IP Library Granted Patent US 12,500,843
Granted Patent B2
US 12,500,843 · App. 18/236,771 · Granted Dec 16, 2025

Method and apparatus for metadata conversion with a flow identifier of a packet sequence in a tunnel-less SDWAN

Inventors: Fidelis Prashanth (San Jose, CA); Jayakrishnan Iyer (Morgan Hill, CA); Apurva Mehta (Cupertino, CA)
Assignee: Versa Networks, Inc.
H04L47/2483H04L43/0847H04L63/029H04L63/0428H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,843
App. No.
18/236,771
Granted
Dec 16, 2025
Kind
B2
Abstract

A flow identifier is described for packet sequences through a secure tunnel of an SD-WAN in a tunnel-less mode. A method includes receiving a sequence of packets from a first client at the first hub, the sequence of packets each having a same flow, facilitating a secure tunnel between the first hub and the second hub, assigning a flow identifier to the sequence of packets, converting fields from a header of the packet to a metadata supplement to the packet to form a reduced packet, encapsulating the reduced packet in a wrapper that includes the flow identifier, and sending the packet of the sequence of packets from the first hub to the second hub the secure tunnel.

Claims (62)

1 . A method to route traffic through a software-defined wide area network (SD-WAN) between a first hub and a second hub, the method comprising:

receiving a sequence of packets from a first client at the first hub, the sequence of packets each having a same flow;

facilitating a secure tunnel between the first hub and the second hub;

assigning a flow identifier to the sequence of packets;

converting fields from a header of the packet to a metadata supplement to the packet to form a reduced packet;

encapsulating the reduced packet in a wrapper that includes the flow identifier; and

sending the packet of the sequence of packets from the first hub to the second hub through the secure tunnel.

2 . The method of claim 1 , wherein converting fields comprises:

removing the header;

combining the header and the flow identifier to form metadata; and

attaching the metadata to a payload of the reduced packet before encapsulating the reduced packet.

3 . The method of claim 1 , further comprising

associating a packet reduction mode with the flow identifier,

wherein converting fields comprises converting fields from a header of the packet to a metadata supplement to the packet to form a reduced packet in accordance with the packet reduction mode.

4 . The method of claim 3 , wherein the packet reduction mode includes a compression level configured to indicate an amount that the fields of the packet header are compressed in the metadata supplement.

5 . The method of claim 3 , wherein the packet reduction mode includes an encryption level configured to indicate an amount of encryption applied to the fields in the metadata supplement.

6 . The method of claim 5 , wherein the encryption level is configured to indicate no encryption.

7 . The method of claim 1 , further comprising performing a capabilities exchange between the first hub and the second hub for the flow identifier before converting the fields.

8 . The method of claim 7 , wherein the capabilities exchange includes determining a packet reduction mode.

9 . The method of claim 1 , wherein establishing the secure tunnel comprises establishing a session, the method further comprising:

encapsulating a start packet of the sequence of packets in a wrapper that includes the flow identifier and the header of the encapsulated start packet;

sending the encapsulated start packet from the first hub to the second hub through the secure tunnel; and

receiving an acknowledgement of the flow identifier from the second hub and updating a state of the session with the acknowledgement.

10 . The method of claim 1 , further comprising:

receiving a second flow identifier from the second hub through the secure tunnel;

saving the second flow identifier;

receiving reply encapsulated packets directed to a source address of the sequence of packets; and

using the second flow identifier to identify subsequent reply encapsulated packets received from the second hub.

11 . The method of claim 10 , further comprising:

decapsulating the reply encapsulated packets;

recreating headers of the decapsulated reply encapsulated packets based on metadata supplements of the decapsulated reply packets and a packet reduction mode associated with the second flow identifier; and

forwarding the decapsulated reply packets to the source address of the sequence of packets.

