IP Library › Granted Patent US 12,309,122
Granted Patent B2
US 12,309,122 · App. 17/453,090 · Granted May 20, 2025

Dynamic virtual private network protocol configuration

Inventors: Hemant Kumar Sivaswamy (Pune, IN); Venkata Vara Prasad Karri (Visakhapatnam, IN); Sarbajit K. Rakshit (Kolkata, IN); Seema Nagar (Bangalore, IN)
Assignee: International Business Machines Corporation
H04L63/0272G06N20/00H04L41/0813H04L41/0894H04L41/0895H04L63/029H04L63/083H04L63/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,122
App. No.
17/453,090
Granted
May 20, 2025
Kind
B2
Abstract

Provided is a computer-implemented method, system, and computer program product for dynamically configuring a virtual private network (VPN) protocol of a VPN tunnel. A processor may analyze data activity associated with a first device, where the first device is connected to a second device using a VPN tunnel. The processor may compare the analyzed data activity to a set of policies for determining a VPN protocol to apply to the VPN tunnel. The processor may identify, based on the comparing, a first VPN protocol from a plurality of VPN protocols. The processor may apply the first VPN protocol to the VPN tunnel.

Claims (76)

1. A computer-implemented method for dynamically configuring a virtual private network (VPN) protocol of a VPN tunnel, the method comprising:

analyzing data activity associated with a first device, wherein the first device is connected to a second device using a VPN tunnel;

comparing the analyzed data activity to a set of policies for determining a VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a first VPN protocol from a plurality of VPN protocols;

applying the first VPN protocol to the VPN tunnel; and

continuously monitoring the data activity for a change indicative of a requirement to apply a different VPN protocol to the VPN tunnel.

2. The computer-implemented method of claim 1 , further comprising:

identifying a change in the data activity to a second data activity associated with the first device;

analyzing the second data activity;

comparing the analyzed second data activity to the set of policies for determining the VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a second VPN protocol from the plurality of VPN protocols; and

applying the second VPN protocol to the VPN tunnel.

3. The computer-implemented method of claim 1 , wherein each policy of set of policies correlates to applying a specific VPN protocol based on a security level required for a given data activity.

4. The computer-implemented method of claim 1 , wherein analyzing the data activity comprises analyzing one or more data activity chosen from the group consisting of:

a type of data being transmitted using the VPN tunnel;

a type of activity being performed with the data;

a login credential associated with the first device;

data traffic and network bandwidth associated with the VPN tunnel; and

a location of data being transmitted using the VPN tunnel.

5. The computer-implemented method of claim 1 , wherein the set of policies are based upon applying historical VPN protocols to historical data activities related to the first device.

6. The computer-implemented method of claim 1 , wherein analyzing the data activity associated with the first device further comprises determining a posture of the first device.

7. The computer-implemented method of claim 6 , wherein the posture comprises one or more security attributes and a location of the first device.

8. The computer-implemented method of claim 7 , further comprising:

detecting a change in the posture of the first device; and

re-analyzing, based on detecting the change in posture, the configuration of the VPN protocol.

9. The computer-implemented method of claim 1 , wherein the plurality of VPN protocols comprises two or more VPN protocols from the group consisting of:

Internet Protocol Security (IPSec);

Layer 2 Tunneling Protocol (L2TP);

Point-to-Point Tunneling Protocol (PPTP);

Secure Sockets Layer (SSL);

Transport Layer Security (TLS);

Open VPN; and

Secure Shell (SSH).

10. The computer-implemented method of claim 1 , wherein analyzing the data activity associated with the first device is performed using machine learning.

11. A system comprising:

a processor; and

a computer-readable storage medium communicatively coupled to the processor and storing program instructions which, when executed by the processor, cause the processor to perform a method comprising:

analyzing data activity associated with a first device, wherein the first device is connected to a second device using a VPN tunnel;

comparing the analyzed data activity to a set of policies for determining a VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a first VPN protocol from a plurality of VPN protocols;

applying the first VPN protocol to the VPN tunnel; and

continuously monitoring the data activity for a change indicative of a requirement to apply a different VPN protocol to the VPN tunnel.

12. The system of claim 11 , wherein the method performed by the processor further comprises:

identifying a change in the data activity to a second data activity associated with the first device;

analyzing the second data activity;

comparing the analyzed second data activity to the set of policies for determining the VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a second VPN protocol from the plurality of VPN protocols; and

applying the second VPN protocol to the VPN tunnel.

13. The system of claim 11 , wherein each policy of set of policies correlates to applying a specific VPN protocol based on a security level required for a given data activity.

