IP Library Granted Patent US 11,711,337
Granted Patent B1
US 11,711,337 · App. 17/724,967 · Granted Jul 25, 2023

Domain name system configuration during virtual private network connection

Inventor: Lukas Baltrenas (Vilnius, LT)
Assignee: Oversec, UAB
H04L61/4511H04L12/4633H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,337
App. No.
17/724,967
Granted
Jul 25, 2023
Kind
B1
Abstract

Domain name system (DNS) configuration during virtual private network (VPN) connection includes establishing a VPN tunnel between a client device and a VPN system entry server, which includes configuring a first DNS server as an operative DNS server for the VPN tunnel, and obtaining first content by transmitting to the VPN entry server, a first request that identifies a first external source for the first content, receiving from the VPN entry server a DNS configuration message indicating a second DNS server, configuring the second DNS server as the operative DNS server, and receiving from the VPN entry server, via the VPN tunnel, the first content, wherein the VPN entry server obtained the first content from the first VPN system exit server identified by the VPN entry server using the second DNS server, and the first VPN system exit server obtained the first content from the first external source.

Claims (73)

1. A method for domain name system configuration during virtual private network connection, the method comprising:

establishing, by a virtual private network entry server, a virtual private network tunnel between the virtual private network entry server and a client device, wherein establishing the virtual private network tunnel includes receiving, from the client device, virtual private network configuration data indicating a first domain name system server configured as an operative domain name system server for the virtual private network tunnel;

receiving, by the virtual private network entry server, a first protocol data unit, wherein the first protocol data unit includes at least a portion of a first request for first content, wherein the first request identifies a first external source for the first content;

determining, by the virtual private network entry server, that a first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server;

in response to determining that the first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server:

identifying, by the virtual private network entry server, a second domain name system server, such that the first virtual private network system exit server for obtaining the first content is available using the second domain name system server;

transmitting, by the virtual private network entry server, to the client device, a second protocol data unit including a domain name system configuration message, wherein the domain name system configuration message indicates the second domain name system server, such that the client device configures the second domain name system server as the operative domain name system server for the virtual private network tunnel;

obtaining, by the virtual private network entry server, from the first virtual private network system exit server, the first content, wherein the first virtual private network system exit server obtained the first content from the first external source; and

transmitting, to the client device, via the virtual private network tunnel, the first content.

2. The method of claim 1 , wherein:

receiving the virtual private network configuration data includes receiving the first protocol data unit.

3. The method of claim 1 , wherein:

receiving the first protocol data unit includes receiving a universal resource locator value indicative of the first external source.

4. The method of claim 1 , further comprising:

receiving, by the virtual private network entry server, from the client device, a third protocol data unit, wherein the third protocol data unit includes at least a portion of a second request for second content that identifies a second external source for the second content;

determining, by the virtual private network entry server, that a second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server;

in response to determining that the second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server:

obtaining, by the virtual private network entry server, from the second virtual private network system exit server, the second content, wherein the second virtual private network system exit server obtained the second content from the second external source; and

transmitting, to the client device, via the virtual private network tunnel, the second content, such that the client device omits reconfiguring the operative domain name system server to obtain the second content.

5. The method of claim 4 , wherein:

the second content is obtained prior to obtaining the first content, such that the second content is obtained wherein the operative domain name system server is the first domain name system server.

6. The method of claim 4 , wherein:

the second content is obtained subsequent to obtaining the first content, such that the second content is obtained wherein the operative domain name system server is the second domain name system server.

7. The method of claim 4 , wherein a geographic location of the first virtual private network exit server differs from a geographic location of the second virtual private network exit server.

8. A virtual private network entry server apparatus comprising:

a non-transitory computer-readable storage medium; and

a processor configured to execute instructions stored in the non-transitory computer-readable storage medium to:

establish a virtual private network tunnel between the virtual private network entry server apparatus and a client device, wherein to establish the virtual private network tunnel the processor executes the instructions to receive, from the client device, virtual private network configuration data indicating a first domain name system server configured as an operative domain name system server for the virtual private network tunnel;

receive a first protocol data unit, wherein the first protocol data unit includes at least a portion of a first request for first content, wherein the first request identifies a first external source for the first content;

determine that a first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server;

in response to determining that the first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server:

identify a second domain name system server, such that the first virtual private network system exit server for obtaining the first content is available using the second domain name system server;

transmit, to the client device, a second protocol data unit including a domain name system configuration message, wherein the domain name system configuration message indicates the second domain name system server, such that the client device configures the second domain name system server as the operative domain name system server for the virtual private network tunnel;

obtain, from the first virtual private network system exit server, the first content, wherein the first virtual private network system exit server obtained the first content from the first external source; and

transmit, to the client device, via the virtual private network tunnel, the first content.

