Multiple vpn multi-link traffic routing

By optimizing network traffic routing in a multi-VPN environment, the problems of insufficient network connectivity responsiveness and bandwidth utilization in different environments are solved, achieving more efficient network traffic routing and ensuring the stable operation of applications.

CN116648890BActive Publication Date: 2025-12-05DELL PROD LP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180085271.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-18
Filing Date
2021-04-29
Publication Date
2025-12-05
Estimated Expiration
2041-04-29

AI Technical Summary

Technical Problem

Existing technologies struggle to efficiently achieve seamless, reliable, and secure network connectivity across various network environments, especially when user locations change. Inadequate network traffic routing leads to insufficient responsiveness and bandwidth utilization in some applications.

Method used

By establishing multiple Virtual Private Network (VPN) connections, identifying the configuration policies of each VPN, configuring multiple queues, creating tunnel indicators, mapping network traffic queues to specific VPNs, optimizing network traffic queues, optimizing network traffic routing operations, and using a network traffic filtering platform to create many-to-many mappings, multi-link network traffic routing can be achieved.

Benefits of technology

It improves network connectivity responsiveness and bandwidth utilization, ensures stable operation of applications in different network environments, and provides a more efficient network traffic routing solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116648890B_ABST
    Figure CN116648890B_ABST
Patent Text Reader

Abstract

A system, method, and computer readable medium for performing traffic routing operations. The traffic routing operations include establishing a plurality of virtual private network (VPN) connections within an information handling system; obtaining a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type of a plurality of link types; configuring a plurality of queues for packets being communicated via the plurality of virtual private network connections, the plurality of queues being greater than the plurality of VPN connections; creating a tunnel indication for each of the plurality of VPN connections; mapping the tunnel indication for each of the plurality of VPN connections to a respective queue of the plurality of queues; and mapping each of the plurality of queues to a link of a particular VPN connection.
Need to check novelty before this filing date? Find Prior Art

Description

Background of the Invention Technical Field

[0002] This invention relates to information processing systems. More specifically, embodiments of the invention relate to performing network traffic routing operations. Background Technology

[0003] As the value and uses of information continue to increase, individuals and businesses are seeking more ways to process and store it. One option available to users is an information processing system. Information processing systems typically process, compile, store, and / or transmit information or data for business, personal, or other purposes, thereby allowing users to leverage the value of information. Because the needs and requirements of technology and information processing can vary between different users or applications, information processing systems can also vary in terms of what information is processed, how it is processed, how much information is processed, stored, or transmitted, and how quickly and efficiently it can be processed, stored, or transmitted. Variations in information processing systems allow them to be general-purpose or configured for specific users or purposes (such as financial transaction processing, flight booking, corporate data storage, or global communications). Furthermore, information processing systems can include a variety of hardware and software components that can be configured to process, store, and transmit information, and can include one or more computer systems, data storage systems, and networking systems. Summary of the Invention

[0004] In one embodiment, the present invention relates to a method for performing traffic routing operations, the method comprising: establishing a plurality of Virtual Private Network (VPN) connections within an information processing system; obtaining a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type among a plurality of links; configuring a plurality of queues for packets being transmitted via the plurality of VPN connections, the plurality of queues being larger than the plurality of VPN connections; creating a tunnel indication for each of the plurality of VPN connections; mapping the tunnel indication for each of the plurality of VPN connections to a corresponding queue among the plurality of queues; and mapping each queue among the plurality of queues to a link of a particular VPN connection.

[0005] In another embodiment, the present invention relates to a system comprising: a processor; a data bus coupled to the processor; and a non-transitory computer-readable storage medium embodying computer program code coupled to the data bus, the computer program code interacting with a plurality of computer operations and including instructions executable by the processor and configured to: establish a plurality of Virtual Private Network (VPN) connections within an information processing system; obtain a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type among a plurality of links; configure a plurality of queues for packets being transmitted via the plurality of VPN connections, the plurality of queues being larger than the plurality of VPN connections; create a tunnel indication for each of the plurality of VPN connections; map the tunnel indication for each of the plurality of VPN connections to a corresponding queue among the plurality of queues; and map each queue among the plurality of queues to a link of a particular VPN connection.

[0006] In another embodiment, the present invention relates to a computer-readable storage medium embodying computer program code including computer-executable instructions configured to: establish a plurality of Virtual Private Network (VPN) connections within an information processing system; obtain a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one link type supported by a plurality of links; configure a plurality of queues for packets being transmitted via the plurality of VPN connections, the plurality of queues being larger than the plurality of VPN connections; create a tunnel indication for each of the plurality of VPN connections; map the tunnel indication for each of the plurality of VPN connections to a corresponding queue in the plurality of queues; and map each queue in the plurality of queues to a link of a particular VPN connection. Attached Figure Description

[0007] The invention will be better understood by referring to the accompanying drawings, and many of its objectives, features, and advantages will become apparent to those skilled in the art. The same reference numerals are used throughout the several drawings to refer to the same or similar elements.

