US2023064345A1PendingUtilityA1

Device Network Mapping Obscuration

Assignee: AT & T IP I LPPriority: May 4, 2021Filed: Nov 14, 2022Published: Mar 2, 2023
Est. expiryMay 4, 2041(~14.8 yrs left)· nominal 20-yr term from priority
H04L 63/0428H04L 12/4641H04L 63/0272H04L 63/0407
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A sender device can determine that data associated with an application is to be sent to a service via a network. The sender device can generate resource queries directed to at least two participant devices and receive responses indicating whether each of the participant devices has a resource available to host a virtual network function (“VNF”). The sender device can generate commands directed to security interface applications executed by the participant devices. The commands can instruct the participant devices to instantiate the VNFs. The sender device can partition the data into data partitions directed to the participant devices. The sender device can send the data partitions to the VNFs of the participant devices. The VNFs can forward the data partitions to a network access device that can combine the data partitions and send the data to the service via the network.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 determining, by a sender device comprising a processor, that data associated with an application is to be sent to a service via a network;   in response to determining that the data is to be sent to the service via the network, generating, by the sender device, a resource query directed to a participant device, wherein the resource query causes the participant device to respond with a resource query response indicating whether the participant device has a resource capable of hosting a virtual network function;   sending, by the sender device, the resource query to the participant device;   receiving, by the sender device, the resource query response indicating that the participant device has the resource capable of hosting the virtual network function;   generating, by the sender device, a command directed to the participant device, wherein the command instructs the participant device to instantiate the virtual network function using the resource;   sending, by the sender device, the command to the participant device, wherein the participant device instantiates the virtual network function in accordance with the command;   partitioning, by the sender device, the data into a plurality of data partitions; and   sending, by the sender device, the plurality of data partitions to a plurality of virtual network functions operating on a plurality of participant devices, wherein the plurality of virtual network functions comprise the virtual network function, wherein the plurality of participant devices comprise the participant device, and wherein the plurality of participant devices forward, via the plurality of virtual network functions, the plurality of data partitions to a network access device that combines the plurality of data partitions and sends the data to the service via the network.   
     
     
         2 . The method of  claim 1 , wherein the command further instructs the participant device to instantiate a network randomizer engine in the virtual network function. 
     
     
         3 . The method of  claim 2 , further comprising:
 determining, by the sender device, an exclusionary data traffic characteristic, wherein the exclusionary data traffic characteristic instructs the network randomizer engine to exclude data traffic having the exclusionary data traffic characteristic; and   sending, by the sender device, the data traffic having the exclusionary data traffic characteristic to the network randomizer engine.   
     
     
         4 . The method of  claim 1 , further comprising encrypting, by the sender device, the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices. 
     
     
         5 . The method of  claim 4 , wherein encrypting, by the sender device, the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices comprises encrypting, by the sender device, each data partition of the plurality of data partitions using a unique encryption key. 
     
     
         6 . A computer-readable storage medium comprising computer-executable instructions that, when executed by a processor of a sender device, cause the processor to perform operations comprising:
 determining that data associated with an application is to be sent to a service via a network;   in response to determining that the data is to be sent to the service via the network, generating a resource query directed to a participant device, wherein the resource query causes the participant device to respond with a resource query response indicating whether the participant device has a resource capable of hosting a virtual network function;   sending the resource query to the participant device;   receiving the resource query response indicating that the participant device has the resource capable of hosting the virtual network function;   generating a command directed to the participant device, wherein the command instructs the participant device to instantiate the virtual network function using the resource;   sending the command to the participant device, wherein the participant device instantiates the virtual network function in accordance with the command;   partitioning the data into a plurality of data partitions; and   sending the plurality of data partitions to a plurality of virtual network functions operating on a plurality of participant devices, wherein the plurality of virtual network functions comprise the virtual network function, wherein the plurality of participant devices comprise the participant device, and wherein the plurality of participant devices forward, via the plurality of virtual network functions, the plurality of data partitions to a network access device that combines the plurality of data partitions and sends the data to the service via the network.   
     
     
         7 . The computer-readable storage medium of  claim 6 , wherein the command further instructs the participant device to instantiate a network randomizer engine in the virtual network function. 
     
     
         8 . The computer-readable storage medium of  claim 7 , wherein the operations further comprise:
 determining an exclusionary data traffic characteristic, wherein the exclusionary data traffic characteristic instructs the network randomizer engine to exclude data traffic having the exclusionary data traffic characteristic; and   sending the data traffic having the exclusionary data traffic characteristic to the network randomizer engine.   
     
     
         9 . The computer-readable storage medium of  claim 6 , wherein the operations further comprise encrypting the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices. 
     
     
         10 . The computer-readable storage medium of  claim 9 , wherein encrypting the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices comprises encrypting each data partition of the plurality of data partitions using a unique encryption key. 
     
     
         11 . A sender device comprising:
 a processor; and   a memory comprising computer-executable instructions that, when executed by the processor, cause the processor to perform operations comprising:
 determining that data associated with an application is to be sent to a service via a network, 
 in response to determining that the data is to be sent to the service via the network, generating a resource query directed to a participant device, wherein the resource query causes the participant device to respond with a resource query response indicating whether the participant device has a resource capable of hosting a virtual network function, 
 sending the resource query to the participant device, 
 receiving the resource query response indicating that the participant device has the resource capable of hosting the virtual network function, 
 generating a command directed to the participant device, wherein the command instructs the participant device to instantiate the virtual network function using the resource, 
 sending the command to the participant device, wherein the participant device instantiates the virtual network function in accordance with the command; partitioning the data into a plurality of data partitions, and 
 sending the plurality of data partitions to a plurality of virtual network functions operating on a plurality of participant devices, wherein the plurality of virtual network functions comprise the virtual network function, wherein the plurality of participant devices comprise the participant device, and wherein the plurality of participant devices forward, via the plurality of virtual network functions, the plurality of data partitions to a network access device that combines the plurality of data partitions and sends the data to the service via the network. 
   
     
     
         12 . The sender device of  claim 11 , wherein the command further instructs the participant device to instantiate a network randomizer engine in the virtual network function. 
     
     
         13 . The sender device of  claim 12 , wherein the operations further comprise:
 determining an exclusionary data traffic characteristic, wherein the exclusionary data traffic characteristic instructs the network randomizer engine to exclude data traffic having the exclusionary data traffic characteristic; and   sending the data traffic having the exclusionary data traffic characteristic to the network randomizer engine.   
     
     
         14 . The sender device of  claim 13 , wherein the exclusionary data traffic characteristic comprises a transmission delay, a queuing delay, a throughput change, a packet order change, or a transmission power level change. 
     
     
         15 . The sender device of  claim 11 , further comprising encrypting the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices. 
     
     
         16 . The sender device of  claim 15 , wherein encrypting the plurality of data partitions prior to sending the plurality of data partitions to the plurality of virtual network functions operating on the plurality of participant devices comprises encrypting each data partition of the plurality of data partitions using a unique encryption key. 
     
     
         17 . The sender device of  claim 11 , further comprising a security interface component, wherein the security interface component comprises the processor and the memory. 
     
     
         18 . The sender device of  claim 17 , wherein the memory comprises a security interface application comprising the computer-executable instructions. 
     
     
         19 . The sender device of  claim 18 , wherein the memory further comprises the application. 
     
     
         20 . The sender device of  claim 19 , wherein the application comprises an Internet of Things application.

Join the waitlist — get patent alerts

Track US2023064345A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.