IP Library Granted Patent US 11,863,421
Granted Patent B2
US 11,863,421 · App. 17/712,743 · Granted Jan 2, 2024

System and method for optimal multiserver VPN routing

Inventors: Karolis Kaciulis (Kaisiadorys, LT); Donatas Budvytis (Vilnius, LT)
Assignee: Netflow, UAB
H04L45/02H04L45/34H04L63/0272H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,421
App. No.
17/712,743
Granted
Jan 2, 2024
Kind
B2
Abstract

A method and system for a VPN setup in which one of the peers' outgoing traffic is dynamically rerouted to exit VPN servers based on infrastructure or user requirements without losing the initial connection state or leaking unencrypted network traffic is described. One exemplary embodiment describes a method for a client to change their routing to multiple server locations. Another exemplary embodiment describes a method for the entry VPN servers to reroute traffic based on strategic traffic analysis.

Claims (47)

1. A method for routing a VPN connection, comprising:

maintaining, between an entry VPN server and a device, a single VPN connection;

receiving, from the device, a first traffic and a second traffic;

forwarding the first traffic from the entry VPN server to a first exit VPN server and the second traffic from the entry VPN server to a second exit VPN server;

aggregating data activity packets from the first traffic into first traffic information; and

assigning a configuration strategy to the device based on the first traffic information for routing the first traffic information through the second exit VPN server.

2. The method of claim 1 , wherein the second traffic originates from the device after the first traffic.

3. The method of claim 1 , wherein the configuration strategy is generated based on at least one of used protocols, target IP addresses, or target ports.

4. The method of claim 1 , wherein the first traffic is directed to a first target, and the second traffic is directed to the first target or to a second target that is different from the first target.

5. The method of claim 4 , comprising:

receiving, from the device, instructions to route at least one of the first traffic or the second traffic through a third exit VPN server;

receiving, from the device, a third traffic that is directed to the first target or to the second target; and

forwarding the third traffic through the third exit VPN server.

6. The method of claim 5 , wherein at least one of the first traffic, the second traffic, or the third traffic includes at least one of TCP datagrams or UDP datagrams.

7. The method of claim 5 , wherein the instructions include a reference to a geographic location of the third exit VPN server.

8. The method of claim 5 , wherein data transfer between the entry VPN server and the first exit VPN server, the second exit VPN server, or the third exit VPN server is conducted over an encrypted connection.

9. The method of claim 1 , comprising:

receiving an updated configuration strategy from a centralized data channel for a service provider infrastructure.

10. The method of claim 1 , wherein the second traffic is associated with a different domain than a domain of the first traffic.

11. The method of claim 1 , wherein the data activity packets of the first traffic are aggregated while the first traffic is routed.

12. A computing apparatus for routing a VPN connection, the apparatus comprising:

one or more processors; and

a memory coupled to the one or more processors, the memory storing computer executable instructions that, when executed by the one or more processors, operate the computing apparatus to:

maintain, between an entry VPN server and a device, a single VPN connection;

receive, from the device, a first traffic and a second traffic;

forward the first traffic from the entry VPN server to a first exit VPN server and the second traffic from the entry VPN server to a second exit VPN server;

aggregate data activity packets from the first traffic into first traffic information; and

assign a configuration strategy to the device based on the first traffic information for routing the first traffic information through the second exit VPN server.

13. The computing apparatus of claim 12 , wherein the configuration strategy is generated based on at least one of used protocols, target IP addresses, or target ports.

14. The computing apparatus of claim 12 , wherein the first traffic is directed to a first target, and the second traffic is directed to the first target or to a second target that is different from the first target.

15. The computing apparatus of claim 14 , wherein the computer executable instructions operate the computing apparatus to:

receive, from the device, instructions to route at least one of the first traffic or the second traffic through a third exit VPN server;

receive, from the device, a third traffic that is directed to the first target or to the second target; and

forward the third traffic through the third exit VPN server.

16. The computing apparatus of claim 15 , wherein data transfer between the entry VPN server and the first exit VPN server, the second exit VPN server, or the third exit VPN server is conducted over an encrypted connection.

17. A non-transitory computer-readable medium comprising stored computer-executable instructions that are configured to:

maintain, between an entry VPN server and a device, a single VPN connection;

receive, from the device, a first traffic and a second traffic;

forward the first traffic from the entry VPN server to a first exit VPN server and the second traffic from the entry VPN server to a second exit VPN server;

aggregate data activity packets from the first traffic into first traffic information; and

assign a configuration strategy to the device based on the first traffic information for routing the first traffic information through the second exit VPN server.

18. The non-transitory computer-readable medium of claim 17 , wherein the configuration strategy is generated based on at least one of used protocols, target IP addresses, or target ports.

19. The non-transitory computer-readable medium of claim 17 , wherein the first traffic is directed to a first target, and the second traffic is directed to the first target or to a second target that is different from the first target, and wherein the computer-executable instructions are configured to:

receive, from the device, instructions to route at least one of the first traffic or the second traffic through a third exit VPN server;

receive, from the device, a third traffic that is directed to the first target or to the second target; and

forward the third traffic through the third exit VPN server.

20. The non-transitory computer-readable medium of claim 19 , wherein data transfer between the entry VPN server and the first exit VPN server, the second exit VPN server, or the third exit VPN server is conducted over an encrypted connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2022
From: KACIULIS, KAROLIS; BUDVYTIS, DONATAS
To: NETFLOW, UAB
Reel/Frame 060176/0209 →
Continuity (2)
Continuation 17214852 · Mar 27, 2021
Related Publication 20220311695A1 · Sep 29, 2022
Cited By (1)
US 12,413,566