CloudFlare, Inc.

États‑Unis d’Amérique

Retour au propriétaire

1-100 de 447 pour CloudFlare, Inc. et 1 filiale Trier par
Recheche Texte
Affiner par
Type PI
        Brevet 402
        Marque 45
Juridiction
        États-Unis 429
        International 15
        Canada 2
        Europe 1
Propriétaire / Filiale
[Owner] CloudFlare, Inc. 445
Jaal, LLC 2
Date
Nouveautés (dernières 4 semaines) 1
2026 juillet 1
2026 juin 2
2026 mai 1
2026 avril 1
Voir plus
Classe IPC
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole 174
H04L 29/08 - Procédure de commande de la transmission, p.ex. procédure de commande du niveau de la liaison 121
H04L 9/40 - Protocoles réseaux de sécurité 84
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données 65
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes 55
Voir plus
Classe NICE
42 - Services scientifiques, technologiques et industriels, recherche et conception 36
09 - Appareils et instruments scientifiques et électriques 13
38 - Services de télécommunications 7
37 - Services de construction; extraction minière; installation et réparation 1
41 - Éducation, divertissements, activités sportives et culturelles 1
Voir plus
Statut
En Instance 29
Enregistré / En vigueur 418
  1     2     3     ...     5        Prochaine page

1.

IMPLEMENTING A QUEUING SYSTEM WITH AN ARTIFICIAL QUEUE FOR SUSPECTED BOT TRAFFIC

      
Numéro d'application 19003770
Statut En instance
Date de dépôt 2024-12-27
Date de la première publication 2026-07-02
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Mccorkle, Piper
  • Payne, Oliver Conway
  • Semeria, Fabienne Heitiare
  • Lee, Sally
  • Erwin-Martinetti, Adam
  • To, Davis
  • Olache-Anderson, Arielle Loran

Abrégé

An edge server of a plurality of edge servers of a distributed cloud computing network receives a request from a requesting device to access a web application hosted at an origin server. The edge server sends a first page to the requesting device that includes a challenge. Based on a first response to the challenge, the edge server determines that the request has indications of being initiated by a malicious bot. The edge server sends a second response to the requesting device that includes a second page that indicates that the requesting device is in a queue. The queue is an artificial queue that has the appearance of a legitimate queue, but requests placed in the artificial queue do not ever reach the origin server. The edge server can periodically modify the second page to indicate progress in the artificial queue.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

2.

Enforcing Application Access Policies For a Private Self-Hosted Application at a Secure Web Gateway

      
Numéro d'application 18988715
Statut En instance
Date de dépôt 2024-12-19
Date de la première publication 2026-06-25
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Leitão Libânio Gomes, Eduardo Joaquim
  • Li, Jesse
  • Johnson, Kenneth A.
  • Borkenstein, Michael

Abrégé

Enforcing application access policies for a private self-hosted application at a secure web gateway. Configuration is received for a private self-hosted application, for an access policy for accessing the private self-hosted application, and for an L7 policy that applies to L7 traffic that is scoped to the private self-hosted application. From the access policy, one or more rules to be evaluated by a secure web gateway are generated. An HTTP request is received at the secure web gateway that is destined for the private self-hosted application. The secure web gateway evaluates the HTTP request against the L7 policy. If the HTTP request is not to be blocked by the L7 policy, the secure web gateway evaluates the HTTP request against the generated rules. If the HTTP request is not to be blocked by the generated rules, the HTTP request is transmitted to the private self-hosted application.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

3.

ENFORCING APPLICATION ACCESS POLICIES FOR A PRIVATE SELF-HOSTED APPLICATION AT A SECURE WEB GATEWAY

      
Numéro d'application US2025060608
Numéro de publication 2026/136844
Statut Délivré - en vigueur
Date de dépôt 2025-12-19
Date de publication 2026-06-25
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Leitão Libânio Gomes, Eduardo Joaquim
  • Li, Jesse
  • Johnson, Kenneth A.
  • Borkenstein, Michael

Abrégé

Enforcing application access policies for a private self-hosted application at a secure web gateway. Configuration is received for a private self-hosted application, for an access policy for accessing the private self-hosted application, and for an L7 policy that applies to L7 traffic that is scoped to the private self-hosted application. From the access policy, one or more rules to be evaluated by a secure web gateway are generated. An HTTP request is received at the secure web gateway that is destined for the private self-hosted application. The secure web gateway evaluates the HTTP request against the L7 policy. If the HTTP request is not to be blocked by the L7 policy, the secure web gateway evaluates the HTTP request against the generated rules. If the HTTP request is not to be blocked by the generated rules, the HTTP request is transmitted to the private self-hosted application.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau
  • H04L 67/306 - Profils des utilisateurs

4.

EMDASH

      
Numéro de série 99826906
Statut En instance
Date de dépôt 2026-05-15
Propriétaire Cloudflare, Inc. (USA)
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Computer software development in the field of content management systems and web-based applications; Cloud computing featuring software for use in database management and digital content management systems; Cloud computing featuring software for use in operating content management systems, namely, software as a service (SAAS) services featuring software for digital content creation, management, and optimization; Software as a service (SAAS) services featuring software for building, managing, and deploying content management systems and web-based applications; Providing temporary use of on-line non-downloadable software development tools for authoring, editing, and publishing digital content

5.

Determining and Enforcing Data Location of Internet Traffic Routing Using Transport Layer Security (TLS) Server Name Indication (SNI)

      
Numéro d'application 18907378
Statut En instance
Date de dépôt 2024-10-04
Date de la première publication 2026-04-09
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Arnfeld, Thomas Graham
  • Jones, Nicholas

Abrégé

A compute server receives a secure session request as part of a secure session handshake. The request includes a Server Name Indication (SNI) field. The compute server determines a hostname from the SNI field and determines that a policy is applicable for the determined hostname. The policy indicates a first location where decrypting and servicing traffic for the determined hostname is permitted. The compute server determines that its location does not satisfy the determined policy. The compute server proxies the secure session handshake between the client network application and a second server that satisfies the determined policy. The compute server proxies layer 4 traffic transmitted over the secure session between the client network application and the second server.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

6.

Automatic Speculation Configuration Management

      
Numéro d'application 19345675
Statut En instance
Date de dépôt 2025-09-30
Date de la première publication 2026-03-26
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Krivit, Alex
  • Ahmad, Syed Suleman
  • Gumport, Matthew
  • Harwood, Connor
  • Hatzopoulos, Thomas
  • Kim, Jee Hoon
  • Park, Young Keun
  • Seure, Anthony Raymond Rabia
  • Gadani, Avani
  • Woodhead, William

Abrégé

Automatic speculation configuration management is described. An intermediary server receives a request from a client. The resource is retrieved from the origin server, where the resource includes link(s) to other resource(s). The intermediary server generates and transmits a response that includes a header that references a speculation configuration for prefetching at least one of the other resource(s). The intermediary server receives a request for the speculation configuration from the client. The intermediary server generates and transmits a response to the client that includes the speculation configuration. The intermediary server receives a prefetching request from the client for one of the resources indicated in the speculation configuration, retrieves that resource, and transmits a response to the client with that resource.

Classes IPC  ?

  • H04L 47/83 - Contrôle d'admissionAllocation des ressources basée sur la prédiction d'utilisation
  • H04L 47/78 - Architectures d'allocation des ressources

7.

SYSTEM FOR CROSS-DOMAIN IDENTITY MANAGEMENT (SCIM) PROXY SERVICE

      
Numéro d'application US2025042561
Numéro de publication 2026/043870
Statut Délivré - en vigueur
Date de dépôt 2025-08-19
Date de publication 2026-02-26
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Johnson, Kenny
  • Bauman, Gabriel Andrew
  • Hiller, Kyle
  • Holland, Alexander Jay
  • Kerns, Russell Louis
  • Li, Jesse
  • Royal, James Howard
  • Davisson, Akemi Leigh

Abrégé

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transforms the SCIM resource to create a transformed SCIM resource that is applicable for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the transformed SCIM resource.

Classes IPC  ?

  • H04L 67/56 - Approvisionnement des services mandataires
  • G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 21/31 - Authentification de l’utilisateur
  • G06F 21/41 - Authentification de l’utilisateur par une seule ouverture de session qui donne accès à plusieurs ordinateurs

8.

System for Cross-Domain Identity Management (SCIM) Proxy Service

      
Numéro d'application 19061492
Statut En instance
Date de dépôt 2025-02-24
Date de la première publication 2026-02-19
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Johnson, Kenny
  • Bauman, Gabriel Andrew
  • Hiller, Kyle
  • Holland, Alexander Jay
  • Kerns, Russell Louis
  • Li, Jesse
  • Royal, James Howard
  • Davisson, Akemi Leigh

Abrégé

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the SCIM resource.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès

9.

Managing Artificial Intelligence Inference Requests That Are Directed to An AI Model External To A Distributed Cloud Computing Network

      
Numéro d'application 19345779
Statut En instance
Date de dépôt 2025-09-30
Date de la première publication 2026-01-29
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chen, Michelle
  • Knecht, Dane Orion
  • Martinho, Celso
  • Moshe, Yoav
  • Badoiu, Simona Andreea

Abrégé

A compute server of a distributed cloud computing network receives an inference request that is directed to an AI model hosted at a destination external to the distributed cloud computing network. The compute server determines that the inference request satisfies security rules associated with the AI model. Upon determining that the inference request is not answerable from a cache, the compute server transmits the inference request to the AI model hosted at the external destination. The compute server receives an inference response from the AI model in response to the inference request, transmits the inference response, and stores the inference request and the inference response in cache.

Classes IPC  ?

  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande
  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
  • H04L 67/1014 - Sélection du serveur pour la répartition de charge basée sur le contenu d'une demande

10.

Artificial Intelligence Service(s) in a Distributed Cloud Computing Network Including Function Calling

      
Numéro d'application 19251619
Statut En instance
Date de dépôt 2025-06-26
Date de la première publication 2026-01-01
Propriétaire Cloudflare, Inc. (USA)
Inventeur(s)
  • Turan, Harley
  • Chen, Michelle
  • Hart, Michael
  • Shah, Dhravya
  • Kipp, Jesse

Abrégé

A compute server of a distributed cloud computing network receives an inference request. The inference request triggers execution of code that is related to an AI application that interacts with the inference request and causes its input to be run through an AI model. Helper code executing on the compute server transmits an inference request to the AI model, where this inference request includes a prompt and one or more function definitions, and where the AI model is executing in the same datacenter as the compute server. The helper code receives a result of the AI model executing the inference request, where it includes structured data for calling a function. The helper code calls the function using the structured data. The helper code receives a response to the called function. The code processes a response to the inference request based at least on the received response to the called function.

Classes IPC  ?

  • G06N 5/04 - Modèles d’inférence ou de raisonnement

11.

INSPECTING REQUESTS FOR SECRETS USED FOR AUTHENTICATIONS WITH RESOURCES BY AN INTERMEDIARY SERVER

      
Numéro d'application 18757127
Statut En instance
Date de dépôt 2024-06-27
Date de la première publication 2026-01-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Guinn, Iii, Albert Lee

Abrégé

An intermediary server receives a first HTTP request from a client to access a resource hosted by a host server. The intermediary server can analyze the first HTTP request to identify a secret associated with the first HTTP request and apply a hashing algorithm to the identified secret to generate a hashed version of the identified secret. The intermediary server then updates a data structure with a client identifier associated with the first HTTP request, a resource identifier associated with the resource, the hashed version of the identified secret, and a time of the first HTTP request. The intermediary server then generates a dashboard interface based on data stored in the data structure, where the dashboard interface displays a history of requests for resources by clients.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

12.

Access control of external capabilities exposed by a resource server for artificial intelligence models

      
Numéro d'application 19286205
Numéro de brevet 12513139
Statut Délivré - en vigueur
Date de dépôt 2025-07-30
Date de la première publication 2025-12-30
Date d'octroi 2025-12-30
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Royal, James Howard
  • Li, Jesse
  • Johnson, Kenneth A.

Abrégé

Controlling access to external capabilities exposed by a resource server for artificial intelligence models. An access server receives an authorization request from a resource client for authorization of a resource server. The access server determines a set of capabilities associated with the resource server and enforces access policies to identify permitted capabilities subject to user consent. A consent page is presented to the user agent for selective approval of capabilities. After receiving user consent, the access server generates an access token that is capable of being used as a credential for the consented capabilities. Subsequent requests from the resource server are validated and routed to the appropriate capabilities, with responses returned accordingly.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

13.

IDENTIFYING MALICIOUS CLIENT NETWORK APPLICATIONS BASED ON NETWORK REQUEST CHARACTERISTICS

      
Numéro d'application 19316981
Statut En instance
Date de dépôt 2025-09-02
Date de la première publication 2025-12-18
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Bilas, Maciej
  • Graham-Cumming, John
  • Majkowski, Marek

Abrégé

An edge server receives a plurality of requests from a client network application for actions to be performed on a resource that is hosted at an origin server. The edge server determines request attributes of the requests and associates the request attributes with a session identifying the client network application. The edge server generates a confidence value for the client network application based at least on the determined request attributes of the plurality of requests and computed session metrics of the session. When the confidence value indicates that the client network application is malicious, the edge server performs one or more mitigation actions.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
  • H04L 43/04 - Traitement des données de surveillance capturées, p. ex. pour la génération de fichiers journaux
  • H04L 67/146 - Marqueurs pour l'identification sans ambiguïté d'une session particulière, p. ex. mouchard de session ou encodage d'URL

14.

