IP Library › Granted Patent US 12,547,440
Granted Patent B2
US 12,547,440 · App. 18/205,672 · Granted Feb 10, 2026

Physical routing appliance to connect enterprise networks and cloud computing services, and method of connection

Inventor: Chad Rosenbohm (Cedar Rapids, IA)
G06F9/45558G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,440
App. No.
18/205,672
Granted
Feb 10, 2026
Kind
B2
Abstract

A physical routing appliance facilitates connection of a user installation to a cloud service. At the physical routing appliance, system data received from the user installation may be multiplexed for transmission to a virtual routing appliance at the cloud service as multiplexed data. At the virtual routing appliance, system data received from the cloud service may be multiplexed for transmission to the physical routing appliance as multiplexed data. The physical routing appliance receives the multiplexed data from the virtual routing appliance and formats that data for transmission to the user installation. The virtual routing appliance in turn receives the multiplexed data from the physical routing appliance and formats that data for transmission to the cloud service. A plurality of paths between the physical routing appliance and the virtual routing appliance enable transmission of the multiplexed data as multiplexed data portions without having to retransmit all of the system data.

Claims (49)

1 . A physical routing appliance comprising:

a processor; and

a non-transitory memory storing instructions which, when executed by the processor, perform the following:

responsive to connection of the physical routing appliance to a user installation, configuring the physical routing appliance to communicate with a cloud service;

initiating communication between the physical routing appliance and a cloud service to connect the physical routing appliance to the cloud service, including selecting a type of connection between the physical routing appliance and the cloud service;

responsive to connection of the physical routing appliance to the cloud service, determining whether there is a virtual private cloud for the user installation at the cloud service;

determining whether there is a virtual routing appliance for the user installation at the cloud service; and

responsive to a determination that there is a virtual routing appliance for the user installation at the cloud service, initiating a multiplexed virtual private network (VPN) communication path between the physical routing appliance and the virtual routing appliance, wherein communications between the user installation and the cloud service comprise:

at the physical routing appliance, multiplexing first system data received from the user installation for transmission to the virtual routing appliance as first multiplexed data;

at the virtual routing appliance, multiplexing second system data received from the cloud service for transmission to the physical routing appliance as second multiplexed data;

receiving the second multiplexed data from the virtual routing appliance and demultiplexing the second multiplexed data for transmission to the user installation;

receiving the first multiplexed data from the physical routing appliance and demultiplexing the second multiplexed data for transmission to the cloud service; and

creating a plurality of paths to transmit the first and second multiplexed data between the physical routing appliance and the virtual routing appliance to enable transmission of the first and second multiplexed data as multiplexed data portions without having to retransmit all of the first and second system data.

2 . The appliance of claim 1 , wherein multiplexing the first system data and multiplexing the second system data comprises, at the respective physical routing appliance and virtual routing appliance, deconstructing data received from the respective user installation and cloud service into the multiplexed data portions which are transmitted over the plurality of paths.

3 . The appliance of claim 1 , wherein the user installation is selected from the group consisting of a user device, a plurality of networked user devices, an enterprise network, and a plurality of enterprise networks.

4 . The appliance of claim 1 , wherein the type of connection between the physical routing appliance and the cloud service is selected from the group consisting of a virtual private network (VPN), a scalable zero trust protocol (ZPA), and a direct connection.

5 . The appliance of claim 4 , wherein the direct connection comprises a connection through a public communications network.

6 . The appliance of claim 1 , wherein the configuring comprises editing an existing profile for the physical routing appliance.

7 . The appliance of claim 1 , wherein the configuring comprises creating a new profile for the physical routing appliance.

8 . The appliance of claim 1 , wherein the processor further performs the following:

responsive to a determination that there is no virtual private cloud for the user installation at the cloud service, creating the virtual private cloud.

9 . The appliance of claim 1 , wherein the processor further performs the following:

responsive to a determination that there is no virtual routing appliance for the user installation at the cloud service, creating a virtual routing appliance.

10 . The appliance of claim 1 , further comprising a switch fabric for transmitting the multiplexed data portions.

