IP Library Granted Patent US 11,570,150
Granted Patent B2
US 11,570,150 · App. 16/590,253 · Granted Jan 31, 2023

VPN deep packet inspection

Inventors: Steven C. Work (Seattle, WA); Prakash N. Masanagi (Seattle, WA); Christopher D. Peterson (Seattle, WA)
Assignee: SONICWALL INC.
H04L63/0272H04L63/0281H04L63/164H04L63/166H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,150
App. No.
16/590,253
Granted
Jan 31, 2023
Kind
B2
Abstract

Policy enforcement previously available for web proxy access methods is extended and applied to layer 3 packets flowing through VPN channels. With these extensions, a common security policy is possible that is enforceable between VPN proxied access and VPN tunneled access. Equivalent security policy to tunnel based VPN access without comprising the inherent performance, scalability and application compatibility advantages tunnel based VPNs have over their proxy based VPN counterparts.

Claims (34)

1. A method for securing a computer network, the method comprising:

receiving a list at a gateway device that includes device address information corresponding to application-level information allowing a virtual private network (VPN) session to be established with a device matching at least a portion of the device address information;

receiving a packet at the gateway device, the packet sent over a communication network from an originating device associated with a hardware identifier and a user identifier;

identifying that the packet does not correspond to an existing VPN session at the gateway device;

identifying the application-level information of the originating device at the gateway device by spoofing a protocol exchange with the originating device; and

allowing the VPN session to be established by the gateway device based on at least one of the identified application-level information, the hardware identifier, and the user identifier.

2. The method of claim 1 , further comprising:

identifying that the user identifier and the hardware identifier match authentication information, wherein allowing the VPN session is further based on the user identifier and the hardware identifier matching the authentication information.

3. The method of claim 2 , further comprising accessing the authentication information from an authentication data store, wherein traffic associated with the VPN session flows through the gateway device.

4. The method of claim 1 , wherein the device address information in the list corresponds to a port, and further comprising sending a communication associated with the VPN session via the port in accordance with the port address information.

5. The method of claim 1 , wherein the device address information in the list includes a wildcard corresponding to a plurality of ports over which communications associated with the VPN session are sent.

6. The method of claim 1 , wherein allowing the VPN session includes identifying a proxy server to receive communications associated with the VPN session.

7. The method of claim 6 , further comprising passing to the proxy server an identifier that allows the proxy server to provide policy server requests.

8. An apparatus for securing a computer network, the apparatus comprising:

a network interface that:

receives a list that includes device address information corresponding to application-level information allowing a virtual private network (VPN) session to be established with a device matching at least a portion of the device address information, and

receives a packet that was sent over a communication network from an originating device associated with a hardware identifier and a user identifier;

a memory; and

a processor that executes instruction out of the memory to:

identify that the packet does not correspond to an existing VPN session,

identify the application-level information of the originating device by spoofing a protocol exchange with the originating device, and

allow the VPN session to be established based on at least one of the identified application-level information, the hardware identifier, and the user identifier.

9. The apparatus of claim 8 , wherein the processor executes further instructions to identify that the user identifier and the hardware identifier match authentication information, wherein allowing the VPN session is further based on the user identifier and the hardware identifier matching the authentication information.

10. The apparatus of claim 9 , further comprising an authentication data store that stores the authentication information, wherein the processor accesses the authentication information from the authentication data store.

11. The apparatus of claim 8 , wherein the device address information in the list corresponds to a port, and wherein a communication associated with the VPN session is sent via the port in accordance with the port address information.

12. The apparatus of claim 8 , wherein the device address information in the list includes a wildcard corresponding to a plurality of ports over which communications associated with the VPN session are sent.

13. The apparatus of claim 8 , wherein the processor allows the VPN session by identifying a proxy server to receive communications associated with the VPN session.

14. The apparatus of claim 13 , wherein the network interface passes to the proxy server an identifier that allows the proxy server to provide policy server requests.

15. A non-transitory computer-readable storage medium having embodied thereon a program for implementing a method for securing a computer network, the method comprising:

receiving a list at a gateway device that includes device address information corresponding to application-level information allowing a virtual private network (VPN) session to be established with a device matching at least a portion of the device address information;

receiving a packet that was sent over a communication network from an originating device associated with a hardware identifier and a user identifier;

identifying that the packet does not correspond to an existing VPN session at the gateway device;

identifying the application-level information of the originating device at the gateway device by spoofing a protocol exchange with the originating device; and

allowing the VPN session to be established by the gateway device based on at least one of the identified application-level information, the hardware identifier, and the user identifier.

Assignments (4)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2024
From: PETERSON, CHRISTOPHER
To: SONICWALL US HOLDINGS INC.
Reel/Frame 066491/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2024
From: WORK, STEVEN C.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 066526/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: MASANAGI, PRAKASH NAGAPPA
To: AVENTAIL LLC
Reel/Frame 066187/0374 →
Continuity (3)
Continuation 13773475 · Feb 21, 2013
Provisional Application 61601318 · Feb 21, 2012
Related Publication 20200106747A1 · Apr 2, 2020
Cited By (1)
US 12,695,725