IP Library › Granted Patent US 11,632,267
Granted Patent B2
US 11,632,267 · App. 17/669,535 · Granted Apr 18, 2023

Multi-part TCP connection over VPN

Inventors: Emanuelis Norbutas (Vilnius, LT); Tomas Okmanas (Vilnius, LT); Marijus Briedis (Jurbarkai, LT)
Assignee: 360 IT, UAB
H04L12/4641H04L12/4633H04L47/36
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,267
App. No.
17/669,535
Filed
Feb 11, 2022
Granted
Apr 18, 2023
Kind
B2
Examiner
DOAN, TAN
Art Unit
2442
USPC
709/219
Abstract

An encrypted tunnel is established between a virtual private network (VPN) server and a VPN user device. A request to establish a connection with a target device is received from the VPN user device. The request uses initial connection parameters. The connection the converted into a first connection between the VPN user device and the VPN server and a second connection between the VPN server and the target device. The first connection uses first connection parameters and the second connection uses second connection parameters. At least one parameter of the first connection parameters or of the second connection parameters is different from a corresponding parameter of the initial connection parameters. First network packets received from the VPN user device according to the first connection parameters are converted into second network packets according to the second connection parameters. The second network packets are transmitted to the target device.

Claims (50)

1. A method, comprising:

establishing an encrypted tunnel between a virtual private network (VPN) server and a VPN user device;

receiving via the encrypted tunnel a request from the VPN user device to establish a connection with a target device, wherein the request includes a desired connection parameter that is to be negotiated between the VPN user device and the target device;

selecting a first connection parameter for a first connection between the VPN user device and the VPN server;

converting the connection into the first connection and a second connection between the VPN server and the target device;

transmitting the first connection parameter to the VPN user device, wherein the VPN user device uses the first connection parameter for transmitting network packets to the target device;

negotiating a second connection parameter for data exchange over the second connection between the VPN server and the target device;

converting first network packets received from the VPN user device according to the first connection parameter into second network packets according to the second connection parameter; and

transmitting the second network packets to the target device.

2. The method of claim 1 , wherein the first connection parameter comprises a first maximum segment size (MSS) and the second connection parameter comprises a second MSS that is different from the first MSS.

3. The method of claim 2 , wherein the first MSS is selected to prevent packet fragmentation that is due to VPN-related encapsulation overhead.

4. The method of claim 3 , wherein packets sent over the first connection and the second connection are of a same standard transfer unit size.

5. The method of claim 1 , wherein respective payloads of the first network packets are smaller than respective payloads of the second network packets.

6. The method of claim 1 , further comprising:

setting the second connection parameter based on a distance between the VPN server and the target device.

7. The method of claim 1 , wherein the first network packets include VPN encapsulation headers that are not included in the second network packets.

8. A virtual private network (VPN) server, comprising:

a processor configured to execute instructions to:

establish an encrypted tunnel between the VPN server and a VPN user device;

receive via the encrypted tunnel a request from the VPN user device to establish a connection with a target device, wherein the request includes a desired connection parameter that is to be negotiated between the VPN user device and the target device;

select a first connection parameter for a first connection between the VPN user device and the VPN server;

convert the connection into the first connection and a second connection between the VPN server and the target device;

transmit the first connection parameter to the VPN user device, wherein the VPN user device uses the first connection parameter for transmitting network protocol data units to the target device;

negotiate a second connection parameter for data exchange over the second connection between the VPN server and the target device;

convert first network protocol data units received from the VPN user device according to the first connection parameter into second network protocol data units according to the second connection parameter; and

transmit the second network protocol data units to the target device.

9. The VPN server of claim 8 , wherein the first connection parameter comprises a first maximum segment size (MSS) and the second connection parameter comprises a second MSS that is different from the first MSS.

10. The VPN server of claim 8 , wherein the instructions to convert the connection into the first connection and the second connection between the VPN server and the target device comprise instructions to:

determine to convert the connection into the first connection and the second connection based on a distance between the VPN user device and the target device.

11. The VPN server of claim 9 , wherein the first MSS is selected to prevent fragmentation that is due to VPN-related encapsulation overhead.

12. The VPN server of claim 8 , wherein the network protocol data units sent over the first connection and the second connection are of a same standard transfer unit size.

13. The VPN server of claim 8 , wherein respective payloads of the first network protocol data units are smaller than respective payloads of the second network protocol data units.

14. The VPN server of claim 8 , wherein the processor is further configured to execute instructions to:

set the second connection parameter based on a distance between the VPN server and the target device.

15. The VPN server of claim 8 , wherein the first network protocol data units include VPN encapsulation headers that are not included in the second network protocol data units.

16. A non-transitory computer readable medium storing instructions operable to cause one or more processors to perform operations comprising:

establishing an encrypted tunnel between a virtual private network (VPN) server and a VPN user device;

receiving via the encrypted tunnel a request from the VPN user device to establish a connection with a target device, wherein the request includes a desired connection parameter that is to be negotiated between the VPN user device and the target device;

selecting a first connection parameter for a first connection between the VPN user device and the VPN server;

converting the connection into the first connection and a second connection between the VPN server and the target device;

transmitting the first connection parameter to the VPN user device, wherein the VPN user device uses the first connection parameter for transmitting network packets to the target device;

negotiating a second connection parameter for data exchange over the second connection between the VPN server and the target device,

converting first network packets received from the VPN user device according to the first connection parameter into second network packets according to the second connection parameter; and

transmitting the second network packets to the target device.

17. The non-transitory computer readable medium of claim 16 , wherein the first connection parameter comprises a first maximum segment size (MSS) and the second connection parameter comprises a second MSS that is different from the first MSS.

18. The non-transitory computer readable medium of claim 17 , wherein the first MSS is selected to prevent packet fragmentation that is due to VPN-related encapsulation overhead.

19. The non-transitory computer readable medium of claim 16 , wherein packets sent over the first connection and the second connection are of a same standard transfer unit size.

20. The non-transitory computer readable medium of claim 16 ,

wherein respective payloads of the first network packets are smaller than respective payloads of the second network packets, and

wherein the first network packets include VPN encapsulation headers that are not included in the second network packets.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM 360 IT, UAB TO UAB 360 IT PREVIOUSLY RECORDED ON REEL 59081 FRAME 497. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 6, 2025
From: NORBUTAS, EMANUELIS; OKMANAS, TOMAS; BRIEDIS, MARIJUS
To: UAB 360 IT
Reel/Frame 070441/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2022
From: NORBUTAS, EMANUELIS; OKMANAS, TOMAS; BRIEDIS, MARIJUS
To: 360 IT, UAB
Reel/Frame 059081/0497 →
Continuity (3)
Continuation 17361351 · Jun 29, 2021
Continuation In Part 16780925 · Feb 4, 2020
Related Publication 20220166647A1 · May 26, 2022