IP Library › Granted Patent US 10,225,105
Granted Patent B2
US 10,225,105 · App. 15/204,904 · Granted Mar 5, 2019

Network address translation

Inventors: Francis Dinha (Dublin, CA); James Yonan (Pleasanton, CA)
Assignee: OpenVPN Technologies, Inc.
H04L12/4641H04L12/4633H04L61/2514H04L61/2592H04L45/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,225,105
App. No.
15/204,904
Granted
Mar 5, 2019
Kind
B2
Abstract

A method including receiving, at a virtual private network (VPN) server, an encapsulated packet on one of the ingress addresses wherein the ingress address is associated with the packet information. After processing the packet at the VPN server, the packet source address is transformed to the address of the ingress port before transmitting the packet over a network. The process may be effectuated in the operating system's kernel. The association step may include tracking the ingress port in a data store, or tagging the packet with the ingress address so it can be later used to modify the source address. Transforming may include swapping TCP source and destination port information, changing an IP or TCP header checksum, changing a TCP sequence and acknowledgment number, or changing an IP addresses contained in the data payload.

Claims (22)

1. A method including:

receiving, at a virtual private network (VPN) server, an encapsulated packet on an ingress address, said encapsulated packet having an original source address;

associating the ingress address with the encapsulated packet by storing the original source address and the ingress address in a structured data store;

transforming the original source address to the ingress address to effectuate a transformed packet;

routing the transformed packet to a remote destination;

receiving, at the ingress address, a response packet from the remote destination, and

transforming a destination address of the response packet to the original source address.

2. The method of claim 1 wherein the transforming includes one of either swapping TCP source and destination port information, changing an IP or TCP header checksum, changing a TCP sequence and acknowledgment number, or changing an IP addresses contained in the payload information.

3. The method of claim 1 wherein said storing is in either a database, lookup table, or an XML file.

4. The method of claim 1 further including tagging either the encapsulated packet or the transformed packet with a local IP address and a local port number on which the packet was received.

5. The method of claim 1 wherein the method is substantially performed in the kernel-mode code of an operating system kernel.

6. A processor-readable memory device including non-transitory processor-readable instructions directing one or more processors to effectuate a method including:

receiving, at a virtual private network (VPN) server, an encapsulated packet on an ingress address, said encapsulated packet having an original source address;

associating the ingress address with the encapsulated packet by storing the original source address and the ingress address in a structured data store;

transforming the original source address to the ingress address to effectuate a transformed packet;

routing the transformed packet to a remote destination;

receiving, at the ingress address, a response packet from the remote destination, and

transforming a destination address of the response packet to the original source address.

7. The device of claim 6 wherein the transforming includes one of either swapping TCP source and destination port information, changing an IP or TCP header checksum, changing a TCP sequence and acknowledgment number, or changing an IP addresses contained in the payload information.

8. The device of claim 6 wherein said storing is in either a database, lookup table, or an XML file.

9. The device of claim 1 wherein the further includes tagging either the encapsulated packet or the transformed packet with a local IP address and a local port number on which the packet was received.

10. The device of claim 1 wherein the method is substantially performed in the kernel-mode code of an operating system kernel.

Assignments (1)
CHANGE OF NAME Recorded Mar 2, 2022
From: OPENVPN TECHNOLOGIES INC
To: OPENVPN INC.
Reel/Frame 059781/0677 →
Continuity (2)
Provisional Application 62190236 · Jul 8, 2015
Related Publication 20170012937A1 · Jan 12, 2017
Cited By (2)
US 12,323,392 US 12,665,884