[0008] Figure 1 A general illustration of the components of an information processing system implemented in the systems and methods of the present invention is shown.

[0009] Figure 2 This is a block diagram of an intelligent connected environment;

[0010] Figure 3 A simplified block diagram of the smart connectivity framework is shown;

[0011] Figure 4This illustrates the operating modes used when performing network traffic routing operations; and

[0012] Figure 5 A flowchart illustrating the execution of multi-link network traffic routing operations is shown. Detailed Implementation

[0013] A system, method, and computer-readable medium for performing network traffic routing operations are disclosed. Certain aspects of the invention reflect the growing need to efficiently retrieve data from where it may be stored or generated to where it is needed, whether in data centers, the cloud, the network edge, or a combination thereof. Certain aspects of the invention also reflect the increasing number of network-enabled devices and network connectivity options. These network connectivity options include: personal area networks (PANs), such as Bluetooth; wireless local area networks (WLANs), such as Wi-Fi networks; wireless wide area networks (WWANs), such as 3G, 4G, and 5G cellular networks; satellite networks; and wired networks, such as traditional LANs; and wide area networks (WANs), such as the Internet.

[0014] Certain aspects of this invention reflect the recognition that today's network-enabled productivity, collaboration, work, and entertainment activities are increasingly taking place anywhere and anytime. Similarly, certain aspects of this invention reflect the recognition that these activities are becoming an integral part of daily life, and thus leading to an increased expectation of the need for network connectivity anytime, anywhere. Furthermore, certain aspects of this invention reflect the recognition that users also expect network connectivity to be seamless, reliable, and secure, regardless of the underlying technology used to provide that connectivity.

[0015] For the purposes of this disclosure, an information processing system may include any tool or set of tools operable for calculating, classifying, processing, transmitting, receiving, retrieving, creating, switching, storing, displaying, indicating, detecting, recording, reproducing, processing, or utilizing information, intelligence, or data of any form for commercial, scientific, control, or other purposes. For example, an information processing system may be a personal computer, a network storage device, or any other suitable device, and may vary in size, shape, performance, functionality, and price. An information processing system may include random access memory (RAM), one or more processing resources (such as a central processing unit (CPU) or hardware or software control logic), ROM, and / or other types of non-volatile memory. Additional components of the information processing system may include one or more disk drives, one or more network ports for communicating with external devices, and various input and output (I / O) devices (such as a keyboard, mouse, and video display). The information processing system may also include one or more buses operable for transmitting communication between various hardware components.

[0016] Figure 1 This is a general illustration of an information processing system 100 that can be used to implement the systems and methods of the present invention. The information processing system 100 includes a processor (e.g., a central processing unit or “CPU”) 102, input / output (I / O) devices 104 (such as a display, keyboard, mouse, touchpad, or touchscreen, and associated controllers), a hard disk drive or disk storage device 106, and various other subsystems 108. In various embodiments, the information processing system 100 also includes a network port 110 operable to connect to a network 140, which is also accessible by a service provider server 142. The information processing system 100 also includes a system memory 112 interconnected with the aforementioned devices via one or more buses 114. The system memory 112 also includes an operating system (OS) 116, and in various embodiments may also include a smart connection system 118. In one embodiment, the information processing system 100 is capable of downloading the smart connection system 118 from the service provider server 142. In another embodiment, the smart connection system 118 is provided as a service from the service provider server 142.

[0017] In some embodiments, the intelligent connectivity system 118 may be implemented as including a traffic component 120, a persistence component 122, a context component 124, a security component 126, and a management component 128, or combinations thereof, as described in more detail herein. In some embodiments, the intelligent connectivity system 118 may be implemented to perform intelligent connectivity operations, as described in more detail herein. In some embodiments, the intelligent connectivity operations may be performed by the intelligent connectivity system 118 during operation of the information processing system 100. In some embodiments, the execution of the intelligent connectivity operations may enable improved network connectivity for the information processing system 100.

[0018] Figure 2 This is a block diagram of an intelligent connectivity environment implemented according to an embodiment of the present invention. In some embodiments, the intelligent connectivity environment 200 may include an intelligent connectivity system 118, as described in more detail herein. In some embodiments, the intelligent connectivity system 118 may be implemented on a user device 204. As used herein, user device 204 broadly refers to an information processing system, such as a personal computer, laptop computer, tablet computer, personal digital assistant (PDA), smartphone, mobile phone, or other device capable of transmitting and processing data. In some embodiments, user 202 may use user device 204 to interact with intelligent connectivity system 118.

