IP Library Granted Patent US 12,609,913
Granted Patent B2
US 12,609,913 · App. 18/504,688 · Granted Apr 21, 2026

Clustering of virtual private network servers

Inventors: Donatas Budvytis (Vilnius, LT); Karolis Kaciulis (Kaisiadorys, LT)
Assignee: Netflow, UAB
H04L63/0272H04L63/0435H04L63/0876H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,913
App. No.
18/504,688
Granted
Apr 21, 2026
Kind
B2
Abstract

A VPN connection request is received from a user device. Two or more VPN servers are associated with a single entry Internet Protocol (IP) address. The two or more VPN servers includes a first VPN server and a second VPN server. The single entry IP address is transmitted to the user device. A secure VPN connection is established between the user device and the first VPN server using the single entry IP address. The secure VPN connection is switched to the second VPN server when the first VPN server becomes unavailable such that the secure VPN connection remains intact and the user device continues to communicate via the single entry IP address.

Claims (52)

1 . A method, comprising:

receiving a VPN connection request from a user device;

associating two or more VPN servers with a single entry Internet Protocol (IP) address, wherein the two or more VPN servers includes a first VPN server and a second VPN server;

transmitting the single entry IP address to the user device;

establishing a secure VPN connection between the user device and the first VPN server using the single entry IP address;

transmitting, from the first VPN server to the second VPN server, key information associated with the secure VPN connection, wherein the key information comprises encryption related keys specific to the secure VPN connection between the user device and the first VPN server, the encryption related keys being used for encrypting and decrypting communications in the secure VPN connection; and

switching the secure VPN connection to the second VPN server when the first VPN server becomes unavailable,

wherein the secure VPN connection remains intact and the user device continues to communicate via the single entry IP address, and

wherein the secure VPN connection remains intact by utilizing the key information received by the second VPN server without authenticating again or establishing new encryption keys when switching from the first VPN server to the second VPN server.

2 . The method of claim 1 , wherein the key information associated with the secure VPN connection comprises at least one of an encryption key or a decryption key.

3 . The method of claim 1 , further comprising:

selecting the first VPN server in response to determining that the first VPN server is an optimal server for the user device; and

selecting the second VPN server in response to determining that the second VPN server is a next optimal server after the first VPN server for the user device.

4 . The method of claim 1 , further comprising:

selecting the second VPN server based on factors including at least one of a location of the second VPN server relative to the user device or available bandwidth of the second VPN server.

5 . The method of claim 1 , further comprising:

determining that the first VPN server is unavailable in response to a failure to receive an availability notification from the first VPN server.

6 . The method of claim 1 , further comprising:

monitoring an availability of the first VPN server at configured intervals.

7 . A system, comprising:

one or more processors, the one or more processors configured to execute instructions to:

receive a VPN connection request from a user device;

associate a first VPN server and a second VPN server with a single entry Internet Protocol (IP) address;

transmit the single entry IP address to the user device;

establish a secure VPN connection between the user device and the first VPN server using the single entry IP address;

transmit, from the first VPN server to the second VPN server, a key information associated with the secure VPN connection, wherein the key information comprises encryption related keys specific to the secure VPN connection between the user device and the first VPN server, the encryption related keys being used for encrypting and decrypting communications in the secure VPN connection; and

switch the secure VPN connection to the second VPN server when the first VPN server becomes unavailable,

wherein the secure VPN connection remains intact and the user device continues to communicate via the single entry IP address, and

wherein the secure VPN connection remains intact by utilizing the key information received by the second VPN server without authenticating again or establishing new encryption keys when switching from the first VPN server to the second VPN server.

8 . The system of claim 7 , wherein the key information associated with the secure VPN connection comprises at least one of an encryption key or a decryption key.

9 . The system of claim 7 , wherein the one or more processors is further configured to:

select the first VPN server in response to determining that the first VPN server is an optimal server for the user device; and

select the second VPN server in response to determining that the second VPN server is a next optimal server after the first VPN server for the user device.

10 . The system of claim 7 , wherein the one or more processors is further configured to:

select the second VPN server based on factors including at least one of a location of the second VPN server relative to the user device or available bandwidth of the second VPN server.

11 . The system of claim 7 , wherein the one or more processors is further configured to:

determine that the first VPN server is unavailable in response to a failure to receive an availability notification from the first VPN server.

12 . The system of claim 7 , wherein the one or more processors is further configured to:

monitor an availability of the first VPN server at configured intervals.

13 . Non-transitory computer readable media storing instructions operable to cause one or more processors to perform operations comprising:

receiving a VPN connection request from a user device;

associating a first VPN server and a second VPN server with a single entry Internet Protocol (IP) address;

transmitting the single entry IP address to the user device;

establishing a secure VPN connection between the user device and the first VPN server using the single entry IP address;

transmitting, from the first VPN server to the second VPN server, key information associated with the secure VPN connection, wherein the key information comprises encryption related keys specific to the secure VPN connection between the user device and the first VPN server, the encryption related keys being used for encrypting and decrypting communications in the secure VPN connection; and

switching the secure VPN connection to the second VPN server when the first VPN server becomes unavailable,

wherein the secure VPN connection remains intact and the user device continues to communicate via the single entry IP address, and

wherein the secure VPN connection remains intact by utilizing the key information received by the second VPN server without authenticating again or establishing new encryption keys when switching from the first VPN server to the second VPN server.