11 . A computer-implemented method comprising, on a processor executing instructions stored in a non-transitory memory:

responsive to connection of the physical routing appliance to a user installation, configuring the physical routing appliance to communicate with a cloud service;

initiating communication between the physical routing appliance and a cloud service to connect the physical routing appliance to the cloud service, including selecting a type of connection between the physical routing appliance and the cloud service;

responsive to connection of the physical routing appliance to the cloud service, determining whether there is a virtual private cloud for the user installation at the cloud service;

determining whether there is a virtual routing appliance for the user installation at the cloud service; and

responsive to a determination that there is a virtual routing appliance for the user installation at the cloud service, initiating a multiplexed virtual private network (VPN) communication path between the physical routing appliance and the virtual routing appliance, wherein communications between the user installation and the cloud service comprise:

at the physical routing appliance:

multiplexing first system data received from the user installation for transmission to the virtual routing appliance as first multiplexed data;

formatting data received from the virtual routing appliance for transmission to the user installation;

at the virtual routing appliance:

multiplexing second system data received from the cloud service for transmission to the physical routing appliance as second multiplexed data;

formatting data received from the physical routing appliance for transmission to the cloud service; and

between the physical routing appliance and the virtual routing appliance:

creating a plurality of paths to transmit the first and second multiplexed data between the physical routing appliance and the virtual routing appliance to enable transmission of the first and second multiplexed data as multiplexed data portions without having to retransmit all of the first and second system data.

12 . The computer-implemented method of claim 11 , wherein multiplexing the first system data and multiplexing the second system data comprises, at the respective physical routing appliance and virtual routing appliance, deconstructing data received from the respective user installation and cloud service into the multiplexed data portions which are transmitted over the plurality of paths.

13 . The computer-implemented method of claim 11 , wherein the user installation is selected from the group consisting of a user device, a plurality of networked user devices, an enterprise network, and a plurality of enterprise networks.

14 . The computer-implemented method of claim 11 , wherein the type of connection between the physical routing appliance and the cloud service is selected from the group consisting of a virtual private network (VPN), a scalable zero trust protocol (ZPA), and a direct connection.

15 . The computer-implemented method of claim 14 , wherein the direct connection comprises a connection through a public communications network.

16 . The computer-implemented method of claim 11 , wherein the configuring comprises editing an existing profile for the physical routing appliance.

17 . The computer-implemented method of claim 11 , wherein the configuring comprises creating a new profile for the physical routing appliance.

18 . The computer-implemented method of claim 11 , further comprising:

responsive to a determination that there is no virtual private cloud for the user installation at the cloud service, creating the virtual private cloud.

19 . The computer-implemented method of claim 11 , further comprising:

responsive to a determination that there is no virtual routing appliance for the user installation at the cloud service, creating a virtual routing appliance.

20 . The computer-implemented method of claim 11 , further comprising providing a switch fabric for transmitting the multiplexed data portions.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 23, 2026
From: HUNT, DONALD C.
To: GKDCH, LLC
Reel/Frame 076119/0874 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2026
From: GKDCH, LLP
To: HUNT, DONALD C.
Reel/Frame 076083/0651 →
SECURITY INTEREST Recorded Apr 21, 2026
From: GKDCH, LLC
To: HUNT, DONALD C., MR.
Reel/Frame 075440/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2026
From: ROSENBOHM, CHAD
To: GKDCH, LLC
Reel/Frame 074349/0991 →
Continuity (1)
Related Publication 20240403095A1 · Dec 5, 2024
References Cited (14)
US 8514868B2 · Hill · 2013 [cited by examiner]
US 8650299B1 · Huang · 2014 [cited by examiner]
US 8705513B2 · Van Der Merwe · 2014 [cited by examiner]
US 8868724B2 · Goodwin · 2014 [cited by examiner]
US 9213718B1 · Hrebicek et al. · 2015 [cited by applicant]
US 9391801B2 · Raghu · 2016 [cited by examiner]
US 9563637B2 · Hrebicek et al. · 2017 [cited by applicant]
US 10019128B2 · Goodwin · 2018 [cited by examiner]
US 10411975B2 · Martinez et al. · 2019 [cited by applicant]
US 11533781B2 · Bull et al. · 2022 [cited by applicant]
US 11558245B1 · Kreger-Stickles · 2023 [cited by examiner]
US 11588683B2 · Dumbar et al. · 2023 [cited by applicant]
Open Compute Project, “Switch Abstraction Interface (SAI)”, retrieved from http://opencompute.org, Mar. 28, 2015, 8 pages. [cited by applicant]
https://en.wikipedia.org/wiki/QUIC, accessed Apr. 17, 2023. [cited by applicant]