IP Library Granted Patent US 12,341,696
Granted Patent B2
US 12,341,696 · App. 18/191,333 · Granted Jun 24, 2025

Hierarchical-context area network as a virtual private network infrastructure system

Inventors: Karolis Kaciulis (Kaisiadorys, LT); Nikodemas Zaliauskas (Vilnius, LT); Donatas Budvytis (Vilnius, LT)
Assignee: Netflow, UAB
H04L45/76H04L12/4641H04L61/5007
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,696
App. No.
18/191,333
Granted
Jun 24, 2025
Kind
B2
Abstract

A hierarchical-context area network includes a first virtual private network infrastructure context area network for a first virtual private network infrastructure context area in a first virtual private network infrastructure context level that includes a first virtual private network server, a second virtual private network infrastructure context area network for a second virtual private network infrastructure context area in the second virtual private network infrastructure context level that includes a second virtual private network server, wherein the first virtual private network server receives a protocol data unit from a client device and identifies the second virtual private network server, in accordance with a routing control policy defined by the hierarchical-context area network, as a current point of egress for transporting the protocol data unit through the hierarchical-context area network to send to an external device.

Claims (153)

1. A virtual private network infrastructure (VPNI) system operating a hierarchical-context area network as a VPNI network, wherein the hierarchical-context area network includes a hierarchy of context areas, the VPNI system comprising:

a first virtual private network (VPN) server; and

a second VPN server, wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN) for a first VPNI context area in a first VPNI context level of the hierarchy of VPNI context levels;

a second VPNI CAN for a second VPNI context area in a second VPNI context level of the hierarchy of VPNI context levels, wherein the second VPNI context level includes the first VPNI context level; and

a third VPNI CAN for a third VPNI context area in the first VPNI context level, wherein the third VPNI CAN is allocated a shared IP address;

the first VPN server:

receives, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

in response to the first protocol data unit, identifies, in accordance with a routing control policy defined for the hierarchical-context area network, the second VPN server as a current point of egress for transporting the first protocol data unit through the hierarchical-context area network; and

sends the first protocol data unit from the first VPN server to the current point of egress; and

the second VPN server, as the current point of egress, sends, to the external device, via the Internet, the first protocol data unit.

2. The VPNI system of claim 1 , wherein:

the routing control policy is an account type-based routing control policy; and

identifying the current point of egress includes:

identifying an account type associated with the VPN tunnel; and

identifying the current point of egress in accordance with the account type,

wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a limited-tier account type:

identifying a defined geographic range from a geographic location of the end user device; and

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is within the defined geographic range;

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is a high load server;

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is allocated for the limited-tier account type;

in response to a determination that the account type is a basic-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is an optimal available VPN server based on a geographic location of the end user device;

in response to a determination that the account type is a premium-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server implements a service associated with the premium-tier account type; and

in response to a determination that the account type is an enterprise-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is designated as available for the enterprise-tier account type.

3. The VPNI system of claim 1 , wherein:

the routing control policy is an organization structure-based routing control policy; and

identifying the current point of egress includes:

identifying an organizational tier associated with an account associated with the VPN tunnel; and

identifying the current point of egress in accordance with the organizational tier.

4. The VPNI system of claim 1 , wherein:

the routing control policy is an organization service-based routing control policy; and

identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service.

5. The VPNI system of claim 1 , wherein:

the routing control policy is an organization service-based routing control policy; and

identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service.

6. The VPNI system of claim 1 , wherein:

the routing control policy is an organization functionality-based routing control policy; and

identifying the current point of egress includes:

identifying the current point of egress based on functionality available from the current point of egress.

7. The VPNI system of claim 1 , wherein:

the first VPN server is an ingress node with respect to the VPN tunnel between the first VPN server and the end user device; or

the first VPN server receives the first protocol data unit via a fourth VPN server that is the ingress node with respect to the VPN tunnel between the first VPN server and the end user device.

8. The VPNI system of claim 1 , wherein:

the first VPN server receives the first protocol data unit from a component of the VPNI system such that the first protocol data unit is associated with the VPN tunnel.

9. A method comprising:

operating a hierarchical-context area network as a virtual private network infrastructure (VPNI) network of a virtual private network (VPN) system, wherein the hierarchical-context area network includes a hierarchy of VPNI context levels, wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN) for a first VPNI context area in a first VPNI context level of the hierarchy of VPNI context levels;

a second VPNI CAN for a second VPNI context area in a second VPNI context level of the hierarchy of VPNI context levels, wherein the second VPNI context level includes the first VPNI context level; and

a third VPNI CAN for a third VPNI context area in the first VPNI context level, wherein the third VPNI CAN is allocated a shared IP address;

the VPNI network includes:

a first VPN server, wherein the first VPN server is allocated a first private IP address from a range of available IP addresses defined for the first VPNI CAN; and

a second VPN server, wherein the second VPN server is allocated a second private IP address from a range of available IP addresses defined for the third VPNI CAN; and

operating the hierarchical-context area network includes:

receiving, by the first VPN server, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

in response to receiving the first protocol data unit, identifying, by the first VPN server, in accordance with a routing control policy defined for the hierarchical-context area network, a current point of egress for transporting the first protocol data unit through the hierarchical-context area network, wherein identifying the current point of egress includes identifying the second VPN server as the current point of egress;

sending the first protocol data unit from the first VPN server to the current point of egress; and

sending, by the current point of egress, to the external device, via the Internet, the first protocol data unit.

