IP Library › Granted Patent US 12,587,514
Granted Patent B2
US 12,587,514 · App. 18/453,934 · Granted Mar 24, 2026

Routing packet to TCP tunnel client program

Inventors: Alec R. Synstelien (Chanhassen, MN); Justin L. Synstelien (Chanhassen, MN); Brady M. Synstelien (Chanhassen, MN); Garrett D. Synstelien (Chanhassen, MN); Larry D. Synstelien (Chanhassen, MN)
Assignee: ReadyLinks Inc.
H04L63/0478H04L12/4633H04L63/166H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,514
App. No.
18/453,934
Granted
Mar 24, 2026
Kind
B2
Abstract

A system and method for cloud-based control of network devices is provided. An encrypted connection is established by a network access device with a host using a transmission control protocol (TCP). The network access device determines that a packet to be transmitted to the host is to be routed via a TCP tunnel client program. Based on the determination, the network access device sends the packet to the TCP tunnel client program. The TCP tunnel client program encrypts, signs, and fragments the packet, and the network access device sends the encrypted packet to a remote endpoint associated with the host using the TCP.

Claims (28)

1 . A computer-implemented method for control of network devices, the method comprising:

establishing, by a network access device including a virtual internet protocol (IP) point-to-point interface configured to process network packets, an encrypted connection with a host using a transmission control protocol (TCP), wherein the network access device is configured to be accessed using an application programming interface (API) and to connect to a host or server running a TCP tunnel program;

determining, by the network access device, that a packet to be transmitted to the host is to be routed via the TCP tunnel client program;

sending, by the network access device based on the determination, the packet to the TCP tunnel client program;

encrypting, signing, and fragmenting, by the TCP tunnel client program, the packet to produce an encrypted packet with instructions for control of network devices; and

sending, by the network access device using the TCP, the encrypted packet to a remote endpoint associated with the host.

2 . The method of claim 1 , wherein the network access device is a switch.

3 . The method of claim 1 , wherein the network access device is a tunnel (TUN) device.

4 . The method of claim 1 , wherein the TCP tunnel client program is configured to connect to the host running a TCP tunnel server program.

5 . The method of claim 4 , wherein the TCP tunnel server program is only reachable via TCP port 443.

6 . The method of claim 1 , wherein the encrypted packet traverses through load-balance logic.

7 . The method of claim 6 , wherein the load-balance logic includes one or more of geography, latency, host health, or host server response time.

8 . The method of claim 7 , further comprising directing the encrypted packet to a specific host running a TCP tunnel server program and enabling multiple hosts to run the TCP tunnel server program in parallel.

9 . The method of claim 8 , wherein the TCP tunnel server program is configured to execute on a TCP tunnel server including a cloud-based server or any device which may create a virtual network interface.

10 . A system comprising:

a network access device including a virtual internet protocol (IP) point-to-point interface configured to process network packets), wherein the network access device is configured to be accessed using an application programming interface (API) and to connect to a host or server running a TCP tunnel program, the network access device comprising one or more processors and a data storage system in communication with the one or more processors, wherein the data storage system comprises instructions thereon that, when executed by the one or more processors, causes the one or more processors to:

establish an encrypted connection with a host using a transmission control protocol (TCP);

determine that a packet to be transmitted to the host is to be routed via the TCP tunnel client program;

send, based on the determination, the packet to the TCP tunnel client program;

encrypt, sign, and fragment, using the TCP tunnel client program, the packet to produce an encrypted packet with instructions for control of network devices; and

send, using the TCP, the encrypted packet to a remote endpoint associated with the host.

11 . The system of claim 10 , wherein the network access device is a switch.

12 . The system of claim 10 , wherein the network access device is a tunnel (TUN) device.

13 . The system of claim 10 , wherein the network access device is configured to connect to a host or server running a TCP tunnel server program.

14 . The system of claim 13 , wherein the TCP tunnel server program is configured to execute on a TCP tunnel server including a cloud-based server.

15 . The system of claim 13 , wherein the TCP tunnel client program is configured to connect to the host running the TCP tunnel server program.

16 . The system of claim 10 , wherein the encrypted packet traverses through load-balance logic.

17 . The system of claim 16 , wherein the load-balance logic includes one or more of geography, latency, host health, or host server response time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2026
From: SYNSTELIEN, ALEC R.; SYNSTELIEN, JUSTIN L.; SYNSTELIEN, BRADY M.; SYNSTELIEN, GARRETT D.; SYNSTELIEN, LARRY D.
To: READYLINKS INC.
Reel/Frame 073841/0967 →
Continuity (2)
Provisional Application 63401373 · Aug 26, 2022
Related Publication 20240080307A1 · Mar 7, 2024
References Cited (25)
US 7181766B2 · Bendinelli et al. · 2007 [cited by applicant]
US 7856021B2 · Hasegawa et al. · 2010 [cited by applicant]
US 8332464B2 · Dispensa et al. · 2012 [cited by applicant]
US 8477771B2 · Biswas et al. · 2013 [cited by applicant]
US 11431761B2 · Loiseau · 2022 [cited by examiner]
US 20030014623A1 · Freed · 2003 [cited by examiner]
US 20030195919A1 · Watanuki · 2003 [cited by examiner]
US 20080222166A1 · Hultgren · 2008 [cited by examiner]
US 20080285575A1 · Biswas et al. · 2008 [cited by applicant]
US 20090271504A1 · Ginter · 2009 [cited by examiner]
US 20110145593A1 · Auradkar · 2011 [cited by examiner]
US 20120005369A1 · Capone et al. · 2012 [cited by applicant]
US 20120278878A1 · Barkie · 2012 [cited by examiner]
US 20130332724A1 · Walters · 2013 [cited by examiner]
US 20150317169A1 · Sinha · 2015 [cited by examiner]
US 20180167810A1 · Wu · 2018 [cited by examiner]
US 20180183763A1 · Glazemakers · 2018 [cited by examiner]
US 20200044954A1 · Raut · 2020 [cited by examiner]
US 20220174129A1 · Penz · 2022 [cited by examiner]
US 20230224361A1 · Karuppannan · 2023 [cited by examiner]
“Chinese Application Serial No. 202380062002.0, Notification to Make Rectification mailed Mar. 24, 2025”, with English translation, 2 pages. [cited by applicant]
“International Application Serial No. PCT/US2023/072668, International Preliminary Report on Patentability mailed Mar. 13, 2025”, 6 pgs. [cited by applicant]
“International Application Serial No. PCT/US2023/072668, International Search Report mailed Dec. 18, 2023”, 4 pgs. [cited by applicant]
“International Application Serial No. PCT/US2023/072668, Written Opinion mailed Dec. 18, 2023”, 4 pgs. [cited by applicant]
“European Application Serial No. 23773083.3, Response to Communication pursuant to Rules 161(2) and 162 EPC filed Oct. 2, 2025”, w/ claims, 6 pgs. [cited by applicant]