US 12,192,177 B2
System and method for secure data transfer
Xiaobo Sherry Wei, Santa Clara, CA (US); Ramakrishnan Kunnath, Santa Clara, CA (US); and Arvind Sreekumar, Santa Clara, CA (US)
Assigned to Aviatrix Systems, Inc., Santa Clara, CA (US)
Filed by Aviatrix Systems, Inc., Santa Clara, CA (US)
Filed on Oct. 10, 2023, as Appl. No. 18/378,147.
Application 18/378,147 is a continuation of application No. 17/010,822, filed on Sep. 2, 2020, granted, now 11,784,976, issued on Oct. 10, 2023.
Claims priority of provisional application 62/907,493, filed on Sep. 27, 2019.
Prior Publication US 2024/0048529 A1, Feb. 8, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); G06F 9/455 (2018.01); H04L 12/46 (2006.01); H04L 67/1001 (2022.01); H04L 67/1097 (2022.01); H04L 67/50 (2022.01); H04L 67/51 (2022.01)
CPC H04L 63/0272 (2013.01) [G06F 9/455 (2013.01); H04L 12/4641 (2013.01); H04L 63/04 (2013.01); H04L 63/08 (2013.01); H04L 63/102 (2013.01); H04L 63/20 (2013.01); H04L 67/1001 (2022.05); H04L 67/1097 (2013.01); H04L 67/51 (2022.05); H04L 67/535 (2022.05)] 19 Claims
OG exemplary drawing
 
1. A secure exchange system comprising:
a computing device deployed within an on-premises network and communicatively coupled to a virtual private cloud network;
the virtual private cloud network comprising:
a plurality of gateways, each gateway of the plurality of gateways is configured to generate routing logic and one or more local directories; and
a gateway selector to select one of the plurality of gateways to apply a load balancing scheme directed toward communication sessions from the on-premises network to a plurality of public cloud storage elements forming a public cloud storage service;
a controller configured to:
authenticate a user, the controller communicatively coupled to each of the plurality of gateways to restrict access to at least one local directory of the one or more local directories in response to a failure to authenticate the user,
create a virtual private cloud (VPC) endpoint within a public cloud network infrastructure being logic that enables resources external from the secure exchange system to access the plurality of public cloud storage elements via the one or more local directories within each gateway of the plurality of gateways while avoiding the transfer of data outside the public cloud network infrastructure and over an Internet connection,
wherein the routing logic is configured to communicate information associated with an incoming message relating to an element of the plurality of public cloud storage elements from the on-premises network and generate an inter-cloud message to access the element of the plurality of public cloud storage elements via the VPC endpoint.