Patents by Inventor Ludwin Fuchs
Ludwin Fuchs has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12095743Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.Type: GrantFiled: July 7, 2023Date of Patent: September 17, 2024Assignee: Tyco Fire & Security GmbHInventors: Ludwin Fuchs, Dustin Orion Lundquist
-
Publication number: 20240184260Abstract: Systems and methods for device agility may include an edge device manager configured to identify a container on a local network, determine a local internet protocol (IP) address for the container, and transmit an identifier of the container to an edge device orchestrator. The edge device manager may receive a network address translation (NAT) address assigned by the edge device orchestrator for the container, and manage, using the identifier, changes to the local IP address for the container on the local network according to the NAT address assigned by the edge device orchestrator.Type: ApplicationFiled: December 6, 2023Publication date: June 6, 2024Inventors: Nicholas Marrone, Ludwin Fuchs
-
Publication number: 20240039898Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.Type: ApplicationFiled: July 7, 2023Publication date: February 1, 2024Inventors: Ludwin Fuchs, Dustin Orion Lundquist
-
Patent number: 11729152Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.Type: GrantFiled: February 1, 2021Date of Patent: August 15, 2023Assignee: Tempered Networks, Inc.Inventors: Ludwin Fuchs, Dustin Orion Lundquist
-
Publication number: 20230188446Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: ApplicationFiled: November 17, 2022Publication date: June 15, 2023Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Patent number: 11582129Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: GrantFiled: December 14, 2018Date of Patent: February 14, 2023Assignee: Tempered Networks, Inc.Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Patent number: 11509559Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: GrantFiled: September 5, 2019Date of Patent: November 22, 2022Assignee: Tempered Networks, Inc.Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Publication number: 20210409384Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.Type: ApplicationFiled: February 1, 2021Publication date: December 30, 2021Inventors: Ludwin Fuchs, Dustin Orion Lundquist
-
Patent number: 10911418Abstract: Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.Type: GrantFiled: June 26, 2020Date of Patent: February 2, 2021Assignee: Tempered Networks, Inc.Inventors: Ludwin Fuchs, Dustin Orion Lundquist
-
Patent number: 10797979Abstract: Embodiments are directed to managing communication networks. One or more links associated with a gateway computer may be monitored. Each link may be associated with a network addresses, and the gateway computer is associated with a gateway identifier (GID). Metrics associated with the monitored links may be provided. Scores may be associated with the links based on the metrics. The scores may be modified based on policy information. The links may be compared based on the scores and the policy information. A comparison may be employed to activate a portion of the links such that the activated links may be employed to communicate over the networks with other gateway computers. The links may be compared based on updated metrics. The comparison of the updated metrics may be used to activate another portion of the links that are associated with the GID.Type: GrantFiled: October 26, 2018Date of Patent: October 6, 2020Assignee: Tempered Networks, Inc.Inventors: Ludwin Fuchs, Paul David Lambros Bartell, Bryan David Skene, Jeffrey Michael Ahrenholz, Konstantin Tsoy
-
Publication number: 20190394107Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: ApplicationFiled: September 5, 2019Publication date: December 26, 2019Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Publication number: 20190372876Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: ApplicationFiled: December 14, 2018Publication date: December 5, 2019Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Publication number: 20190363960Abstract: Embodiments are directed to managing communication networks. One or more links associated with a gateway computer may be monitored. Each link may be associated with a network addresses, and the gateway computer is associated with a gateway identifier (GID). Metrics associated with the monitored links may be provided. Scores may be associated with the links based on the metrics. The scores may be modified based on policy information. The links may be compared based on the scores and the policy information. A comparison may be employed to activate a portion of the links such that the activated links may be employed to communicate over the networks with other gateway computers. The links may be compared based on updated metrics. The comparison of the updated metrics may be used to activate another portion of the links that are associated with the GID.Type: ApplicationFiled: October 26, 2018Publication date: November 28, 2019Inventors: Ludwin Fuchs, Paul David Lambros Bartell, Bryan David Skene, Jeffrey Michael Ahrenholz, Konstantin Tsoy
-
Patent number: 10326799Abstract: Embodiments are directed to secure communication over a network. If a source node sends a communication to a target node, a source gateway may forward the communication to the target node. The source gateway may provide a gateway identifier (GID) that may be associated with one or more target gateways associated with the target node. Further, the source gateway may embed marker information that includes at least a portion of the GID in the communication. If the GID is associated with more than one target gateway, a TMD selects one target gateway from the more than one target gateways. Also, the TMD provides a gateway key associated with the selected target gateway that is associated with the communication. And, the TMD may provide the communication to the selected target gateway that provides the communication to the target node.Type: GrantFiled: August 7, 2017Date of Patent: June 18, 2019Assignee: Tempered Networks, Inc. Reel/Frame: 043222/0041Inventors: Bryan David Skene, Jeff James Costlow, Ludwin Fuchs
