Optimizing connections over virtual private networks

US9942199B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9942199-B2
Application numberUS-201314145586-A
CountryUS
Kind codeB2
Filing dateDec 31, 2013
Priority dateDec 31, 2013
Publication dateApr 10, 2018
Grant dateApr 10, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosed embodiments provide a system that provides a virtual private network (VPN). The system includes a routing apparatus on a public network. The routing apparatus accepts a first connection with a client on the VPN and a second connection with a gateway in a private network extended by the VPN. Next, the routing apparatus receives a first set of packets from the client over the first connection, wherein the first set of packets is encrypted. The routing apparatus then routes the first set of packets to the gateway. The system also includes the gateway, which establishes the second connection with the routing apparatus. Next, the gateway decrypts the first set of packets and routes the decrypted first set of packets to a host in the private network.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for providing a virtual private network (VPN), the system comprising: a routing apparatus on a public network, the routing apparatus configured to accept a first connection with a client on the VPN and a second connection with a VPN gateway behind a firewall in a private network extended by the VPN; and the VPN gateway configured to establish the second connection with the routing apparatus, receive a set of packets from a host device of the private network, encrypt the set of packets using a shared secret between the client on the public network and the VPN gateway behind the firewall on the private network, insert a destination identifier of the client on the public network, and route the encrypted set of packets having the destination identifier of the client to the routing apparatus via the second connection; wherein secure access to private resources of the host device behind the firewall of the private network is extended from behind the firewall to the client on the public network and beyond the firewall by the VPN that includes the VPN gateway behind the firewall on the private network and the routing apparatus on the public network; wherein the VPN is extended to the client by the routing apparatus via the public network without requiring the client to install VPN software; wherein the transmission of the packets is associated with at least one of: omitting a three-way handshake between the client and the host device; bypassing checksums on the sets of packets; setting a maximum transmission unit (MTU) associated with transmission of the set of packets; and setting a receive window associated with transmission of the set of packets. 2. The system of claim 1 , further comprising: the client configured to establish the first connection with the routing apparatus, encrypt another set of packets, and transmit the other set of packets over the first connection to the routing apparatus. 3. The system of claim 1 , wherein the routing apparatus is further configured to route the set of packets from the VPN gateway to the client based on the destination identifier added by the VPN gateway. 4. The system of claim 3 , wherein the client is further configured to receive the set of packets over the first connection from the routing apparatus and decrypt the set of packets. 5. The system of claim 2 , wherein the client is further configured to exchange a third set of packets with another client on the VPN through the routing apparatus or a direct connection with the other client. 6. The system of claim 2 , wherein the VPN gateway and the client are further configured to maintain the first and second connections with the routing apparatus by periodically transmitting keep-alive packets to the routing apparatus. 7. The system of claim 1 , wherein each packet from the set of packets comprises destination identifier added by the VPN gateway, a cryptographic header added by the VPN gateway, and a payload. 8. The system of claim 1 , wherein the routing apparatus stores and distributes public keys for the client and the VPN gateway, and the public keys are used to generate the shared secret along with a private key that is not known to the routing apparatus. 9. A computer-implemented method for facilitating use of a virtual private network (VPN), the computer-implemented method comprising: establishing a connection between a routing apparatus on a public network and a VPN gateway behind a firewall in a private network extended by the VPN; receiving, by the VPN gateway, a set of packets from a host device of the private network, encrypting, by the VPN gateway, the set of packets using a shared secret that is unknown to the routing apparatus and shared between a client on the public network and the VPN gateway that is behind the firewall of the private network, and inserting, by the VPN gateway, a destination identifier of the client on the public network; and transmitting, by the VPN gateway, the set of packets having the destination identifier of the client to the routing apparatus; wherein secure access to private resources of the host device behind the firewall of the private network is extended from behind the firewall to the client on the public network and beyond the firewall by the VPN that includes the VPN gateway behind the firewall on the private network and the routing apparatus on the public network; wherein the VPN is extended to the client by the routing apparatus via the public network without requiring the client to install VPN software; wherein the transmission of the set of packets is associated with at least one of: omitting a three-way handshake between the client and the host device; bypassing checksums on the sets of packets; setting a maximum transmission unit (MTU) associated with transmission of the set of packets; and setting a receive window associated with transmission of the set of packets. 10. The computer-implemented method of claim 9 , further comprising: receiving, at the routing apparatus, a second set of packets over the connection, wherein the second set of packets are encrypted by and transmitted from the client; and decrypting the second set of packets at the first node using the shared secret. 11. The computer-implemented method of claim 10 , further comprising: using, by the routing apparatus, the shared secret to verify the second set of packets after receiving the second set of packets from the client. 12. The computer-implemented method of claim 9 , wherein omitting the three-way handshake comprises at least one of: omitting the transmission of one or more packets associated with the three-way handshake; and performing, at the routing apparatus, the three-way handshake with an endpoint associated with the three-way handshake in lieu of transmitting the one or more packets to the VPN gateway. 13. The computer-implemented method of claim 9 , wherein the MTU and the receive window are associated with a previous connection of the routing apparatus with the VPN. 14. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for facilitating use of a virtual private network (VPN), the method comprising: establishing a connection between a routing apparatus on a public network and a VPN gateway behind a firewall in a private network extended by the VPN; receiving, by the VPN gateway, a set of packets from a host device of the private network, encrypting, by the VPN gateway, the set of packets using a shared secret that is unknown to the routing apparatus and shared between a client on the public network and the VPN gateway that is behind the firewall of the private network, and inserting, by the VPN gateway, a destination identifier of the client on the public network; and transmitting, by the VPN gateway, the set of packets having the destination identifier of the client to the routing apparatus; wherein secure access to private resources of the host device behind the firewall of the private network is extended from behind the firewall to the client on the public network and beyond the firewall by the VPN that includes the VPN gateway behind the firewall on the private network and the routing apparatus on the public network; wherein the VPN is extended to the client by the routing apparatus via the public network without requiring the client to install VPN software; wherein the transmission of the set of packets is associated with at least one of: omitting a three-way handshake between the client and the host device; bypassing checksums on the sets of packets

Assignees

Inventors

Classifications

  • Virtual private networks · CPC title

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9942199B2 cover?
The disclosed embodiments provide a system that provides a virtual private network (VPN). The system includes a routing apparatus on a public network. The routing apparatus accepts a first connection with a client on the VPN and a second connection with a gateway in a private network extended by the VPN. Next, the routing apparatus receives a first set of packets from the client over the first …
Who is the assignee on this patent?
Open Invention Network Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/0272. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 10 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).