Dynamic allocation of partitions in a distributed data processing system

      
Numéro d'application 18742844
Numéro de brevet 12524442
Statut Délivré - en vigueur
Date de dépôt 2024-06-13
Date de la première publication 2025-12-18
Date d'octroi 2026-01-13
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Kocikowski, Mikolaj
  • Nuzhdin, Sergii
  • Viglianisi, Gabriele
  • Walwyn, Thomas

Abrégé

A claim is granted over a partition to a consumer. The claim is valid for a period and allows only that consumer to consume data of the partition during the period. The consumer consumes the data until the claim expires or the data in the partition is fully consumed. If the consumer fully consumes the data of the partition prior to the claim expiring, another claim can be granted over another partition to the consumer. Once the claim over the partition expires, the partition is available to be claimed by another consumer.

Classes IPC  ?

  • G06F 16/27 - Réplication, distribution ou synchronisation de données entre bases de données ou dans un système de bases de données distribuéesArchitectures de systèmes de bases de données distribuées à cet effet
  • G06F 16/2455 - Exécution des requêtes

15.

IT Infrastructure Resource Discovery and Management For Distributed Networking

      
Numéro d'application 19289960
Statut En instance
Date de dépôt 2025-08-04
Date de la première publication 2025-11-27
Propriétaire Cloudflare, Inc. (USA)
Inventeur(s)
  • Naylor, David
  • Carino, Eric
  • Mukerjee, Matthew
  • Standt, Ryan
  • Tovino, Michael
  • Tsai, Meigy
  • Welham, Stephen

Abrégé

A method involves receiving, at a Global Resource Catalog (GRC) controller, credentials for one or more target networks within a distributed cloud network. For each target network, the GRC controller uses a respective network access methodology associated with that target network to identify and store a first set of target network resources associated with that network at a GRC database. The GRC controller links or groups a second set of target network resources of the first set of target network resources in the GRC database based on target network resource dependencies determined by the GRC controller. The GRC controller updates the second set of target network resources in the GRC database based on a received event or at a scheduled interval. A distributed cloud network is then updated based on the second set of target network resources stored at the GRC database.

Classes IPC  ?

  • H04L 47/78 - Architectures d'allocation des ressources
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/082 - Réglages de configuration caractérisés par les conditions déclenchant un changement de paramètres la condition étant des mises à jour ou des mises à niveau des fonctionnalités réseau
  • H04L 47/70 - Contrôle d'admissionAllocation des ressources

16.

Automatic speculation configuration management

      
Numéro d'application 18896714
Numéro de brevet 12452193
Statut Délivré - en vigueur
Date de dépôt 2024-09-25
Date de la première publication 2025-10-21
Date d'octroi 2025-10-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Krivit, Alex
  • Ahmad, Syed Suleman
  • Gumport, Matthew
  • Harwood, Connor
  • Hatzopoulos, Thomas
  • Kim, Jee Hoon
  • Park, Young Keun
  • Seure, Anthony Raymond Rabia
  • Gadani, Avani
  • Woodhead, William

Abrégé

Automatic speculation configuration management is described. An intermediary server receives a request from a client. The resource is retrieved from the origin server, where the resource includes link(s) to other resource(s). The intermediary server generates and transmits a response that includes a header that references a speculation configuration for prefetching at least one of the other resource(s). The intermediary server receives a request for the speculation configuration from the client. The intermediary server generates and transmits a response to the client that includes the speculation configuration. The intermediary server receives a prefetching request from the client for one of the resources indicated in the speculation configuration, retrieves that resource, and transmits a response to the client with that resource.

Classes IPC  ?

  • H04L 47/83 - Contrôle d'admissionAllocation des ressources basée sur la prédiction d'utilisation
  • H04L 47/78 - Architectures d'allocation des ressources

17.

Inspecting requests and responses to identify application vulnerabilities

      
Numéro d'application 18744401
Numéro de brevet 12452292
Statut Délivré - en vigueur
Date de dépôt 2024-06-14
Date de la première publication 2025-10-21
Date d'octroi 2025-10-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Appelman, Michiel Louis

Abrégé

An edge server of a cloud-based application vulnerability detection service receives a first request from a requesting device to access a resource hosted by an origin server. The edge server can determine that the first request has indications of including malicious content and block the first request. The edge server can then send a second request to a test environment of the origin server, where the second request is based on the first request. The edge server then receives a response from the origin server responsive to the second request. The cloud-based application vulnerability detection service can analyze the response to determine that the origin server has a vulnerability. The cloud-based application vulnerability detection service then provides information to a customer associated with the origin server indicating that the vulnerability has been blocked by the cloud-based application vulnerability detection service and that the origin server is subject to the vulnerability.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

18.

Sequential consistency across a distributed cloud computing network

      
Numéro d'application 19005664
Numéro de brevet 12632469
Statut Délivré - en vigueur
Date de dépôt 2024-12-30
Date de la première publication 2025-10-02
Date d'octroi 2026-05-19
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Mazzola Paluska, Justin
  • Howard, Joshua Tyler
  • Silverlock, Matthew
  • Varda, Kenton Taylor
  • Ton, Vy Nuthuy

Abrégé

Sequential consistency across a distributed cloud computing network is described. A database includes a primary database and multiple read replica databases. Write queries are transmitted to the primary database, and commit tokens are provided to the read replica databases and the clients. Commit tokens are included in requests from clients. If a request for a read operation received at a read replica database does not include a token that is later than a commit token of the most recent update to the read replica database, the read operation is served by the primary database. If a request for a read operation received at a read replica database includes a token that is later than a commit token of the most recent update to the read replica database, the read replica database delays servicing the read update until it receives an update from the primary database with an updated commit token.

Classes IPC  ?

  • G06F 16/27 - Réplication, distribution ou synchronisation de données entre bases de données ou dans un système de bases de données distribuéesArchitectures de systèmes de bases de données distribuées à cet effet
  • G06F 16/23 - Mise à jour

19.

INFIRE

      
Numéro de série 99362592
Statut En instance
Date de dépôt 2025-08-28
Propriétaire Cloudflare, Inc. (USA)
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Providing online non-downloadable computer software platforms for running, serving, and managing artificial intelligence and large language model (LLM) inference workloads; Providing online non-downloadable computer software platforms for accelerating and optimizing the performance of artificial intelligence and large language model (LLM) inference workloads; Providing temporary use of on-line non-downloadable software and applications for deploying and running artificial intelligence models on an edge computing network

20.

Detecting Application Programming Interface (API) Sequences And Mitigating API Sequence Abuse At The Edge Of A Distributed Cloud Computing Network

      
Numéro d'application 18401192
Statut En instance
Date de dépôt 2023-12-29
Date de la première publication 2025-07-03
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Foster, Peter Alexander
  • Barthonet, Louis Vincent
  • Bilas, Maciej Jakub
  • Guerreiro, Maxime Valentin Junior
  • Rüth, Jan
  • Vissers, Thomas Adriaan M

Abrégé

A first compute server of a distributed cloud computing network that includes multiple compute servers receives an API request that is directed to an API endpoint. The first compute server determines an identifier that uniquely identifies a session that is associated with the API request. Based on the determined identifier, the first compute server determines which of the compute servers of the distributed cloud computing network is responsible for storing information about previous API operations associated with the determined identifier. The first compute server transmits an API sequence request to the determined compute server. In response, the first compute server receives information that specifies a time-ordered sequence of API operations associated with the determined identifier most recently observed. The first compute server may enforce a rule based at least on a sequence of at least two of the latest API operations.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
  • G06F 9/54 - Communication interprogramme

21.

Machine learning-based malicious attachment detector

      
Numéro d'application 17409648
Numéro de brevet 12321453
Statut Délivré - en vigueur
Date de dépôt 2021-08-23
Date de la première publication 2025-06-03
Date d'octroi 2025-06-03
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Zeppenfeld, Torsten
  • Castro, Javier
  • Chang, Yenhsiang

Abrégé

A method includes receiving, from a pre-processor, an output file, the output file having been created by the pre-processor in response to input of an electronic file to the pre-processor, the electronic file being an attachment to an electronic mail message that is in-transit to a recipient computer on a network, the electronic file being a spreadsheet file, the output file containing features that are created by the pre-processor; receiving, from a machine learning-based classifier, malware classification data, the malware classification data being output by the machine learning-based classifier in response to the machine learning-based classifier determining whether the features are indicators of obfuscation, the data used to create the machine learning-based classifier including output files previously created by the pre-processor; in response to the malware classification data matching a criterion, causing the network to modify, delay, or block transmission of the electronic file to the recipient computer.

Classes IPC  ?

  • G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
  • G06F 18/243 - Techniques de classification relatives au nombre de classes
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
  • G06N 3/08 - Méthodes d'apprentissage
  • G06F 12/14 - Protection contre l'utilisation non autorisée de mémoire
  • G06F 21/52 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données
  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole

22.

USING A ZERO-KNOWLEDGE PROOF TO PROVE KNOWLEDGE THAT A WEBSITE VISITOR IS A LEGITIMATE HUMAN USER

      
Numéro d'application 19033124
Statut En instance
Date de dépôt 2025-01-21
Date de la première publication 2025-05-22
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Ladd, Watson Bernard
  • Davidson, Alexander Andrew
  • Fayed, Marwan
  • Hernández, Armando Faz
  • Maram, Sai Krishna Deepak
  • Sullivan, Nicholas Thomas

Abrégé

A client device receives a challenge request from a server to prove that internet traffic was initiated by a human user through verifying a physical interaction between a human user and a hardware component. The client device causes a prompt to be displayed to perform the physical interaction with the hardware component. A cryptographic attestation is received that includes an attestation signature that is generated after confirmation that the physical interaction was performed with the hardware component. A zero-knowledge proof of the attestation signature is generated and transmitted to the server for verification. The client device receives the requested content responsive to the server verifying the validity of the zero-knowledge proof.

Classes IPC  ?

  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
  • G06F 21/32 - Authentification de l’utilisateur par données biométriques, p. ex. empreintes digitales, balayages de l’iris ou empreintes vocales
  • H04L 9/14 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité utilisant plusieurs clés ou algorithmes

23.

DURABLE OBJECTS

      
Numéro de série 99179082
Statut Enregistrée
Date de dépôt 2025-05-10
Date d'enregistrement 2025-12-16
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Cloud computing featuring software for use in developing stateful, serverless applications

24.

Information Technology Infrastructure Resource Grouping

      
Numéro d'application 18930000
Statut En instance
Date de dépôt 2024-10-29
Date de la première publication 2025-05-01
Propriétaire Cloudflare, Inc. (USA)
Inventeur(s)
  • Standt, Ryan
  • Welham, Stephen
  • Tsai, Meigy
  • Naylor, David
  • Carino, Eric

Abrégé

A method involves receiving data identifying a set of information technology (IT) resources of an IT infrastructure and generating a first IT resource dependency graph using the set of IT resources. First INCLUDES and EXCLUDES configuration data indicating one or more IT resources that should either be included or excluded from an IT resource group is received. Initial selection statuses for IT resources in the first dependency graph are set based on the first INCLUDES and EXCLUDES configuration data. A breadth-first search of the first dependency graph is performed to generate the IT resource group based on the initial selection status for the IT resources in the first dependency graph, and the IT infrastructure is updated or managed using the IT resource group.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]

25.

Cache purging in a distributed networked system

      
Numéro d'application 18636032
Numéro de brevet 12360911
Statut Délivré - en vigueur
Date de dépôt 2024-04-15
Date de la première publication 2025-04-10
Date d'octroi 2025-07-15
Propriétaire CLOUDFARE, INC. (USA)
Inventeur(s)
  • Abd Al Hadi, Zaidoon
  • Harwood, Connor
  • Krivit, Alex
  • Shugaeva, Samantha Aki
  • Siloti, Steven Alexander

Abrégé

Purging resources from a cache in a distributed networked system is described. A compute server of a first data center of the distributed networked system receives a purge request to purge a resource from cache. If the purge request does not include a cache key, the compute server determines whether the purge request is valid, and if valid, purges the resource from cache of the first data center, generates a cache key for the resource, and causes the purge request that includes the generated cache key to be sent to other data centers of the distributed networked system for purging the resource from cache. If the purge request includes a cache key, the compute server skips determining whether the purge request is valid and purges the resource from cache based on the cache key.

Classes IPC  ?

  • G06F 12/08 - Adressage ou affectationRéadressage dans des systèmes de mémoires hiérarchiques, p. ex. des systèmes de mémoire virtuelle
  • G06F 12/0891 - Adressage d’un niveau de mémoire dans lequel l’accès aux données ou aux blocs de données désirés nécessite des moyens d’adressage associatif, p. ex. mémoires cache utilisant des moyens d’effacement, d’invalidation ou de réinitialisation
  • G06F 12/14 - Protection contre l'utilisation non autorisée de mémoire

26.

