IP Library Granted Patent US 12,425,348
Granted Patent B2
US 12,425,348 · App. 18/238,278 · Granted Sep 23, 2025

Quality-of-service enabled network communication for virtual private network clients

Inventor: Dhananjay Lal (Englewood, CO)
Assignee: Adeia Guides Inc.
H04L47/2491H04L12/2801H04L12/4641H04L47/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,348
App. No.
18/238,278
Granted
Sep 23, 2025
Kind
B2
Abstract

Systems and methods are provided herein for providing a system to reconfigure a user's access network to provide varying quality of service (QOS) based on flow identification. For example, a policy server (PS) may transmit a plurality of addresses of virtual private network (VPN) servers associated with a priority status to a cable modem (CM) and/or cable modem termination system (CMTS) associated with a client device. The CMTS may notify the PS when the CM and/or CMTS detects VPN traffic between the client device and a VPN server associated with the priority status. In response to the notification, the PS may transmit an update message to the CMTS, wherein the update message comprises an updated configuration. The updated configuration may be used to update the CM and/or CMTS so that the updated CM and/or CMTS process future data packets according to an updated QoS policy.

Claims (79)

1. A method comprising:

transmitting, by a policy server (PS), a plurality of addresses associated with a priority status, wherein:

each address of the plurality of addresses corresponds to at least one virtual private network (VPN) server of a plurality of VPN servers; and

the plurality of addresses are transmitted to one or more of a cable modem (CM) or cable modem termination system (CMTS) associated with a client device;

establishing a VPN connection between the client device and a VPN server of the plurality of VPN servers with a first address;

transmitting, by the client device, egress packets to the VPN server using the VPN connection and the CM, wherein the CM processes the egress packets according to a first egress policy;

receiving, by the client device, ingress packets from the VPN server using the VPN connection and the CMTS, wherein the CMTS processes the ingress packets according to a first ingress policy;

detecting, by at least one of the CM or CMTS, that the plurality of addresses of VPN servers comprises the first address of the VPN server associated with the priority status based on at least one of the egress packets or the ingress packets;

transmitting, by the CMTS, a notification to the PS, wherein the notification indicates occurrence of VPN traffic between the client device and the VPN server, wherein the first address of the VPN server is one of the addresses of the plurality of addresses of VPN servers associated with the priority status;

transmitting, by the PS, an update message to at least one of the CM or CMTS, wherein the update message comprises an updated configuration for at least one of the CM or CMTS;

receiving, by at least one of the CM or CMTS, the update message from the PS; and

updating at least one of the CM or CMTS according to the updated configuration, wherein the updated configuration causes at least one of:

(a) the CM to process future egress packets via the VPN connection according to a second egress policy different than the first egress policy; or

(b) the CMTS to process future ingress packets via the VPN connection according to a second ingress policy different than the first ingress policy.

2. The method of claim 1 , wherein:

the first egress policy and/or the first ingress policy correspond to a first bandwidth allocation and the second egress policy and/or the second ingress policy correspond to a second bandwidth allocation; and

the first bandwidth allocation is less than the second bandwidth allocation.

3. The method of claim 1 , wherein:

the first egress policy and/or the first ingress policy correspond to a first latency allocation and the second egress policy and/or the second ingress policy correspond to a second latency allocation; and

the first latency allocation is less than the second latency allocation.

4. The method of claim 1 , wherein:

the first egress policy and/or the first ingress policy correspond to a first jitter allocation and the second egress policy and/or the second ingress policy correspond to a second jitter allocation; and

the first jitter allocation is less than the second jitter allocation.

5. The method of claim 1 , further comprising:

determining, by at least one of the CM or CMTS, that a first group of data packets correspond to a first flow, wherein the second egress policy and/or the second ingress policy indicates a first quality of service (QOS) for the first flow; and

processing, by at least one of the CM or CMTS, the first group of data packets according to the first QoS.

6. The method of claim 5 , further comprising:

determining, by at least one of the CM or CMTS, that a second group of data packets correspond to a second flow, wherein the second egress policy and/or the second ingress policy indicates a second QoS for the second flow; and

processing, by at least one of the CM or CMTS, the second group of data packets according to the second QoS.

7. The method of claim 5 , wherein at least one of the CM or CMTS determines that the first group of data packets correspond to the first flow based on a 5-tuple associated with the first group of data packets.

8. The method of claim 1 , further comprising:

determining, by at least one of the CM or CMTS, that a first group of data packets correspond to a first traffic type, wherein the second egress policy and/or the second ingress policy indicates a first quality of service (QOS) for the first traffic type; and

processing, by at least one of the CM or CMTS, the first group of data packets according to the first QoS.

9. The method of claim 8 , further comprising:

determining, by at least one of the CM or CMTS, that a second group of data packets correspond to a second traffic type, wherein the second egress policy and/or the second ingress policy indicates a second QoS for the second traffic type; and

processing, by at least one of the CM or CMTS, the second group of data packets according to the second QoS.

10. The method of claim 8 , wherein at least one of the CM or CMTS determines that the first group of data packets correspond to the first traffic type using machine-learning.