10. The method of claim 9 , wherein:

the routing control policy is an account type-based routing control policy; and

identifying the current point of egress includes:

identifying an account type associated with the VPN tunnel; and

identifying the current point of egress in accordance with the account type.

11. The method of claim 10 , wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a limited-tier account type:

identifying a defined geographic range from a geographic location of the end user device; and

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is within the defined geographic range.

12. The method of claim 10 , wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is a high load server.

13. The method of claim 10 , wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is allocated for the limited-tier account type.

14. The method of claim 10 , wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a basic-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is an optimal available VPN server based on a geographic location of the end user device;

in response to a determination that the account type is a premium-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server implements a service associated with the premium-tier account type; and

in response to a determination that the account type is an enterprise-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is designated as available for the enterprise-tier account type.

15. The method of claim 9 , wherein:

the routing control policy is an organization structure-based routing control policy; and

identifying the current point of egress includes:

identifying an organizational tier associated with an account associated with the VPN tunnel; and

identifying the current point of egress in accordance with the organizational tier.

16. The method of claim 9 , wherein:

the routing control policy is an organization service-based routing control policy; and

identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service.

17. The method of claim 9 , wherein:

the routing control policy is an organization service-based routing control policy; and

identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service.

18. The method of claim 9 , wherein:

the routing control policy is an organization functionality-based routing control policy; and

identifying the current point of egress includes:

identifying the current point of egress based on functionality available from the current point of egress.

19. A non-transitory computer-readable storage medium, comprising processor-executable instructions for operating, in response to the instructions, a hierarchical-context area network as a virtual private network infrastructure (VPNI) network, wherein the hierarchical-context area network includes a hierarchy of context areas, wherein:

the hierarchical-context area network includes:

a first VPNI context area network (CAN) for a first VPNI context area in a first VPNI context level of the hierarchy of VPNI context levels;

a second VPNI CAN for a second VPNI context area in a second VPNI context level of the hierarchy of VPNI context levels, wherein the second VPNI context level includes the first VPNI context level; and

a third VPNI CAN for a third VPNI context area in the first VPNI context level, wherein the third VPNI CAN is allocated a shared IP address;

the VPNI network includes:

a first VPN server, wherein the first VPN server is allocated a first private IP address from a range of available IP addresses defined for the first VPNI CAN; and

a second VPN server, wherein the second VPN server is allocated a second private IP address from a range of available IP addresses defined for the third VPNI CAN; and

operating the hierarchical-context area network includes:

receiving, by the first VPN server, from an end user device, via a VPN tunnel between the first VPN server and the end user device, a first protocol data unit addressed to an external device;

in response to receiving the first protocol data unit, identifying, by the first VPN server, in accordance with a routing control policy defined for the hierarchical-context area network, a current point of egress for transporting the first protocol data unit through the hierarchical-context area network, wherein identifying the current point of egress includes identifying the second VPN server as the current point of egress;

sending the first protocol data unit from the first VPN server to the current point of egress; and

sending, by the current point of egress, to the external device, via the Internet, the first protocol data unit.

20. The non-transitory computer-readable storage medium of claim 19 , wherein:

the routing control policy is an account type-based routing control policy; and

identifying the current point of egress includes:

identifying an account type associated with the VPN tunnel; and

identifying the current point of egress in accordance with the account type, wherein identifying the current point of egress in accordance with the account type includes:

in response to a determination that the account type is a limited-tier account type:

identifying a defined geographic range from a geographic location of the end user device; and

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is within the defined geographic range;

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is a high load server;

in response to a determination that the account type is a limited-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is allocated for the limited-tier account type;

in response to a determination that the account type is a basic-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is an optimal available VPN server based on a geographic location of the end user device;

in response to a determination that the account type is a premium-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server implements a service associated with the premium-tier account type; and

in response to a determination that the account type is an enterprise-tier account type:

identifying the second VPN server as the current point of egress in response to a determination that the second VPN server is designated as available for the enterprise-tier account type.

