IP Library Granted Patent US 12,574,354
Granted Patent B2
US 12,574,354 · App. 17/709,182 · Granted Mar 10, 2026

Client filter VPN

Inventors: Jeremy D. Erb (Waterloo, CA); James W. Goruk (Nelson, CA)
Assignee: NETSWEEPER (BARBADOS) INC.
H04L63/0272H04L63/0236H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,354
App. No.
17/709,182
Filed
Mar 30, 2022
Granted
Mar 10, 2026
Kind
B2
Examiner
RONI, SYED A
Art Unit
2432
USPC
726/11
Abstract

A user application is executed with an operating system. The operating system enables access to a remote network resource via a network interface and enables a virtual private network (VPN) connection. The operating system enforces use of the VPN connection by the user application. A network-access application is set as a remote endpoint of the VPN connection. The network-access application communicates with the remote network resource on behalf of the user application.

Claims (33)

1 . A method comprising:

executing a user application with an operating system on a client device, wherein the operating system enables access to a remote network resource via a network interface and creates a virtual private network (VPN) connection at the client device, 1 and wherein the operating system enforces use of the VPN connection by the user application;

setting a network-access application, executed by the operating system, as an endpoint of the VPN connection at the device 2 ;

the network-access application

including:

a proxy configured to communicate with the remote network resource on behalf of the user application by managing data the relationship between network packets as known to the user application and to the remote network resource; 3 and

a filter configured to selectively allow, block, or modify communications between the user application and the remote network resource based on policy decisions received from a policy service;

performing at least one of inspecting, filtering, and modification of traffic by the proxy and the filter.

2 . The method of claim 1 , further comprising the network-access application selectively allowing or blocking communications between the user application and the remote network resource.

3 . The method of claim 1 , further comprising the network-access application monitoring communications between the user application and the remote network resource.

4 . The method of claim 1 , further comprising the network-access application modifying communications between the user application and the remote network resource.

5 . The method of claim 1 , further comprising the network-access application using a proxy to communicate with the remote network resource on behalf of the user application.

6 . The method of claim 5 , further comprising the network-access application maintaining a mapping of data packets communicated between the user application and a plurality of remote network resources to network connections provided by the proxy.

7 . The method of claim 6 , further comprising the network-access application identifying a data packet that does not conform to the mapping and, in response, open a new network connection at the proxy.

8 . The method of claim 1 , further comprising the operating system enforcing use of the VPN connection by all applications except the network-access application.

9 . A device comprising:

memory;

a network interface; and

a processor connected to the memory and the network interface, the processor configured to execute:

an operating system to execute a user application, enable access to a remote network resource via the network interface, and enable a virtual private network (VPN) connection, wherein the operating system enforces use of the VPN connection by the user application; and

a network-access application executed by the operating system, at the client device, 4 the network-access application being set as a remote endpoint of the VPN connection;

wherein the network-access application comprises:

a proxy configured to communicate with the remote network resource on behalf of the user application by managing data the relationship between network packets as known to the user application and to the remote network resource; and

a filter configured to selectively allow, block, or modify communications between the user application and the remote network resource based on policy decisions received from a policy service; and

wherein the network-access application creates the VPN at the device 6 to enable inspection, filtering, and modification of traffic by the proxy and the filter.

10 . The device of claim 9 , wherein the network-access application is configured to selectively allow or block communications between the user application and the remote network resource.

11 . The device of claim 9 , wherein the network-access application is configured to monitor communications between the user application and the remote network resource.

12 . The device of claim 9 , wherein the network-access application is configured to modify communications between the user application and the remote network resource.

13 . The device of claim 9 , wherein the network-access application is configured to maintain a mapping of data packets communicated between the user application and a plurality of remote network resources to network connections provided by the proxy.

14 . The device of claim 13 , wherein the network-access application is configured to identify a data packet that does not conform to the mapping and, in response, open a new network connection at the proxy.

15 . The device of claim 9 , wherein the operating system enforces use of the VPN connection by all applications except the network-access application.

16 . The device of claim 9 wherein the network-access application communicates without encryption with the remote network resource 7 .

17 . The device of claim 9 wherein the network-access application communicates with encryption 8 with the remote network resource.