[0019] In some implementations, the intelligent connectivity environment 200 may include a local area network (LAN) 224, a personal area network (PAN) 206, a wireless local area network (WLAN), a wireless wide area network (WWAN) 226, a satellite network 270, a public switched telephone network (PSTN) 228, and a wide area network (WAN) 230 (such as the Internet), or a combination thereof. In some implementations, the LAN 224 may be based on one or more protocols, such as Ethernet, Asynchronous Transfer Mode (ATM), Token Ring, or Fiber Distributed Data Interface (FDDI). In some implementations, the PAN may be based on one or more protocols typically associated with Bluetooth, ZigBee, or Ultra Wideband (UWB). In some implementations, the WLAN may be based on one or more variations of the IEEE 802.11 wireless communication standard. In some implementations, the WWAN 226 may be based on one or more generations of known cellular network protocols, commonly referred to as 3G, 4G, 5G, etc. In some implementations, the WAN 230 may be based on one or more protocols, such as X.25, Frame Relay, Asynchronous Transfer Mode (ATM), or Telecommunications Protocol / Internet Protocol (TCP / IP).

[0020] In some implementations, user device 204 may be implemented with communication hardware and software that allows it to communicate with one or more wirelessly enabled input / output (I / O) devices via a PAN 206 network link. Examples of such wirelessly enabled I / O devices include a keyboard 208, a mouse 210, a game controller 212, headphones or earphones 214, headsets 216, etc. Those skilled in the art will be familiar with network links; as commonly used, a network link refers to the physical and logical network components used to interconnect hosts or nodes in a network. Those skilled in the art will also recognize that such network links are typically established through the link layer of a telecommunications protocol stack, such as the Internet Protocol Suite or the Open Systems Interconnection (OSI) model. As is typically implemented, a link layer refers to a set of methods and communication protocols that are limited to the network link to which the host (such as the particular user device 204) is physically connected.

[0021] In some embodiments, user equipment 204 may be implemented using communication hardware and software that allows it to communicate with one or more access points 234 via a PAN 244 network link or a WLAN 244 network link or both. Those skilled in the art will be familiar with wireless access point (AP) 234, which generally refers to networking hardware that allows a wirelessly enabled device (such as a particular user equipment 204) to connect to a wired network (such as LAN 224). In various embodiments, AP 234 may be implemented as a standalone device. In some of these embodiments, AP 234 may be implemented as connected to router 232 via LAN 224. In some embodiments, the functionality of AP 234 may be implemented as an integrated component of router 232.

[0022] In some embodiments, user equipment 204 may be implemented with communication hardware and software that allows it to communicate with one or more peripheral devices 236 via a PAN 246 network link, a LAN 248 network link, or a WLAN 250 network link, or a combination thereof. In some embodiments, user equipment 204 may be implemented with communication hardware and software that allows it to communicate with one or more routers 232 via a LAN 240 network link, a WLAN 238 network link, or both. In some embodiments, user equipment 204 may be implemented with communication hardware and software that allows it to communicate with one or more WWAN 226 cell towers 260 via a WWAN 262 network link. In some embodiments, user equipment 204 may be implemented with communication hardware and software that allows it to communicate with one or more satellites 270 via a satellite 276 network link.

[0023] In various embodiments, a specific cell tower 260, or a specific satellite 270, or a combination of both, may be implemented individually or in combination to provide user device 204 with certain location data 278 familiar to those skilled in the art. In some embodiments, user device 204 may be configured to receive such location data 278, which is used as a data source for determining the location '1' 220 to 'n' 222 of user device 204. In some embodiments, location data 278 may include Global Positioning System (GPS) data provided by GPS satellites 270. In some embodiments (not shown), location data 278 may include various Internet Protocol (IP) or other network address information assigned to user device 204. In some embodiments (not shown), location data 278 may also be provided by router 232 or AP 234, or both.

[0024] In some embodiments, one or more satellites 270 may be implemented to establish a satellite network link 274 to base station 272 using known satellite communication protocols. In various embodiments, base station 272 may further be implemented to connect to PSTN 228, which in some embodiments may also be implemented to connect to one or more WWANs 230, or one or more WANs 230, or a combination thereof. In various embodiments, one or more LANs 224 may be implemented to connect to one or more WANs 230, or a combination thereof. In some of these embodiments, one or more routers 232 may be implemented individually or in combination to connect a particular LAN 224 to a particular WAN 230.

[0025] In various embodiments, when user device 204 moves from position '1' 220 to position 'n' 222, the intelligent connectivity system 118 can be implemented to establish specific network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276. In some of these embodiments, the establishment of specific network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276 can be based on the availability of connectivity to the corresponding network. In various embodiments, the intelligent connectivity system 118 can be implemented to switch from one network link 206, 238, 240, 242, 244, 246, 248, 250, 262, 276 to another network link. In some of these embodiments, this switching can be based on corresponding signal strength, available bandwidth, network latency, or a combination thereof, associated with the availability of connectivity to the corresponding network.

