IP Library Granted Patent US 12,328,357
Granted Patent B2
US 12,328,357 · App. 18/419,265 · Granted Jun 10, 2025

Virtual private network (VPN) whose traffic is intelligently routed

Inventors: Christopher Philip Branch (Romford, GB); Naga Sunil Tripirineni (San Jose, CA); Rustam Xing Lalkaka (San Francisco, CA); Nick Wondra (Champaign, IL); Mohd Irtefa (Austin, TX); Matthew Browning Prince (San Francisco, CA); Andrew Taylor Plunk (Austin, TX); Oliver Yu (Austin, TX); Vlad Krasnov (New York, NY)
Assignee: CLOUDFLARE, INC.
H04L67/10H04L12/4633H04L12/4641H04L45/02H04L63/0272H04L67/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,357
App. No.
18/419,265
Granted
Jun 10, 2025
Kind
B2
Abstract

A request is received from a client device over a Virtual Private Network (VPN) tunnel. The request is received at a first one of a plurality of edge servers of a distributed cloud computing network. A destination of the request is determined and an optimized route for transmitting the request toward an origin server is determined. The optimized route is based at least in part on probe data between edge servers of the distributed cloud computing network. The request is transmitted to a next hop as defined by the optimized route.

Claims (53)

1. A method, comprising:

receiving, at a first one of a plurality of edge servers of a distributed cloud computing network, a request from a client device over a secure connection between a client application of the client device and one or more of the plurality of edge servers;

calculating, based at least in part on probe data between the plurality of edge servers of the distributed cloud computing network, an optimized route through the distributed cloud computing network for transmitting the request towards an origin server that corresponds with a destination of the request; and

transmitting the request to a next hop as defined by the optimized route.

2. The method of claim 1 , wherein the optimized route includes a second one of the plurality of edge servers that is connected to the origin server, and wherein the second one of the plurality of edge servers is an egress server.

3. The method of claim 1 , wherein calculating the optimized route through the distributed cloud computing network for transmitting the request towards the origin server that corresponds with the destination of the request further comprises:

transmitting a probe request to each edge server in the plurality of edge servers of the distributed cloud computing network;

receiving the probe data, wherein the probe data is received from one or more origin servers, the probe data including server-to-server probe results and server-to-origin probe results;

calculating the optimized route using the probe data; and

storing the calculated optimized route in an optimized route table.

4. The method of claim 3 , wherein the server-to-server probe results includes determining, for each edge server to edge server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT), a TCP minimum RTT, a TCP maximum RTT, a TCP median RTT, and a TCP standard deviation.

5. The method of claim 3 , wherein the server-to-origin probe results includes determining, for each edge server to origin server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT) to a corresponding origin server of an edge server to origin server link, a TCP minimum RTT to the corresponding origin server, a TCP maximum RTT to the corresponding origin server, a TCP median RTT to the corresponding origin server, a TCP standard deviation to the corresponding origin server, bandwidth to the corresponding origin server, and packet loss to the corresponding origin server.

6. The method of claim 1 , wherein the optimized route is optimized based on one or more factors, the one or more factors including speed and reliability.

7. The method of claim 1 , further comprising:

receiving, at the first one of the plurality of edge servers of the distributed cloud computing network, a second request from the client device over the secure connection;

determining that there is not an optimized route through the distributed cloud computing network for transmission of the second request toward a second origin server that corresponds with a second destination of the second request; and

transmitting the request toward the second origin server via a default route.

8. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations comprising:

receiving, at a first one of a plurality of edge servers of a distributed cloud computing network, a request from a client device over a secure connection between a client application of the client device and one or more of the plurality of edge servers;

calculating, based at least in part on probe data between the plurality of edge servers of the distributed cloud computing network, an optimized route through the distributed cloud computing network for transmitting the request towards an origin server that corresponds with a destination of the request; and

transmitting the request to a next hop as defined by the optimized route.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the optimized route includes a second one of the plurality of edge servers that is connected to the origin server, and wherein the second one of the plurality of edge servers is an egress server.

10. The non-transitory machine-readable storage medium of claim 8 , wherein calculating the optimized route through the distributed cloud computing network for transmitting the request towards the origin server that corresponds with the destination of the request further causes said processor to perform operations comprising:

transmitting a probe request to each edge server in the plurality of edge servers of the distributed cloud computing network;

receiving the probe data, wherein the probe data is received from one or more origin servers, the probe data including server-to-server probe results and server-to-origin probe results;

calculating the optimized route using the probe data; and

storing the calculated optimized route in an optimized route table.

