. The set of ISAs can be scalable to overlay differently sized core networks, to create the private overlay network. Connections to the private overlay network can be managed by the ISAs in a distributed fashion, implementing a peer-to-peer dynamic mesh policy. The industrial security system disclosed may be particularly advantageous in environments such as public utility systems, medical facilities, and energy delivery systems.
    Type: Grant
    Filed: May 16, 2016
    Date of Patent: July 31, 2018
    Assignee: Tempered Networks, Inc.
    Inventors: David Mattes, Ludwin Fuchs, Eric Artzt
  • Patent number: 9729580
    Abstract: Embodiments are directed towards, gateway computers and management platform server computers for managing secure communication over a network. Gateway computer may intercept communications from unauthenticated source node computers directed to target node computers. If the unauthenticated node computer provides its credentials in response to a request for credentials from the gateway computer, the credentials and the intercepted communications may be provided to a management platform server for further processing. The management platform server may authenticate the unauthenticated source node computer based on its credentials and the intercepted communication and the management platform server may determine a target gateway computer that corresponds to the target node computer based on content of the intercepted communication. The management platform server may provide configuration information for generating a secure private network connection between the gateway computer and the target gateway computer.
    Type: Grant
    Filed: July 30, 2015
    Date of Patent: August 8, 2017
    Assignee: Tempered Networks, Inc.
    Inventors: David Mattes, Ludwin Fuchs
  • Patent number: 9729581
    Abstract: Embodiments are directed to secure communication over a network. If a source node sends a communication to a target node, a source gateway may forward the communication to the target node. The source gateway may provide a gateway identifier (GID) that may be associated with one or more target gateways associated with the target node. Further, the source gateway may embed marker information that includes at least a portion of the GID in the communication. If the GID is associated with more than one target gateway, a TMD selects one target gateway from the more than one target gateways. Also, the TMD provides a gateway key associated with the selected target gateway that is associated with the communication. And, the TMD may provide the communication to the selected target gateway that provides the communication to the target node.
    Type: Grant
    Filed: July 1, 2016
    Date of Patent: August 8, 2017
    Assignee: Tempered Networks, Inc.
    Inventors: Bryan David Skene, Jeff James Costlow, Ludwin Fuchs
  • Patent number: 9621514
    Abstract: Embodiments are directed to managing secure communication between a plurality of node computers over a network. If overlay networks for node computers are provided for communicating between the node computers, a mesh network may be configured. If a node computer that may be associated with the overlay networks sends a communication to other node computers also associated with the overlay networks, a gateway computer associated with the node computer may perform actions to process the communication. The gateway computer may select an overlay network based on the node computer. Target gateway computers associated with the other node computers may be determined based on the overlay network and the mesh network. Physical paths from the gateway computer to the target gateway computers may be determined. The gateway computer may send the communication to the target gateway computers over the physical paths and then to the other node computers.
    Type: Grant
    Filed: March 28, 2016
    Date of Patent: April 11, 2017
    Assignee: Tempered Networks, Inc.
    Inventors: Robert George Gilde, Jeffrey Anthony Pancottine