[0026] In some implementations, the intelligent connectivity system 118 may be configured to switch from one network link 206, 238, 240, 242, 244, 246, 248, 250, 262, 276 to another network link based on the user device 204 being located at specific locations '1' 220 to 'n' 222. In various implementations, the intelligent connectivity system 118 may be configured to establish two or more simultaneous network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276. In some of these implementations, the bandwidth corresponding to each of the two or more network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276 may be combined to provide aggregated network link bandwidth for use by the user device.

[0027] In various embodiments, the intelligent connectivity system 118 may be implemented to assign network connections corresponding to specific software application or user device 204 processes to specific network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276. In some embodiments, the intelligent connectivity system 118 may be implemented to assign two or more software application or user device 204 processes to two or more network links respectively based on the corresponding attributes of the two or more network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276. For example, the intelligent connectivity system 118 may be implemented to assign a wirelessly enabled game controller 212 to the PAN 206 link, while information generated and received by a game executed on the user device 204 may be assigned to the WLAN 238 network link.

[0028] In some of these implementations, assigning two or more software applications or user device 204 processes, or combinations thereof, to two or more network links 206, 238, 240, 242, 244, 246, 248, 250, 262, 276, respectively, may be done depending on where user device 204 is located, from '1' 220 to 'n' 222. As an example, at location '1' 220, only a lower-speed (e.g., 300 Mbps) WLAN 238 network link may be available, but at location 'n' 222, both a high-speed (e.g., 100 Gbps) LAN 240 network link and a relatively high-speed (e.g., 1.7 Gbps) WLAN 238 network link may be available. In this example, user 202 may want to play a specific online game while conducting an online chat session, regardless of whether they are at location '1' 220 or 'n' 222. Continuing with this example, the bandwidth of the WLAN 238 network link at location '1'220 may be insufficient to support the network connectivity requirements of online games. Therefore, the additional overhead of network traffic associated with online chat sessions may cause the game to not perform as responsively as expected.

[0029] However, the intelligent connectivity system 118 can be implemented to assign online chat sessions to the higher-speed WLAN 238 network link available at location "n" 222 and online games to the high-speed LAN 240 network link available at location "n" 222. Thus, since the LAN 238 network link available at location "n" 220 provides a speed of 100Gbps, the responsiveness of online games will likely be improved, while online chat sessions will be fully supported by the 1.7Gbps speed of the WLAN 240 network link. Those skilled in the art will recognize that many such embodiments and examples are possible. Therefore, the foregoing is not intended to limit the spirit, scope, or intent of the invention.

[0030] In some embodiments, the intelligent connectivity system 118 may be implemented to establish and manage one or more Virtual Private Network (VPN) connections over one or more corresponding network links. Those skilled in the art will be familiar with VPNs, which, as commonly implemented, use known tunneling protocols to extend a private network (such as a private LAN 224) across a public WAN 230 (such as the Internet) to enable users 202 to send and receive data from external resources (such as remote servers) using their user equipment 204 as if it were directly connected to the private network. Some embodiments of the invention reflect the understanding that a single VPN may not always be sufficient for certain operating modes, as described in more detail herein.

[0031] Therefore, in some implementations, the intelligent connectivity system 118 can also be implemented to perform multi-link network traffic routing operations. As used herein, multi-link traffic routing operation broadly refers to any operation performed to route network traffic over two or more network links, as described in more detail herein. In various implementations, as described in more detail herein, multi-link traffic operations can be performed to perform many-to-many mappings of multiple VPN connections to multiple corresponding network links. In some of these implementations, the many-to-many mapping can be optimized for a specific multi-link configuration. As used herein, because it involves many-to-many mappings of multiple VPN connections to multiple corresponding network links, optimization broadly refers to using certain network link attributes (e.g., available bandwidth, congestion, latency, signal strength, supported protocols, etc.) to determine which network link is best suited for the allocation of a particular VPN.

[0032] In some implementations, multi-link traffic operation is initiated by identifying concurrently operating VPNs. In various implementations, the intelligent connectivity system 118 may be configured to perform certain actions to identify such concurrently operating VPNs. A configuration policy is then determined, respectively, for each identified VPN. In various implementations, for each VPN, the configuration policy may be configured to include certain information associated with the types of network links supported, the types of traffic that each network link can route, and so on.

[0033] As described in more detail herein, a network filtering driver (NFD) is then used to create n+1 first-in-first-out (FIFO) network traffic queues, where “n” is defined as the number of previously identified VPNs. Subsequently, at startup, a network tunnel indicator is created for each identified VPN. In some implementations, the network tunnel indicator may be implemented as a network tunnel pointer familiar to those skilled in the art. As an example, network tunnel pointers '1' and '2' may be generated separately for VPNs '1' and '2'.

