IP Library Granted Patent US 12,192,094
Granted Patent B2
US 12,192,094 · App. 17/509,904 · Granted Jan 7, 2025

Method and apparatus of automatic route optimization in a private virtual network for client devices of a local network

Inventor: Christopher Philip Branch (Romford, GB)
Assignee: CLOUDFARE, INC.
H04L45/124H04L45/02H04L45/123H04L45/74H04L63/0272H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,094
App. No.
17/509,904
Granted
Jan 7, 2025
Kind
B2
Abstract

A client device establishes a first VPN connection with a VPN server. Traffic is sent from the client device through the first VPN connection that is destined to a different client device that has a second VPN connection with the VPN server. The client device receives a public network address of the different client device and routing metrics from the VPN server. Based at least in part on the routing metrics, the client device determines an optimal route to the different client device, where the optimal route is a connection between the client device and the different client device that does not traverse the VPN server. The client device establishes a VPN connection with the different client device and transmits traffic to that different client device using the VPN connection using the public network address of the different client device.

Claims (50)

1. A method in a client device, comprising:

establishing a first virtual private network (VPN) connection with a VPN server, wherein the VPN server is remote from the client device;

transmitting to the VPN server, through the first VPN connection, traffic from the client device that is destined to a different client device that has a second VPN connection with the VPN server;

receiving, from the VPN server over the first VPN connection, a public network address of the different client device;

receiving, from the VPN server, routing metrics related to traffic transmitted through the first VPN connection and the second VPN connection;

determining, based at least in part on the routing metrics, an optimal route from the client device to the different client device, wherein the optimal route is a connection between the client device and the different client device that does not traverse the VPN server;

establishing a third VPN connection with the different client device; and

transmitting traffic destined for the different client device using the third VPN connection that is encapsulated with packets destined to the public network address of the different client device.

2. The method of claim 1 , further comprising:

prior to receiving the public network address of the different client device, transmitting a local network address identifying the client device in a local network to the VPN server, wherein the client device and the different client device are part of a same local network.

3. The method of claim 1 , further comprising:

transmitting a local network address identifying the different client device to the VPN server.

4. The method of claim 1 , wherein the routing metrics include for each one of the first VPN connection and the second VPN connection one or more of a measure of link utilization, an indication of a number of hops, a measure of speed, a measure of packet loss, a measure of latency, a measure of path reliability, a measure of path bandwidth, and a measure of throughput.

5. The method of claim 1 , wherein determining the optimal route from the client device to the different client device further is based on one or more routing metrics for routes within a local network for which the client device and the different client device are a part.

6. The method of claim 1 , wherein establishing the third VPN connection with the different client device is based on cryptographic credentials associated with the client device and the different client device.

7. The method of claim 1 , wherein the client device and the different client device are part of a same local network.

8. A client device, comprising:

one or more processors; and

a non-transitory computer readable storage medium that stores code, which when executed by the one or more processors causes the client device to perform operations including:

establishing a first virtual private network (VPN) connection with a VPN server, wherein the VPN server is remote from the client device;

transmitting to the VPN server, through the first VPN connection, traffic from the client device that is destined to a different client device that has a second VPN connection with the VPN server;

receiving, from the VPN server over the first VPN connection, a public network address of the different client device;

receiving, from the VPN server, routing metrics related to traffic transmitted through the first VPN connection and the second VPN connection;

determining, based at least in part on the routing metrics, an optimal route from the client device to the different client device, wherein the optimal route is a connection between the client device and the different client device that does not traverse the VPN server;

establishing a third VPN connection with the different client device; and

transmitting traffic destined for the different client device using the third VPN connection that is encapsulated with packets destined to the public network address of the different client device.

9. The client device of claim 8 , wherein the operations further comprise:

prior to receiving the public network address of the different client device, transmitting a local network address identifying the client device in a local network to the VPN server, wherein the client device and the different client device are part of a same local network.

10. The client device of claim 8 , wherein the operations further comprise:

transmitting a local network address identifying the different client device to the VPN server.

11. The client device of claim 8 , wherein the routing metrics include for each one of the first VPN connection and the second VPN connection one or more of a measure of link utilization, an indication of a number of hops, a measure of speed, a measure of packet loss, a measure of latency, a measure of path reliability, a measure of path bandwidth, and a measure of throughput.

12. The client device of claim 8 , wherein determining the optimal route from the client device to the different client device further is based on one or more routing metrics for routes within a local network for which the client device and the different client device are a part.

13. The client device of claim 8 , wherein establishing the third VPN connection with the different client device is based on cryptographic credentials associated with the client device and the different client device.

14. The client device of claim 8 , wherein the client device and the different client device are part of a same local network.

15. A non-transitory computer readable storage medium that stores instructions which when executed by one or more processors of a client device cause said processors to perform operations including:

establishing a first virtual private network (VPN) connection with a VPN server, wherein the VPN server is remote from the client device;

transmitting to the VPN server, through the first VPN connection, traffic from the client device that is destined to a different client device that has a second VPN connection with the VPN server;

receiving, from the VPN server over the first VPN connection, a public network address of the different client device;

receiving, from the VPN server, routing metrics related to traffic transmitted through the first VPN connection and the second VPN connection;

determining, based at least in part on the routing metrics, an optimal route from the client device to the different client device, wherein the optimal route is a connection between the client device and the different client device that does not traverse the VPN server;

establishing a third VPN connection with the different client device; and

transmitting traffic destined for the different client device using the third VPN connection that is encapsulated with packets destined to the public network address of the different client device.

16. The non-transitory computer readable storage medium of claim 15 , wherein the operations further comprise:

prior to receiving the public network address of the different client device, transmitting a local network address identifying the client device in a local network to the VPN server, wherein the client device and the different client device are part of a same local network.