11. The method of claim 1 , further comprising:

determining, by at least one of the CM or CMTS, that an inner head of a data packet corresponds to a first traffic type, wherein the second egress policy and/or the second ingress policy indicates a first quality of service (QOS) for the first traffic type; and

processing, by at least one of the CM or CMTS, the data packet according to the first QoS.

12. A method comprising:

transmitting, by an enterprise virtual private network (VPN) quality of service (Qos) adapter (EVQA), a plurality of addresses associated with a priority status to one or more of a cable modem (CM) or cable modem termination system (CMTS) associated with a client device, wherein:

each address of the plurality of addresses corresponds to at least one (VPN) server of a plurality of VPN servers;

the CM processes a plurality of egress packets from the client device according to a first egress policy; and

the CMTS processes a plurality of ingress packets to the client device according to a first ingress policy;

receiving, by the EVQA, from at least one of the CM or CMTS, a notification, wherein the notification indicates occurrence of VPN traffic between the client device and a VPN server of the plurality of VPN servers, wherein the address of the VPN server is one of the addresses of the plurality of addresses associated with the priority status; and

transmitting, by the EVQA, an update message comprising an updated configuration for at least one of the CM or CMTS to at least one of the CM or CMTS, wherein the update message causes at least one of:

the CM to process a plurality of future egress packets to the VPN server according to a second egress policy different than the first egress policy; or

the CMTS to process a plurality of future ingress packets from the VPN server according to a second ingress policy different than the first ingress policy.

13. The method of claim 12 , wherein:

the first egress policy and/or the first ingress policy correspond to a first bandwidth allocation and the second egress policy and/or the second ingress policy correspond to a second bandwidth allocation; and

the first bandwidth allocation is less than the second bandwidth allocation.

14. The method of claim 12 , wherein:

the first egress policy and/or the first ingress policy correspond to a first latency allocation and the second egress policy and/or the second ingress policy correspond to a second latency allocation; and

the first latency allocation is less than the second latency allocation.

15. The method of claim 12 , wherein:

the first egress policy and/or the first ingress policy correspond to a first jitter allocation and the second egress policy and/or the second ingress policy correspond to a second jitter allocation; and

the first jitter allocation is less than the second jitter allocation.

16. The method of claim 12 , wherein:

the second egress policy and/or the second ingress policy indicates a first QoS for a first flow; and

at least one of the CM or CMTS processes a first group of data packets associated with the first flow according to the first QoS.

17. The method of claim 16 , wherein:

the second egress policy and/or the second ingress policy indicates a second QoS for a second flow; and

at least one of the CM or CMTS processes a second group of data packets associated with the second flow according to the second QoS.

18. The method of claim 16 , wherein at least one of the CM or CMTS determines that the first group of data packets correspond to the first flow based on a 5-tuple associated with the first group of data packets.

19. The method of claim 12 , wherein:

the second egress policy and/or the second ingress policy indicates a first QoS for a first traffic type; and

at least one of the CM or CMTS processes a first group of data packets according to the first QoS.

20. An apparatus comprising:

control circuitry; and

at least one memory including computer program code for one or more programs, the at least one memory and the computer program code configured to, with the control circuitry, cause the apparatus to perform at least the following:

transmit a plurality of addresses associated with a priority status to one or more of a cable modem (CM) or cable modem termination system (CMTS) associated with a client device, wherein:

each address of the plurality of addresses corresponds to at least one virtual private network (VPN) server of a plurality of VPN servers;

the CM processes a plurality of egress packets from the client device according to a first egress policy; and

the CMTS processes a plurality of ingress packets to the client device according to a first ingress policy;

receive from at least one of the CM or CMTS, a notification, wherein the notification indicates occurrence of VPN traffic between the client device and a VPN server of the plurality of VPN servers, wherein the address of the VPN server is one of the addresses of the plurality of addresses associated with the priority status; and

transmit an update message comprising an updated configuration for at least one of the CM or CMTS to at least one of the CM or CMTS, wherein the update message causes at least one of:

the CM to process a plurality of future egress packets to the VPN server according to a second egress policy different than the first egress policy; or