21. The non-transitory computer-readable storage medium of claim 19 , wherein:

the routing control policy is an organization structure-based routing control policy, wherein identifying the current point of egress includes:

identifying an organizational tier associated with an account associated with the VPN tunnel; and

identifying the current point of egress in accordance with the organizational tier;

the routing control policy is an organization service-based routing control policy, wherein identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service;

the routing control policy is an organization service-based routing control policy, wherein identifying the current point of egress includes:

identifying a type of service corresponding to the first protocol data unit; and

identifying the current point of egress in accordance with the type of service; or

the routing control policy is an organization functionality-based routing control policy, wherein identifying the current point of egress includes:

identifying the current point of egress based on functionality available from the current point of egress.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2023
From: KACIULIS, KAROLIS; ZALIAUSKAS, NIKODEMAS; BUDVYTIS, DONATAS
To: NETFLOW, UAB
Reel/Frame 063157/0062 →
Continuity (1)
Related Publication 20240333646A1 · Oct 3, 2024
References Cited (44)
US 8442030B2 · Dennison · 2013 [cited by applicant]
US 8750288B2 · Nakil et al. · 2014 [cited by applicant]
US 9094285B2 · Gorkemli et al. · 2015 [cited by applicant]
US 9319300B2 · Huynh Van et al. · 2016 [cited by applicant]
US 9722935B2 · Bouanen et al. · 2017 [cited by applicant]
US 9900250B2 · Dong et al. · 2018 [cited by applicant]
US 9912614B2 · Koganti · 2018 [cited by applicant]
US 10097372B2 · Bhattacharya et al. · 2018 [cited by applicant]
US 10148506B1 · Anburose et al. · 2018 [cited by applicant]
US 10200274B1 · Suryanarayana et al. · 2019 [cited by applicant]
US 10326532B2 · Ashrafi · 2019 [cited by applicant]
US 10361972B2 · Biruduraju · 2019 [cited by applicant]
US 10705808B2 · Chiosi et al. · 2020 [cited by applicant]
US 10749796B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10757576B2 · Ashrafi · 2020 [cited by applicant]
US 10819629B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10972386B2 · Mackie et al. · 2021 [cited by applicant]
US 10999197B2 · Hooda et al. · 2021 [cited by applicant]
US 11134010B2 · Mehmedagic et al. · 2021 [cited by applicant]
US 20040057439A1 · Ould-Brahim · 2004 [cited by examiner]
US 20050165834A1 · Nadeau · 2005 [cited by examiner]
US 20100165832A1 · Kini · 2010 [cited by examiner]
US 20170317919A1 · Fernando et al. · 2017 [cited by applicant]
US 20170366395A1 · Goldfarb · 2017 [cited by examiner]
US 20180302321A1 · Manthiramoorthy et al. · 2018 [cited by applicant]
US 20190280964A1 · Michael et al. · 2019 [cited by applicant]
US 20190319847A1 · Nahar · 2019 [cited by examiner]
US 20200099659A1 · Cometto et al. · 2020 [cited by applicant]
US 20200403970A1 · Chastain et al. · 2020 [cited by applicant]
US 20210111998A1 · Saavedra · 2021 [cited by applicant]
US 20210399920A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20220103523A1 · Starr et al. · 2022 [cited by applicant]
US 20240251017A1 · Byard et al. · 2024 [cited by applicant]
“Jason A. Donenfeld, WireGuard: Next Generation Kernel Network Tunnel, 2020, www.wiregurad.com, pp. 1-20” (Year: 2020). [cited by examiner]
“Micheal Kerrisk, veth(4)—Linux manual page, Mar. 22, 2021, The Linux Programming Interface, pp. 1-2” (Year: 2021). [cited by examiner]
“Michael Kerrisk, ip-netns(8)—Linux manual page, Jan. 16, 2013, The Linux Programming Interface, pp. 1-6” (Year: 2013). [cited by examiner]
“Hangbin Liu, Introduction to Linux Interfaces for virtual networking, 2018, Red Hat Developer, pp. 1-25” (Year: 2018). [cited by examiner]
“Open Shortest Path First, 1989, Wikipedia, pp. 1-23” (Year: 2023). [cited by examiner]
“Border Gateway Protocol, 2023, Wikipedia, pp. 1-25” (Year: 2023). [cited by examiner]
“Transport Layer Security, 2023, Wikipedia, pp. 1-41” (Year: 2023). [cited by examiner]
Virtual eXtensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks, M. Mahalingam Storvisor et al., <https://www.rfc-editor.org/rfc/rfc7348.html>, Aug. 2014, 22 … [cited by applicant]
Wikipedia, Software-defined networking, https://en.wikipedia.org/wiki/Software-defined_networking, Apr. 10, 2023, 15 pages. [cited by applicant]
RFC 4271: A Border Gateway Protocol 4 (BGP-4), Y. Rekhter, et al, https://www.rfc-editor.org/rfc/rfc4271, Jan. 2006, 104 pages. [cited by applicant]
Wikipedia, OSI model, <https://en.wikipedia.org/wiki/OSI_model>, Apr. 10, 2023, 8 pages. [cited by applicant]
Cited By (3)
US 12,549,522 US 12,647,397 US 12,665,873