IP Library › Granted Patent US 12,218,822
Granted Patent B2
US 12,218,822 · App. 18/191,340 · Granted Feb 4, 2025

Hierarchical-context area network as a virtual private network infrastructure system

Inventors: Karolis Kaciulis (Kaisiadorys, LT); Nikodemas Zaliauskas (Vilnius, LT); Donatas Budvytis (Vilnius, LT)
Assignee: Netflow, UAB
H04L45/04H04L12/4641H04L45/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,822
App. No.
18/191,340
Granted
Feb 4, 2025
Kind
B2
Abstract

Operating a hierarchical-context area network includes receiving a first protocol data unit from an end user device via a virtual private network tunnel by a first virtual private network server, obtaining the first protocol data unit from the first virtual private network server, by a second virtual private network server as a current point of egress for transporting the first protocol data unit through the hierarchical-context area network, identifying, by the second virtual private network server, available data transport pathways for transporting the first protocol data unit through the hierarchical-context area network, pseudo-randomly identifying, by the second virtual private network server, an available data transport pathway from the available data transport pathways as a current data transport pathway, and sending, by the second VPN server, to the external device, via the data transport pathway, the first protocol data unit.

Claims (84)

1. A method comprising:

operating a hierarchical-context area network as a virtual private network infrastructure (VPNI) network, wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN), wherein the first VPNI CAN is a level-one context area network;

a second VPNI CAN, wherein the second VPNI CAN is a level-two context area network; and

a third VPNI CAN, wherein the third VPNI CAN is a level-one context area network, wherein the third VPNI CAN is allocated a shared IP address; and

operating the hierarchical-context area network includes:

receiving, by a first VPN server in the first VPNI CAN, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

identifying, by the first VPN server, a second VPN server in the third VPNI CAN as a current point of egress for transmitting the first protocol data unit to the external device, wherein the second VPN server is associated with the shared IP address;

obtaining, by the second VPN server as the current point of egress, the first protocol data unit, from the first VPN server, via the second VPNI CAN;

identifying, by the second VPN server, available data transport pathways for transporting the first protocol data unit through the hierarchical-context area network, wherein the available data transport pathways include:

a first available data transport pathway that includes the second VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network; and

a second available data transport pathway that includes the third VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network;

pseudo-randomly identifying, by the second VPN server, an available data transport pathway from the available data transport pathways as a current data transport pathway; and

in response to a determination that the current data transport pathway is the first available data transport pathway, sending, by the second VPN server, to the external device, via the Internet, the first protocol data unit; or

in response to a determination that the current available data transport pathway is the second available data transport pathway:

sending, by the second VPN server, to the third VPN server, via the third VPNI CAN, the first protocol data unit; and

sending, by the third VPN server, to the external device, via the Internet, the first protocol data unit.

2. The method of claim 1 , wherein operating the hierarchical-context area network includes:

enabling automatic egress randomization for the VPN tunnel in accordance with an automatic egress randomization policy associated with the end user account.

3. The method of claim 1 , wherein identifying the available data transport pathways includes using Equal-cost multi-path routing.

4. The method of claim 1 , wherein the available data transport pathways have equal routing priority.

5. The method of claim 1 , wherein receiving the first protocol data unit includes determining that the first protocol data unit is associated with a first protocol data unit flow based on a source address from the first protocol data unit and a destination address from the first protocol data unit.

6. The method of claim 5 , wherein identifying the available data transport pathways includes:

identifying, by the second VPN server, an automatic egress randomization pool that includes available VPN servers in the third VPNI CAN, wherein the available VPN servers include the second VPN server and a third VPN server, wherein identifying the automatic egress randomization pool includes identifying the automatic egress randomization pool for the first protocol data unit flow.

7. The method of claim 1 , wherein pseudo-randomly identifying the available data transport pathway from the available data transport pathways as the current data transport pathway includes using Equal-cost multi-path routing.

8. The method of claim 1 , wherein:

the available data transport pathways include a third available data transport pathway that includes the second VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network and includes an external routing device as a next-hop between the hierarchical-context area network and the external device; and

operating the hierarchical-context area network includes:

in response to a determination that the current data transport pathway is third available data transport pathway, sending, by the second VPN server, to the external routing device, via the Internet, the first protocol data unit.

9. The method of claim 1 , wherein sending, by the second VPN server, to the external device, via the Internet, the first protocol data unit includes:

using a public IP address of the second VPN server as the source address in the first protocol data unit.

