IP Library Granted Patent US 9,407,456
Granted Patent B2
US 9,407,456 · App. 13/038,340 · Granted Aug 2, 2016

Secure access to remote resources over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,407,456
App. No.
13/038,340
Granted
Aug 2, 2016
Kind
B2
Abstract

A client computer hosts a virtual private network tool to establish a virtual private network connection with a remote network. Upon startup, the virtual private network tool collects critical network information for the client computer, and sends this critical network information to an address assignment server in the remote network. The address assignment server compares the critical network information with a pool of available addresses in the remote network, and assigns addresses for use by the client computer that do not conflict with the addresses for local resources. The address assignment server also provides routing information for resources in the remote network to the virtual private network tool. The virtual private network tool will postpone loading this routing information into the routing tables of the client computer until the client computer requests access to a specific resource in the remote network. When the client computer requests access to a specific resource in the remote network, the virtual private network tool will only provide the routing table with the routing information for that specific remote resource.

Claims (36)

1. A method for securely accessing a remote resource on a private network, the method comprising:

storing in a memory of a client computing device a routing rule for accessing a remote resource; and

executing instructions stored in the memory of the client computing device, wherein execution of the instructions by a processor:

provides to a routing table stored in the memory of the client computing device one or more initial routing rules for accessing a name server in the network, wherein the one or more initial routing rules are limited to one or more routing rules necessary for accessing the name server;

requests access to the remote resource by a client application stored in the memory of the client computing device using the name of the remote resource;

transmits to the name server an address resolution query for the name of the remote resource based on the one or more initial routing rules;

intercepts a reply from the name server intended for the client application, the reply including a network address corresponding to the name of the resource;

obtains from the memory the routing rule corresponding to the name of the requested resource;

determines that the client computing device is permitted to access the requested resource based on the routing rule;

generates a routing rule for the network address identified in the reply;

provides to the client application the routing rule for the network address generated from the intercepted reply; and

opens by the client application a secure connection with the remote network based on the routing rule.

2. The method of claim 1 , wherein the name server is a Domain Name Server or Windows Internet Naming Service server.

3. The method of claim 1 , wherein determining that the client computing device is permitted to access the requested resource based on the routing rule includes comparing authentication information of the client computing device with an access policy, the access policy used for determining which remote resource the client computing device is permitted to access.

4. The method of claim 1 , wherein opening a secure connection with the remote network includes opening a redirect all connection mode.

5. The method of claim 1 , wherein opening a secure connection with the remote network includes opening a split tunnel connection mode.

6. The method of claim 1 , wherein the routing rule contains a resource identifier value and a permission value.

7. The method of claim 1 , wherein the routing rule includes information corresponding to the name of a requested remote resource.

8. The method of claim 1 , wherein the routing rule indicates that the client computing device is permitted to access the requested remote resource.

9. A non-transitory computer-readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for securely accessing a remote resource on a private network, the method comprising:

providing to a routing table stored in a memory of a client computing device one or more initial routing rules for accessing a name server in the network, wherein the one or more initial routing rules are limited to the routing rules necessary for accessing the name server;

requesting access to the remote resource by a client application stored in the memory of the client computing device using the name of the remote resource;

transmitting to the name server an address resolution query for the name of the remote resource based on the one or more initial routing rules;

intercepting a reply from the name server intended for the client application, the reply including a network address corresponding to the name of the resource;

obtaining from the memory the routing rule corresponding to the name of the requested resource;

determining that the client computing device is permitted to access the requested resource based on the routing rule;

generating a routing rule for the network address identified in the reply;

providing to the client application the routing rule for the network address generated from the intercepted reply; and

opening by the client application a secure connection with the remote network based on the routing rule.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the name server is a Domain Name Server or Windows Internet Naming Service server.

11. The non-transitory computer-readable storage medium of claim 9 , wherein determining that the client computing device is permitted to access the requested resource based on the routing rule includes comparing authentication information of the client computing device with an access policy, the access policy used for determining which remote resource the client computing device is permitted to access.

12. The non-transitory computer-readable storage medium of claim 9 , wherein opening a secure connection with the remote network includes opening a redirect all connection mode.

13. The non-transitory computer-readable storage medium of claim 9 , wherein opening a secure connection with the remote network includes opening a split tunnel connection mode.

14. The non-transitory computer-readable storage medium of claim 9 , wherein the routing rule contains a resource identifier value and a permission value.

15. The non-transitory computer-readable storage medium of claim 9 , wherein the routing rule includes information corresponding to the name of a requested remote resource.

16. The non-transitory computer-readable storage medium of claim 9 , wherein the routing rule indicates that the client computing device is permitted to access the requested remote resource.

Assignments (14)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS INC.
Reel/Frame 043950/0437 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2011
From: HOOVER, PAUL LAWRENCE; DEL ERICKSON, RODGER; SAUVE, BRYAN
To: AVENTAIL CORPORATION
Reel/Frame 025883/0423 →
MERGER Recorded Mar 1, 2011
From: AVENTAIL CORPORATION
To: AVENTAIL LLC
Reel/Frame 025883/0560 →