[0034] Subsequently, the associated configuration policy for each VPN is transmitted to the NFD. In some embodiments, the associated configuration policy for a VPN can be implemented to define which networks do not need to use the VPN. In some embodiments, the associated configuration policy for a VPN can be implemented to define which types of network links (e.g., WLAN, WWAN 226, etc.) are supported for the VPN. In some embodiments, a configuration policy can be implemented to define which network traffic is allowed to be routed to which VPN. In some embodiments, the associated configuration policy for each VPN can be implemented to create a list of available VPNs and their associated available network links. Those skilled in the art will recognize that many such embodiments using such configuration policies are possible. Therefore, the foregoing is not intended to limit the spirit, scope, or intent of the invention.

[0035] Subsequently, the intelligent connectivity system 118 can receive requests from the operating system (OS) of the user device 204 to allocate or reassign existing network traffic queues to previously identified VPNs. Continuing the previous example, network traffic queue "1" → network tunnel "1", network traffic queue "2" → network tunnel "1", and network traffic queue "3" → network tunnel without non-VPN network traffic. If such a request is received, it is determined whether a new network traffic queue is needed. If so, a new network traffic queue is generated and mapped to the associated network tunnel. Subsequently, or if it was previously determined that a new network traffic queue is not needed, each available network traffic queue is mapped to an available network link, and then the corresponding new VPN is established.

[0036] Figure 3A simplified block diagram of an intelligent connectivity framework implemented according to an embodiment of the present invention is shown. In various embodiments, the intelligent connectivity framework 300 may be implemented as including certain computing and communication hardware 302, certain basic software and firmware 304, an intelligent connectivity system 118, and one or more operating modes 312, or combinations thereof. In some embodiments, the computing and communication hardware 302 and the basic software and firmware 304, or combinations thereof, may be implemented on a user device, as described in more detail herein.

[0037] In various embodiments, certain base software and firmware 304 may be implemented using certain computing and communication hardware 302, as described in more detail herein, to detect the availability of connectivity to a particular network. In various embodiments, certain base software and firmware 304 may also be implemented using certain computing and communication hardware 302 to establish a network link with the detected network, as also described in more detail herein, for transmitting information. In some embodiments, the information may be transmitted via one or more Virtual Private Network (VPN) connections. In some embodiments, the base software and firmware 304 may be implemented as including a network traffic filtering platform 306, as described in more detail herein.

[0038] In some embodiments, the smart connectivity system 118 may be implemented to perform smart connectivity operations. As used herein, smart connectivity operations are broadly defined as any operation that enhances the ability of a user device to utilize network connectivity provided by one or more networks (as described in more detail herein). In various embodiments, the smart connectivity system 118 may be implemented to perform specific smart connectivity operations, either alone or in combination, using certain computing and communication hardware 302 and certain underlying software and firmware 304.

[0039] In some embodiments, the intelligent connectivity system 118 may be implemented as including a traffic component 120, a persistence component 122, a context component 124, a security component 126, and a management component 128, or a combination thereof. In some embodiments, the traffic component 120, persistence component 122, context component 124, security component 126, or management component 128 may be implemented individually or in combination to perform specific intelligent connectivity operations. In some embodiments, the traffic component 120 may be implemented to determine whether one or more networks are available to provide network connectivity to the information processing system 100. In some embodiments, the traffic component 120 may be implemented to use one or more networks individually or in combination to provide network connectivity to a user device.

[0040] In some embodiments, the persistence component 122 may be implemented to use two or more networks, individually or in combination, to provide network connectivity continuity to the user device. In some embodiments, the context component 124 may be implemented to select one or more networks to provide network connectivity to the user device based on the context in which the user device is being used. In some embodiments, the security component 126 may be implemented to select one or more networks to provide secure network connectivity to the user device. In various embodiments, the management component 128 may be implemented to manage certain aspects of the network connectivity provided to the user device by one or more networks.

[0041] In various embodiments, the intelligent connectivity system 118 may be implemented to provide a certain network connection to the user device at a specific time or location, or both, based on the user device's current operating mode 312. As used herein, the user device's operating mode 312 broadly refers to the purpose that it can be used to achieve. In some embodiments, the user device's operating mode 312 may be associated with using a particular user device to achieve productivity 314, collaboration 316, work 318, or entertainment 320, or a combination thereof.

[0042] As used herein, and because it relates to operational mode 312, productivity 314 broadly refers to the ratio of output to input. For example, a consultant at a construction company might need to estimate the cost of a project at a client's work site. In this example, the consultant could input certain information related to the project (such as the quantity and cost of certain materials and expected labor costs) into a project estimation application running on a mobile user device. Continuing with this example, the estimator can achieve a certain level of productivity 314 by simply using the project estimation application to generate an initial estimate.

