IP Library Granted Patent US 9,762,541
Granted Patent B2
US 9,762,541 · App. 14/860,651 · Granted Sep 12, 2017

Intelligent sorting for N-way secure split tunnel

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,762,541
App. No.
14/860,651
Granted
Sep 12, 2017
Kind
B2
Abstract

A method of intelligently sorting packets/datagrams for sending through appropriate branches of a N-way split VPN tunnel according to embodiments of the present invention allow for efficient movement of network traffic to and from a remote network location. Intelligent sorting may be based on a wide range of criteria in order to implement different policies. For example, datagrams may be sorted for sending through the branches of a 3-way split tunnel so that all traffic from a remote network location ultimately destined to servers at a central location may be sent via a secure VPN tunnel, all traffic that matches a “white-list” of trusted external sites may be sent directly to and from these sites to the remote network location, and all other traffic may be redirected through a Web service that scrubs and filters the traffic to/from questionable sites. Furthermore, the VPN tunnel may be chosen to minimize latency, to detour around network failures, or to conserve energy by minimizing the number of routers a datagram passes through.

Claims (18)

1. A method comprising:

sorting outgoing datagrams into one of at least three categories, wherein the three categories include a first category of datagrams addressed to a central network location, a second category of datagrams addressed to destinations on a white list, and a third category of datagrams addressed to other destinations absent from the white list;

sending datagrams in the first category to the central network location along an N-way split virtual private network tunnel, wherein N is a multiple of three;

sending datagrams in the second category to the destinations on the white list along the N-way split virtual private network tunnel;

sending datagrams in the third category to a scanning service website along the N-way split virtual private network tunnel, the scanning service website configured to provide a first scrubbing service for HTTP datagrams and a second scrubbing service for SMTP, POP, and IMAP datagrams.

2. The method of claim 1 , comprising:

determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category;

sending the datagrams in the first category, datagrams in the second category, and datagrams in the third category along the corresponding branches.

3. The method of claim 1 , comprising:

determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category, wherein the corresponding branches are determined using network latency of splits of the N-way split virtual private network tunnel.

4. The method of claim 1 , comprising:

determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category, wherein the corresponding branches are determined using an end-user.

5. The method of claim 1 , comprising determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category, wherein the end-user is identified using an authentication datagram transmitted from an end-user device of the end-user.

6. The method of claim 1 , comprising determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category, wherein the corresponding branches are determined using hop count.

7. The method of claim 1 , comprising determining corresponding branches of the N-way split virtual private network tunnel to send datagrams in the first category, datagrams in the second category, and datagrams in the third category, wherein the corresponding branches are determined using a device type of an end-user device.

8. The method of claim 1 , wherein the white list includes fully-qualified domain names of the destinations on the white list.

9. The method of claim 1 , wherein the white list includes IP addresses mapped to fully-qualified domain names of the destinations on the white list.

10. The method of claim 1 , further comprising sending credentials identifying an end user's username and a MAC address of an end-user device along with datagrams in the third category to the scanning service website.

Assignments (5)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2020
From: AEROHIVE NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 052473/0843 →
SECURITY INTEREST Recorded Aug 12, 2019
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 050023/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2016
From: PARETO NETWORKS, INC.
To: AEROHIVE NETWORKS, INC.
Reel/Frame 037547/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2016
From: MOWER, CARL STEVEN; PALMER, MATTHEW ALAN
To: PARETO NETWORKS, INC.
Reel/Frame 037568/0747 →