IP Library Granted Patent US 12,489,679
Granted Patent B2
US 12,489,679 · App. 18/668,084 · Granted Dec 2, 2025

System and method for controlling network device(s) at a primary network device

Inventors: Cheuk Pang Kong (Kowloon, HK); Alex Wing Hong Chan (Kowloon, HK); Yu Yeung (Kowloon, HK)
Assignee: Pismo Labs Technology Limited
H04L41/0894H04L12/4633H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,679
App. No.
18/668,084
Granted
Dec 2, 2025
Kind
B2
Abstract

This present invention discloses methods and systems for transmitting data packets over a wide area network (WAN) through secondary network devices connected to a primary network device. The primary network device first takes control of the secondary network devices' network settings. Then, it creates two separate connections: one for managing the secondary network devices (using management interfaces) and another for transmitting data (using transmission interfaces). The data packets transmit through the WAN connection on the secondary network devices using a special tunnel created within the data connection, following rules set by a policy.

Claims (49)

1 . A method for transmitting data packets through a WAN interface of at least one secondary network device at a primary network device, comprising:

a. enabling a function of managing and controlling the network configuration of the at least one secondary network device;

b. establishing a first connection and a second connection with the at least one secondary network device;

c. establishing a management tunnel through the first connection;

d. establishing at least one data tunnel through the second connection; and

e. transmitting data packets via the WAN interface of the second connection through a first data tunnel according to a policy;

wherein:

the first connection is a connection established between a first management interface and a second management interface;

the second connection is a connection established between a first transmission interface and a second transmission interface;

the first data tunnel is a data tunnel of the at least one data tunnel established between a first data tunnel interface and a second data tunnel interface; and

the first data tunnel is corresponding to the WAN interface.

2 . The method of claim 1 , further comprising:

a. receiving a first request from the at least one secondary network device;

b. sending a first reply for replying to the first request.

3 . The method of claim 2 , wherein the primary network device may require authentication from a third device before replying to the first request with the first reply.

4 . The method of claim 1 , wherein the at least one secondary network device allows only modifications of the network configuration of the at least one secondary network device made by the primary network device.

5 . The method of claim 1 , wherein the policy may be based on one or more of the following: type of network interface, service provider, bandwidth, throughput, latency, cost, location, type of data packet, application, user, user group, user preference, source address, and destination address.

6 . The method of claim 1 , wherein the first management interface, the second management interface, the first transmission interface, and the second transmission interface are virtual network interfaces.

7 . The method of claim 1 , further comprising:

assigning each of the first management interface, the second management interface, the first transmission interface, and the second transmission interface with a reserved IP address individually.

8 . The method of claim 1 , wherein the first management interface and the first transmission interface are in a first subnet.

9 . The method of claim 8 , wherein the first data tunnel interface is in a second subnet.

10 . The method of claim 9 , wherein the first subnet and the second subnet are different subnets.

11 . A primary network device, comprising:

at least one processing unit;

a plurality of network interfaces; and

at least one non-transitory computer-readable storage medium storing program instruction executable by at least one processing unit for:

a. enabling a function of managing and controlling the network configuration of at least one secondary network device;

b. establishing a first connection and a second connection with the at least one secondary network device;

c. establishing a management tunnel through the first connection;

d. establishing at least one data tunnel through the second connection; and

e. transmitting data packets via a WAN interface of the second connection through a first data tunnel according to a policy;

wherein:

the first connection is a connection established between a first management interface and a second management interface;

the second connection is a connection established between a first transmission interface and a second transmission interface;

the first data tunnel is a data tunnel of the at least one data tunnel established between a first data tunnel interface and a second data tunnel interface; and

the first data tunnel is corresponding to the WAN interface.

12 . The primary network device of claim 11 , wherein the at least one non-transitory computer-readable storage medium further storing program instruction executable by at least one processing unit for:

a. receiving a first request from the at least one secondary network device;

b. sending a first reply for replying to the first request.

13 . The primary network device of claim 12 , wherein the primary network device may require authentication from a third device before replying to the first request with the first reply.

14 . The primary network device of claim 11 , wherein the at least one secondary network device is locked and allows only modifications made by the primary network device.

15 . The primary network device of claim 11 , wherein the policy may be based on one or more of the following: type of network interface, service provider, bandwidth, throughput, latency, cost, location, type of data packet, application, user, user group, user preference, source address, and destination address.

16 . The primary network device of claim 11 , wherein the first management interface, the second management interface, the first transmission interface, and the second transmission interface is a virtual network interface.

17 . The primary network device of claim 11 , wherein the at least one non-transitory computer-readable storage medium further storing program instruction executable by at least one processing unit for:

assigning a reserved IP address to each of the first management interface, the second management interface, the first transmission interface and the second transmission interface individually.

18 . The primary network device of claim 11 , wherein the first management interface and the first transmission interface are in a first subnet.

19 . The primary network device of claim 18 , wherein the first data tunnel interface is in a second subnet.

20 . The primary network device of claim 19 , wherein the first subnet and the second subnet are different subnets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2024
From: KONG, CHEUK PANG; CHAN, ALEX WING HONG; YEUNG, YU
To: PISMO LABS TECHNOLOGY LIMITED
Reel/Frame 067452/0957 →
Continuity (1)
Related Publication 20250358187A1 · Nov 20, 2025
References Cited (4)
US 6199165B1 · Grunner · 2001 [cited by examiner]
US 7218615B2 · Schwartze · 2007 [cited by examiner]
US 11206203B2 · Kane · 2021 [cited by examiner]
US 20090287800A1 · Chi · 2009 [cited by examiner]