12 . The method of claim 1 , further comprising:

receiving an error message from the second hub including the flow identifier;

facilitating a secure tunnel again between the first hub and the second hub in response to receiving the error message;

assigning a second flow identifier to the sequence of packets;

encapsulating a second start packet of the sequence of packets in a wrapper, the wrapper including the second flow identifier; and

sending the encapsulated second start packet of the sequence of packets from the first hub to the second hub through the secure tunnel.

13 . The method of claim 1 , wherein the sequence of packets each having a same flow each have a same 5-tuple.

14 . The method of claim 1 , further comprising increasing a value of a maximum segment size parameter of a header of the reduced packet before encapsulating the reduced packet.

15 . A non-transitory computer-readable storage medium containing program instructions, which when executed by the computer cause the computer to perform operations comprising:

receiving a sequence of packets from a first client at a first hub, the sequence of packets each having a same flow;

facilitating a secure tunnel between the first hub and a second hub;

assigning a flow identifier to the sequence of packets;

converting fields from a header of the packet to a metadata supplement to the packet to form a reduced packet;

encapsulating the reduced packet in a wrapper that includes the flow identifier; and

sending the packet of the sequence of packets from the first hub to the second hub through the secure tunnel.

16 . The medium of claim 15 , wherein converting fields comprises removing the header and combining the header and the flow identifier to form metadata attached to a payload of the reduced packet before encapsulating the reduced packet.

17 . The medium of claim 15 , further comprising

associating a packet reduction mode with the flow identifier,

wherein converting fields comprises converting fields from a header of the packet to a metadata supplement to the packet to form a reduced packet in accordance with the packet reduction mode.

18 . The medium of claim 17 , wherein the packet reduction mode includes a compression level configured to indicate an amount that the fields are compressed in the metadata supplement.

19 . The medium of claim 17 , wherein the packet reduction mode includes an encryption level configured to indicate an amount of encryption applied to the fields in the metadata supplement.

20 . A network node comprising:

a communications interface configured to receive a sequence of packets from a first client at the network node, the sequence of packets each having a same flow;

a session management module configured to facilitate a secure tunnel and an associated session between the network node and the hub; and

a processor configured to assign a flow identifier to the sequence of packets, to convert fields from a header of the packet to a metadata supplement to the packet to form a reduced packet, and to encapsulate the reduced packet in a wrapper that includes the flow identifier,

wherein the communications interface is further to send the packet of the sequence of packets from the network node to the hub through the secure tunnel.

21 . The network node of claim 20 , wherein the processor is further configured to perform a capabilities exchange between the network node and the hub for the flow identifier before converting the fields.

22 . The network node of claim 20 , wherein:

the processor is further configured to encapsulate a start packet of the sequence of packets in a wrapper that includes the flow identifier, the header of the encapsulated start packet including the associated fields; and