-
Patent number: 10178133Abstract: Embodiments are directed towards, gateway computers and management platform server computers for managing secure communication over a network. Gateway computer may intercept communications from unauthenticated source node computers directed to target node computers. If the unauthenticated node computer provides its credentials in response to a request for credentials from the gateway computer, the credentials and the intercepted communications may be provided to a management platform server for further processing. The management platform server may authenticate the unauthenticated source node computer based on its credentials and the intercepted communication and the management platform server may determine a target gateway computer that corresponds to the target node computer based on content of the intercepted communication. The management platform server may provide configuration information for generating a secure private network connection between the gateway computer and the target gateway computer.Type: GrantFiled: August 7, 2017Date of Patent: January 8, 2019Assignee: Tempered Networks, Inc.Inventors: David Mattes, Ludwin Fuchs
-
Patent number: 10158545Abstract: Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.Type: GrantFiled: May 31, 2018Date of Patent: December 18, 2018Assignee: Tempered Networks, Inc.Inventors: Nicholas Anthony Marrone, Bryan David Skene, Ludwin Fuchs, Jeffrey Scott Hussey
-
Patent number: 10116539Abstract: Embodiments are directed to managing communication networks. One or more links associated with a gateway computer may be monitored. Each link may be associated with a network addresses, and the gateway computer is associated with a gateway identifier (GID). Metrics associated with the monitored links may be provided. Scores may be associated with the links based on the metrics. The scores may be modified based on policy information. The links may be compared based on the scores and the policy information. A comparison may be employed to activate a portion of the links such that the activated links may be employed to communicate over the networks with other gateway computers. The links may be compared based on updated metrics. The comparison of the updated metrics may be used to activate another portion of the links that are associated with the GID.Type: GrantFiled: May 23, 2018Date of Patent: October 30, 2018Assignee: Tempered Networks, Inc.Inventors: Ludwin Fuchs, Paul David Lambros Bartell, Bryan David Skene, Jeffrey Michael Ahrenholz, Konstantin Tsoy
-
Patent number: 10038725Abstract: A private overlay network is introduced into an existing core network infrastructure to control information flow between private secure environments. Such a scheme can be used to connect a factory automation network linking operations devices to a corporate network linking various business units, with enhanced network security. Such a connection can be facilitated by introducing into the existing infrastructure a set of industrial security appliances (ISAs) that work together to create an encrypted tunnel between the two networks. The set of ISAs can be scalable to overlay differently sized core networks, to create the private overlay network. Connections to the private overlay network can be managed by the ISAs in a distributed fashion, implementing a peer-to-peer dynamic mesh policy. The industrial security system disclosed may be particularly advantageous in environments such as public utility systems, medical facilities, and energy delivery systems.Type: GrantFiled: May 16, 2016Date of Patent: July 31, 2018Assignee: Tempered Networks, Inc.Inventors: David Mattes, Ludwin Fuchs, Eric Artzt
-
Publication number: 20180183833Abstract: Embodiments are directed to secure communication over a network. If a source node sends a communication to a target node, a source gateway may forward the communication to the target node. The source gateway may provide a gateway identifier (GID) that may be associated with one or more target gateways associated with the target node. Further, the source gateway may embed marker information that includes at least a portion of the GID in the communication. If the GID is associated with more than one target gateway, a TMD selects one target gateway from the more than one target gateways. Also, the TMD provides a gateway key associated with the selected target gateway that is associated with the communication. And, the TMD may provide the communication to the selected target gateway that provides the communication to the target node.Type: ApplicationFiled: August 7, 2017Publication date: June 28, 2018Inventors: Bryan David Skene, Jeff James Costlow, Ludwin Fuchs
-
Publication number: 20180183834Abstract: Embodiments are directed towards, gateway computers and management platform server computers for managing secure communication over a network. Gateway computer may intercept communications from unauthenticated source node computers directed to target node computers. If the unauthenticated node computer provides its credentials in response to a request for credentials from the gateway computer, the credentials and the intercepted communications may be provided to a management platform server for further processing. The management platform server may authenticate the unauthenticated source node computer based on its credentials and the intercepted communication and the management platform server may determine a target gateway computer that corresponds to the target node computer based on content of the intercepted communication. The management platform server may provide configuration information for generating a secure private network connection between the gateway computer and the target gateway computer.Type: ApplicationFiled: August 7, 2017Publication date: June 28, 2018Inventors: David Mattes, Ludwin Fuchs