EP4779937A2

System and method for a global virtual network

Abstract

Systems and methods for connecting devices via a virtual global network are disclosed. In one embodiment the network system may comprise a first device in communication with a first endpoint device and a second device in communication with a second endpoint device. The first and second devices may be connected with a communication path. The communication path may comprise one or more intermediate tunnels connecting each endpoint device to one or more intermediate access point servers and one or more control servers.

EP4779937A2, drawing sheet 1
Sheet 1 of 69

Term

9.3 yearsto projected expiry

Projected expiry 28 January 2036, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 1 independent, 14 dependent

  1. 1
    A method performed by a plurality of processors, the method comprising:constructing a multi-layer virtual network over the top of an underlying extended infrastructure comprising network service provided by multiple network service providers, the multi-layer virtual network comprising: a plurality of endpoint devices, a plurality of access point servers, for each given access point server of the plurality of access point servers, a respective plurality of intermediate secure tunnel connections formed over the top of one or more portions of the underlying infrastructure, wherein each intermediate tunnel connection of the respective plurality of intermediate secure tunnel connections connects that given access point server to a respective peer device that is either a respective other of the plurality of access point servers or a selected endpoint device of the plurality of endpoint devices, a plurality of end-to-end tunnel connections, each end-to-end tunnel connection formed between a given respective pair of devices selected from the plurality of endpoint devices and passing through a selected respective one or more of the plurality of access point servers, each end-to-end tunnel connection comprising a respective set of neutral hops, one neutral hop at each of the given pair of devices and at each of the selected one or more access point devices that such end-to-end tunnel connection passes through, the respective set of neutral hops together forming a logical tunnel path that uses selected ones of the intermediate secure tunnel connections for transport between pairs of the neutral hops along a path between the given pair of devices, wherein at least some of the end-to-end tunnel connections comprise extended end-to-end tunnel connections having multiple access-point-server neutral hops;identifying a plurality of candidate communication paths between a first network node and a second network node, at least a first one of the identified candidate communication paths comprising a first extended end-to-end tunnel connection of the plurality of end-to-end tunnel connections;determining a plurality of ratings corresponding respectively to the plurality of candidate communication paths;and selecting the candidate communication path comprising the first extended end-to-end tunnel connection from the plurality of candidate communication paths based on the plurality of ratings, wherein the selected communication path is used to communicate data between the first network node and the second network node.