17. The non-transitory computer readable storage medium of claim 15 , wherein the operations further comprise:

transmitting a local network address identifying the different client device to the VPN server.

18. The non-transitory computer readable storage medium of claim 15 , wherein the routing metrics include for each one of the first VPN connection and the second VPN connection one or more of a measure of link utilization, an indication of a number of hops, a measure of speed, a measure of packet loss, a measure of latency, a measure of path reliability, a measure of path bandwidth, and a measure of throughput.

19. The non-transitory computer readable storage medium of claim 15 , wherein determining the optimal route from the client device to the different client device further is based on one or more routing metrics for routes within a local network for which the client device and the different client device are a part.

20. The non-transitory computer readable storage medium of claim 15 , wherein establishing the third VPN connection with the different client device is based on cryptographic credentials associated with the client device and the different client device.

21. The non-transitory computer readable storage medium of claim 15 , wherein the client device and the different client device are part of a same local network.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2021
From: BRANCH, CHRISTOPHER PHILIP
To: CLOUDFLARE, INC.
Reel/Frame 057903/0747 →
Continuity (2)
Continuation 16387431 · Apr 17, 2019
Related Publication 20220045934A1 · Feb 10, 2022
References Cited (58)
US 6567405B1 · Borella · 2003 [cited by examiner]
US 7376087B2 · Srikrishna · 2008 [cited by applicant]
US 9319445B2 · Garmark · 2016 [cited by examiner]
US 10181906B1 · Harel · 2019 [cited by examiner]
US 10397061B1 · Chawla et al. · 2019 [cited by applicant]
US 10601779B1 · Matthews et al. · 2020 [cited by applicant]
US 20020075844A1 · Hagen · 2002 [cited by examiner]
US 20030046390A1 · Ball · 2003 [cited by examiner]
US 20030106067A1 · Hoskins · 2003 [cited by examiner]
US 20030212772A1 · Harris · 2003 [cited by examiner]
US 20040168062A1 · Isozaki et al. · 2004 [cited by applicant]
US 20040174887A1 · Lee · 2004 [cited by examiner]
US 20050228894A1 · Takabayashi et al. · 2005 [cited by applicant]
US 20060293028A1 · Gadamsetty et al. · 2006 [cited by applicant]
US 20070127461A1 · Yamada · 2007 [cited by examiner]
US 20070299954A1 · Fatula · 2007 [cited by applicant]
US 20080034416A1 · Kumar · 2008 [cited by examiner]
US 20080259938A1 · Keene · 2008 [cited by examiner]
US 20100131960A1 · Suganthi · 2010 [cited by examiner]
US 20100165881A1 · Hof et al. · 2010 [cited by applicant]
US 20100228879A1 · Wiget et al. · 2010 [cited by applicant]
US 20110219131A1 · Allen et al. · 2011 [cited by applicant]
US 20120096540A1 · Hilgenkamp · 2012 [cited by applicant]
US 20130031244A1 · Zhang et al. · 2013 [cited by applicant]
US 20130182712A1 · Aguayo et al. · 2013 [cited by applicant]
US 20140115114A1 · Garmark · 2014 [cited by examiner]
US 20150043350A1 · Basilier · 2015 [cited by applicant]
US 20150172109A1 · Alhandy · 2015 [cited by applicant]
US 20150249644A1 · Xu · 2015 [cited by applicant]
US 20160006837A1 · Reynolds et al. · 2016 [cited by applicant]
US 20160073327A1 · Clougherty · 2016 [cited by examiner]
US 20160277277A1 · Chan et al. · 2016 [cited by applicant]
US 20160373356A1 · Xu et al. · 2016 [cited by applicant]
US 20170134254A1 · Mueller · 2017 [cited by applicant]
US 20170142198A1 · Alhandy · 2017 [cited by applicant]
US 20170279717A1 · Bethers et al. · 2017 [cited by applicant]
US 20180103085A1 · Fang et al. · 2018 [cited by applicant]
US 20180255145A1 · Wang · 2018 [cited by applicant]
US 20180343192A1 · Antonyraj et al. · 2018 [cited by applicant]
US 20190052630A1 · Lapidous et al. · 2019 [cited by applicant]
US 20190068250A1 · Kim · 2019 [cited by examiner]
US 20190253382A1 · Ramaraj · 2019 [cited by examiner]
US 20190312836A1 · Phillips · 2019 [cited by applicant]
US 20190312933A1 · Richards et al. · 2019 [cited by applicant]
US 20200154272A1 · Uy et al. · 2020 [cited by applicant]
US 20200162431A1 · Goldschlag · 2020 [cited by examiner]
US 20200177550A1 · Valluri et al. · 2020 [cited by applicant]
US 20230164077A1 · Branch · 2023 [cited by examiner]
WO WO2014172854A1 · 2014 [cited by examiner]
WO WO2015002342A1 · 2015 [cited by examiner]
WO WO2016048370A1 · 2016 [cited by examiner]
WO WO2017179286A1 · 2017 [cited by examiner]
WO WO2018086696A1 · 2018 [cited by examiner]
Final Office Action, U.S. Appl. No. 16/387,431, filed Apr. 29, 2021, 19 pages. [cited by applicant]
Networks and Tunnel Routing, Cloud VPN, Google Cloud, Nov. 6, 2018, 9 pages, downloaded at https://cloud.google.com/vpn/docs/concepts-networks-routing on Jan. 22, 2019. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/387,431, Nov. 13, 2020, 16 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/387,431, Sep. 15, 2021, 10 pages. [cited by applicant]
Virtual Private Network, Wikipedia, Jan. 15, 2019, 9 pages, downloaded at hllps://en.wikipedia.org/wiki/Virtual_private-network on Jan. 22, 2019. [cited by applicant]