Patent · US Active

Virtual private network (VPN)-as-a-service with delivery optimizations while maintaining end-to-end data security

US11411996B2 · kind B2 · utility

4Cited by
6References
8Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 23, 2019
Grant dateAug 9, 2022
Priority date
Expiry dateApr 23, 2039

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L45/50
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A mechanism to facilitate a private network (VPN)-as-a-service, preferably within the context of an overlay IP routing mechanism implemented within an overlay network. A network-as-a-service customer operates endpoints that are desired to be connected to one another securely and privately using the overlay IP (OIP) routing mechanism. The overlay provides delivery of packets end-to-end between overlay network appliances positioned at the endpoints. During such delivery, the appliances are configured such that the data portion of each packet has a distinct encryption context from the encryption context of the TCP/IP portion of the packet. By establishing and maintaining these distinct encryption contexts, the overlay network can decrypt and access the TCP/IP flow. This enables the overlay network provider to apply one or more TCP optimizations. At the same time, the separate encryption contexts ensure the data portion of each packet is never available in the clear at any point during transport.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.