14 . The non-transitory computer readable media of claim 13 , wherein the key information associated with the secure VPN connection comprises at least one of an encryption key or a decryption key.

15 . The non-transitory computer readable media of claim 13 , wherein the operations further comprise: selecting the first VPN server in response to determining that the first VPN server is an optimal server for the user device; and selecting the second VPN server in response to determining that the second VPN server is a next optimal server after the first VPN server for the user device.

16 . The non-transitory computer readable media of claim 13 , wherein the operations further comprise: selecting the second VPN server based on factors including at least one of geographic proximity a location of the second VPN server relative to the user device or available bandwidth of the second VPN server.

17 . The non-transitory computer readable media of claim 13 , wherein the operations further comprise: determining that the first VPN server is unavailable in response to a failure to receive an availability notification from the first VPN server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2023
From: BUDVYTIS, DONATAS; KACIULIS, KAROLIS
To: NETFLOW, UAB
Reel/Frame 066000/0756 →
Continuity (3)
Continuation 17403801 · Aug 16, 2021
Division 17402541 · Aug 15, 2021
Related Publication 20240080302A1 · Mar 7, 2024
References Cited (43)
US 6032118A · Tello et al. · 2000 [cited by applicant]
US 6662221B1 · Gonda et al. · 2003 [cited by applicant]
US 6772226B1 · Bommareddy · 2004 [cited by examiner]
US 7376743B1 · Bazzinotti et al. · 2008 [cited by applicant]
US 8104081B2 · Khanna et al. · 2012 [cited by applicant]
US 8239934B2 · Brown et al. · 2012 [cited by applicant]
US 9438564B1 · Weng et al. · 2016 [cited by applicant]
US 10764313B1 · Mushtaq · 2020 [cited by examiner]
US 11005929B1 · Chamarajanagar · 2021 [cited by examiner]
US 11190491B1 · Kaciulis et al. · 2021 [cited by applicant]
US 11245670B1 · Celiesius · 2022 [cited by examiner]
US 11271858B1 · Pabijanskas et al. · 2022 [cited by applicant]
US 11297038B1 · Kolaitis et al. · 2022 [cited by applicant]
US 11336717B1 · Celiesius · 2022 [cited by applicant]
US 11363001B1 · Kolaitis et al. · 2022 [cited by applicant]
US 20030093691A1 · Simon et al. · 2003 [cited by applicant]
US 20050180319A1 · Hutnik et al. · 2005 [cited by applicant]
US 20060070115A1 · Yamada et al. · 2006 [cited by applicant]
US 20070113275A1 · Khanna · 2007 [cited by examiner]
US 20070299954A1 · Fatula · 2007 [cited by applicant]
US 20080263209A1 · Pisharody · 2008 [cited by examiner]
US 20090046729A1 · Nagata · 2009 [cited by applicant]
US 20090144817A1 · Kumar · 2009 [cited by examiner]
US 20090292824A1 · Marashi et al. · 2009 [cited by applicant]
US 20110107414A1 · Diab et al. · 2011 [cited by applicant]
US 20120096269A1 · McAlister · 2012 [cited by examiner]
US 20140136597A1 · Bland et al. · 2014 [cited by applicant]
US 20140301249A1 · Moss et al. · 2014 [cited by applicant]
US 20150188889A1 · Lawson · 2015 [cited by applicant]
US 20160286001A1 · Chan · 2016 [cited by examiner]
US 20180041613A1 · Lapidous et al. · 2018 [cited by applicant]
US 20180091417A1 · Ore et al. · 2018 [cited by applicant]
US 20180191838A1 · Friedman · 2018 [cited by examiner]
US 20190297897A1 · Mitter et al. · 2019 [cited by applicant]
US 20190327312A1 · Gupta et al. · 2019 [cited by applicant]
US 20200314212A1 · Branch et al. · 2020 [cited by applicant]
US 20210281529A1 · Baron et al. · 2021 [cited by applicant]
US 20210297897A1 · Cunningham et al. · 2021 [cited by applicant]
US 20220255900A1 · Gupta · 2022 [cited by examiner]
Chandra et al, VPN for Remote Digital Evidence Acquisition, Nov. 2, 2007, IEEE, pp. 1-4. (Year: 2007). [cited by examiner]
Xu et al, Research on Network Security of VPN Technology, Dec. 6, 2020, IEEE, pp. 539-542. (Year: 2020). [cited by examiner]
Qian et al, Balancing Request Denial Probability and Latency in an Agent-Based VPN Architecture, IEEE, Dec. 17, 2010, pp. 282-295. (Year:2010). [cited by applicant]
Wolinsky et al, On the Design of Scalable Self-Configuring Virtual Networks, IEEE, Nov. 20, 2009, pp. 1-12. (Year: 2009). [cited by applicant]