[0043] However, if the user device can establish two Virtual Private Network (VPN) connections using available network connectivity—one to the consultant's resources and the other to the client's resources—the consultant can achieve a higher level of productivity.314 If so, the consultant can use the first VPN connection to securely access past estimates for similar projects, which can then be used to prepare the final estimate for the client. Once the final estimate is complete, the second VPN connection can be used to present the final estimate to the client.

[0044] As used herein, and because it relates to mode 312 of operation, collaboration 316 broadly refers to actions involving interaction with someone to achieve a common purpose. Those skilled in the art will recognize that many examples of such a common purpose are possible. As one example, a common purpose could be a group of individuals with shared interests using their respective user devices to participate in a video conference to produce or create something. As another example, a common purpose could be a group of friends using their respective user devices to meet regularly via video conference to maintain their relationship.

[0045] As used herein, and because it relates to mode 312 of operation, work 318 broadly refers to the effort or exertion required to produce or accomplish something. Those skilled in the art will recognize that work can take many forms. As an example, a pest control worker can be paid for work. In this example, the pest control worker might stop at a coffee shop, access its public Wi-Fi network, and establish a VPN connection to their office. Once connected, the pest control worker can securely download their tasks for the day. Then, one by one, they proceed to each location and complete their tasks. Continuing with this example, after completing each task, the pest control worker can then complete a report. Once completed, the pest control worker can access a cellular network, establish a VPN connection, and then securely upload each report to their office.

[0046] Some embodiments of the present invention reflect the understanding that not all assignments 318 are performed for monetary reward. For example, some assignments 318 may be performed for educational purposes. To illustrate this example, a student may use a mobile user device, wherever they are, to access knowledge resources via a network connection, use those resources to complete assignments, and then submit the assignments using the same or a different network connection.

[0047] As another example, some work 318 can be performed for altruistic reasons. To illustrate this example, a member of a nonprofit organization might volunteer to check on the health of elderly residents. In this example, the volunteer could use their home Wi-Fi connection to establish a VPN connection with the nonprofit. Once the VPN connection is established, they download a list of residents planned for the day and their addresses to their tablet. They then use the tablet to record the status of each resident throughout the morning. The volunteer then stops at a restaurant for lunch. After ordering their food, they access the restaurant's Wi-Fi network, establish a VPN connection with the nonprofit, and upload a report summarizing their morning's work.

[0048] As used herein, and because it relates to mode 312 of operation, entertainment 320 broadly refers to the act of providing or being provided with entertainment or enjoyment. Those skilled in the art will recognize that entertainment can take many forms. As an example, a user can use a mobile device to wirelessly connect to their home's local area network (LAN). Once the connection is established, the user can access a streaming movie service. Once accessed and a movie selected, the user can wirelessly connect a pair of headphones to their mobile device using Bluetooth. Once connected, the user can watch the movie on their mobile device while simultaneously listening to the movie's audio through their wireless headphones.

[0049] As another example, a user can use a gaming computer to play online multiplayer games. In this example, the user can have the gaming computer use a wired connection to their LAN at home, and their mobile phone use a cellular network connection. Continuing with this example, the gaming computer can use the wired connection to the LAN to ensure that any available bandwidth on the LAN is dedicated to the online game itself. Similarly, the user can use the mobile phone's cellular connection to communicate with other players in the online game.

[0050] Certain embodiments of the invention reflect that a particular operating mode 312 can be associated with simultaneously using a particular user device to achieve productivity 314, collaboration 316, work 318, or entertainment 320, or a combination thereof. As an example, a game developer can use a user device in conjunction with one or more network connections while developing a game. In this example, the developer can use the user device and the one or more network connections to improve their productivity 314, collaboration with colleagues 316, work 318 in various aspects of the game, while always deriving entertainment 320 from the game itself. Those skilled in the art will recognize that many such examples of operating modes 312 are possible. Therefore, the foregoing is not intended to limit the spirit, scope, or intent of the invention.

[0051] Figure 4 The diagram illustrates the operating modes used when performing network traffic routing operations according to embodiments of the invention. In some embodiments, network traffic routing operation 400 may be implemented as including operation in user mode 402 and operation in kernel mode 404. Those skilled in the art will recognize operation in user mode 402, which refers to the operation when the operating system (OS) of an information processing system (IHS) is running user applications such as word processors and spreadsheet programs. Those skilled in the art will also recognize that core OS components run in kernel mode 404. Similarly, drivers typically run in kernel mode 404, although some drivers may be implemented to run in user mode 402.

[0052] In some implementations, a transition from user mode 402 to kernel mode 404 may occur when OS service 412 invokes loadable kernel module (LKM) 414. In some implementations, OS service 412 may be implemented as network OS service 412. In some implementations, network OS service 412 may be invoked to establish a network link with a specific network, as described in more detail herein.