10. A virtual private network infrastructure (VPNI) system operating a hierarchical-context area network as a VPNI network, the VPNI system comprising:

a first virtual private network (VPN) server;

a second VPN server, wherein the second VPN server is associated with a first IP address; and

a third VPN server, wherein the third VPN server is associated with a second IP address, and wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN), wherein the first VPNI CAN is a level-one context area network;

a second VPNI CAN, wherein the second VPNI CAN is a level-two context area network; and

a third VPNI CAN, wherein the third VPNI CAN is a level-one context area network, wherein the third VPNI CAN is allocated a shared IP address;

the first VPN server:

obtains, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

identifies the second VPN server in the third VPNI CAN as a current point of egress for transmitting the first protocol data unit to the external device, wherein the second VPN server is associated with the shared IP address;

the second VPN server as the current point of egress:

obtains the first protocol data unit, from the first VPN server, via the second VPNI CAN;

identifies available data transport pathways for transporting the first protocol data unit through the hierarchical-context area network, wherein the available data transport pathways include:

a first available data transport pathway that includes the second VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network; and

a second available data transport pathway that includes the third VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network;

pseudo-randomly identifies an available data transport pathway from the available data transport pathways as a current data transport pathway; and

in response to a determination that the current data transport pathway is the first available data transport pathway, sends, to the external device, via the Internet, the first protocol data unit; or

in response to a determination that the current available data transport pathway is the second available data transport pathway:

sends, to the third VPN server, via the third VPNI CAN, the first protocol data unit, such that the third VPN server sends, to the external device, via the Internet, the first protocol data unit.

11. The VPNI system of claim 10 , wherein, to identify the available data transport pathways, the second VPN server uses Equal-cost multi-path routing.

12. The VPNI system of claim 10 , wherein the available data transport pathways have equal routing priority.

13. The VPNI system of claim 10 , wherein the first VPN server determines that the first protocol data unit is associated with a first protocol data unit flow based on a source address from the first protocol data unit and a destination address from the first protocol data unit.

14. The VPNI system of claim 13 , wherein:

to identify the available data transport pathways, the second VPN server identifies an automatic egress randomization pool that includes available VPN servers in the third VPNI CAN, wherein the available VPN servers include the second VPN server and a third VPN server; and

to identify the automatic egress randomization pool, the second VPN server identifies the automatic egress randomization pool for the first protocol data unit flow.

15. The VPNI system of claim 10 , wherein, to pseudo-randomly identify the available data transport pathway from the available data transport pathways as the current data transport pathway, the second VPN server uses Equal-cost multi-path routing.

16. The VPNI system of claim 10 , wherein:

the available data transport pathways include a third available data transport pathway that includes the second VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network and includes an external routing device as a next-hop between the hierarchical-context area network and the external device; and

the second VPN server:

in response to a determination that the current data transport pathway is third available data transport pathway, sends, to the external routing device, via the Internet, the first protocol data unit.

17. The VPNI system of claim 16 , wherein to send, to the external device, via the Internet, the first protocol data unit, the second VPN server:

uses the first IP address as the source address in the first protocol data unit, wherein the first IP address is a public IP address of the second VPN server.

18. A non-transitory computer-readable storage medium, comprising processor-executable instructions for operating, in response to the instructions, a hierarchical-context area network as a virtual private network infrastructure (VPNI) network, wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN), wherein the first VPNI CAN is a level-one context area network;

a second VPNI CAN, wherein the first VPNI CAN is a level-two context area network; and

a third VPNI CAN, wherein the third VPNI CAN is a level-one context area network, wherein the third VPNI CAN is allocated a shared IP address; and

operating the hierarchical-context area network includes:

receiving, by a first VPN server in the first VPNI CAN, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

identifying, by the first VPN server, a second VPN server in the third VPNI CAN as a current point of egress for transmitting the first protocol data unit to the external device, wherein the second VPN server is associated with the shared IP address;

obtaining, by the second VPN server as the current point of egress, the first protocol data unit, from the first VPN server, via the second VPNI CAN;

identifying, by the second VPN server, available data transport pathways for transporting the first protocol data unit through the hierarchical-context area network, wherein the available data transport pathways include:

a first available data transport pathway that includes the second VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network; and

a second available data transport pathway that includes the third VPN server as the current point of egress for transporting the first protocol data unit through the hierarchical-context area network;

pseudo-randomly identifying, by the second VPN server, an available data transport pathway from the available data transport pathways as a current data transport pathway; and

in response to a determination that the current data transport pathway is the first available data transport pathway, sending, by the second VPN server, to the external device, via the Internet, the first protocol data unit; or

in response to a determination that the current available data transport pathway is the second available data transport pathway:

sending, by the second VPN server, to the third VPN server, via the third VPNI CAN, the first protocol data unit; and

sending, by the third VPN server, to the external device, via the Internet, the first protocol data unit.

19. The non-transitory computer-readable storage medium of claim 18 , wherein identifying the available data transport pathways includes using Equal-cost multi-path routing.

