US2019068404A1PendingUtilityA1

Vpn usage to create wide area network backbone over the internet

Assignee: ALTERWAN INCPriority: Jul 10, 2000Filed: Apr 24, 2018Published: Feb 28, 2019
Est. expiryJul 10, 2020(expired)· nominal 20-yr term from priority
H04L 63/0209H04L 12/2856H04L 45/20H04L 45/308H04L 47/24H04L 45/74H04L 45/04H04L 47/726H04L 45/12H04L 49/354H04L 47/12H04L 12/4641H04L 12/4633
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A wide area network using the internet as a backbone utilizing specially selected ISX/ISP providers whose routers route packets of said wide area network along private tunnels through the internet comprised of high bandwidth, low hop-count data paths. Firewalls are provided at each end of each private tunnel which recognize IP packets addressed to devices at the other end of the tunnel and encapsulate these packets in other IP packets which have a header which includes as the destination address, the IP address of the untrusted side of the firewall at the other end of the tunnel. The payload sections of these packets are the original IP packets and are encrypted and decrypted at both ends of the private tunnel using the same encryption algorithm using the same key or keys.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method of routing packets at a first machine, the packets originating from one or more sources and destined for one or more destinations, the method comprising:
 receiving the packets;   filtering the received packets to distinguish first packets which are to be associated with a virtual private network from second packets which are not to be associated with the virtual private network;   encapsulating the first packets;   accessing a routing table and routing the encapsulated packets for forwarding of the first packets to a destination of the one or more destinations; and   accessing a routing table and routing the second packets for forwarding to a destination of the one or more destinations;   wherein routing the encapsulated packets includes using only one or more first routes to route the encapsulated packets, and wherein routing the second packets includes using only one or more second routes to route the second packets.   
     
     
         3 . The method of  claim 2 , wherein the method further comprises:
 identifying a first destination from the first packets;   identifying a second machine which is geographically associated with the first destination, wherein the second machine is configured to de-encapsulate ones of the encapsulated packets which are received by the second machine, and to forward the de-encapsulated packets to the first destination; and   transmitting the ones the encapsulated packets intended for the first destination via a non-blocking bandwidth route to the second machine for forwarding to the first destination.   
     
     
         4 . The method of  claim 2 , wherein the method further comprises:
 identifying a first destination from the first packets;   identifying a second machine which is geographically associated with the first destination, wherein the second machine is configured to de-encapsulate ones of the encapsulated packets which are received by the second machine, and to forward the de-encapsulated packets to the first destination; and   transmitting the ones the encapsulated packets intended for the first destination via a hop-count limited route to the second machine for forwarding to the first destination.   
     
     
         5 . The method of  claim 2 , wherein:
 accessing a routing table and routing the encapsulated packets for forwarding of the first packets to the one or more destinations comprises accessing at least one first routing table and routing the encapsulated packets via a route identified by the at least one first routing table; and   accessing a routing table and routing the second packets for forwarding to the one or more destinations comprises accessing at least one second routing table and routing the second packets via a route identified by the at least one second routing table.   
     
     
         6 . The method of  claim 2 , wherein receiving the packets includes using a channel service unit to receive the packets via a dedicated connection that directly links the first machine with a network associated with a predetermined client. 
     
     
         7 . The method of  claim 2 , wherein filtering the received packets includes examining header information of the received packets, comparing a network destination address from said header information with a predetermined address, and identifying ones of the received packets as ones of the first packets when the network address matches the predetermined address. 
     
     
         8 . The method of  claim 2 , wherein filtering the received packets includes examining header information of the received packets, comparing a network address from said header information with a list having at least one predetermined address, identifying ones of the received packets as ones of the first packets when the network address matches the predetermined address, and identifying ones of the received packets as ones of the second packets when the network address does not match any predetermined address in the list. 
     
     
         9 . The method of  claim 2 , wherein filtering the received packets includes determining whether the received packets are accompanied by a mnemonic label corresponding to the virtual private network and, for ones of the received packets which are companied by the mnemonic label, identifying the ones of the received packets as ones of the first packets. 
     
     
         10 . The method of  claim 2 , wherein the receiving the packets comprises receiving mixed traffic, comprising both the first packets and the second packets, from a first network. 
     
     
         11 . The method of  claim 2 , wherein the one or more first routes comprise one or more transmission paths that meet a minimum transmission requirement relative to other available transmission paths. 
     
     
         12 . The method of  claim 2 , wherein the method further comprises dynamically changing a routing table used to route the encapsulated packets. 
     
     
         13 . The method of  claim 12 , where dynamically changing the routing table includes changing the table responsive to at least one of:
 change associated with an available transmission path; and   a fault-tolerance criterion.   
     
