IP Library Granted Patent US 8,272,046
Granted Patent B2
US 8,272,046 · App. 11/939,429 · Granted Sep 18, 2012

Network mobility over a multi-path virtual private network

Assignee: Cisco Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,272,046
App. No.
11/939,429
Granted
Sep 18, 2012
Kind
B2
Abstract

Methods and apparatus for applying a single virtual private network (VPN) address to tunnels or connections associated with different access interfaces are disclosed. In one embodiment, a method includes establishing a first tunnel between a node and a VPN server. The first tunnel has a first address. The method also includes assigning a VPN address to the first tunnel, as well as establishing a second tunnel between the node and the VPN server. The second tunnel has a second address. The VPN address is assigned to the second tunnel, and VPN address is accessed by both the first address and the second address.

Claims (42)

1. A method comprising:

establishing a first tunnel between a node and a virtual private network (VPN) server, wherein the first tunnel has a first address;

assigning a VPN address to the first tunnel;

establishing a second tunnel between the node and the VPN server, wherein the second tunnel has a second address; and

assigning the VPN address to the second tunnel, wherein the VPN address is arranged to be accessed by the first address and the second address.

2. The method of claim 1 further including:

utilizing the first tunnel and the second tunnel to transmit and to receive data substantially simultaneously in an aggregated manner.

3. The method of claim 1 wherein the first address is a first Internet Protocol (IP) address and the second address is a second IP address.

4. The method of claim 1 wherein the node is a mobile node.

5. The method of claim 4 wherein the mobile node is in communication with a mobile network, and the VPN server is in communication with a local area network.

6. The method of claim 1 wherein the first tunnel is associated with a Wi-Fi interface, and the second tunnel is associated with a cellular interface.

7. The method of claim 1 wherein establishing the first tunnel includes initiating a first Internet key exchange (IKE) session for the first address and establishing the second tunnel includes initiating a second IKE session for the second address, initiating the second IKE session including specifying the VPN address.

8. The method of claim 7 further including establishing an Internet Protocol security protocol suite (IPSec) session with the VPN address.

9. The method of claim 1 wherein traffic is arranged to be exchanged between the node and the VPN server using the second tunnel if the first tunnel is unavailable.

10. Logic encoded in one or more non-transitory computer-readable media for execution and when executed, operable to:

establish a first tunnel between a node and a virtual private network (VPN) server, wherein the first tunnel has a first address;

assign a VPN address to the first tunnel;

establish a second tunnel between the node and the VPN server, wherein the second tunnel has a second address; and

assign the VPN address to the second tunnel, wherein the VPN address is arranged to be accessed by the first address and the second address.

11. The logic of claim 10 wherein the first address is a first Internet Protocol (IP) address and the second address is a second IP address.

12. The logic of claim 10 wherein the node is a mobile node.

13. The logic of claim 12 wherein the mobile node is in communication with a mobile network, and the VPN server is in communication with a local area network.

14. The logic of claim 10 wherein the first tunnel is associated with a Wi-Fi interface, and the second tunnel is associated with a cellular interface.

15. The logic of claim 10 wherein the logic operable to establish the first tunnel is further operable to initiate a first Internet key exchange (IKE) session for the first address and to establish the second tunnel includes initiating a second IKE session for the second address, the logic operable to initiate the second IKE session further being operable to specify the VPN address.

16. The logic of claim 15 further including logic operable to establish an Internet Protocol security protocol suite (IPSec) session with the VPN address.

17. An apparatus comprising:

means for establishing a first tunnel to a node, wherein the first tunnel has a first address;

means for assigning a virtual private network (VPN) address to the first tunnel;

means for establishing a second tunnel to the node, wherein the second tunnel has a second address; and

means for assigning the VPN address to the second tunnel, wherein the VPN address is arranged to be accessed by the first address and the second address.

18. The apparatus of claim 17 wherein the first address is a first Internet Protocol (IP) address and the second address is a second IP address.

19. The apparatus of claim 17 wherein the node is a mobile node.

20. The apparatus of claim 19 wherein the mobile node is in communication with a mobile network, and the apparatus further includes means for communicating with a local area network.

21. The apparatus of claim 17 wherein the first tunnel is associated with a Wi-Fi interface, and the second tunnel is associated with a cellular interface.

22. The apparatus of claim 17 wherein the means for establishing the first tunnel include means for initiating a first Internet key exchange (IKE) session for the first address and the means for establishing the second tunnel include means for initiating a second IKE session for the second address, the means for initiating the second IKE session including means for specifying the VPN address.

23. The apparatus of claim 22 further including means for establishing an Internet Protocol security protocol suite (IPSec) session with the VPN address.

24. An apparatus comprising:

a port arrangement;

logic, embodied on a non-transitory medium, for establishing a plurality of tunnels between the port arrangement and a node; and

logic, embodied on a non-transitory medium, for assigning a common virtual private network (VPN) address to the plurality of tunnels.

25. The apparatus of claim 24 wherein the logic for establishing the plurality of tunnels includes logic for establishing a first tunnel and logic for establishing a second tunnel, the first tunnel having a first address and the second tunnel having a second address.

26. The apparatus of claim 25 wherein the logic for assigning the common VPN address to the plurality of tunnels includes logic for obtaining the common VPN address for the first tunnel and logic for assigning the common VPN address to the second tunnel, wherein the common VPN address is arranged to be accessed by the first address and the second address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2007
From: GUNDAVELLI, SRINATH; TRAN, PAULINA DUNG; LEUNG, KENT
To: CISCO TECHNOLOGY, INC.
Reel/Frame 020104/0530 →
Continuity (1)
Related Publication 20090122990A1 · May 14, 2009