11. The non-transitory machine-readable storage medium of claim 10 , wherein the server-to-server probe results includes determining, for each edge server to edge server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT), a TCP minimum RTT, a TCP maximum RTT, a TCP median RTT, and a TCP standard deviation.

12. The non-transitory machine-readable storage medium of claim 10 , wherein the server-to-origin probe results includes determining, for each edge server to origin server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT) to a corresponding origin server of an edge server to origin server link, a TCP minimum RTT to the corresponding origin server, a TCP maximum RTT to the corresponding origin server, a TCP median RTT to the corresponding origin server, a TCP standard deviation to the corresponding origin server, bandwidth to the corresponding origin server, and packet loss to the corresponding origin server.

13. The non-transitory machine-readable storage medium of claim 8 , wherein the optimized route is optimized based on one or more factors, the one or more factors including speed and reliability.

14. The non-transitory machine-readable storage medium of claim 8 , the operations further comprising:

receiving, at the first one of the plurality of edge servers of the distributed cloud computing network, a second request from the client device over the secure connection;

determining that there is not an optimized route through the distributed cloud computing network for transmission of the second request toward a second origin server that corresponds with a second destination of the second request; and

transmitting the request toward the second origin server via a default route.

15. A server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the server to perform operations including:

receiving, at a first one of a plurality of edge servers of a distributed cloud computing network, a request from a client device over a secure connection between a client application of the client device and one or more of the plurality of edge servers;

calculating, based at least in part on probe data between the plurality of edge servers of the distributed cloud computing network, an optimized route through the distributed cloud computing network for transmitting the request towards an origin server that corresponds with a destination of the request; and

transmitting the request to a next hop as defined by the optimized route.

16. The server of claim 15 , wherein the optimized route includes a second one of the plurality of edge servers that is connected to the origin server, and wherein the second one of the plurality of edge servers is an egress server.

17. The server of claim 15 , wherein calculating the optimized route through the distributed cloud computing network for transmitting the request towards the origin server that corresponds with the destination of the request further comprises:

transmitting a probe request to each edge server in the plurality of edge servers of the distributed cloud computing network;

receiving the probe data, wherein the probe data is received from one or more origin servers, the probe data including server-to-server probe results and server-to-origin probe results;

calculating the optimized route using the probe data; and

storing the calculated optimized route in an optimized route table.

18. The server of claim 17 , wherein the server-to-server probe results includes determining, for each edge server to edge server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT), a TCP minimum RTT, a TCP maximum RTT, a TCP median RTT, and a TCP standard deviation.

19. The server of claim 17 , wherein the server-to-origin probe results includes determining, for each edge server to origin server link, one or more of the following: a Transmission Control Protocol (TCP) average round trip time (RTT) to a corresponding origin server of an edge server to origin server link, a TCP minimum RTT to the corresponding origin server, a TCP maximum RTT to the corresponding origin server, a TCP median RTT to the corresponding origin server, a TCP standard deviation to the corresponding origin server, bandwidth to the corresponding origin server, and packet loss to the corresponding origin server.

20. The server of claim 15 , wherein the optimized route is optimized based on one or more factors, the one or more factors including speed and reliability.

21. The server of claim 15 , the operations further comprising:

receiving, at the first one of the plurality of edge servers of the distributed cloud computing network, a second request from the client device over the secure connection;

determining that there is not an optimized route through the distributed cloud computing network for transmission of the second request toward a second origin server that corresponds with a second destination of the second request; and