MANAGING ARTIFICIAL INTELLIGENCE INFERENCE REQUESTS THAT ARE DIRECTED TO AN AI MODEL EXTERNAL TO A DISTRIBUTED CLOUD COMPUTING NETWORK

      
Numéro d'application US2024048719
Numéro de publication 2025/072561
Statut Délivré - en vigueur
Date de dépôt 2024-09-26
Date de publication 2025-04-03
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chen, Michelle
  • Knecht, Dane Orion
  • Martinho, Celso
  • Moshe, Yoav
  • Badoiu, Simona Andreea

Abrégé

A compute server of a distributed cloud computing network receives an inference request that is directed to an AI model hosted at a destination external to the distributed cloud computing network. The compute server determines that the inference request satisfies security rules associated with the AI model. Upon determining that the inference request is not answerable from a cache, the compute server transmits the inference request to the AI model hosted at the external destination. The compute server receives an inference response from the AI model in response to the inference request, transmits the inference response, and stores the inference request and the inference response in cache.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
  • G06N 20/00 - Apprentissage automatique

27.

Managing artificial intelligence inference requests that are directed to an AI model external to a distributed cloud computing network

      
Numéro d'application 18898508
Numéro de brevet 12452345
Statut Délivré - en vigueur
Date de dépôt 2024-09-26
Date de la première publication 2025-03-27
Date d'octroi 2025-10-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chen, Michelle
  • Knecht, Dane Orion
  • Martinho, Celso
  • Moshe, Yoav
  • Badoiu, Simona Andreea

Abrégé

A compute server of a distributed cloud computing network receives an inference request that is directed to an AI model hosted at a destination external to the distributed cloud computing network. The compute server determines that the inference request satisfies security rules associated with the AI model. Upon determining that the inference request is not answerable from a cache, the compute server transmits the inference request to the AI model hosted at the external destination. The compute server receives an inference response from the AI model in response to the inference request, transmits the inference response, and stores the inference request and the inference response in cache.

Classes IPC  ?

  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
  • H04L 67/1014 - Sélection du serveur pour la répartition de charge basée sur le contenu d'une demande
  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande

28.

ARTIFICIAL INTELLIGENCE SERVICE(S) IN A DISTRIBUTED CLOUD COMPUTING NETWORK

      
Numéro d'application 18898515
Statut En instance
Date de dépôt 2024-09-26
Date de la première publication 2025-03-27
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Hart, Michael
  • Adler, Keith
  • Chamorro, Derek Arturo
  • Irvine-Broque, Brendan Martin
  • Knecht, Dane Orion
  • Kozlov, Rita
  • Kipp, Jesse Thomas
  • Martinho, Celso
  • Muttreja, Manish
  • Rehg, Isaac
  • Robinett, Richard Lawrence
  • Sarma, Syona
  • Sauleau, Sven
  • Wittig, Phillip David

Abrégé

A first compute server of a plurality of compute servers of a distributed cloud computing network receives an inference request. The first compute server determines that the received inference request triggers execution of code at the distributed cloud computing network, where the code is related to an artificial intelligence (AI) application that interacts with the inference request and causes input of the inference request to be run through an AI model. If the AI model is not loaded at the first compute server but is loaded at a second compute server, the inference request is routed to the second compute server for performing the inference operation.

Classes IPC  ?

  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
  • H04L 67/1014 - Sélection du serveur pour la répartition de charge basée sur le contenu d'une demande

29.

System for cross-domain identity management (SCIM) proxy service

      
Numéro d'application 18809098
Numéro de brevet 12238098
Statut Délivré - en vigueur
Date de dépôt 2024-08-19
Date de la première publication 2025-02-25
Date d'octroi 2025-02-25
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Johnson, Kenny
  • Bauman, Gabriel Andrew
  • Hiller, Kyle
  • Holland, Alexander Jay
  • Kerns, Russell Louis
  • Li, Jesse
  • Royal, James Howard
  • Davisson, Akemi Leigh

Abrégé

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transforms the SCIM resource to create a transformed SCIM resource that is applicable for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the transformed SCIM resource.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès

30.

Inter-process serving of machine learning features from mapped memory for machine learning models

      
Numéro d'application 18413776
Numéro de brevet 12373211
Statut Délivré - en vigueur
Date de dépôt 2024-01-16
Date de la première publication 2025-01-30
Date d'octroi 2025-07-29
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Bocharov, Oleksandr

Abrégé

Inter-process serving of machine learning features from mapped memory for machine learning models is described. ML features are populated in a data structure that is serialized. State data is stored that indicates that reader process(es) are to read from a first memory mapped data file and not a second memory mapped data file. The serialized bytes are stored in the second memory mapped data file and the state data is updated to indicate that the reader process(es) are to read from the second memory mapped data file. A request is received and parsed to prepare keys from attributes of the request. Based on the state data, the serialized bytes are read from the second memory mapped data file that correspond to the keys. The serialized bytes are deserialized and copied to a data structure available to an inference algorithm.

Classes IPC  ?

  • G06F 9/30 - Dispositions pour exécuter des instructions machines, p. ex. décodage d'instructions
  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]

31.

UNIFIED NETWORK SERVICE THAT CONNECTS MULTIPLE DISPARATE PRIVATE NETWORKS AND END USER CLIENT DEVICES OPERATING ON SEPARATE NETWORKS

      
Numéro d'application 18902611
Statut En instance
Date de dépôt 2024-09-30
Date de la première publication 2025-01-16
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Wondra, Nicholas Alexander
  • Postelnik, Igor
  • Vanderwater, Michael John
  • Chalmers, Adam Simon
  • Diegues, Nuno Miguel Lourenço
  • Harutyunyan, Arég
  • Heine, Erich Alfred

Abrégé

A unified network service that connects multiple disparate private networks and end user client devices operating on separate networks is described. The multiple disparate private networks and end user client devices connect to a distributed cloud computing network that provides routing services, security services, and performance services, and that can be controlled consistently regardless of the connection type. The unified network service provides uniform access control at the L3 layer (e.g., at the IP layer) or at a higher layer using user identity information (e.g., a zero-trust model). The disparate private networks are run on top of the distributed cloud computing network. The virtual routing layer of the distributed cloud computing network allows customers of the service to have private resources visible only to client devices (e.g., user devices of the customer and/or server devices of the customer) of the organization while using address space that potentially overlaps with other customers of the distributed cloud computing network.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau

32.

Sequential consistency across a distributed cloud computing network

      
Numéro d'application 18740932
Numéro de brevet 12182167
Statut Délivré - en vigueur
Date de dépôt 2024-06-12
Date de la première publication 2024-12-31
Date d'octroi 2024-12-31
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Mazzola Paluska, Justin
  • Howard, Joshua Tyler
  • Silverlock, Matthew
  • Varda, Kenton Taylor
  • Ton, Vy Nuthuy

Abrégé

Sequential consistency across a distributed cloud computing network is described. A database includes a primary database and multiple read replica databases. Write queries are transmitted to the primary database, and commit tokens are provided to the read replica databases and the clients. Commit tokens are included in requests from clients. If a request for a read operation received at a read replica database does not include a token that is later than a commit token of the most recent update to the read replica database, the read replica database performs the read operation. If a request for a read operation received at a read replica database includes a token that is later than a commit token of the most recent update to the read replica database, the read replica database delays servicing the read update until it receives an update from the primary database with an updated commit token.

Classes IPC  ?

  • G06F 16/27 - Réplication, distribution ou synchronisation de données entre bases de données ou dans un système de bases de données distribuéesArchitectures de systèmes de bases de données distribuées à cet effet
  • G06F 16/23 - Mise à jour

33.

Distributed key management system with a key lookup service

      
Numéro d'application 18433124
Numéro de brevet 12348614
Statut Délivré - en vigueur
Date de dépôt 2024-02-05
Date de la première publication 2024-11-28
Date d'octroi 2025-07-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Pak, Michael

Abrégé

A first intermediate key management system (KMS) server of a distributed KMS receives a key lookup service (KLS) query from a KMS client for determining an identity of KMS server(s) that are capable of performing a first operation with a first managed key. The first intermediate KMS server is one of the intermediate KMS servers of the distributed KMS. The first KMS server determines the identity of one or more of the KMS servers that are capable of performing the first operation with the first managed key. The first KMS server transmits a KLS response to the KMS client that includes the identity of the KMS server(s) that are capable of performing the first operation with the first managed key.

Classes IPC  ?

34.

State management and storage with policy enforcement in a distributed cloud computing network

      
Numéro d'application 18766015
Numéro de brevet 12395556
Statut Délivré - en vigueur
Date de dépôt 2024-07-08
Date de la première publication 2024-10-31
Date d'octroi 2025-08-19
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Varda, Kenton Taylor
  • Robinson, Alex Dwane
  • Hoerner, Brett Joseph
  • Koeninger, Loren Cody
  • Mckeon, Gregory Richard

Abrégé

An object worker is instantiated at a compute server of a distributed cloud computing network, where the object worker includes a single instantiation of a piece of code that solely controls reading/writing to an object. An external communication policy is associated with the first object worker. If the external communication policy does not allow the object worker to send communications with the object to an asset that is external to the distributed cloud computing network, the communication is prevented from being sent. If the external communication policy allows the object worker to send communications with the object to the asset that is external to the distributed cloud computing network, the communication is sent from the first object worker to the asset.

Classes IPC  ?

  • H04L 67/1097 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau pour le stockage distribué de données dans des réseaux, p. ex. dispositions de transport pour le système de fichiers réseau [NFS], réseaux de stockage [SAN] ou stockage en réseau [NAS]
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/01 - Protocoles
  • H04L 67/1021 - Sélection du serveur pour la répartition de charge basée sur la localisation du client ou du serveur

35.

Zero trust authentication

      
Numéro d'application 17590657
Numéro de brevet 12457097
Statut Délivré - en vigueur
Date de dépôt 2022-02-01
Date de la première publication 2024-10-24
Date d'octroi 2025-10-28
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Heilman, Ethan
  • Mugnier, Lucie
  • Goldberg, Sharon
  • Marcus, Yuval
  • Lipman, Sebastien

Abrégé

Systems and methods for zero trust authentication. In certain embodiments, a method may comprise providing, from a client computing system to an identity provider (IdP) authority, an authentication nonce value generated by hashing a random value and a public key of the client computing system, and receiving, at the client computing system from the IdP authority, an authorization token including the authentication nonce value, where the authorization token is signed by a private key of the IdP authority. The method may further comprise providing a message including the authorization token from the client computing system to a target computing system via an intermediary co-signer (ICS) configured to authenticate the message.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • H04L 9/08 - Répartition de clés
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système

36.

POLICY-BASED BLOCKING OF VULNERABLE SOFTWARE INSTALLATIONS USING A PROXY

      
Numéro d'application 18190582
Statut En instance
Date de dépôt 2023-03-27
Date de la première publication 2024-10-03
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Plunk, Andrew Taylor
  • Aggarwal, Ankur
  • Maceiras, Adrian Mateo
  • Kipp, Jesse

Abrégé

A proxy server receives a request from a client network application executing on a client device. The proxy server detects that the request is for a software dependency installation package. The proxy server determines a risk score associated with the software dependency installation package. Based on the risk score associated with the software dependency installation package, the proxy server determines that the software dependency installation package violates a policy. When the software dependency installation package violates the policy, the proxy server blocks the request and stores a log entry in an auditing system including data indicating the blocking of the request.

Classes IPC  ?

  • G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
  • G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures

37.

SECURING AN APPLICATION OR SERVICE OVER A NETWORK INTERCONNECT USING A DEDICATED EGRESS IP ADDRESS

      
Numéro d'application 18603722
Statut En instance
Date de dépôt 2024-03-13
Date de la première publication 2024-09-19
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Tuber, David Zachary
  • Arnfeld, Thomas Graham
  • Johnson, Kenneth
  • Strickx, Tom
  • Valentine, Lee

Abrégé

A first compute server of a distributed cloud computing network receives traffic that is destined for a private application or service running on a server of a customer external of the distributed cloud computing network. That server is connected with the distributed cloud computing network through a network interconnect. One or more policies that are configured for the customer are used to determine whether the traffic is allowed to access the private application or service. The first compute server transmits the traffic to a second compute server of the distributed cloud computing network that has the network interconnect. The second compute server transmits the traffic to the server over the network interconnect using as its source IP address an IP address that is dedicated to the customer.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

38.

IT infrastructure resource discovery and management for distributed networking

      
Numéro d'application 18597234
Numéro de brevet 12407625
Statut Délivré - en vigueur
Date de dépôt 2024-03-06
Date de la première publication 2024-09-12
Date d'octroi 2025-09-02
Propriétaire Cloudflare, Inc. (USA)
Inventeur(s)
  • Naylor, David
  • Carino, Eric
  • Mukerjee, Matthew
  • Standt, Ryan
  • Tovino, Michael
  • Tsai, Meigy
  • Welham, Stephen

Abrégé

A method involves receiving, at a Global Resource Catalog (GRC) controller, credentials for one or more target networks within a distributed cloud network. For each target network, the GRC controller uses a respective network access methodology associated with that target network to identify and store a first set of target network resources associated with that network at a GRC database. The GRC controller links or groups a second set of target network resources of the first set of target network resources in the GRC database based on target network resource dependencies determined by the GRC controller. The GRC controller updates the second set of target network resources in the GRC database based on a received event or at a scheduled interval. A distributed cloud network is then updated based on the second set of target network resources stored at the GRC database.