9. The virtual private network entry server apparatus of claim 8 , wherein:

to receive the virtual private network configuration data, the processor executes the instructions to receive the first protocol data unit.

10. The virtual private network entry server apparatus of claim 8 , wherein:

to receive the first protocol data unit, the processor executes the instructions to receive a universal resource locator value indicative of the first external source.

11. The virtual private network entry server apparatus of claim 8 , wherein the processor executes the instructions to:

receive, from the client device, a third protocol data unit, wherein the third protocol data unit includes at least a portion of a second request for second content that identifies a second external source for the second content;

determine that a second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server;

in response to determining that the second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server:

obtain, from the second virtual private network system exit server, the second content, wherein the second virtual private network system exit server obtained the second content from the second external source; and

transmit, to the client device, via the virtual private network tunnel, the second content, such that the client device omits reconfiguring the operative domain name system server to obtain the second content.

12. The virtual private network entry server apparatus of claim 11 , wherein:

the processor executes the instructions to obtain the second content prior to obtaining the first content, such that the operative domain name system server is the first domain name system server.

13. The virtual private network entry server apparatus of claim 11 , wherein:

the processor executes the instructions to obtain the second content subsequent to obtaining the first content, such that the operative domain name system server is the second domain name system server.

14. The virtual private network entry server apparatus of claim 11 , wherein a geographic location of the first virtual private network exit server differs from a geographic location of the second virtual private network exit server.

15. A non-transitory computer-readable storage medium, comprising executable instructions that, when executed by a processor, perform:

establishing, by a virtual private network entry server, a virtual private network tunnel between the virtual private network entry server and a client device, wherein establishing the virtual private network tunnel includes receiving, from the client device, virtual private network configuration data indicating a first domain name system server configured as an operative domain name system server for the virtual private network tunnel;

receiving, by the virtual private network entry server, a first protocol data unit, wherein the first protocol data unit includes at least a portion of a first request for first content, wherein the first request identifies a first external source for the first content;

determining, by the virtual private network entry server, that a first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server;

in response to determining that the first virtual private network system exit server for obtaining the first content from the first external source is unavailable using the first domain name system server:

identifying, by the virtual private network entry server, a second domain name system server, such that the first virtual private network system exit server for obtaining the first content is available using the second domain name system server;

transmitting, by the virtual private network entry server, to the client device, a second protocol data unit including a domain name system configuration message, wherein the domain name system configuration message indicates the second domain name system server, such that the client device configures the second domain name system server as the operative domain name system server for the virtual private network tunnel;

obtaining, by the virtual private network entry server, from the first virtual private network system exit server, the first content, wherein the first virtual private network system exit server obtained the first content from the first external source; and

transmitting, to the client device, via the virtual private network tunnel, the first content.

16. The non-transitory computer-readable storage medium of claim 15 , wherein:

receiving the virtual private network configuration data includes receiving the first protocol data unit.

17. The non-transitory computer-readable storage medium of claim 15 , wherein:

receiving the first protocol data unit includes receiving a universal resource locator value indicative of the first external source.

18. The non-transitory computer-readable storage medium of claim 15 , further comprising:

receiving, by the virtual private network entry server, from the client device, a third protocol data unit, wherein the third protocol data unit includes at least a portion of a second request for second content that identifies a second external source for the second content;

determining, by the virtual private network entry server, that a second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server;

in response to determining that the second virtual private network system exit server for obtaining the second content from the second external source is available using the operative domain name system server:

obtaining, by the virtual private network entry server, from the second virtual private network system exit server, the second content, wherein the second virtual private network system exit server obtained the second content from the second external source; and

transmitting, to the client device, via the virtual private network tunnel, the second content, such that the client device omits reconfiguring the operative domain name system server to obtain the second content.

19. The non-transitory computer-readable storage medium of claim 18 , wherein:

the second content is obtained prior to obtaining the first content, such that the operative domain name system server is the first domain name system server.

20. The non-transitory computer-readable storage medium of claim 18 , wherein:

the second content is obtained subsequent to obtaining the first content, such that the operative domain name system server is the second domain name system server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: OVERSEC, UAB
To: UAB 360 IT
Reel/Frame 070202/0565 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2022
From: BALTRENAS, LUKAS
To: OVERSEC, UAB
Reel/Frame 059652/0098 →
Continuity (1)
Continuation 17677461 · Feb 22, 2022