     
         14 . A method of routing packets at a first machine, the packets originating from one or more sources and destined for one or more destinations, the method comprising:
 receiving the packets;   filtering the received packets to distinguish first packets which are to be associated with a virtual private network from second packets which are not to be associated with the virtual private network;   encapsulating the first packets;   accessing a routing table and routing the encapsulated packets for forwarding of the first packets to a destination of the one or more destinations; and   accessing a routing table and routing the second packets for forwarding to a destination of the one or more destinations;   wherein routing the encapsulated packets includes using only one or more preplanned first routes associated with a predetermined private tunnel to route the encapsulated packets, and wherein routing the second packets includes using only one or more second routes to route the second packets.   
     
     
         15 . The method of  claim 14 , wherein the method further comprises:
 identifying a first destination from the first packets;   identifying a second machine which is geographically associated with the first destination, wherein the second machine is configured to de-encapsulate ones of the encapsulated packets which are received by the second machine, and to forward the de-encapsulated packets to the first destination; and   transmitting the ones the encapsulated packets intended for the first destination via a non-blocking bandwidth route to the second machine for forwarding to the first destination.   
     
     
         16 . The method of  claim 14 , wherein the method further comprises:
 identifying a first destination from the first packets;   identifying a second machine which is geographically associated with the first destination, wherein the second machine is configured to de-encapsulate ones of the encapsulated packets which are received by the second machine, and to forward the de-encapsulated packets to the first destination; and   transmitting the ones the encapsulated packets intended for the first destination via a hop-count limited route to the second machine for forwarding to the first destination.   
     
     
         17 . The method of  claim 14 , wherein:
 accessing a routing table and routing the encapsulated packets for forwarding of the first packets to the one or more destinations comprises accessing at least one first routing table and routing the encapsulated packets via a route identified by the at least one first routing table; and   accessing a routing table and routing the second packets for forwarding to the one or more destinations comprises accessing at least one second routing table and routing the second packets via a route identified by the at least one second routing table.   
     
     
         18 . The method of  claim 14 , wherein receiving the packets includes using a channel service unit to receive the packets via a dedicated connection that directly links the machine with a network associated with a predetermined client. 
     
     
         19 . The method of  claim 14 , wherein filtering the received packets includes examining header information of the received packets, comparing a network destination address from said header information with a predetermined address, and identifying ones of the received packets as ones of the first packets when the network address matches the predetermined address. 
     
     
         20 . The method of  claim 14 , wherein filtering the received packets includes examining header information of the received packets, comparing a network address from said header information with a list having at least one predetermined address, identifying ones of the received packets as ones of the first packets when the network address matches the predetermined address, and identifying ones of the received packets as ones of the second packets when the network address does not match any predetermined address in the list. 
     
     
         21 . The method of  claim 20 , wherein filtering the received packets includes determining whether the received packets are accompanied by a mnemonic label corresponding to the virtual private network and, for ones of the received packets which are companied by the mnemonic label, identifying the received packets as ones of the first packets. 
     
     
         22 . The method of  claim 14 , wherein receiving the packets comprises receiving mixed traffic, comprising both the first packets and the second packets, from a first network, and wherein routing the encapsulated packets comprises transmitting the packets to a second machine, the second machine configured to de-encapsulate the encapsulated packets, the second machine also configured to route the de-encapsulated packets together with other traffic not associated with the virtual private network to the first destination. 
     
     
         23 . The method of  claim 14 , wherein the one or more first routes comprise one or more transmission paths that meet a minimum transmission requirement relative to other available transmission paths. 
     
     
         24 . The method of  claim 14 , wherein the method further comprises dynamically changing a routing table used to route the encapsulated packets. 
     
     
         25 . The method of  claim 24 , where dynamically changing the routing table includes changing the table responsive to at least one of:
 change associated with an available transmission path; and   a fault-tolerance criterion.   
     
     
         26 . A method of routing packets at a first machine, the packets originating from one or more sources and destined for one or more destinations, the method comprising:
 receiving the packets;   filtering the received packets to distinguish first packets which are to be associated with a virtual private network from second packets which are not to be associated with the virtual private network;   encrypting the first packets, and encapsulating the encrypted first packets;   accessing a routing table and routing the encapsulated packets for forwarding of the first packets to a destination of the one or more destinations; and   accessing a routing table and routing the second packets for forwarding to a destination of the one or more destinations;   wherein routing the encapsulated packets includes using only one or more preplanned first routes associated with a predetermined private tunnel to route the encapsulated packets to at least one predetermined second machine, the at least one predetermined second machine configured to de-encapsulate the encapsulated packets, and configured to decrypt the de-encapsulated packets and forward the decrypted packets to a destination of the one or more destinations;   wherein routing the second packets includes using only one or more second routes to route the second packets.   
     
     
         27 . The method of  claim 26 , wherein receiving the packets comprises receiving mixed traffic, comprising both the first packets and the second packets, from a first network, and wherein routing the encapsulated packets comprises transmitting the encapsulated packets to a second machine, the second machine configured to de-encapsulate the encapsulated packets transmitted to the second machine and do decrypt the de-encapsulated packets, the second machine also configured to route the decrypted packets together with other traffic not associated with the virtual private network to the first destination.

Join the waitlist — get patent alerts

Track US2019068404A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.