14. The system of claim 11 , wherein analyzing the data activity comprises analyzing one or more data activity chosen from the group consisting of:

a type of data being transmitted using the VPN tunnel;

a type of activity being performed with the data;

a login credential associated with the first device;

data traffic and network bandwidth associated with the VPN tunnel; and

a location of data being transmitted using the VPN tunnel.

15. The system of claim 11 , wherein the set of policies are based upon applying historical VPN protocols to historical data activities related to the first device.

16. A computer program product comprising a computer-readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform a method comprising:

analyzing data activity associated with a first device, wherein the first device is connected to a second device using a VPN tunnel;

comparing the analyzed data activity to a set of policies for determining a VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a first VPN protocol from a plurality of VPN protocols;

applying the first VPN protocol to the VPN tunnel; and

continuously monitoring the data activity for a change indicative of a requirement to apply a different VPN protocol to the VPN tunnel.

17. The computer program product of claim 16 , wherein the method performed by the processor further comprises:

identifying a change in the data activity to a second data activity associated with the first device;

analyzing the second data activity;

comparing the analyzed second data activity to the set of policies for determining the VPN protocol to apply to the VPN tunnel;

identifying, based on the comparing, a second VPN protocol from the plurality of VPN protocols; and

applying the second VPN protocol to the VPN tunnel.

18. The computer program product of claim 16 , wherein each policy of set of policies correlates to applying a specific VPN protocol based on a security level required for a given data activity.

19. The computer program product of claim 16 , wherein analyzing the data activity comprises analyzing one or more data activity chosen from the group consisting of:

a type of data being transmitted using the VPN tunnel;

a type of activity being performed with the data;

a login credential associated with the first device;

data traffic and network bandwidth associated with the VPN tunnel; and

a location of data being transmitted using the VPN tunnel.

20. The computer program product of claim 16 , wherein the set of policies are based upon applying historical VPN protocols to historical data activities related to the first device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: SIVASWAMY, HEMANT KUMAR; RAKSHIT, SARBAJIT K.; NAGAR, SEEMA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057984/0301 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: KARRI, VENKATA VARA PRASAD
To: IBM INDIA PRIVATE LIMITED
Reel/Frame 057984/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: IBM INDIA PRIVATE LIMITED
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057984/0467 →
Continuity (1)
Related Publication 20230139329A1 · May 4, 2023
References Cited (19)
US 6473863B1 · Genty et al. · 2002 [cited by applicant]
US 8516569B2 · Babula et al. · 2013 [cited by applicant]
US 10187321B2 · Maino et al. · 2019 [cited by applicant]
US 10505904B2 · Hoy et al. · 2019 [cited by applicant]
US 11757841B2 · Žaliauskas · 2023 [cited by examiner]
US 20070074283A1 · Croak · 2007 [cited by examiner]
US 20150188949A1 · Mahaffey · 2015 [cited by examiner]
US 20180152977A1 · Baron · 2018 [cited by examiner]
US 20210168138A1 · Paruchuri · 2021 [cited by examiner]
US 20220286911A1 · Howe · 2022 [cited by examiner]
“Dynamic VPN Routing,” https://docs.appian.com/suite/help/20.3/Dynamic_VPN_Routing.html, printed Aug. 27, 2021, 3 pgs. [cited by applicant]
“Dynamic VPNs with Pulse Secure Clients,” https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-dynamic-vpns-with-pulse-secure-clients.html, Jan. 13, 2021, printed Jul. 27, 2021,… [cited by applicant]
“Types of VPN and types of VPN Protocols,” https://www.vpnoneclick.com/types-of-vpn-and-types-of-vpn-protocols/, printed Aug. 27, 2021, 4 pgs. [cited by applicant]
Bahnasse et al., “Study and evaluation of the high availability of a Dynamic Multipoint Virtual Private Network,” https://www.researchgate.net/publication/277882842, Jul. 2015, 6 pgs. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing,” Recommendations of the National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pgs. [cited by applicant]
On Point, “Site-to-Site Hybrid VPN Configuration,” https://www.onpointcorp.com/wp-content/uploads/2020/01/Hybrid-VPN.pdf, accessed Aug. 27, 2021, 9 pgs. [cited by applicant]
Parmenter, T., dynamic multipoint VPN (DMVPN), https://searchnetworking.techtarget.com/definition/dynamic-multipoint-VPN-DMVPN, printed Aug. 27, 2021, 4 pgs. [cited by applicant]
Tizazu et al., “Dynamic routing influence on secure enterprise network based on DMVPN,” https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7993894, ICUFN 2017, pp. 756-759. [cited by applicant]
ul Abideen et al., “VPN Traffic Detection in SSL-Protected Channel,” https://www.researchgate.net/publication/336883770, Security and Communication Networks, Oct. 2019, 26 pgs. [cited by applicant]