20. The non-transitory computer-readable storage medium of claim 18 , wherein pseudo-randomly identifying the available data transport pathway from the available data transport pathways as the current data transport pathway includes using Equal-cost multi-path routing.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2023
From: KACIULIS, KAROLIS; ZALIAUSKAS, NIKODEMAS; BUDVYTIS, DONATAS
To: NETFLOW, UAB
Reel/Frame 063157/0182 →
Continuity (1)
Related Publication 20240333628A1 · Oct 3, 2024
References Cited (39)
US 8442030B2 · Dennison · 2013 [cited by applicant]
US 8750288B2 · Nakil et al. · 2014 [cited by applicant]
US 9094285B2 · Gorkemli et al. · 2015 [cited by applicant]
US 9319300B2 · Huynh Van et al. · 2016 [cited by applicant]
US 9722935B2 · Bouanen et al. · 2017 [cited by applicant]
US 9900250B2 · Dong et al. · 2018 [cited by applicant]
US 9912614B2 · Koganti · 2018 [cited by applicant]
US 10097372B2 · Bhattacharya et al. · 2018 [cited by applicant]
US 10148506B1 · Anburose et al. · 2018 [cited by applicant]
US 10200274B1 · Suryanarayana et al. · 2019 [cited by applicant]
US 10326532B2 · Ashrafi · 2019 [cited by applicant]
US 10361972B2 · Biruduraju · 2019 [cited by applicant]
US 10705808B2 · Chiosi et al. · 2020 [cited by applicant]
US 10749796B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10757576B2 · Ashrafi · 2020 [cited by applicant]
US 10819629B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10972386B2 · Mackie et al. · 2021 [cited by applicant]
US 10999197B2 · Hooda et al. · 2021 [cited by applicant]
US 11134010B2 · Mehmedagic et al. · 2021 [cited by applicant]
US 20170317919A1 · Fernando et al. · 2017 [cited by applicant]
US 20180302321A1 · Manthiramoorthy et al. · 2018 [cited by applicant]
US 20190280964A1 · Michael et al. · 2019 [cited by applicant]
US 20200099659A1 · Cometto et al. · 2020 [cited by applicant]
US 20200403970A1 · Chastain et al. · 2020 [cited by applicant]
US 20210111998A1 · Saavedra · 2021 [cited by applicant]
US 20210399920A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20220103523A1 · Starr · 2022 [cited by examiner]
US 20240251017A1 · Byard · 2024 [cited by examiner]
Virtual eXetensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks, M. Mahalingam Storvisor et al., <https://www.rfc-editor.org/rfc/rfc7348.html>, Aug. 2014, 22… [cited by applicant]
Wikipedia, Software-defined networking, https://en.wikipedia.org/wiki/Software-defined_networking, Apr. 10, 2023, 15 pages. [cited by applicant]
RFC 4271: A Border Gateway Protocol 4 (BGP-4), Y. Rekhter, et al, https://www.rfc-editor.org/rfc/rfc4271, Jan. 2006, 104 pages. [cited by applicant]
WireGuard: Next Generation Kernel Network Tunnel, Jason A. Donenfeld ,https://www.wireguard.com/papers/wireguard.pdf, Jun. 1, 2020, 20 pages. [cited by applicant]
Wikipedia, OSI model, <https://en.wikipedia.org/wiki/OSI_model>, Apr. 10, 2023, 8 pages. [cited by applicant]
Veth(4)—Linux manual page, Linux/UNIX system programming training, Michael Kerrisk, https://man7.org/linux/man-pages/man4/veth.4.html, Dec. 18, 2022, 2 pages. [cited by applicant]
Ip-netns(8)—Linux manual page, Linux/UNIX system programming training, Michael Kerrisk, https://man7.org/linux/man-pages/man8/ip-netns.8.html, Dec. 18, 2022, 6 pages. [cited by applicant]
Introduction to Linux interfaces for virtual networking, Hangbin Liu, https://developers.redhat com/blog/2018/10/22/introduction-to-linux-interfaces-for-virtual-networking, Oct. 22, 2018, 25 pages. [cited by applicant]
Wikipedia, Open Shortest Path First, https://en.wikipedia.org/wiki/Open_Shortest_Path_First, Apr. 10, 2023, 23 pages. [cited by applicant]
Wikipedia, Border Gateway Protocol, https://en.wikipedia.org/wiki/Border_Gateway_Protocol, Apr. 10, 2023, 25 pages. [cited by applicant]
Wikipedia, Transport Layer Security, https://en.wikipedia.org/wiki/Transport_Layer_Security, Apr. 10, 2023, 41 pages. [cited by applicant]
Cited By (2)
US 12,549,522 US 12,647,397