IP Library Granted Patent US 11,665,141
Granted Patent B1
US 11,665,141 · App. 17/686,952 · Granted May 30, 2023

Virtual private network connection status detection

Inventors: Darjus Ilcevic (Vilnius, LT); Gvidas Uzkuras (Vilnius, LT)
Assignee: Oversec, UAB
H04L63/0272H04L61/5061H04L63/0807H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,141
App. No.
17/686,952
Granted
May 30, 2023
Kind
B1
Abstract

Virtual private network (VPN) service provider infrastructure (SPI) receives a request to access a VPN from a client device. The VPN SPI selects an Internet Protocol (IP) address for access to the VPN by the client device from a pool of IP addresses. The VPN SPI provides access to the VPN for the client device via the IP address. The VPN SPI receives one or more handshake notifications from the client device. The VPN SPI determines that a threshold time period has passed since a latest-in-time handshake notification of the one or more handshake notifications. The VPN SPI disconnects the client device from the VPN in response to determining that the threshold time period has passed. The VPN SPI adds the IP address to the pool of IP addresses in response to disconnecting the client device from the VPN.

Claims (55)

1. A method comprising:

selecting an Internet Protocol (IP) address for access to a virtual private network (VPN) by a client device from a pool of IP addresses;

providing access to the VPN for the client device via the IP address;

receiving one or more handshake notifications from the client device, wherein receiving a handshake notification of the one or more handshake notifications comprises:

receiving a request, from the client device after the client device was granted access to the VPN, to download or upload data via the VPN,

storing a timestamp associated with the request to download or upload the data,

transmitting an echo request packet to the client device, and

receiving an echo reply in response to the echo request packet;

calculating a time difference between a current time and a stored timestamp of a latest-in-time handshake notification from the client device;

in response to determining that a threshold time period has passed since the latest-in-time handshake notification of the one or more handshake notifications based on the computed time difference being at least the threshold time period, disconnecting the client device from the VPN; and

adding the IP address to the pool of IP addresses.

2. The method of claim 1 , wherein the IP address is reserved for use solely by the client device from a time when the client device is provided access to the VPN until a time when the client device is disconnected from the VPN.

3. The method of claim 1 , wherein the pool of IP addresses corresponds to an account tier of a user of the client device.

4. The method of claim 1 , further comprising:

authenticating the client device by verifying that a user account, associated with a user, used to login to a VPN service is a valid account.

5. The method of claim 1 , wherein determining that at least the threshold time period has passed comprises:

determining that a time difference between the time stamp of the latest-in-time handshake notification and a current time exceeds the threshold time period.

6. The method of claim 1 , wherein the one or more handshake notifications are received periodically from the client device.

7. The method of claim 4 , wherein authenticating the client device is based on a JavaScript token received from the client device.

8. The method of claim 4 , wherein authenticating the client device is based on a JavaScript Object Notation (JSON) Web Token (JWT) received from the client device.

9. An apparatus comprising:

a non-transitory memory storing instructions; and

a processor that executes the instructions to:

select an Internet Protocol (IP) address for access to a virtual private network (VPN) by a client device from a pool of IP addresses;

provide access to the VPN for the client device via the IP address;

receive one or more handshake notifications from the client device, wherein receiving a handshake notification of the one or more handshake notifications comprises:

receiving a request, from the client device after the client device was granted access to the VPN, to download or upload data via the VPN,

storing a timestamp associated with the request to download or upload the data,

transmitting an echo request packet to the client device, and

receiving an echo reply in response to the echo request packet;

calculate a time difference between a current time and a stored timestamp of a latest-in-time handshake notification from the client device;

in response to determining that a threshold time period has passed since the latest-in-time handshake notification of the one or more handshake notifications based on the computed time difference being at least the threshold time period, disconnect the client device from the VPN; and

add the IP address to the pool of IP addresses.

10. The apparatus of claim 9 , wherein the IP address is reserved for use solely by the client device from a time when the client device is provided access to the VPN until a time when the client device is disconnected from the VPN.

11. The apparatus of claim 9 , wherein the pool of IP addresses corresponds to an account tier of a user of the client device.

12. The apparatus of claim 9 , wherein the processor further executes the instructions to:

authenticate the client device by verifying that a user account, associated with a user, used to login to a VPN service is a valid account.

13. The apparatus of claim 12 , wherein authenticating the client device is based on a JavaScript token received from the client device.

14. The apparatus of claim 12 , wherein authenticating the client device is based on a JavaScript Object Notation (JSON) Web Token (JWT) received from the client device.

15. A non-transitory computer readable medium storing instructions that, when executed by a computer, cause the computer to perform operations comprising:

selecting an Internet Protocol (IP) address for access to a virtual private network (VPN) by a client device from a pool of IP addresses;

providing access to the VPN for the client device via the IP address;

receiving one or more handshake notifications from the client device, wherein receiving a handshake notification of the one or more handshake notifications comprises:

receiving a request, from the client device after the client device was granted access to the VPN, to download or upload data via the VPN,

storing a timestamp associated with the request to download or upload the data,

transmitting an echo request packet to the client device, and

receiving an echo reply in response to the echo request packet;

calculating a time difference between a current time and a stored timestamp of a latest-in-time handshake notification from the client device;

in response to determining that a threshold time period has passed since the latest-in-time handshake notification of the one or more handshake notifications based on the computed time difference being at least the threshold time period, disconnecting the client device from the VPN; and

add the IP address to the pool of IP addresses.

16. The computer readable medium of claim 15 , wherein the IP address is reserved for use solely by the client device from a time when the client device is provided access to the VPN until a time when the client device is disconnected from the VPN.

17. The computer readable medium of claim 15 , wherein the pool of IP addresses corresponds to an account tier of a user of the client device.

18. The computer readable medium of claim 15 , the operations further comprising:

authenticating the client device by verifying that a user account, associated with a user, used to login to a VPN service is a valid account.

19. The computer readable medium of claim 18 , wherein authenticating the client device is based on a JavaScript token received from the client device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: OVERSEC, UAB
To: UAB 360 IT
Reel/Frame 070202/0565 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2022
From: ILCEVIC, DARJUS; UZKURAS, GVIDAS
To: OVERSEC, UAB
Reel/Frame 059175/0229 →
Cited By (1)
US 12,200,066