Classes IPC  ?

  • H04L 47/78 - Architectures d'allocation des ressources
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/082 - Réglages de configuration caractérisés par les conditions déclenchant un changement de paramètres la condition étant des mises à jour ou des mises à niveau des fonctionnalités réseau
  • H04L 47/70 - Contrôle d'admissionAllocation des ressources

39.

Enforcing security policies in a zero trust security framework using a behavioral score

      
Numéro d'application 18407009
Numéro de brevet 12278843
Statut Délivré - en vigueur
Date de dépôt 2024-01-08
Date de la première publication 2024-08-29
Date d'octroi 2025-04-15
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Sutherland, Edwin Donald
  • Nagoormeera, Sheril

Abrégé

A management server retrieves access logs associated with a plurality of identities and generates a plurality of behavioral scores for the plurality of identities. The behavioral score for a particular identity increases responsive to access approvals and decreases responsive to access denials for that particular identity. A proxy server receives a first request to access a resource associated with a first identity of the plurality of identities and determines a zero trust access policy for the resource. When a first behavioral score for the first identity satisfies a behavioral score threshold for the zero trust access policy, the proxy server provides the resource. The proxy server receives a second request to access the resource associated with a second identity. When a second behavioral score for the second identity fails to satisfy the behavioral score threshold, the proxy server performs an action defined in the zero trust access policy.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/0894 - Gestion de la configuration du réseau basée sur des règles

40.

DYNAMIC SELECTION OF WHERE TO EXECUTE APPLICATION CODE IN A DISTRIBUTED CLOUD COMPUTING NETWORK

      
Numéro d'application US2023085572
Numéro de publication 2024/167587
Statut Délivré - en vigueur
Date de dépôt 2023-12-21
Date de publication 2024-08-15
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Hart, Michael
  • Cabral, Alyson
  • Varda, Kenton Taylor

Abrégé

A request is received from a client device at a first datacenter of a distributed cloud computing network. The first request triggers execution of code at the distributed cloud computing network. The execution of the code includes transmitting additional requests to destination(s) external to the distributed cloud computing network. A second datacenter of the distributed cloud computing network is selected to execute the code, where the selection is based on an optimization goal. The code is executed at the second datacenter. The first datacenter receives a result from the code being executed at the second datacenter. The first datacenter transmits a response to the client device that is based at least in part on the result.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]

41.

Dynamic selection of where to execute application code in a distributed cloud computing network

      
Numéro d'application 18362721
Numéro de brevet 12314773
Statut Délivré - en vigueur
Date de dépôt 2023-07-31
Date de la première publication 2024-08-08
Date d'octroi 2025-05-27
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Hart, Michael
  • Cabral, Alyson
  • Varda, Kenton Taylor

Abrégé

A request is received from a client device at a first datacenter a distributed cloud computing network. The distributed cloud computing network includes multiple datacenters. The received request triggers execution of code at the distributed cloud computing network. The code includes a first function and a second function. A determination is made to execute the first function at the first datacenter and to execute the second function at a second datacenter of the distributed cloud computing network. The first function is executed at the first datacenter to get a first result. The first datacenter causes the second function to be executed at the second datacenter. The first datacenter receives, from the second datacenter, a second result from the execution of the second function. The first datacenter transmits a response to the client device that is based at least in part on the first result and the second result.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]

42.

Machine learning based web application firewall

      
Numéro d'application 18478191
Numéro de brevet 12224987
Statut Délivré - en vigueur
Date de dépôt 2023-09-29
Date de la première publication 2024-08-01
Date d'octroi 2025-02-11
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Grover, Vikram
  • Gabor, Petre Gabriel
  • Robert, Nicholas Mikhail

Abrégé

A machine learning (ML) based web application firewall (WAF) is described. Transformation(s) are applied to raw data including normalizing and generating a signature over the normalized data. The signature and the normalized data are vectorized to create a first and second vector of integers respectively. The first and second vector of integers are input into an ML model, which outputs a score that indicates a probability of the raw data being of a type that is malicious. A traffic processing rule is enforced that instructs a WAF to block traffic when the score is above a threshold that indicates the raw data is of the type that is malicious.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 30/27 - Optimisation, vérification ou simulation de l’objet conçu utilisant l’apprentissage automatique, p. ex. l’intelligence artificielle, les réseaux neuronaux, les machines à support de vecteur [MSV] ou l’apprentissage d’un modèle
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle

43.

State management and persistent data storage in a distributed cloud computing network

      
Numéro d'application 18401201
Numéro de brevet 12050799
Statut Délivré - en vigueur
Date de dépôt 2023-12-29
Date de la première publication 2024-07-30
Date d'octroi 2024-07-30
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Varda, Kenton Taylor
  • Maddern, Glen Patrick
  • Robinson, Alex Dwane

Abrégé

A first compute server of a distributed cloud computing network executes an application that controls reading and writing access to associated persistent data. The first compute server performs a write operation to the persistent data on local storage, notifies a piece of code that controls outgoing messages from the application that the write operation is pending, and transmits write information for the write operation to a set of other compute servers. If an acknowledgement of the write information is received from a quorum of the other compute servers, the application notifies the piece of code that the write operation is confirmed. Periodically the write information is transmitted to an external storage system. If a confirmation that the write information has been written is received from the storage system, the first compute server transmits a write confirmation notice to the other compute servers, which can then delete the write information.

Classes IPC  ?

  • G06F 3/06 - Entrée numérique à partir de, ou sortie numérique vers des supports d'enregistrement

44.

VERIFICATION OF SELECTED INBOUND ELECTRONIC MAIL MESSAGES

      
Numéro d'application 18623875
Statut En instance
Date de dépôt 2024-04-01
Date de la première publication 2024-07-25
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Flester, Michael J.

Abrégé

An email verification system is described. The email verification system stores names and associated email addresses. An email is received that has a sender name and a sender email address. If the email verification system determines that the sender name matches a stored name but the sender email address does not match with an email address associated with the stored name, the email is prevented from being transmitted to its recipient unless the email is verified as being legitimate. The email verification system transmits a request to verify the email via a configured verification method. If a response is received that verifies the email as legitimate, the email is delivered; otherwise the email is blocked.

Classes IPC  ?

  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • G06F 21/31 - Authentification de l’utilisateur

45.

SELECTIVE TRAFFIC PROCESSING IN A DISTRIBUTED CLOUD COMPUTING NETWORK

      
Numéro d'application 18433010
Statut En instance
Date de dépôt 2024-02-05
Date de la première publication 2024-07-18
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Van Der Mandele, Achiel Paul
  • Reeves, Eric

Abrégé

A server receives internet traffic from a client device. The server is one of multiple servers of a distributed cloud computing network which are each associated with a set of server identity(ies) including a server/data center certification identity. The server processes, at layer 3, the internet traffic including participating in a layer 3 DDoS protection service. If the traffic is not dropped by the layer 3 DDoS protection service, further processing is performed. The server determines whether it is permitted to process the traffic at layers 5-7 including whether it is associated with a server/data center certification identity that meets a selected criteria for the destination of the internet traffic. If the server does not meet the criteria, it transmits the traffic to another one of the multiple servers for processing the traffic at layers 5-7.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/01 - Protocoles
  • H04L 67/288 - Dispositifs intermédiaires distribués, c.-à-d. dispositifs intermédiaires pour l'interaction avec d'autres dispositifs intermédiaires de même niveau
  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande
  • H04L 69/325 - Protocoles de communication intra-couche entre entités paires ou définitions d'unité de données de protocole [PDU] dans la couche réseau [couche OSI 3], p. ex. X.25

46.

Dynamically modifying HTTP connections

      
Numéro d'application 18614278
Numéro de brevet 12513214
Statut Délivré - en vigueur
Date de dépôt 2024-03-22
Date de la première publication 2024-07-11
Date d'octroi 2025-12-30
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Pardue, Lucas

Abrégé

A condition exists that triggers an HTTP server to modify one or more HTTP connections for one or more HTTP clients that are connected to the HTTP server. The HTTP server dynamically modifies the one or more HTTP connections including dynamically modifying one or more runtime behaviors for the one or more HTTP connections. For each of the one or more HTTP clients, the HTTP server monitors that HTTP client to determine whether it is complying with the modified one or more runtime behaviors. If one of the one or more HTTP clients is not complying with the modified one or more runtime behaviors, the HTTP server performs a mitigation action on that HTTP client.

Classes IPC  ?

  • H04L 67/142 - Gestion des états de session pour les protocoles sans étatÉtats des sessions de signalisationSignalisation des états de sessionMécanismes de conservation d’état
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/143 - Interruption ou inactivation de sessions, p. ex. fin de session contrôlée par un événement

47.

Logging access types based on inserting tenant control headers into requests

      
Numéro d'application 18326811
Numéro de brevet 12034726
Statut Délivré - en vigueur
Date de dépôt 2023-05-31
Date de la première publication 2024-07-09
Date d'octroi 2024-07-09
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Maceiras, Adrian Mateo
  • Martin, Andrew Kenneth Godfrey

Abrégé

A proxy server receives a first request from a first user to access a resource hosted by a cloud-based server. The proxy server inserts a first tenant control header into the first request specifying a tenant identifier. The tenant identifier indicates a tenant permitted to access the resource. The proxy server then transmits the first request with the inserted first tenant control header to the cloud-based server. In response to receiving a first response indicating a rejection of the first request with the inserted first tenant control header, the proxy server transmits the first request again to the cloud-based server but without the first tenant control header. The proxy server then logs the first request as an access request using a non-permitted tenant identifier.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06Q 30/01 - Services de relation avec la clientèle
  • H04L 67/56 - Approvisionnement des services mandataires

48.

PINGORA

      
Numéro de série 98632083
Statut Enregistrée
Date de dépôt 2024-07-03
Date d'enregistrement 2025-04-08
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ?
  • 09 - Appareils et instruments scientifiques et électriques
  • 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Downloadable software libraries for creating HTTP proxy services, content delivery network (CDN) services, load balancing services, secure tunneling services, and cloud storage services; Downloadable network access server operating software Computer services, namely, providing HTTP proxy services, content delivery network (CDN) services, network traffic load balancing services, secure tunneling network services, and cloud storage services for electronic data via virtual and non-virtual servers to others

49.

SYSTEM AND METHOD FOR SECURING CLOUD BASED SERVICES

      
Numéro d'application 17909731
Statut En instance
Date de dépôt 2021-03-03
Date de la première publication 2024-06-27
Propriétaire CLOUDFLARE, INC (USA)
Inventeur(s)
  • Brown, Neil
  • Jefferson, Vernon

Abrégé

A cloud security proxy is described that is able to process requests for cloud services in order to validate the requests against specified rules and/or policies. The cloud security proxy provides greater security for cloud-based applications while providing developers with greater flexibility in the choice of development tools while maintaining a strong security posture for the organization.

Classes IPC  ?

50.

Establishing and using a tunnel from an origin server in a distributed edge compute and routing service

      
Numéro d'application 18587091
Numéro de brevet 12425366
Statut Délivré - en vigueur
Date de dépôt 2024-02-26
Date de la première publication 2024-06-13
Date d'octroi 2025-09-23
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Knecht, Dane Orion
  • Graham-Cumming, John
  • Grant, Dani
  • Branch, Christopher Philip
  • Paseka, Tom

Abrégé

An edge server of a distributed edge compute and routing service receives a tunnel connection request from a tunnel client residing on an origin server, that requests a tunnel be established between the edge server and the tunnel client. The request identifies the hostname that is to be tunneled. An IP address is assigned for the tunnel. DNS record(s) are added or changed that associate the hostname with the assigned IP address. Routing rules are installed in the edge servers of the distributed edge compute and routing service to reach the edge server for the tunneled hostname. The edge server receives a request for a resource of the tunneled hostname from another edge server that received the request from a client, where the other edge server is not connected to the origin server. The request is transmitted from the edge server to the origin server over the tunnel.

Classes IPC  ?

  • H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 61/2592 - Traduction d'adresses de protocole Internet [IP] en utilisant la tunnelisation ou l'encapsulation
  • H04L 67/01 - Protocoles
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau
  • H04L 67/1017 - Sélection du serveur pour la répartition de charge basée sur un mécanisme à tour de rôle
  • H04L 67/1031 - Commande du fonctionnement des serveurs par un répartiteur de charge, p. ex. en ajoutant ou en supprimant de serveurs qui servent des requêtes
  • H04L 61/5007 - Adresses de protocole Internet [IP]

51.

MULTI-PARTY SPLIT-KEY AUTHENTICATION

      
Numéro d'application 18527565
Statut En instance
Date de dépôt 2023-12-04
Date de la première publication 2024-06-06
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Heilman, Ethan
  • Mugnier, Lucie
  • Goldberg, Sharon
  • Merfeld, John
  • Marcus, Yuval
  • Samborski, Ann Ming
  • Dadireddy, Saicharan

Abrégé

Systems and methods are disclosed for performing multi-party, split-key authentication in cryptography. In certain embodiments, a system may comprise a key broker configured to receive a request for a root certificate, generate a secret key based on the request, generate the root certificate based on the secret key, split the secret key into a plurality of shards, provide a first shard of the plurality of shards to an agent, and delete the first shard at the key broker. The key broker may further receive a partially signed client certificate signed with the first shard, generate a fully signed client certificate based on the partially signed client certificate and a second shard of the plurality of shards, and issue the fully signed client certificate.

