IP Library Granted Patent US 11,689,581
Granted Patent B2
US 11,689,581 · App. 16/545,030 · Granted Jun 27, 2023

Segregating VPN traffic based on the originating application

Inventor: Craig Farley Newell (Atlanta, GA)
Assignee: VMware, INC.
H04L65/1033H04L12/4633H04L12/4641H04L43/062H04L45/00H04L47/10H04L47/15H04L47/2441H04L47/70H04L47/824H04L49/354H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,581
App. No.
16/545,030
Granted
Jun 27, 2023
Kind
B2
Abstract

Disclosed are various examples for segregating virtual private network (VPN) traffic based on the originating client application. A network gateway receives network traffic from a tunnel endpoint of an application-specific virtual private network tunnel. The network traffic originates from a client application executed in a client device. The network gateway identifies a particular virtual local area network through which the network traffic is received. The network gateway determines, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, characteristics of the client application or the client device from a set of mobile device management attributes. The network gateway determines whether to route the network traffic to a destination based at least in part on the characteristics.

Claims (40)

1. A system, comprising:

at least one computing device; and

a network gateway executable by the at least one computing device, the network gateway configured to cause the at least one computing device to at least:

receive network traffic from a tunnel endpoint of an application-specific virtual private network tunnel, the network traffic originating from a client application executed in a client device;

identify a particular virtual local area network through which the network traffic is received;

determine, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, at least one characteristic of the client application or the client device from a set of one or more mobile device management attributes; and

determine whether to route the network traffic to a destination based at least in part on the at least one characteristic.

2. The system of claim 1 , wherein the set of one or more mobile device management attributes are received by the network gateway from a device management service.

3. The system of claim 1 , wherein the network gateway is further configured to cause the at least one computing device to at least receive data from the tunnel endpoint through each of a plurality of virtual local area networks corresponding to the mapping of virtual local area network identifiers.

4. The system of claim 1 , wherein the network gateway is further configured to cause the at least one computing device to at least identify the particular virtual local area network from a unique identifier in headers of a stream of Ethernet frames corresponding to the network traffic.

5. The system of claim 1 , wherein the network gateway is further configured to cause the at least one computing device to at least identify the particular virtual local area network from a generic routing encapsulation (GRE) header in the network traffic.

6. The system of claim 1 , wherein determining whether to route the network traffic to the destination further comprises determining whether the client application should have access to a virtual network segment of an internal network through which the destination is reachable, the client application being a managed client application.

7. The system of claim 1 , wherein the network gateway is further configured to cause the at least one computing device to at least drop the network traffic upon determining not to route the network traffic to the destination.

8. The system of claim 1 , wherein the network gateway is further configured to cause the at least one computing device to at least forward the network traffic using the particular virtual local area network upon determining to route the network traffic to the destination.

9. The system of claim 8 , wherein the network gateway is further configured to cause the at least one computing device to at least receive response network traffic from the destination using the particular virtual local area network.

10. The system of claim 9 , wherein the network gateway is further configured to cause the at least one computing device to at least return the response network traffic to the tunnel endpoint.

11. A computer-implemented method, comprising:

receiving network traffic from a tunnel endpoint of an application-specific virtual private network tunnel, the network traffic originating from a client application executed in a client device;

identifying a particular virtual local area network through which the network traffic is received;

determining, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, at least one characteristic of the client application or the client device from a set of one or more mobile device management attributes; and

determining whether to route the network traffic to a destination based at least in part on the at least one characteristic.

12. The method of claim 11 , further comprising receiving the set of one or more mobile device management attributes from a device management service.

13. The method of claim 11 , further comprising receiving data from the tunnel endpoint through each of a plurality of virtual local area networks corresponding to the mapping of virtual local area network identifiers.

14. The method of claim 11 , further comprising identifying the particular virtual local area network from a unique identifier in headers of a stream of Ethernet frames corresponding to the network traffic.

15. The method of claim 11 , further comprising identifying the particular virtual local area network from a generic routing encapsulation (GRE) header in the network traffic.

16. The method of claim 11 , wherein determining whether to route the network traffic to the destination further comprises determining whether the client application should have access to a virtual network segment of an internal network through which the destination is reachable, the client application being a managed client application.

17. The method of claim 11 , further comprising:

forwarding the network traffic using the particular virtual local area network upon determining to route the network traffic to the destination;

receiving response network traffic from the destination using the particular virtual local area network; and

returning the response network traffic to the tunnel endpoint.

18. A non-transitory computer-readable medium embodying a program executable in at least one computing device, wherein when executed the program causes the at least one computing device to at least:

receive network traffic from a tunnel endpoint of an application-specific virtual private network tunnel, the network traffic originating from a client application executed in a client device;

identify a particular virtual local area network through which the network traffic is received;

determine, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, at least one characteristic of the client application or the client device from a set of one or more mobile device management attributes; and

determine whether to route the network traffic to a destination based at least in part on the at least one characteristic.

19. The non-transitory computer-readable medium of claim 18 , wherein when executed the program further causes the at least one computing device to at least identify the particular virtual local area network from a unique identifier in headers of a stream of Ethernet frames corresponding to the network traffic or from a generic routing encapsulation (GRE) header in the network traffic.

20. The non-transitory computer-readable medium of claim 18 , wherein when executed the program further causes the at least one computing device to at least:

forwarding the network traffic using the particular virtual local area network upon determining to route the network traffic to the destination;

receiving response network traffic from the destination using the particular virtual local area network; and

returning the response network traffic to the tunnel endpoint.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2019
From: NEWELL, CRAIG FARLEY
To: AIRWATCH LLC
Reel/Frame 050194/0391 →
Continuity (2)
Division 15015697 · Feb 4, 2016
Related Publication 20190373024A1 · Dec 5, 2019