IP Library Granted Patent US 12,647,397
Granted Patent B2
US 12,647,397 · App. 18/191,315 · Granted Jun 2, 2026

Hierarchical-context area network as a virtual private network infrastructure system

Inventors: Karolis Kaciulis (Kaisiadorys, LT); Nikodemas Zaliauskas (Vilnius, LT); Donatas Budvytis (Vilnius, LT)
Assignee: Netflow, UAB
H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,397
App. No.
18/191,315
Filed
Mar 28, 2023
Granted
Jun 2, 2026
Kind
B2
Art Unit
2447
USPC
726/15
Abstract

A hierarchical-context area network includes a first, level-one, context area network, a second, level-one, context area network, and a third, level-two, context area network, wherein the first context area network is allocated a first shared IP address in a first range, the first context area network includes a first VPN server having a second IP address in the first range, the second context area network is allocated a second shared IP address in a second range, the second context area network includes a second VPN server having a fourth IP address in the second range, communication between the first VPN server and the second VPN server is unavailable via context area networks other than via a data link layer network established between the first VPN server and the second VPN server via the third context area network.

Claims (86)

1 . A method comprising:

operating a hierarchical-context area network as a virtual private network infrastructure network, wherein the hierarchical-context area network includes a hierarchy of context areas, wherein:

the hierarchical-context area network includes:

a first context area network, wherein the first context area network is a level-one context area network corresponding to a first context level;

a second context area network, wherein the second context area network is a level-one context area network corresponding to the first context level; and

a third context area network, wherein the third context area network is a level-two context area network corresponding to a second context level that includes the first context level;

the first context area network is allocated, in the hierarchical-context area network, a first range of Internet Protocol addresses, wherein the first range of Internet Protocol addresses includes a first Internet Protocol address allocated as a first shared Internet Protocol address for the first context area network;

the first context area network includes a first virtual private network server having a second Internet Protocol address in the first range of Internet Protocol addresses, different from the first shared Internet Protocol address;

the second context area network is allocated, in the hierarchical-context area network, a second range of Internet Protocol addresses, wherein the second range of Internet Protocol addresses includes a third Internet Protocol address allocated as a second shared Internet Protocol address for the second context area network;

the second context area network includes a second virtual private network server having a fourth Internet Protocol address in the second range of Internet Protocol addresses, different from the second shared Internet Protocol address;

communication between the first virtual private network server and the second virtual private network server is unavailable via the first context area network;

communication between the first virtual private network server and the second virtual private network server is unavailable via the second context area network; and

communication between the first virtual private network server and the second virtual private network server is available via a data link layer network established between the first virtual private network server and the second virtual private network server via the third context area network.

2 . The method of claim 1 , wherein operating the hierarchical-context area network includes:

operating a hierarchical-context area network manager at a virtual private network infrastructure administration server for managing the hierarchical-context area network, the hierarchical-context area network manager configured in accordance with hierarchical-context area network manager configuration data obtained from a virtual private network control infrastructure device.

3 . The method of claim 2 , wherein operating the hierarchical-context area network includes:

operating a virtual private network operating system of the first virtual private network server, the virtual private network operating system configured in accordance with virtual private network server configuration data obtained from the virtual private network control infrastructure device.

4 . The method of claim 3 , wherein operating the hierarchical-context area network manager includes:

registering the first virtual private network server as a component of the hierarchical-context area network in accordance with virtual private network server registration data identifying the first virtual private network server obtained by the hierarchical-context area network manager from the virtual private network control infrastructure device.

5 . The method of claim 4 , wherein operating the virtual private network operating system includes:

sending, by the first virtual private network server, a peering data request, to the hierarchical-context area network manager.

6 . The method of claim 5 , wherein operating the hierarchical-context area network manager includes the hierarchical-context area network manager:

receiving the peering data request;

obtaining, responsive to the peering data request, peering data that identifies a second virtual private network server of the hierarchical-context area network as a peer of the first virtual private network server; and

sending a peering data response indicating the peering data to the first virtual private network server.

7 . The method of claim 6 , wherein operating the virtual private network operating system includes:

receiving the peering data response; and

configuring the second virtual private network server as a virtual private network infrastructure peer in the hierarchical-context area network.