Classes IPC  ?

  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
  • H04L 9/08 - Répartition de clés

52.

Phishing email campaign identification

      
Numéro d'application 18433090
Numéro de brevet 12452303
Statut Délivré - en vigueur
Date de dépôt 2024-02-05
Date de la première publication 2024-05-30
Date d'octroi 2025-10-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Castro, Javier

Abrégé

A computer-implemented method, executed by one or more email detection computers, receives from a computer network, a first email message from a first sender account to a first recipient account and having a plurality of attributes. The method determines that the first email message is a phishing email, extracts a subset of attributes, normalizes transformable attributes, and generates a hash representation from fixed attributes and the normalized transformable attributes, stores the hash representation in a database, receives a second email message, and determines that the second email message is a phishing email based on the stored hash representation.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES
  • H04L 9/08 - Répartition de clés
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système

53.

Network layer performance and security provided by a distributed cloud computing network

      
Numéro d'application 18434031
Numéro de brevet 12294471
Statut Délivré - en vigueur
Date de dépôt 2024-02-06
Date de la première publication 2024-05-30
Date d'octroi 2025-05-06
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Wondra, Nicholas Alexander
  • Van Der Mandele, Achiel Paul
  • Forster, Alexander
  • Reeves, Eric
  • Madruga, Joaquin
  • Lalkaka, Rustam Xing
  • Majkowski, Marek Przemyslaw

Abrégé

A first computing device of a distributed cloud computing network receives an IP packet that is destined to an origin server of an origin network. The first computing device processes the received IP packet and encapsulates the IP packet inside an outer packet to generate an encapsulated packet, where the outer packet has a source IP address that is advertised as an anycast IP address at the distributed cloud computing network, and a destination IP address of an origin router of the origin network. The encapsulated packet is transmitted to the origin router.

Classes IPC  ?

54.

Identity proxy and access gateway

      
Numéro d'application 18425713
Numéro de brevet 12335263
Statut Délivré - en vigueur
Date de dépôt 2024-01-29
Date de la première publication 2024-05-23
Date d'octroi 2025-06-17
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Royal, James Howard
  • Rhea, Samuel Douglas

Abrégé

A server transmits to a third-party application a request for a resource that is received from a client. The server receives an authentication request from the client device that has been generated by the third-party application. The server transmits an identity provider selection page to the client device that allows the client device to select an identity provider. The server causes the client device to transmit a second authentication request to a selected identity provider. The server receives an authentication response that was generated by the identity provider that includes the identity of the user. The server enforces access rule(s) including identity-based rule(s) and/or non-identity based rule(s). If the user is permitted to access the third-party application, the server causes an authentication response to be transmitted from the client device to the third-party application that indicates the user has successfully authenticated.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • H04L 9/40 - Protocoles réseaux de sécurité

55.

Isolating internet-of-things (IoT) devices using a secure overlay network

      
Numéro d'application 18407060
Numéro de brevet 12267346
Statut Délivré - en vigueur
Date de dépôt 2024-01-08
Date de la première publication 2024-05-16
Date d'octroi 2025-04-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Cinnamon, Molly Rose
  • Paseka, Tom
  • Wondra, Nicholas

Abrégé

A server of a distributed cloud computing network receives, over a tunnel established between a customer-premises equipment and the compute server, traffic from an Internet-of-Things (IoT) device that is connected to the CPE. The server enforces an egress traffic policy to determine whether the traffic is permitted to be transmitted to the destination. If the traffic is not permitted to be transmitted to the destination, the server drops the traffic. If the traffic is permitted to be transmitted to the destination, the server transmits the traffic to the destination.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

56.

Virtual private network (VPN) whose traffic is intelligently routed

      
Numéro d'application 18419265
Numéro de brevet 12328357
Statut Délivré - en vigueur
Date de dépôt 2024-01-22
Date de la première publication 2024-05-16
Date d'octroi 2025-06-10
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Branch, Christopher Philip
  • Tripirineni, Naga Sunil
  • Lalkaka, Rustam Xing
  • Wondra, Nick
  • Irtefa, Mohd
  • Prince, Matthew Browning
  • Plunk, Andrew Taylor
  • Yu, Oliver
  • Krasnov, Vlad

Abrégé

A request is received from a client device over a Virtual Private Network (VPN) tunnel. The request is received at a first one of a plurality of edge servers of a distributed cloud computing network. A destination of the request is determined and an optimized route for transmitting the request toward an origin server is determined. The optimized route is based at least in part on probe data between edge servers of the distributed cloud computing network. The request is transmitted to a next hop as defined by the optimized route.

Classes IPC  ?

  • H04L 12/721 - Procédures de routage, p.ex. routage par le chemin le plus court, routage par la source, routage à état de lien ou routage par vecteur de distance
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
  • H04L 45/02 - Mise à jour ou découverte de topologie
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau
  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande

57.

Theft prevention for sensitive information

      
Numéro d'application 18419307
Numéro de brevet 12455937
Statut Délivré - en vigueur
Date de dépôt 2024-01-22
Date de la première publication 2024-05-16
Date d'octroi 2025-10-28
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Remington, Darren
  • Conrad, Michael
  • Koenig, Killian
  • Sundberg, Trevor
  • Harnett, David

Abrégé

Methods, systems, and techniques for application isolation by remote-enabling applications are provided. Example embodiments provide an Adaptive Rendering Application Isolation System (“ARAIS”), which transparently enables applications to run in an isolated execution environment yet be rendered locally in a manner that facilitates preventing theft of sensitive information while allowing users to interact with any third-party application or website via the local environment without overburdening available bandwidth or computational resources by, in some cases, evaluating only select information responsive only to select events, as compared to whitelist/blacklist techniques, monitoring all information provided by the user, or other techniques. The ARAIS typically includes an orchestrator server that comprises one or more of a sensitive-information theft-prevention logic engine, information-theft prevention engines, or a rules engine. These components cooperate to deliver isolation-ready technology with sensitive-information theft prevention to client applications.

Classes IPC  ?

  • G06F 16/957 - Optimisation de la navigation, p. ex. mise en cache ou distillation de contenus
  • G06F 9/451 - Dispositions d’exécution pour interfaces utilisateur
  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 21/71 - Protection de composants spécifiques internes ou périphériques, où la protection d'un composant mène à la protection de tout le calculateur pour assurer la sécurité du calcul ou du traitement de l’information
  • G06F 40/14 - Documents en configuration arborescente
  • H04L 67/131 - Protocoles pour jeux, simulations en réseau ou réalité virtuelle

58.

Business email compromise detection system

      
Numéro d'application 18395400
Numéro de brevet 12430617
Statut Délivré - en vigueur
Date de dépôt 2023-12-22
Date de la première publication 2024-05-02
Date d'octroi 2025-09-30
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Batchu, Umalatha
  • Zeppenfeld, Torsten
  • Darche, Blake
  • Syme, Philip

Abrégé

An email is received that is from an email sender. From the email, the display name of the email sender, an email address of the email sender, and an email domain of the email sender, is extracted. A score is determined for the email based on at least: the extracted display name of the email sender, the extracted email address of the email sender, and the extracted email domain of the email sender, where the score indicates a probability that the email is from a legitimate sender. Message content of the email is input into multiple classifiers each corresponding to a particular message type. The message type of the email is determined based on output of the classifiers. Based on at least the determined score for the email and the determined message type of the email, a determination is made whether the email is associated with a BEC attack.

Classes IPC  ?

  • G06Q 10/107 - Gestion informatisée du courrier électronique
  • G06F 40/205 - Analyse syntaxique
  • G06N 7/01 - Modèles graphiques probabilistes, p. ex. réseaux probabilistes
  • G06Q 30/018 - Certification d’entreprises ou de produits
  • G06Q 40/02 - Opérations bancaires, p. ex. calcul d'intérêts ou tenue de compte
  • H04L 9/40 - Protocoles réseaux de sécurité

59.

Selection of an egress IP address for egress traffic of a distributed cloud computing network

      
Numéro d'application 18392521
Numéro de brevet 12273316
Statut Délivré - en vigueur
Date de dépôt 2023-12-21
Date de la première publication 2024-04-18
Date d'octroi 2025-04-08
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Majkowski, Marek Przemyslaw
  • Ehrat, Braden Michael
  • Isasi, Sergi
  • Knecht, Dane Orion
  • Kozlov, Dina
  • Lalkaka, Rustam Xing
  • Reeves, Eric
  • Yu, Oliver Zi-Gang

Abrégé

A map of IP addresses of a distributed cloud computing network to one or more groupings is stored. The IP addresses are anycast IP addresses for which compute servers of the distributed cloud computing network share. These IP addresses are to be used as source IP addresses when transmitting traffic to destinations external to the cloud computing network. The map is made available to external destinations. Traffic is received at the distributed cloud computing network that is destined to an external destination. An IP address is selected based on the characteristic(s) applicable for the traffic and the map. The distributed cloud computing network transmits the traffic to the external destination using the selected IP address.

Classes IPC  ?

60.

Cloud computing platform that executes code in a distributed cloud computing network

      
Numéro d'application 18393385
Numéro de brevet 12248792
Statut Délivré - en vigueur
Date de dépôt 2023-12-21
Date de la première publication 2024-04-18
Date d'octroi 2025-03-11
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Varda, Kenton Taylor
  • Bloom, Zachary Aaron
  • Majkowski, Marek Przemyslaw
  • Stepanyan, Ingvar
  • Kloepper, Kyle
  • Knecht, Dane Orion
  • Graham-Cumming, John
  • Grant, Dani

Abrégé

A compute server receives a request that triggers execution of a code piece out of multiple code pieces. A single process at the compute server executes the code piece, which is run in an isolated execution environment. Each other code piece runs in other isolated execution environments respectively and executed by the single process. The code piece, when executed, modifies a response to the request. The response is generated based at least in part on the executed code piece. The generated response is transmitted.

Classes IPC  ?

  • G06F 9/448 - Paradigmes d’exécution, p. ex. implémentation de paradigmes de programmation
  • G06F 9/455 - ÉmulationInterprétationSimulation de logiciel, p. ex. virtualisation ou émulation des moteurs d’exécution d’applications ou de systèmes d’exploitation
  • G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/50 - Gestion des services réseau, p. ex. en assurant une bonne réalisation du service conformément aux accords
  • H04L 67/00 - Dispositions ou protocoles de réseau pour la prise en charge de services ou d'applications réseau
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau
  • H04L 67/53 - Services réseau en utilisant des fournisseurs tiers de services
  • H04L 67/63 - Ordonnancement ou organisation du service des demandes d'application, p. ex. demandes de transmission de données d'application en utilisant l'analyse et l'optimisation des ressources réseau requises en acheminant une demande de service en fonction du contenu ou du contexte de la demande

61.

Persisting encrypted remote browser data at a local browser for use in a remote browser

      
Numéro d'application 18318146
Numéro de brevet 12105829
Statut Délivré - en vigueur
Date de dépôt 2023-05-16
Date de la première publication 2024-04-18
Date d'octroi 2024-10-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Claeys, Joshua Thomas
  • Buzbee, Benjamin
  • Cauchois, Pierre
  • Koenig, Killian
  • Sundberg, Trevor

Abrégé

A remote browsing session is initiated between a remote browser client executing on a client device and a remote browser host executing on a remote browser server. The remote browser host receives from the client device, encrypted remote browser data of remote browser data that affects the remote browser session. The remote browser client does not have access to a decryption key for the encrypted remote browser data. The encrypted remote browser data is decrypted to reveal the remote browser data. The remote browser host is configured with the remote browser data. The remote browser host manages updates to the remote browser data during the remote browsing session. Periodically, updates to the remote browser data are encrypted and transmitted to the remote browser client for storage.

Classes IPC  ?

  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/146 - Marqueurs pour l'identification sans ambiguïté d'une session particulière, p. ex. mouchard de session ou encodage d'URL

62.

Cache purging in a distributed networked system

      
Numéro d'application 18482707
Numéro de brevet 11960407
Statut Délivré - en vigueur
Date de dépôt 2023-10-06
Date de la première publication 2024-04-16
Date d'octroi 2024-04-16
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Abd Al Hadi, Zaidoon
  • Harwood, Connor
  • Krivit, Alex
  • Shugaeva, Samantha Aki
  • Siloti, Steven Alexander

Abrégé

Purging resources from a cache in a distributed networked system is described. A first data center of the distributed networked system receives a purge request to purge a resource from cache. If the purge request does not include a cache key, the first data center determines whether the purge request is valid, and if valid, purges the resource from cache of the first data center, generates a cache key for the resource, and causes the purge request that includes the generated cache key to be sent to other data centers of the distributed networked system for purging the resource from cache. If the purge request includes a cache key, the first data center skips determining whether the purge request is valid and purges the resource from cache based on the cache key.

Classes IPC  ?

  • G06F 12/08 - Adressage ou affectationRéadressage dans des systèmes de mémoires hiérarchiques, p. ex. des systèmes de mémoire virtuelle
  • G06F 12/0891 - Adressage d’un niveau de mémoire dans lequel l’accès aux données ou aux blocs de données désirés nécessite des moyens d’adressage associatif, p. ex. mémoires cache utilisant des moyens d’effacement, d’invalidation ou de réinitialisation
  • G06F 12/14 - Protection contre l'utilisation non autorisée de mémoire

63.