[0053] Those skilled in the art will be familiar with LKM 414, an object file containing the code (also known as the base kernel) used to extend the running kernel of an operating system (OS). As is typically implemented, LKM 414 is used to add support for new hardware, such as device drivers or file systems, or to add system calls, or combinations thereof. It is also a common practice to unload LKM 414 when the functionality it provides is no longer needed, in order to free up memory and other resources.

[0054] Those skilled in the art will also recognize that most current Unix-like systems and LKM 414 is supported, although they may be referred to by different names. For example, LKM is called a kernel loadable module (kld) in FreeBSD. In the context of kernel extensions (kexts), they are referred to as kernel extensions. It is called a kernel extension module in [the context of the kernel], and in [the context of the kernel extension module] In this context, it is referred to as a kernel-mode driver. Other known names for LKM 414 include Downloadable Kernel Module (DKM), Kernel Loadable Module (KLM), and Simple Kernel Module (KMOD).

[0055] As those skilled in the art will recognize, the LKM executes as part of an executable program in kernel mode 414, which includes kernel-mode OS components 404 that manage input / output (I / O) and shared memory 422 components (often referred to as the I / O control system), processes and threads, security, etc. Those skilled in the art will also recognize that the LKM 414 is typically layered, with higher-level drivers typically receiving data from applications, filtering the data, and passing the data to lower-level drivers that support device functionality. In some embodiments, network traffic filtering platform 206 performs network filtering operations. In some embodiments, network traffic filtering operations receive data from a specific LKM 414, filter the data, and pass the filtered data to the OS network driver. In some embodiments, network traffic filtering platform 306 may be implemented as... Filtering platform. Similarly, in some implementations, the OS network driver 426 can be in various... Driver Model (WDM) is a driver implementation.

[0056] Figure 5 A flowchart illustrating a multi-link network traffic routing operation performed according to an embodiment of the present invention is shown. In this embodiment, the multi-link network traffic routing operation is initiated in step 503, followed by the identification of concurrently operating Virtual Private Networks (VPNs) in step 504. Then, in step 506, a configuration policy associated with each identified VPN is determined. As described in more detail herein, a network traffic filtering platform is then used in step 508 to create n+1 First-In-First-Out (FIFO) network traffic queues, where “n” is defined as the number of previously identified VPNs. Subsequently, at startup, a network tunnel pointer familiar to those skilled in the art is created for each identified VPN in step 510.

[0057] Then, in step 512, the associated configuration policy for each VPN is transmitted to the network traffic filtering platform. Subsequently, in step 514, a request is received from the user device's operating system (OS) to allocate or reassign existing network traffic queues to previously identified VPNs. Then, in step 516, it is determined whether new network traffic queues are needed. If so, in step 518, new network traffic queues are generated and mapped to their associated VPN tunnels. Thereafter, or if it is determined in step 516 that new network traffic queues are not needed, in step 520, each available network traffic queue is mapped to an available network link, and subsequently, in step 522, a new VPN is established.

[0058] Then, in step 524, the OS of the user device performs ongoing operations to monitor network traffic, network links, and the status of each VPN in response to the occurrence of a network traffic queue remapping event. Then, in step 526, it is determined whether a network traffic queue remapping event has occurred. If yes, the process continues to step 514. Otherwise, in step 528, it is determined whether to terminate the multi-link network traffic routing operation. If no, the process continues to step 524. Otherwise, the multi-link network traffic routing operation terminates in step 530.

[0059] As will be understood by those skilled in the art, this invention can be embodied as a method, system, or computer program product. Therefore, embodiments of the invention can be implemented entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in a combination of software and hardware. These different embodiments are generally referred to herein as “circuit,” “module,” or “system.” Furthermore, the invention can take the form of a computer program product on a computer-usable storage medium embodying computer-usable program code.

[0060] Any suitable computer-usable or computer-readable medium may be used. Computer-usable or computer-readable media can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses. More specific examples (not an exhaustive list) of computer-readable media will include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable optical disc read-only memory (CD-ROM), optical storage devices, or magnetic storage devices. In the context of this document, computer-usable or computer-readable storage media can be any medium that can contain, store, transmit, or transfer programs for use by or in connection with an instruction execution system, device, or apparatus.

[0061] The computer program code for performing the operations of this invention can be written using object-oriented programming languages ​​such as Java, Smalltalk, and C++. However, it can also be written using conventional programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer via a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0062] Embodiments of the invention are described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams.

[0063] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of writing, the article of writing including instruction means that implement the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0064] Computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus, thereby producing a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0065] This invention is well-suited to achieving the aforementioned advantages, as well as other inherent advantages therein. Although the invention has been depicted, described, and defined by reference to specific embodiments thereof, such reference does not imply limitation of the invention, nor should such limitation be inferred. The invention is capable of considerable modifications, alterations, and equivalents in form and function, as will be apparent to those skilled in the art. The depicted and described embodiments are merely exemplary and do not exhaustively cover the scope of the invention.