8 . A virtual private network infrastructure system, which includes at least one processor performing instructions stored in at least one memory, operating a hierarchical-context area network as a virtual private network infrastructure network, wherein the hierarchical-context area network includes a hierarchy of context areas, the virtual private network infrastructure system comprising:

a virtual private network infrastructure administration server;

virtual private network control infrastructure device; and

a first virtual private network server, wherein:

the hierarchical-context area network includes:

a first context area network, wherein the first context area network is a level-one context area network corresponding to a first context level;

a second context area network, wherein the second context area network is a level-one context area network corresponding to the first context level; and

a third context area network, wherein the third context area network is a level-two context area network corresponding to a second context level that includes the first context level;

the first context area network is allocated, in the hierarchical-context area network, a first range of Internet Protocol addresses, wherein the first range of Internet Protocol addresses includes a first Internet Protocol address allocated as a first shared Internet Protocol address for the first context area network;

the first context area network includes the first virtual private network server, the first virtual private network server having a second Internet Protocol address in the first range of Internet Protocol addresses, different from the first shared Internet Protocol address;

the second context area network is allocated, in the hierarchical-context area network, a second range of Internet Protocol addresses, wherein the second range of Internet Protocol addresses includes a third Internet Protocol address allocated as a second shared Internet Protocol address for the second context area network;

the second context area network includes a second virtual private network server having a fourth Internet Protocol address in the second range of Internet Protocol addresses, different from the second shared Internet Protocol address;

communication between the first virtual private network server and the second virtual private network server is unavailable via the first context area network;

communication between the first virtual private network server and the second virtual private network server is unavailable via the second context area network; and

communication between the first virtual private network server and the second virtual private network server is available via a data link layer network established between the first virtual private network server and the second virtual private network server via the third context area network.

9 . The virtual private network infrastructure system of claim 8 , wherein operating the hierarchical-context area network includes:

the virtual private network infrastructure administration server operating a hierarchical-context area network manager for managing the hierarchical-context area network, the hierarchical-context area network manager configured in accordance with hierarchical-context area network manager configuration data obtained from the virtual private network control infrastructure device.

10 . The virtual private network infrastructure system of claim 9 , wherein operating the hierarchical-context area network includes:

the first virtual private network server operating a virtual private network operating system, the virtual private network operating system configured in accordance with virtual private network server configuration data obtained from the virtual private network control infrastructure device.

11 . The virtual private network infrastructure system of claim 10 , wherein operating the hierarchical-context area network includes:

the hierarchical-context area network manager registering the first virtual private network server as a component of the hierarchical-context area network in accordance with virtual private network server registration data identifying the first virtual private network server obtained by the hierarchical-context area network manager from the virtual private network control infrastructure device.

12 . The virtual private network infrastructure system of claim 11 , wherein operating the hierarchical-context area network includes:

the virtual private network operating system sending a peering data request to the hierarchical-context area network manager.

13 . The virtual private network infrastructure system of claim 12 , wherein operating the hierarchical-context area network includes the hierarchical-context area network manager:

receiving the peering data request;

obtaining, responsive to the peering data request, peering data that identifies the second virtual private network server as a peer of the first virtual private network server; and

sending a peering data response indicating the peering data to the first virtual private network server.

14 . The virtual private network infrastructure system of claim 13 , wherein operating the hierarchical-context area network includes the virtual private network operating system:

receiving the peering data response; and

configuring the second virtual private network server as a virtual private network infrastructure peer in the hierarchical-context area network.

15 . A non-transitory computer-readable storage medium, comprising processor-executable instructions for operating, in response to the instructions, a hierarchical-context area network as a virtual private network infrastructure network, wherein the hierarchical-context area network includes a hierarchy of context areas, wherein:

the hierarchical-context area network includes:

a first context area network, wherein the first context area network is a level-one context area network corresponding to a first context level;

a second context area network, wherein the second context area network is a level-one context area network corresponding to the first context level; and

a third context area network, wherein the third context area network is a level-two context area network corresponding to a second context level that includes the first context level;

the first context area network is allocated, in the hierarchical-context area network, a first range of Internet Protocol addresses, wherein the first range of Internet Protocol addresses includes a first Internet Protocol address allocated as a first shared Internet Protocol address for the first context area network;

the first context area network includes a first virtual private network server having a second Internet Protocol address in the first range of Internet Protocol addresses, different from the first shared Internet Protocol address;

the second context area network is allocated, in the hierarchical-context area network, a second range of Internet Protocol addresses, wherein the second range of Internet Protocol addresses includes a third Internet Protocol address allocated as a second shared Internet Protocol address for the second context area network;