Authoritative domain name system (DNS) server responding to DNS requests with IP addresses selected from a larger pool of IP addresses

      
Numéro d'application 18508122
Numéro de brevet 12445483
Statut Délivré - en vigueur
Date de dépôt 2023-11-13
Date de la première publication 2024-04-11
Date d'octroi 2025-10-14
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Holloway, Lee Hahn
  • Rao, Srikanth N.
  • Prince, Matthew Browning
  • Tourne, Matthieu Philippe François
  • Pye, Ian Gerald
  • Bejjani, Ray Raymond
  • Rodery, Jr., Terry Paul

Abrégé

An authoritative domain name system (DNS) server receives DNS requests for domains. The authoritative DNS server transmits DNS responses to the DNS requests with address records that include IP addresses that are selected from a larger pool of IP addresses, where a first DNS response can include IP addresses different from IP addresses included in a second DNS response for the same domain. Also, the same IP addresses may be returned for a first domain and a different, second domain. The authoritative DNS server may select the IP addresses to include in DNS responses to the DNS requests using a round-robin process.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
  • G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité

64.

Distributed key management system

      
Numéro d'application 18321694
Numéro de brevet 12401500
Statut Délivré - en vigueur
Date de dépôt 2023-05-22
Date de la première publication 2024-04-04
Date d'octroi 2025-08-26
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Pak, Michael
  • Korchagin, Ignat
  • Robinson, Chase

Abrégé

A distributed key management system (KMS) includes a central KMS server and multiple intermediate KMS servers. The central KMS server replicates managed keys to the intermediate KMS servers. An intermediate KMS server receives a KMS service request from a KMS client, where any of the intermediate KMS servers are capable of servicing the request. The intermediate KMS server performs the action requested if it has access to the necessary managed key and returns the response to the KMS client. If it does not have access to the necessary managed key, the intermediate KMS server transmits a request for the managed key to the central KMS server. The intermediate KMS server receives the managed key, performs the action requested, and returns the response to the KMS client.

Classes IPC  ?

65.

Isolating suspicious links in email messages

      
Numéro d'application 18361564
Numéro de brevet 11949707
Statut Délivré - en vigueur
Date de dépôt 2023-07-28
Date de la première publication 2024-04-02
Date d'octroi 2024-04-02
Propriétaire CLOUDFARE, INC. (USA)
Inventeur(s)
  • Syme, Philip
  • Chen, Michelle
  • Eckman, Jeremy Michael
  • Flester, Michael J.
  • Mohan, Shalabh
  • Obezuk, Timothy

Abrégé

Isolating suspicious email links is described. An email security service receives an email that includes a link that refers to an external resource. A first suspicious link determination is performed to determine whether the link is suspicious. If the link is suspicious, the link is rewritten to refer to the email security and the email is delivered to the recipient. A request from a client device is received responsive to the link being opened. A second suspicious link determination is performed to determine whether the link is suspicious. If the link is suspicious, an interstitial page is transmitted to the client device that includes an option that, when selected, causes the first link to be opened in a remote browser isolation session.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

66.

Identity-Based Policy Enforcement for SIM Devices

      
Numéro d'application 18474819
Statut En instance
Date de dépôt 2023-09-26
Date de la première publication 2024-03-28
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Silverlock, Matthew
  • Ehrig, Christian
  • Yu, Oliver Zi-Gang
  • Wondra, Nicholas Alexander
  • Mota, Catarina Pires

Abrégé

Traffic is received at a distributed cloud computing network. The traffic originates from a computing device using a mobile data connection. The traffic is associated with an identifier that identifies a SIM of the computing device. Using the SIM identifier, an identity for identity-based policy enforcement at the distributed cloud computing network is determined. The identity is uniquely associated with the SIM identifier. An identity-based policy that is applicable for the received traffic for the determined identity is determined. The identity-based policy is enforced.

Classes IPC  ?

  • H04W 8/26 - Adressage ou numérotation de réseau pour support de mobilité
  • H04W 8/18 - Traitement de données utilisateur ou abonné, p. ex. services faisant l'objet d'un abonnement, préférences utilisateur ou profils utilisateurTransfert de données utilisateur ou abonné
  • H04W 12/08 - Sécurité d'accès
  • H04W 12/72 - Identité de l’abonné

67.

Cloud-based security service that includes external evaluation for accessing a third-party application

      
Numéro d'application 18527887
Numéro de brevet 12363174
Statut Délivré - en vigueur
Date de dépôt 2023-12-04
Date de la première publication 2024-03-28
Date d'octroi 2025-07-15
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Royal, James Howard

Abrégé

A cloud-based security service that includes external evaluation for accessing a third-party application. The security service receives a request to access a third-party application from a client device. The security service enforces a set of one or more access policies configured for the third-party application including an external evaluation rule. As part of enforcing the external evaluation rule, the security service transmits an external evaluation request to an external endpoint defined in the external evaluation rule. The external evaluation request includes an identity of a user associated with the request. The security service receives the result of the external evaluation. If the external evaluation passed, the security service grants access to the third-party application based at least in part on its passing.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

68.

Dynamically modifying HTTP connections

      
Numéro d'application 18148352
Numéro de brevet 11943308
Statut Délivré - en vigueur
Date de dépôt 2022-12-29
Date de la première publication 2024-03-26
Date d'octroi 2024-03-26
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Pardue, Lucas

Abrégé

A condition exists that triggers an HTTP server to modify one or more HTTP connections for one or more HTTP clients that are connected to the HTTP server. The HTTP server dynamically modifies the one or more HTTP connections including dynamically modifying one or more HTTP connection resource parameters for the one or more HTTP connections. For each of the one or more HTTP clients, the HTTP server monitors that HTTP client to determine whether it is complying with the modified one or more HTTP connection resource parameters. If one of the one or more HTTP clients is not complying with the modified one or more HTTP connection resource parameters, the HTTP server closes an HTTP connection to that HTTP client.

Classes IPC  ?

  • H04L 67/142 - Gestion des états de session pour les protocoles sans étatÉtats des sessions de signalisationSignalisation des états de sessionMécanismes de conservation d’état
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/143 - Interruption ou inactivation de sessions, p. ex. fin de session contrôlée par un événement

69.

Secure private traffic exchange in a unified network service

      
Numéro d'application 18521351
Numéro de brevet 12457196
Statut Délivré - en vigueur
Date de dépôt 2023-11-28
Date de la première publication 2024-03-21
Date d'octroi 2025-10-28
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Wondra, Nicholas Alexander

Abrégé

Traffic is received at an interface of a compute server. Identity information associated with the traffic is determined including an identifier of a customer to which the traffic is attributable. An egress policy configured for the first customer is used to determine whether the traffic is allowed to be transmitted to a destination where that destination is a resource of a second customer. If the traffic is allowed to be transmitted, the traffic and identity information is transmitted over a cross-customer GRE tunnel to a namespace of the second costumer on the compute server. An ingress policy configured for the second customer is used to determine whether the traffic is allowed to be transmitted to the destination, and if it is, then the traffic is transmitted.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau

70.

State management and object storage in a distributed cloud computing network

      
Numéro d'application 18508201
Numéro de brevet 12284247
Statut Délivré - en vigueur
Date de dépôt 2023-11-13
Date de la première publication 2024-03-14
Date d'octroi 2025-04-22
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Varda, Kenton Taylor
  • Kloepper, Kyle

Abrégé

A first compute server of a distributed cloud computing network receives a request from a first client device for an object to be handled by an object worker that includes a single instantiation of a piece of code that solely controls reading and writing access to the first object. A determination is made that the object worker is instantiated for the object and is currently running in the first compute server, and the piece of code processes the first request. The first compute server receives a message to be processed by the first object worker from a second compute server. The message includes a second request for the object from a second client device connected to the second compute server. The piece of code processes the message and transmits a reply to the second compute server.

Classes IPC  ?

  • H04L 67/1095 - Réplication ou mise en miroir des données, p. ex. l’ordonnancement ou le transport pour la synchronisation des données entre les nœuds du réseau
  • H04L 67/00 - Dispositions ou protocoles de réseau pour la prise en charge de services ou d'applications réseau
  • H04L 67/01 - Protocoles

71.

Miscellaneous Design

      
Numéro d'application 1780245
Statut Enregistrée
Date de dépôt 2024-01-08
Date d'enregistrement 2024-01-08
Propriétaire Cloudflare, Inc. (USA)
Classes de Nice  ?
  • 09 - Appareils et instruments scientifiques et électriques
  • 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Computer software and firmware for monitoring and controlling online traffic to computer servers; computer software for wireless content delivery; computer anti-virus software. Computer security services in the nature of providing authentication, issuance, validation and revocation of digital certificates; computer security services, namely, restricting unauthorized access to computer networks; computer services, namely, monitoring, testing, analyzing, and reporting on the internet traffic control and content control of the web sites of others; computer virus protection services; data conversion of computer program data or information, other than physical conversion; data conversion of electronic information; parking domain names for others, namely, providing computer servers for electronic storage of domain name addresses.

72.

Traffic load balancing between a plurality of points of presence of a cloud computing infrastructure

      
Numéro d'application 18516543
Numéro de brevet 12395377
Statut Délivré - en vigueur
Date de dépôt 2023-11-21
Date de la première publication 2024-03-14
Date d'octroi 2025-08-19
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Wragg, David Paul
  • Guðmundsson, Ólafur
  • Bauer, Lorenz Mathias
  • Fabre, Arthur
  • Majkowski, Marek Przemyslaw

Abrégé

Methods and system of traffic load balancing between a plurality of Points of Presence (PoP) of a cloud computing infrastructure are described. A first PoP of multiple PoPs of cloud computing infrastructure that provides a cloud computing service receives a packet. The packet includes as a destination address an anycast address advertised by the first PoP for reaching the cloud computing service. The first PoP identifies a network address of a second PoP that is different from the first PoP. The first PoP forwards the packets as an encapsulated packet to the second PoP to be processed in the second PoP according to the cloud computing service.

Classes IPC  ?

  • H04L 67/1008 - Sélection du serveur pour la répartition de charge basée sur les paramètres des serveurs, p. ex. la mémoire disponible ou la charge de travail
  • H04L 45/00 - Routage ou recherche de routes de paquets dans les réseaux de commutation de données
  • H04L 47/122 - Prévention de la congestionRécupération de la congestion en détournant le trafic des entités congestionnées
  • H04L 67/1001 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau pour accéder à un serveur parmi une pluralité de serveurs répliqués

73.

Phishing email campaign identification

      
Numéro d'application 17574443
Numéro de brevet 11895151
Statut Délivré - en vigueur
Date de dépôt 2022-01-12
Date de la première publication 2024-02-06
Date d'octroi 2024-02-06
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Castro, Javier

Abrégé

A computer-implemented method, executed by one or more email detection computers, receives from a computer network, a first email message from a first sender account to a first recipient account and having a plurality of attributes. The method determines that the first email message is a phishing email, extracts a subset of attributes, normalizes transformable attributes, and generates a hash representation from fixed attributes and the normalized transformable attributes, stores the hash representation in a database, receives a second email message, and determines that the second email message is a phishing email based on the stored hash representation.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
  • H04L 9/08 - Répartition de clés
  • H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES

74.

Distributed key management system with a key lookup service

      
Numéro d'application 18322265
Numéro de brevet 11895227
Statut Délivré - en vigueur
Date de dépôt 2023-05-23
Date de la première publication 2024-02-06
Date d'octroi 2024-02-06
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Pak, Michael

Abrégé

A first intermediate key management system (KMS) server of a distributed KMS receives a key lookup service (KLS) query from a KMS client for determining an identity of KMS server(s) that are capable of performing a first operation with a first managed key. The first intermediate KMS server is one of the intermediate KMS servers of the distributed KMS. The first KMS server determines the identity of one or more of the KMS servers that are capable of performing the first operation with the first managed key. The first KMS server transmits a KLS response to the KMS client that includes the identity of the KMS server(s) that are capable of performing the first operation with the first managed key.

Classes IPC  ?

75.

Inter-process serving of machine learning features from mapped memory for machine learning models

      
Numéro d'application 18359818
Numéro de brevet 11875151
Statut Délivré - en vigueur
Date de dépôt 2023-07-26
Date de la première publication 2024-01-16
Date d'octroi 2024-01-16
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Bocharov, Oleksandr

Abrégé

Inter-process serving of machine learning features from mapped memory for machine learning models is described. ML features are populated in a data structure that is serialized. State data is stored that indicates that reader process(es) are to read from a first memory mapped data file and not a second memory mapped data file. The serialized bytes are stored in the second memory mapped data file and the state data is updated to indicate that the reader process(es) are to read from the second memory mapped data file. A request is received and parsed to prepare keys from attributes of the request. Based on the state data, the serialized bytes are read from the second memory mapped data file that correspond to the keys. The serialized bytes are deserialized and copied to a data structure available to an inference algorithm.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
  • G06F 9/30 - Dispositions pour exécuter des instructions machines, p. ex. décodage d'instructions

76.