[0066] Therefore, the invention is intended to be limited only by the spirit and scope of the appended claims, and the equivalents are fully understood in all respects.

Claims

1. A computer-implemented method for performing traffic routing operations, comprising: establishing a plurality of virtual private network (VPN) connections via an information handling system; obtaining a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type of a plurality of links; configuring a plurality of queues for packets being communicated via the plurality of virtual private network connections, the plurality of queues being greater than the plurality of VPN connections; creating a tunnel indication for each of the plurality of VPN connections; mapping the tunnel indication for each of the plurality of VPN connections to a respective queue of the plurality of queues; and mapping each of the plurality of queues to a link of a particular VPN connection, the mapping using the configuration policy for each of the plurality of VPN connections.

2. The method of claim 1, wherein: the traffic routing operations comprise user mode operations, the user mode operations performing operating system services.

3. The method of claim 1, wherein: the traffic routing operations comprise kernel mode operations, the kernel mode operations performing multi-link network traffic operations, the multi-link network traffic operations interacting with an input / output control system.

4. The method of claim 3, wherein: the input / output control system comprises a filtering platform, the filtering platform performing network filtering operations.

5. The method of claim 3, wherein: the input / output control system comprises a loadable kernel module, the loadable kernel module interacting with an input / output control system of the information handling system.

6. The method of claim 1, further comprising: performing a many-to-many mapping of the plurality of VPN connections to the plurality of links, the many-to-many mapping optimized for multi-link configurations.

7. A system, comprising: a processor; a data bus coupled to the processor; and a non-transitory computer readable storage medium embodying computer program code, the non-transitory computer readable storage medium coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for: establishing a plurality of virtual private network (VPN) connections via an information handling system; obtaining a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type of a plurality of links; configuring a plurality of queues for packets being communicated via the plurality of virtual private network connections, the plurality of queues being greater than the plurality of VPN connections; creating a tunnel indication for each of the plurality of VPN connections; mapping the tunnel indication for each of the plurality of VPN connections to a respective queue of the plurality of queues; and mapping each of the plurality of queues to a link of a particular VPN connection, the mapping using the configuration policy for each of the plurality of VPN connections.

8. The system of claim 7, wherein: ​ ​ ​ Traffic routing operations include user mode operations that perform operating system services.

9. The system of claim 7, wherein: Traffic routing operations include kernel mode operations that perform multi-link network traffic operations that interact with an input / output control system.

10. The system of claim 9, wherein: The input / output control system includes a filtering platform that performs network filtering operations.

11. The system of claim 9, wherein: The input / output control system includes a loadable kernel module that interacts with an input / output control system of the information processing system.

12. The system of claim 7, wherein the instructions executable by the processor are further configured for: performing a many-to-many mapping of the multiple VPN connections to the multiple links, the many-to-many mapping optimized for a multi-link configuration.

13. A non-transitory computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for: establishing a plurality of virtual private network (VPN) connections via an information processing system; obtaining a configuration policy for each of the plurality of VPN connections, the configuration policy for each of the plurality of VPN connections including an indication of at least one supported link type of a plurality of links; configuring a plurality of queues for packets being communicated via the plurality of virtual private network connections, the plurality of queues greater than the plurality of VPN connections; creating a tunnel indication for each of the plurality of VPN connections; mapping the tunnel indication for each of the plurality of VPN connections to a respective queue of the plurality of queues; and mapping each of the plurality of queues to a link of a particular VPN connection, the mapping using the configuration policy for each of the plurality of VPN connections.

14. The non-transitory computer-readable storage medium of claim 13, wherein: Traffic routing operations include user mode operations that perform operating system services.

15. The non-transitory computer-readable storage medium of claim 13, wherein: Traffic routing operations include kernel mode operations that perform multi-link network traffic operations that interact with an input / output control system.

16. The non-transitory computer-readable storage medium of claim 15, wherein: The input / output control system includes a filtering platform that performs network filtering operations.

17. The non-transitory computer-readable storage medium of claim 15, wherein: The input / output control system includes a loadable kernel module that interacts with an input / output control system of the information processing system.

18. The non-transitory computer-readable storage medium of claim 13, wherein the computer executable instructions are further configured for: ​ Performing a many-to-many mapping of the plurality of VPN connections to the plurality of links, the many-to-many mapping optimized for multi-link configurations.

19. The non-transitory computer-readable storage medium of claim 13, wherein: The computer-executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory computer-readable storage medium of claim 13, wherein: The computer-executable instructions are provided to a user on-demand by a service provider.

Citation Information

Patent Citations

  • Message processing method and device

    CN102164069A