the second context area network includes a second virtual private network server having a fourth Internet Protocol address in the second range of Internet Protocol addresses, different from the second shared Internet Protocol address;

communication between the first virtual private network server and the second virtual private network server is unavailable via the first context area network;

communication between the first virtual private network server and the second virtual private network server is unavailable via the second context area network; and

communication between the first virtual private network server and the second virtual private network server is available via a data link layer network established between the first virtual private network server and the second virtual private network server via the third context area network.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein operating the hierarchical-context area network includes:

operating a hierarchical-context area network manager at a virtual private network infrastructure administration server for managing the hierarchical-context area network, the hierarchical-context area network manager configured in accordance with hierarchical-context area network manager configuration data obtained from a virtual private network control infrastructure device.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein operating the hierarchical-context area network includes:

operating a virtual private network operating system of the first virtual private network server, the virtual private network operating system configured in accordance with virtual private network server configuration data obtained from the virtual private network control infrastructure device.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein operating the hierarchical-context area network manager includes:

registering the first virtual private network server as a component of the hierarchical-context area network in accordance with virtual private network server registration data identifying the first virtual private network server obtained by the hierarchical-context area network manager from the virtual private network control infrastructure device.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein operating the virtual private network operating system includes:

sending, by the first virtual private network server, a peering data request, to the hierarchical-context area network manager.

20 . The non-transitory computer-readable storage medium of claim 19 , wherein:

operating the hierarchical-context area network manager includes the hierarchical-context area network manager:

receiving the peering data request;

obtaining, responsive to the peering data request, peering data that identifies a second virtual private network server of the hierarchical-context area network as a peer of the first virtual private network server; and

sending a peering data response indicating the peering data to the first virtual private network server; and

operating the virtual private network operating system includes:

receiving the peering data response; and

configuring the second virtual private network server as a virtual private network infrastructure peer in the hierarchical-context area network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: KACIULIS, KAROLIS; ZALIAUSKAS, NIKODEMAS; BUDVYTIS, DONATAS
To: NETFLOW, UAB
Reel/Frame 063131/0516 →
Continuity (1)
Related Publication 20240333686A1 · Oct 3, 2024
References Cited (71)
US 7752486B2 · Satran · 2010 [cited by examiner]
US 8442030B2 · Dennison · 2013 [cited by applicant]
US 8750288B2 · Nakil et al. · 2014 [cited by applicant]
US 9094285B2 · Gorkemli et al. · 2015 [cited by applicant]
US 9319300B2 · Huynh Van et al. · 2016 [cited by applicant]
US 9722935B2 · Bouanen et al. · 2017 [cited by applicant]
US 9900250B2 · Dong et al. · 2018 [cited by applicant]
US 9912614B2 · Koganti · 2018 [cited by applicant]
US 10097372B2 · Bhattacharya et al. · 2018 [cited by applicant]
US 10148506B1 · Anburose et al. · 2018 [cited by applicant]
US 10200274B1 · Suryanarayana et al. · 2019 [cited by applicant]
US 10326532B2 · Ashrafi · 2019 [cited by applicant]
US 10361972B2 · Biruduraju · 2019 [cited by applicant]
US 10397189B1 · Hashmi · 2019 [cited by applicant]
US 10705808B2 · Chiosi et al. · 2020 [cited by applicant]
US 10749796B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10757576B2 · Ashrafi · 2020 [cited by applicant]
US 10819629B2 · Dowlatkhah et al. · 2020 [cited by applicant]
US 10972386B2 · Mackie et al. · 2021 [cited by applicant]
US 10999197B2 · Tooda et al. · 2021 [cited by applicant]
US 11025483B1 · Hashmi · 2021 [cited by applicant]
US 11134010B2 · Mehmedagic et al. · 2021 [cited by applicant]
US 11310146B1 · Kaciulis et al. · 2022 [cited by applicant]
US 12218822B2 · Kaciulis et al. · 2025 [cited by applicant]
US 12341696B2 · Kaciulis et al. · 2025 [cited by applicant]
US 20040057439A1 · Ould-Brahim · 2004 [cited by applicant]
US 20050165834A1 · Nadeau et al. · 2005 [cited by applicant]
US 20060075083A1 · Liu · 2006 [cited by examiner]
US 20090228466A1 · Peters · 2009 [cited by examiner]
US 20100154050A1 · Mukkara · 2010 [cited by examiner]
US 20100165832A1 · Kini et al. · 2010 [cited by applicant]
US 20110194404A1 · Kluger et al. · 2011 [cited by applicant]
US 20140101325A1 · Young · 2014 [cited by examiner]
US 20170026417A1 · Ermagan et al. · 2017 [cited by applicant]
US 20170317919A1 · Fernando et al. · 2017 [cited by applicant]
US 20170366395A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180062992A1 · Cohn et al. · 2018 [cited by applicant]
US 20180167457A1 · Soderlund · 2018 [cited by examiner]
US 20180262498A1 · Be'ery et al. · 2018 [cited by applicant]
US 20180302321A1 · Manthiramoorthy et al. · 2018 [cited by applicant]
US 20190081930A1 · Hunt · 2019 [cited by applicant]
US 20190280964A1 · Michael et al. · 2019 [cited by applicant]
US 20190319847A1 · Nahar et al. · 2019 [cited by applicant]
US 20200099659A1 · Cometto et al. · 2020 [cited by applicant]
US 20200403970A1 · Chastain et al. · 2020 [cited by applicant]
US 20210029195A1 · Kolbe et al. · 2021 [cited by applicant]
US 20210111998A1 · Saavedra · 2021 [cited by applicant]
US 20210399920A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20220103523A1 · Starr et al. · 2022 [cited by applicant]
US 20220224623A1 · Kamath et al. · 2022 [cited by applicant]
US 20230006972A1 · Kolaitis et al. · 2023 [cited by applicant]
US 20230052050A1 · Budvytis et al. · 2023 [cited by applicant]
US 20240187380A1 · Funka et al. · 2024 [cited by applicant]
US 20240251017A1 · Byard et al. · 2024 [cited by applicant]
US 20240333628A1 · Kaciulis et al. · 2024 [cited by applicant]
US 20240333646A1 · Kaciulis et al. · 2024 [cited by applicant]
US 20240333686A1 · Kaciulis et al. · 2024 [cited by applicant]
US 20240333687A1 · Kaciulis et al. · 2024 [cited by applicant]
US 20240333688A1 · Kaciulis et al. · 2024 [cited by applicant]
US 20250071065A1 · Lal · 2025 [cited by applicant]
Virtual eXetensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks, M. Mahalingam Storvisor et al., <https://www.rfc-editor.org/rfc/rfc7348.html>, Aug. 2014, 22… [cited by applicant]
Wikipedia, Software-defined networking, https://en.wikipedia.org/wiki/Software-defined_networking, Apr. 10, 2023, 15 pages. [cited by applicant]
RFC 4271: A Border Gateway Protocol 4 (BGP-4), Y. Rekhter, et al., https://www.rfc-editor.org/rfc/rfc4271, Jan. 2006, 104 pages. [cited by applicant]
WireGuard: Next Generation Kemmel Network Tunnel, Jason A. Donenfeld ,https://www.wireguard.com/papers/wireguard.pdf <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.wireguard.com%2Fpapers%2Fwiregu… [cited by applicant]
Wikipedia, OSI model, <https://en.wikipedia.org/wiki/OSI_model>, Apr. 10, 2023, 8 pages. [cited by applicant]
Veth(4)—Linux manual page, Linux/UNIX system programming training, Michael Kerrisk, https:/man7.org/linux/man-pages/man4/veth.4.html <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fman7.org%2Flinux%2F… [cited by applicant]
Ip-netns(8)—Linux manual page, Linux/UNIX system programming training, Michael Kerrisk, https://man7.org/linux/man-pages/man8/ip-netns.8.html <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fman7.org%2… [cited by applicant]
Introduction to Linux interfaces for virtual networking, Hangbin Liu, https:/developers.redhat.com/blog/2018/10/22/introduction-to-linux-interfaces-for-virtual-networking <https://nam10.safelinks.protection.outlook.com/… [cited by applicant]
Wikipedia, Open Shortest Path First, https://en.wikipedia.org/wiki/Open_Shortest_Path_First <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FOpen_Shortest_Path_First&data=05%7… [cited by applicant]
Wikipedia, Border Gateway Protocol, https://en.wikipedia.org/wiki/Border_Gateway_Protocol<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FBorder_Gateway_Protocol&data=05%7C01%… [cited by applicant]
Wikipedia, Transport Layer Security, https://en.wikipedia.org/wiki/Transport_Layer_Security<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FTransport_Layer_Security&data=05%7C… [cited by applicant]