Enforcing security policies in a zero trust security framework using a behavioral score

      
Numéro d'application 18175815
Numéro de brevet 11870818
Statut Délivré - en vigueur
Date de dépôt 2023-02-28
Date de la première publication 2024-01-09
Date d'octroi 2024-01-09
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Sutherland, Edwin Donald
  • Nagoormeera, Sheril

Abrégé

A management server retrieves access logs associated with a plurality of identities and generates a plurality of behavioral scores for the plurality of identities. The behavioral score for a particular identity increases responsive to access approvals and decreases responsive to access denials for that particular identity. A proxy server receives a first request to access a resource associated with a first identity of the plurality of identities and determines a zero trust access policy for the resource. When a first behavioral score for the first identity satisfies a behavioral score threshold for the zero trust access policy, the proxy server provides the resource. The proxy server receives a second request to access the resource associated with a second identity. When a second behavioral score for the second identity fails to satisfy the behavioral score threshold, the proxy server performs an action defined in the zero trust access policy.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/0894 - Gestion de la configuration du réseau basée sur des règles

77.

ORANGE CLOUD DESIGN

      
Numéro d'application 231552000
Statut En instance
Date de dépôt 2024-01-08
Propriétaire Cloudflare, Inc. (USA)
Classes de Nice  ?
  • 09 - Appareils et instruments scientifiques et électriques
  • 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

(1) Computer software and firmware for monitoring and controlling online traffic to computer servers; computer software for wireless content delivery; computer anti-virus software. (1) Computer security services in the nature of providing authentication, issuance, validation and revocation of digital certificates; computer security services, namely, restricting unauthorized access to computer networks; computer services, namely, monitoring, testing, analyzing, and reporting on the internet traffic control and content control of the web sites of others; computer virus protection services; data conversion of computer program data or information, other than physical conversion; data conversion of electronic information; parking domain names for others, namely, providing computer servers for electronic storage of domain name addresses.

78.

CLOUDFLARE

      
Numéro de série 98335888
Statut Enregistrée
Date de dépôt 2023-12-29
Date d'enregistrement 2024-09-17
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ? 38 - Services de télécommunications

Produits et services

Providing virtual private network (VPN) services, namely, private and secure electronic communications over a private or public computer network; Providing secure and private access for users to the internet; Providing electronic telecommunication connections to enable users of computers and mobile computing devices to securely connect to a remote server in order to allow for secure and private transmission and receipt of data and communications over the internet; Electronic data transmission; Electronic transmission of data through a secure and private connection over the internet featuring encryption; Providing user access to global computer networks; Computer network services, namely, providing network communication services in the nature of transmission of voice, audio, visual images and data by data networks and providing access to global computer networks

79.

Miscellaneous Design

      
Numéro de série 98335949
Statut Enregistrée
Date de dépôt 2023-12-29
Date d'enregistrement 2024-09-17
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ? 38 - Services de télécommunications

Produits et services

Providing virtual private network (VPN) services, namely, private and secure electronic communications over a private or public computer network; Providing secure and private access for users to the internet; Providing electronic telecommunication connections to enable users of computers and mobile computing devices to securely connect to a remote server in order to allow for secure and private transmission and receipt of data and communications over the internet; Electronic data transmission; Electronic transmission of data through a secure and private connection over the internet featuring encryption; Providing user access to global computer networks; Computer network services, namely, providing network communication services in the nature of transmission of voice, audio, visual images and data by data networks and providing access to global computer networks; Peer-to-peer network computer services, namely, electronic transmission of audio, video, data, and documents among computers

80.

Cloud-based security service that includes external evaluation for accessing a third-party application

      
Numéro d'application 17936572
Numéro de brevet 11838327
Statut Délivré - en vigueur
Date de dépôt 2022-09-29
Date de la première publication 2023-12-05
Date d'octroi 2023-12-05
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Royal, James Howard

Abrégé

A cloud-based security service that includes external evaluation for accessing a third-party application. The security service receives a request to access a third-party application from a client device. The security service enforces a set of one or more access policies configured for the third-party application including an external evaluation rule. As part of enforcing the external evaluation rule, the security service transmits an external evaluation request to an external endpoint defined in the external evaluation rule. The external evaluation request includes an identity of a user associated with the request. The security service receives the result of the external evaluation. If the external evaluation passed, the security service grants access to the third-party application based at least in part on its passing.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

81.

WEB BROWSER REMOTING ACROSS A NETWORK USING DRAW COMMANDS

      
Numéro d'application 18355587
Statut En instance
Date de dépôt 2023-07-20
Date de la première publication 2023-11-16
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Sundberg, Trevor
  • Koenig, Killian
  • Remington, Darren
  • Buzbee, Benjamin
  • Conrad, Michael
  • Harnett, David

Abrégé

A server receives from a client device that is executing a web browser application a request to initiate a remote application in the server. The server instantiates an instance of the remote application. The server intercepts draw commands associated with the remote application instance. The server provides the draw commands to the client to cause the web browser application to render portion(s) of output based on the draw commands. The server receives an input event from the web browser application. The server provides the client one or more draw commands based on the input event to cause the web browser application to render portion(s) of output based on those draw commands.

Classes IPC  ?

  • G06F 16/957 - Optimisation de la navigation, p. ex. mise en cache ou distillation de contenus
  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 21/71 - Protection de composants spécifiques internes ou périphériques, où la protection d'un composant mène à la protection de tout le calculateur pour assurer la sécurité du calcul ou du traitement de l’information
  • G06F 9/451 - Dispositions d’exécution pour interfaces utilisateur
  • G06F 40/14 - Documents en configuration arborescente
  • H04L 67/131 - Protocoles pour jeux, simulations en réseau ou réalité virtuelle

82.

Remoting application across a network using draw commands with an isolator application

      
Numéro d'application 18333285
Numéro de brevet 12093429
Statut Délivré - en vigueur
Date de dépôt 2023-06-12
Date de la première publication 2023-10-26
Date d'octroi 2024-09-17
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Buzbee, Benjamin
  • Koenig, Killian
  • Sundberg, Trevor
  • Conrad, Michael
  • Remington, Darren
  • Harnett, David

Abrégé

A client device instantiates an isolator application. A request to instantiate a remote application in a server device is sent by the isolator application instance. The isolator application instance receives, from the remote application instance, draw commands and position information that correspond to the draw commands. The isolator application instance renders one or more portions of output based on the draw commands and the position information.

Classes IPC  ?

  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 11/36 - Prévention d'erreurs par analyse, par débogage ou par test de logiciel
  • G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
  • G06F 21/71 - Protection de composants spécifiques internes ou périphériques, où la protection d'un composant mène à la protection de tout le calculateur pour assurer la sécurité du calcul ou du traitement de l’information
  • H04L 9/40 - Protocoles réseaux de sécurité

83.

Application remoting across a network using draw commands

      
Numéro d'application 18338045
Numéro de brevet 12455936
Statut Délivré - en vigueur
Date de dépôt 2023-06-20
Date de la première publication 2023-10-19
Date d'octroi 2025-10-28
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Remington, Darren
  • Sundberg, Trevor
  • Koenig, Killian
  • Buzbee, Benjamin
  • Conrad, Michael
  • Harnett, David

Abrégé

A server receives from a client device that is executing a client application a request to initiate a remote application in the server. The server instantiates an instance of the remote application. The server intercepts draw commands associated with the remote application instance. The server provides the draw commands to the client to cause the client application to render portion(s) of output based on the draw commands. The server receives an input event from the client application. The server provides the client one or more draw commands based on the input event to cause the client application to render portion(s) of output based on those draw commands.

Classes IPC  ?

  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06F 9/451 - Dispositions d’exécution pour interfaces utilisateur
  • G06F 16/957 - Optimisation de la navigation, p. ex. mise en cache ou distillation de contenus
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 21/71 - Protection de composants spécifiques internes ou périphériques, où la protection d'un composant mène à la protection de tout le calculateur pour assurer la sécurité du calcul ou du traitement de l’information
  • G06F 40/14 - Documents en configuration arborescente
  • H04L 67/131 - Protocoles pour jeux, simulations en réseau ou réalité virtuelle

84.

Machine learning based web application firewall

      
Numéro d'application 18161719
Numéro de brevet 11792162
Statut Délivré - en vigueur
Date de dépôt 2023-01-30
Date de la première publication 2023-10-17
Date d'octroi 2023-10-17
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Grover, Vikram
  • Gabor, Petre Gabriel
  • Robert, Nicholas Mikhail

Abrégé

A machine learning (ML) based web application firewall (WAF) is described. Transformation(s) are applied to raw data including normalizing and generating a signature over the normalized data. The signature and the normalized data are vectorized to create a first and second vector of integers that are input into an ML model that includes a first stage that operates on the first vector of integers to identify candidate signature tokens that are commonly associated with different classes of attack, and a second stage that operates on the candidate signature tokens and the second vector of integers and conditions attention on the second vector of integers on the candidate signature tokens. The ML model outputs a score that indicates a probability of the raw data being of a type that is malicious. A traffic processing rule is enforced that instructs a WAF to block traffic when the score is above a threshold.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 30/27 - Optimisation, vérification ou simulation de l’objet conçu utilisant l’apprentissage automatique, p. ex. l’intelligence artificielle, les réseaux neuronaux, les machines à support de vecteur [MSV] ou l’apprentissage d’un modèle
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle

85.

Method and system for determining a path maximum transmission unit (MTU) between endpoints of a generic routing encapsulation (GRE) tunnel

      
Numéro d'application 18333297
Numéro de brevet 12107768
Statut Délivré - en vigueur
Date de dépôt 2023-06-12
Date de la première publication 2023-10-12
Date d'octroi 2024-10-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Wondra, Nicholas Alexander
  • Heine, Erich Alfred
  • Zhai, Yan

Abrégé

A method of path MTU determination in Generic Routing Encapsulation (GRE) tunnel is presented. A source network device (ND) transmits, to a destination ND that is a second endpoint of the GRE tunnel, a first outer packet including a first inner packet, where the first inner packet includes a first inner header that is used to deliver the first inner packet to the source network device, a first inner GRE header, and a first payload. The source ND receives the first inner packet. The source ND transmits a second outer packet including a second inner packet that includes a second payload that has a size greater than a size of the first payload. The source ND determines that the second inner packet is not received and determines a path MTU between the source ND and the destination ND based on a size of the first and the second outer packets.

Classes IPC  ?

  • H04L 47/36 - Commande de fluxCommande de la congestion en déterminant la taille des paquets, p. ex. l’unité de transfert maximale [MTU]
  • H04L 12/46 - Interconnexion de réseaux

86.

Methods and apparatuses for providing internet-based proxy services

      
Numéro d'application 18333319
Numéro de brevet 12323395
Statut Délivré - en vigueur
Date de dépôt 2023-06-12
Date de la première publication 2023-10-12
Date d'octroi 2025-06-03
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Holloway, Lee Hahn
  • Prince, Matthew Browning
  • Pye, Ian Gerald
  • Tourne, Matthieu Philippe François
  • Zatlyn, Michelle Marie

Abrégé

A proxy server receives, from multiple visitors of multiple client devices, a plurality of requests for actions to be performed on identified network resources belonging to a plurality of origin servers. At least some of the origin servers belong to different domains and are owned by different entities. The proxy server and the origin servers are also owned by different entities. The proxy server analyzes each request it receives to determine whether that request poses a threat and whether the visitor belonging to the request poses a threat. The proxy server blocks those requests from visitors that pose a threat or in which the request itself poses a threat. The proxy server transmits the requests that are not a threat and is from a visitor that is not a threat to the appropriate origin server.

Classes IPC  ?

  • G06F 21/00 - Dispositions de sécurité pour protéger les calculateurs, leurs composants, les programmes ou les données contre une activité non autorisée
  • G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
  • G06F 16/95 - Recherche dans le Web
  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
  • G06F 40/14 - Documents en configuration arborescente
  • G06F 40/143 - Balisage, p. ex. utilisation du langage SGML ou de définitions de type de document
  • G06Q 10/107 - Gestion informatisée du courrier électronique
  • G06Q 30/0241 - Publicités
  • G06Q 30/0251 - Publicités ciblées
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 47/74 - Mesures pour pallier la non-disponibilité des ressources
  • H04L 51/42 - Aspects liés aux boîtes aux lettres, p. ex. synchronisation des boîtes aux lettres
  • H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
  • H04L 61/5007 - Adresses de protocole Internet [IP]
  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 67/146 - Marqueurs pour l'identification sans ambiguïté d'une session particulière, p. ex. mouchard de session ou encodage d'URL
  • H04L 67/56 - Approvisionnement des services mandataires
  • H04L 67/561 - Ajout de données fonctionnelles à l’application ou de données de commande de l’application, p. ex. métadonnées
  • H04L 67/568 - Stockage temporaire des données à un stade intermédiaire, p. ex. par mise en antémémoire
  • H04L 69/40 - Dispositions, protocoles ou services de réseau indépendants de la charge utile de l'application et non couverts dans un des autres groupes de la présente sous-classe pour se remettre d'une défaillance d'une instance de protocole ou d'une entité, p. ex. protocoles de redondance de service, état de redondance de protocole ou redirection de service de protocole
  • H04L 61/59 - Utilisation de mandataires pour l’adressage

87.