the CMTS to process a plurality of future ingress packets from the VPN server according to a second ingress policy different than the first ingress policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: LAL, DHANANJAY
To: ADEIA GUIDES INC.
Reel/Frame 065370/0308 →
Continuity (1)
Related Publication 20250071065A1 · Feb 27, 2025
References Cited (35)
US 6693878B1 · Daruwalla · 2004 [cited by examiner]
US 8184530B1 · Swan · 2012 [cited by examiner]
US 20050088977A1 · Roch et al. · 2005 [cited by applicant]
US 20090225762A1 · Davidson et al. · 2009 [cited by applicant]
US 20100290366A1 · Garcia · 2010 [cited by examiner]
US 20110314086A1 · Finkelstein et al. · 2011 [cited by applicant]
US 20150043350A1 · Basilier · 2015 [cited by examiner]
US 20180219958A1 · Bernstein et al. · 2018 [cited by applicant]
US 20190225762A1 · Tsutsumi et al. · 2019 [cited by applicant]
US 20210067414A1 · Costa · 2021 [cited by examiner]
US 20210234834A1 · Koshy · 2021 [cited by examiner]
US 20250008379A1 · Lal et al. · 2025 [cited by applicant]
WO 2009109803A1 · 2009 [cited by applicant]
Blight, et al. “Policy-based networking architecture for QoS interworking in IP management-scalable architecture for large-scale enterprise-public interoperation,” [URL: http://ieeexplore.ieee.org/ie15/6244/16698/007707… [cited by applicant]
He, J., et al., “Managing enterprise VPN with PBN”, Enterprise Networking, Applications and Services Conference Proceedings S, 83-88 (2011). [cited by applicant]
“Specification #: 23.501,” [retrieved from URL: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationld=3144], 1 page. [cited by applicant]
“Using Virtual Private Network (VPN″ for IoT,” [retrieve from URL: https://iot.onesimcard.com/virtual-private-network-IoT/ on Oct. 25, 2023], 3 pages. [cited by applicant]
“5G Network Slicing,” [retrieve from URL: https://www.viavisolutions.com/en-US/5g-network-slicing on Oct. 25, 2023], 9 pages. [cited by applicant]
“Differentiated services,” WikipediA, [retrieved from URL: https://en.wikipedia.org/wiki/Differentiated_services on Oct. 25, 2023], 8 pages. [cited by applicant]
“How to trigger a network slice in a non-public network,” [retrieved from URL: https://cumucore.com/blog/how-to-trigger-a-network-slice-in-a-non-public-network/ on Oct. 24, 2023], 8 pages. [cited by applicant]
“IPsec-VPNs-vs-SSI-VPNs,” [retrieved from URL: https://www.cloudflare.com/learning/network-layer/ipsec-vs-ssl-vpn/ on Oct. 25, 2023], 5 pages. [cited by applicant]
“OpenSync. It's the only way,” [retrieved from URL: https://www.opensync.io/ on Oct. 25, 2023], 8 pages. [cited by applicant]
“PacketCableSpecification-MultimediaSpecification-PKT-SP-MM-107-151111” , [retrieved from URL: https://community.cablelabs.com/wiki/plugins/servlet/cablelabs/alfresco/download?id=152f0820-cf0c-4a23-ada3-898746e490c2 on … [cited by applicant]
“SANOJA-IPsec-Tunnel-2021,” [retrieved from URL: https://www.twingate.com/blog/ipsec-tunnel-mode/], 8 pages (2021). [cited by applicant]
“Using Virtual Private Network (VPN″ for loT,” [retrieve from URL: https://iot.onesimcard.com/virtual-private-network-IoT/ on Oct. 25, 2023], 3 pages. [cited by applicant]
“Virtual Private Networking, Addressing and Routing for VPNs,” [retrieved from URL: https://wwwdisc.chimica.unipd.it/luigino.feltre/pubblica/unix/winnt_doc/2000/inbe_vpn_tcsa.html on Oct. 17, 2023], 1-12 pages. [cited by applicant]
“What is 5QI in 5G,” [retrieve from URL: https://www.5gworldpro.com/uncategorized/what-is-5qi-in-5g.html#:˜: text=What%20is%20the%20meaning%20of,be%20standardized%20or%20non%2Dstandardized], 2 pages (2023). [cited by applicant]
“What is IP Sec—How IPSec VPNs work,” [retrieved from URL: https://www.cloudflare.com/learning/network-layer/what-is-ipsec/#:˜: text=IPsec%20is%20a%20group%20of,where%20the%20packets%20come%20from on Oct. 17, 2023], 7 p… [cited by applicant]
“What is SLL VPN?,” [retrieved from URL: https://www.fortinet.com/resources/cyberglossary/ssl-vpn on Oct. 25, 2023], pp. 1-5. [cited by applicant]
“Wi-Fi Certified Wmm Programs,” [retrieved from URL: https://www.wi-fi.org/discover-wi-fi/wi-fi-certified-wmm-programs on Oct. 25, 2023], 3 pages. [cited by applicant]
Beijar, N., Serving up secure IoT with network slicing security, [retrieved from URL: https://www.ericsson.com/en/blog/2019/9/future-network-slicing-security-iot], 8 pages (2019). [cited by applicant]
Huang, et al., “Chapter 2: SLL VPN Technology,” [retrieved from URL: https://www.networkworld.com/article/2268575/chapter-2--ssl-vpn-technology.html], 1-5 (2008). [cited by applicant]
Huang, Y-F., et al., “Research on QoS Classification of network Encrypted Traffic Behavior Based on Machine Learning,” Electronics, 10(1376), 1-24 (2021). [cited by applicant]
Patel, M., “IPsec VPNs: What They Are and How to Set Them Up,” [retrieved from URL: https://www.twingate.com/blog/ipsec-vpn], 1-12 (2021). [cited by applicant]
Riddel, J., “Chapter 14: Multimedia Applications,” Network World, 1-2 (2007). [cited by applicant]