the communications interface is further configured to send the encapsulated start packet from the network node to the hub through the secure tunnel, and to receive an acknowledgement of the flow identifier from the hub, the session management module updating a state of the session with the acknowledgement.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: PRASHANTH, FIDELIS; IYER, JAYAKRISHNAN; MEHTA, APURVA
To: VERSA NETWORKS, INC.
Reel/Frame 064680/0329 →
Continuity (3)
Provisional Application 63437095 · Jan 4, 2023
Provisional Application 63476316 · Dec 20, 2022
Related Publication 20240205197A1 · Jun 20, 2024
References Cited (56)
US 5446736A · Gleeson · 1995 [cited by examiner]
US 8428087B1 · Vincent · 2013 [cited by examiner]
US 10091102B2 · Thubert · 2018 [cited by examiner]
US 10594516B2 · Cidon · 2020 [cited by examiner]
US 10805181B2 · Boutros · 2020 [cited by examiner]
US 10979402B1 · Hartley et al. · 2021 [cited by applicant]
US 11398975B2 · Sung · 2022 [cited by examiner]
US 11516049B2 · Cidon · 2022 [cited by examiner]
US 11671367B1 · Shukla · 2023 [cited by examiner]
US 11722471B1 · Ramanujan · 2023 [cited by examiner]
US 20060259608A1 · Kim · 2006 [cited by examiner]
US 20080080508A1 · Das · 2008 [cited by examiner]
US 20100103837A1 · Jungck · 2010 [cited by examiner]
US 20100299446A1 · Huang · 2010 [cited by examiner]
US 20110296002A1 · Caram · 2011 [cited by examiner]
US 20150063158A1 · Nedeltchev · 2015 [cited by examiner]
US 20150172169A1 · DeCusatis · 2015 [cited by examiner]
US 20160127520A1 · Tewari · 2016 [cited by examiner]
US 20160192235A1 · Ahluwalia · 2016 [cited by examiner]
US 20170063783A1 · Yong · 2017 [cited by examiner]
US 20180013584A1 · Shen · 2018 [cited by examiner]
US 20190104035A1 · Cidon · 2019 [cited by examiner]
US 20190158605A1 · Markuze · 2019 [cited by examiner]
US 20190199636A1 · Narayanan · 2019 [cited by examiner]
US 20190238363A1 · Boutros · 2019 [cited by examiner]
US 20190238364A1 · Boutros · 2019 [cited by examiner]
US 20190268973A1 · Bull · 2019 [cited by examiner]
US 20200177555A1 · Sawant · 2020 [cited by examiner]
US 20200213151A1 · Srivatsan · 2020 [cited by examiner]
US 20200366526A1 · Boutros · 2020 [cited by examiner]
US 20210036888A1 · Vadde Makkalla · 2021 [cited by examiner]
US 20210144791A1 · Kang et al. · 2021 [cited by applicant]
US 20210184983A1 · Ramaswamy · 2021 [cited by examiner]
US 20220006756A1 · Ramaswamy · 2022 [cited by examiner]
US 20220052984A1 · Valluri · 2022 [cited by examiner]
US 20220116792A1 · Smoot · 2022 [cited by examiner]
US 20220345400A1 · He · 2022 [cited by examiner]
US 20220360566A1 · Sawant · 2022 [cited by examiner]
US 20220394017A1 · Solanki · 2022 [cited by examiner]
US 20230026874A1 · Camarillo Garvia · 2023 [cited by examiner]
US 20230059537A1 · Gavand · 2023 [cited by examiner]
US 20230097734A1 · Parla · 2023 [cited by examiner]
US 20230118718A1 · Solanki · 2023 [cited by examiner]
US 20230179521A1 · Markuze · 2023 [cited by examiner]
US 20230208769A1 · Iyer · 2023 [cited by examiner]
US 20230216772A1 · Veyland · 2023 [cited by examiner]
US 20230353421A1 · Hatte · 2023 [cited by examiner]
US 20240040472A1 · Satyanarayana · 2024 [cited by examiner]
US 20240205197A1 · Prashanth · 2024 [cited by examiner]
CN 101682858B · 2015 [cited by examiner]
Rawat, Priyanka, Jean Marie Bonnin, and Laurent Toutain. “Designing a tunneling header compression (TuCP) for tunneling over IP.” 2008 IEEE International Symposium on Wireless Communication Systems. IEEE, 2008. [cited by examiner]
Davis, Jonathan J., and Ernest Foo. “Automated feature engineering for HTTP tunnel detection.” computers & security 59 (2016): 166-185. [cited by examiner]
Opmane, Inara, et al. “ZERO: An efficient ethernet-over-IP tunneling protocol.” Inter-cooperative Collective Intelligence: Techniques and Applications (2014): 349-373. [cited by examiner]
Non-Final Office Action for U.S. Appl. No. 18/236,741, dated Jul. 26, 2024, 19 pages. [cited by applicant]
Notice of Allowance (U.S. Appl. No. 18/236,759) dated Feb. 28, 2023, 23 pgs. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/236,741, dated Jan. 16, 2025, 17 pages. [cited by applicant]