Establishing a cryptographic tunnel between a first tunnel endpoint and a second tunnel endpoint where a private key used during the tunnel establishment is remotely located from the second tunnel endpoint

      
Numéro d'application 18333333
Numéro de brevet 11949776
Statut Délivré - en vigueur
Date de dépôt 2023-06-12
Date de la première publication 2023-10-12
Date d'octroi 2024-04-02
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Ladd, Watson Bernard
  • Krasnov, Vladislav

Abrégé

A responder device receives, from an initiator device, a request to initiate a cryptographic tunnel between the initiator device and the responder device. The responder device does not include a static private key to be used in an asymmetric cryptography algorithm when establishing the tunnel. The responder device transmits a request to a key server that has access to the static private key and receives a response that is based on at least a result of at least one cryptographic operation using the static private key. The responder device receives from the key server, or generates, a transport key(s) for the responder device to use for sending and receiving data on the cryptographic tunnel. The responder device transmits a response to the initiator device that includes information for the initiator device to generate a transport key(s) that it is to use for sending and receiving data on the cryptographic tunnel.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • H04L 9/08 - Répartition de clés
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
  • H04L 12/46 - Interconnexion de réseaux

88.

HYPERDRIVE

      
Numéro de série 98202663
Statut Enregistrée
Date de dépôt 2023-09-28
Date d'enregistrement 2024-11-26
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Providing online non-downloadable computer software platforms for database optimization and acceleration, namely, enabling third party cloud computing applications to cache database data queries; Providing temporary use of online non-downloadable software development tools for database optimization and acceleration, namely, providing database connection pooling for third-party cloud computing applications; Software as a service (SAAS) services featuring software for use in database optimization and acceleration, namely, caching database data queries in a cloud computing environment and for managing database connection pools

89.

Unified network service that connects multiple disparate private networks and end user client devices operating on separate networks

      
Numéro d'application 18326745
Numéro de brevet 12107827
Statut Délivré - en vigueur
Date de dépôt 2023-05-31
Date de la première publication 2023-09-28
Date d'octroi 2024-10-01
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Wondra, Nicholas Alexander
  • Postelnik, Igor
  • Vanderwater, Michael John
  • Chalmers, Adam Simon
  • Diegues, Nuno Miguel Lourenço
  • Harutyunyan, Arég
  • Heine, Erich Alfred

Abrégé

A unified network service that connects multiple disparate private networks and end user client devices operating on separate networks is described. The multiple disparate private networks and end user client devices connect to a distributed cloud computing network that provides routing services, security services, and performance services, and that can be controlled consistently regardless of the connection type. The unified network service provides uniform access control at the L3 layer (e.g., at the IP layer) or at a higher layer using user identity information (e.g., a zero-trust model). The disparate private networks are run on top of the distributed cloud computing network. The virtual routing layer of the distributed cloud computing network allows customers of the service to have private resources visible only to client devices (e.g., user devices of the customer and/or server devices of the customer) of the organization while using address space that potentially overlaps with other customers of the distributed cloud computing network.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau

90.

WORKERS AI

      
Numéro de série 98200043
Statut Enregistrée
Date de dépôt 2023-09-27
Date d'enregistrement 2024-11-19
Propriétaire Cloudflare, Inc. ()
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Platform as a service (PAAS) featuring computer software platforms for use in enabling third-party users to store, deploy and manage executable software applications; Providing temporary use of on-line non-downloadable software development tools for third-party development of custom software applications; Software as a service (SAAS) services featuring software for use in enabling third-party users to store, deploy and manage executable software applications

91.

Isolating internet-of-things (IoT) devices using a secure overlay network

      
Numéro d'application 17962799
Numéro de brevet 11870797
Statut Délivré - en vigueur
Date de dépôt 2022-10-10
Date de la première publication 2023-09-21
Date d'octroi 2024-01-09
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Cinnamon, Molly Rose
  • Paseka, Tom
  • Wondra, Nicholas

Abrégé

A server of a distributed cloud computing network receives, over a tunnel established between a customer-premises equipment and the compute server, traffic from an Internet-of-Things (IoT) device that is connected to the CPE. The server enforces an egress traffic policy to determine whether the traffic is permitted to be transmitted to the destination. If the traffic is not permitted to be transmitted to the destination, the server drops the traffic. If the traffic is permitted to be transmitted to the destination, the server transmits the traffic to the destination.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

92.

ISOLATING INTERNET-OF-THINGS (IOT) DEVICES USING A SECURE OVERLAY NETWORK

      
Numéro d'application US2023015545
Numéro de publication 2023/177893
Statut Délivré - en vigueur
Date de dépôt 2023-03-17
Date de publication 2023-09-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Cinnamon, Molly Rose
  • Paseka, Tom
  • Wondra, Nicholas

Abrégé

A server of a distributed cloud computing network receives, over a tunnel established between a customer-premises equipment and the compute server, traffic from an Internet-of-Things (IoT) device that is connected to the CPE. The server enforces an egress traffic policy to determine whether the traffic is permitted to be transmitted to the destination. If the traffic is not permitted to be transmitted to the destination, the server drops the traffic. If the traffic is permitted to be transmitted to the destination, the server transmits the traffic to the destination.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité

93.

Dynamic selection of where to execute application code in a distributed cloud computing network

      
Numéro d'application 18166400
Numéro de brevet 11755381
Statut Délivré - en vigueur
Date de dépôt 2023-02-08
Date de la première publication 2023-09-12
Date d'octroi 2023-09-12
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Hart, Michael
  • Cabral, Alyson
  • Varda, Kenton Taylor

Abrégé

A request is received from a client device at a first datacenter of a distributed cloud computing network. The first request triggers execution of code at the distributed cloud computing network. The execution of the code includes transmitting additional requests to destination(s) external to the distributed cloud computing network. A second datacenter of the distributed cloud computing network is selected to execute the code, where the selection is based on an optimization goal. The code is executed at the second datacenter. The first datacenter receives a result from the code being executed at the second datacenter. The first datacenter transmits a response to the client device that is based at least in part on the result.

Classes IPC  ?

  • G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]

94.

Verification of selected inbound electronic mail messages

      
Numéro d'application 18153059
Numéro de brevet 11949641
Statut Délivré - en vigueur
Date de dépôt 2023-01-11
Date de la première publication 2023-07-13
Date d'octroi 2024-04-02
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Flester, Michael J.

Abrégé

An email verification system is described. The email verification system stores names and associated email addresses. An email is received that has a sender name and a sender email address. If the email verification system determines that the sender name matches a stored name but the sender email address does not match with an email address associated with the stored name, the email is prevented from being transmitted to its recipient unless the email is verified as being legitimate. The email verification system transmits a request to verify the email via a configured verification method. If a response is received that verifies the email as legitimate, the email is delivered; otherwise the email is blocked.

Classes IPC  ?

  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • G06F 21/31 - Authentification de l’utilisateur

95.

Secure session capability using public-key cryptography without access to the private key

      
Numéro d'application 18092750
Numéro de brevet 11991157
Statut Délivré - en vigueur
Date de dépôt 2023-01-03
Date de la première publication 2023-07-13
Date d'octroi 2024-05-21
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Pahl, Sébastien Andreas Henry
  • Tourne, Matthieu Philippe François
  • Sikora, Piotr
  • Bejjani, Ray Raymond
  • Knecht, Dane Orion
  • Prince, Matthew Browning
  • Graham-Cumming, John
  • Holloway, Lee Hahn
  • Strasheim, Albertus

Abrégé

A server establishes a secure session with a client device where a private key used in the handshake is stored in a different server. An encrypted connection is established between the first server and the second server. A message is received from the client device that initiates a procedure to establish the secure session between the client device and the first server. As part of this procedure, the first server transmits over the encrypted connection a request to the second server to use the private key. The first server receives, over the encrypted connection, a response to the request that includes a result of the use of the private key. The first server uses the result during the procedure to establish the secure session.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/33 - Authentification de l’utilisateur par certificats
  • H04L 9/08 - Répartition de clés
  • H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système

96.

Non-HTTP layer 7 protocol applications running in the browser

      
Numéro d'application 17956695
Numéro de brevet 11909808
Statut Délivré - en vigueur
Date de dépôt 2022-09-29
Date de la première publication 2023-06-22
Date d'octroi 2024-02-20
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Koenig, Killian
  • Knecht, Dane Orion
  • Royal, James

Abrégé

A server receives from a browser executing on a client device an HTTP request. The server transmits a response to the HTTP request to the browser. The response includes code that when executed by the browser, executes a non-HTTP layer 7 protocol client that communicates with a non-HTTP layer 7 protocol service at an external network. The server receives, from the non-HTTP layer 7 protocol client executing in the browser, data related to the non-HTTP layer 7 protocol service. The server proxies the data related to the non-HTTP layer 7 protocol service over a layer 4 tunnel that is interfaced with the non-HTTP layer 7 protocol service. The server logs event data received from the non-HTTP layer 7 protocol client executing in the browser.

Classes IPC  ?

  • H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/51 - Découverte ou gestion de ceux-ci, p. ex. protocole de localisation de service [SLP] ou services du Web
  • H04L 67/561 - Ajout de données fonctionnelles à l’application ou de données de commande de l’application, p. ex. métadonnées

97.

Loading and managing third-party tools on a website

      
Numéro d'application 18146459
Numéro de brevet 12026272
Statut Délivré - en vigueur
Date de dépôt 2022-12-27
Date de la première publication 2023-06-08
Date d'octroi 2024-07-02
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Dovrat, Yair
  • Moshe, Yoav

Abrégé

Managing the loading of third-party tools on a website is described. Configuration is received for loading the third-party tools. An intermediary server receives a request for a page that is hosted at an origin server. The intermediary server retrieves the page and modifies the page including automatically including a third-party tool manager to the retrieved page. The third-party tool manager includes a set of one or more client-side scripts that, when executed by the client network application, collects, and transmits information to the intermediary server for loading the third-party tools. The intermediary server loads the third-party tools based on the received information and the configuration. The intermediary server causes event data to be transmitted to third-party tool servers that correspond with the third-party tools.

Classes IPC  ?

  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • H04L 9/40 - Protocoles réseaux de sécurité

98.

Method and apparatus for distributed emulation of behavior of a malicious domain

      
Numéro d'application 17958201
Numéro de brevet 12047414
Statut Délivré - en vigueur
Date de dépôt 2022-09-30
Date de la première publication 2023-06-01
Date d'octroi 2024-07-23
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s) Paine, Justin Matthew

Abrégé

Methods and apparatuses for enabling compatibility between multiple versions of an application programming interface (API) are described. When a first API request is received at a compute server, the compute server determines whether the first API request is of a first version of an API that is different from a second version of the API used in an origin server to which the first API request is destined. In response to determining that the first API request is of the first version of the API that is different from the second version of the API used in the origin server to which the first API request is destined, an API compatibility enabler is executed to convert the first API request into a second API request in the second version of the API. The second API request is fulfilled instead of the first API request.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau

99.

Method and apparatus for traffic optimization in virtual private networks (VPNs)

      
Numéro d'application 18158694
Numéro de brevet 11863448
Statut Délivré - en vigueur
Date de dépôt 2023-01-24
Date de la première publication 2023-05-25
Date d'octroi 2024-01-02
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Branch, Christopher Philip
  • Knecht, Dane Orion

Abrégé

Traffic optimization in virtual private networks (VPNs) is described. A client device establishes a first VPN connection with a first server according to a first VPN route configuration that specifies a first VPN route to the first server. Flow(s) of traffic is forwarded through the first VPN connection to the first server. The client device receives a second VPN route configuration that specifies a second VPN route to a second server of the plurality of servers for establishing a second VPN connection, where the second VPN connection satisfies a set of traffic optimization criteria. The client device establishes the second VPN connection with the second server according to the second VPN route configuration. Traffic is forwarded through the second VPN connection to the second server.

Classes IPC  ?

  • H04L 45/745 - Recherche de table d'adressesFiltrage d'adresses
  • H04L 12/46 - Interconnexion de réseaux
  • H04L 67/10 - Protocoles dans lesquels une application est distribuée parmi les nœuds du réseau
  • H04L 67/01 - Protocoles
  • H04L 67/56 - Approvisionnement des services mandataires

100.

Distributed key management system

      
Numéro d'application 17956689
Numéro de brevet 11658812
Statut Délivré - en vigueur
Date de dépôt 2022-09-29
Date de la première publication 2023-05-23
Date d'octroi 2023-05-23
Propriétaire CLOUDFLARE, INC. (USA)
Inventeur(s)
  • Chamorro, Derek
  • Pak, Michael
  • Korchagin, Ignat
  • Robinson, Chase

Abrégé

A distributed key management system (KMS) includes a central KMS server and multiple intermediate KMS servers. The central KMS server replicates managed keys to the intermediate KMS servers. An intermediate KMS server receives a KMS service request from a KMS client, where any of the intermediate KMS servers are capable of servicing the request. The intermediate KMS server performs the action requested if it has access to the necessary managed key and returns the response to the KMS client. If it does not have access to the necessary managed key, the intermediate KMS server transmits a request for the managed key to the central KMS server. The intermediate KMS server receives the managed key, performs the action requested, and returns the response to the KMS client.

Classes IPC  ?

  1     2     3     ...     5        Prochaine page