transmitting the request toward the second origin server via a default route.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: BRANCH, CHRISTOPHER PHILIP; TRIPIRINENI, NAGA SUNIL; LALKAKA, RUSTAM XING; WONDRA, NICK; IRTEFA, MOHD; PRINCE, MATTHEW BROWNING; PLUNK, ANDREW TAYLOR; YU, OLIVER; KRASNOV, VLAD
To: CLOUDFLARE, INC.
Reel/Frame 066219/0519 →
Continuity (4)
Continuation 17893003 · Aug 22, 2022
Continuation 16836613 · Mar 31, 2020
Provisional Application 62827812 · Apr 1, 2019
Related Publication 20240163350A1 · May 16, 2024
References Cited (61)
US 6751729B1 · Giniger et al. · 2004 [cited by applicant]
US 7254634B1 · Davis et al. · 2007 [cited by applicant]
US 7783777B1 · Pabla et al. · 2010 [cited by applicant]
US 8819187B1 · Hofmann · 2014 [cited by applicant]
US 9419845B2 · Wainner et al. · 2016 [cited by applicant]
US 9635705B2 · Lu et al. · 2017 [cited by applicant]
US 9736710B2 · Kim et al. · 2017 [cited by applicant]
US 10374953B1 · Branch et al. · 2019 [cited by applicant]
US 10659256B2 · Ore et al. · 2020 [cited by applicant]
US 10687188B2 · Kim et al. · 2020 [cited by applicant]
US 11115480B2 · Markuze et al. · 2021 [cited by applicant]
US 11425216B2 · Branch · 2022 [cited by examiner]
US 11882199B2 · Branch · 2024 [cited by examiner]
US 20030174648A1 · Wang et al. · 2003 [cited by applicant]
US 20060159039A1 · Jung et al. · 2006 [cited by applicant]
US 20060182034A1 · Klinker · 2006 [cited by examiner]
US 20070153782A1 · Fletcher et al. · 2007 [cited by applicant]
US 20070248091A1 · Khalid et al. · 2007 [cited by applicant]
US 20080259944A1 · Raghunath et al. · 2008 [cited by applicant]
US 20090034418A1 · Flammer et al. · 2009 [cited by applicant]
US 20090034419A1 · Flammer et al. · 2009 [cited by applicant]
US 20110225311A1 · Liu · 2011 [cited by examiner]
US 20110225312A1 · Liu · 2011 [cited by examiner]
US 20130010621A1 · Yoshiuchi et al. · 2013 [cited by applicant]
US 20130205025A1 · Shamsee et al. · 2013 [cited by applicant]
US 20140105174A1 · Agrawal et al. · 2014 [cited by applicant]
US 20140259109A1 · Houston et al. · 2014 [cited by applicant]
US 20150039881A1 · Scheidt et al. · 2015 [cited by applicant]
US 20150295888A1 · Maslak · 2015 [cited by applicant]
US 20150373688A1 · Samuel Raj · 2015 [cited by examiner]
US 20160119279A1 · Maslak et al. · 2016 [cited by applicant]
US 20160191651A1 · Balakrishnan et al. · 2016 [cited by applicant]
US 20160191664A1 · Balakrishnan et al. · 2016 [cited by applicant]
US 20160380975A1 · Reddy et al. · 2016 [cited by applicant]
US 20170026461A1 · Boutros et al. · 2017 [cited by applicant]
US 20170063674A1 · Maskalik et al. · 2017 [cited by applicant]
US 20170195161A1 · Ruel et al. · 2017 [cited by applicant]
US 20180103013A1 · Imai et al. · 2018 [cited by applicant]
US 20180115547A1 · Peterson et al. · 2018 [cited by applicant]
US 20180176121A1 · Jayaraman · 2018 [cited by examiner]
US 20180212876A1 · Bacthu · 2018 [cited by examiner]
US 20180248876A1 · Sakura et al. · 2018 [cited by applicant]
US 20180278688A1 · Gal et al. · 2018 [cited by applicant]
US 20180376338A1 · Ashrafi · 2018 [cited by applicant]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190235714A1 · Bilange et al. · 2019 [cited by applicant]
US 20190238449A1 · Michael et al. · 2019 [cited by applicant]
US 20190246160A1 · Williams et al. · 2019 [cited by applicant]
US 20190260599A1 · Williams et al. · 2019 [cited by applicant]
US 20190339840A1 · Park et al. · 2019 [cited by applicant]
US 20200136862A1 · Jain et al. · 2020 [cited by applicant]
US 20200137192A1 · Ioannidis · 2020 [cited by examiner]
US 20200314212A1 · Branch et al. · 2020 [cited by applicant]
Lalkaka, Rustam, “Introducing Argo—A faster, more reliable, more secure Internet for everyone”, Cloudflare, Available Online at <https://blog.cloudflare.com/argo/>, May 18, 2017, pp. 1-9. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/836,613, Oct. 6, 2020, 9 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/893,003, May 10, 2023, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/836,613, Apr. 26, 2022, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/836,613, Apr. 19, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/836,613, Aug. 17, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/836,613, Dec. 14, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/893,003, Sep. 29, 2023, 8 pages. [cited by applicant]