IP Library Granted Patent US 12,218,914
Granted Patent B2
US 12,218,914 · App. 17/746,814 · Granted Feb 4, 2025

Policy-based dynamic VPN profile selection using DNS protocol

Inventor: Raghavendra Singh Niranjan (Bengaluru, IN)
Assignee: Infoblox Inc.
H04L63/0272H04L61/4511H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,914
App. No.
17/746,814
Granted
Feb 4, 2025
Kind
B2
Abstract

Techniques for policy-based dynamic VPN profile selection using DNS protocol are provided. In some embodiments, a system/process/computer program product for policy-based dynamic VPN profile selection using DNS protocol includes receiving, at a DNS server for an enterprise network, a Domain Name System (DNS) request for a resource from an endpoint client; determining an IP address and an authentication token for the endpoint client to access the resource using a secure tunnel; and sending a DNS response, from the DNS server, including the IP address and the authentication token to the endpoint client.

Claims (29)

1. A system, comprising:

a processor configured to:

receive, at a DNS server for an enterprise network, a Domain Name System (DNS) request for a resource from an endpoint client, wherein the DNS request includes a Fully Qualified Domain Name (FQDN) and a client ID associated with the endpoint client;

determine an Internet Protocol (IP) address and an authentication token for the endpoint client to access the resource using a secure tunnel, wherein the DNS server, via an authentication request including the FQDN and the client ID, requests the authentication token from an endpoint server, wherein the endpoint server identifies a set of authentication tokens based on a first client ID or a second client ID, determines the authentication token from the set of authentication tokens based on the FQDN, and returns the IP address and the authentication token to the DNS server; and

send a DNS response, from the DNS server, including the IP address and the authentication token to the endpoint client; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the authentication token includes an authentication cookie.

3. The system recited in claim 1 , wherein the IP address and the authentication token are determined based on a policy for dynamic Virtual Private Network (VPN) profile selection using DNS protocol.

4. The system recited in claim 1 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol to facilitate DNS-based split tunneling.

5. The system recited in claim 1 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol, and wherein the policy includes a plurality of VPN rules that can be updated at runtime for dynamic VPN gateway allocation for a plurality of endpoint clients associated with the enterprise network.

6. The system recited in claim 1 ,

wherein the authentication token is generated at the endpoint server for each new session associated with the endpoint client.

7. A method, comprising:

receiving, at a DNS server for an enterprise network, a Domain Name System (DNS) request for a resource from an endpoint client, wherein the DNS request includes a Fully Qualified Domain Name (FQDN) and a client ID associated with the endpoint client;

determining an IP address and an authentication token for the endpoint client to access the resource using a secure tunnel, wherein the DNS server, via an authentication request including the FQDN and the client ID, requests the authentication token from an endpoint server, wherein the endpoint server identifies a set of authentication tokens based on a first client ID or a second client ID, determines the authentication token from the set of authentication tokens based on the FQDN, and returns the IP address and the authentication token to the DNS server; and

sending a DNS response, from the DNS server, including the IP address and the authentication token to the endpoint client.

8. The method of claim 7 , wherein the authentication token includes an authentication cookie.

9. The method of claim 7 , wherein the IP address and the authentication token are determined based on a policy for dynamic Virtual Private Network (VPN) profile selection using DNS protocol.

10. The method of claim 7 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol to facilitate DNS-based split tunneling.

11. The method of claim 7 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol, and wherein the policy includes a plurality of VPN rules that can be updated at runtime for dynamic VPN gateway allocation for a plurality of endpoint clients associated with the enterprise network.

12. The method of claim 7 , wherein the authentication token is generated at the endpoint server for each new session associated with the endpoint client.

13. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, at a DNS server for an enterprise network, a Domain Name System (DNS) request for a resource from an endpoint client, wherein the DNS request includes a Fully Qualified Domain Name (FQDN) and a client ID associated with the endpoint client;

determining an IP address and an authentication token for the endpoint client to access the resource using a secure tunnel, wherein the DNS server, via an authentication request including the FQDN and the client ID, requests the authentication token from an endpoint server, wherein the endpoint server identifies a set of authentication tokens based on a first client ID or a second client ID, determines the authentication token from the set of authentication tokens based on the FQDN, and returns the IP address and the authentication token to the DNS server; and

sending a DNS response, from the DNS server, including the IP address and the authentication token to the endpoint client.

14. The computer program product of claim 13 , wherein the authentication token includes an authentication cookie.

15. The computer program product of claim 13 , wherein the IP address and the authentication token are determined based on a policy for dynamic Virtual Private Network (VPN) profile selection using DNS protocol.

16. The computer program product of claim 13 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol to facilitate DNS-based split tunneling.

17. The computer program product of claim 13 , wherein the IP address and the authentication token are determined based on a policy for dynamic VPN profile selection using DNS protocol, and wherein the policy includes a plurality of VPN rules that can be updated at runtime for dynamic VPN gateway allocation for a plurality of endpoint clients associated with the enterprise network.

Assignments (3)
SECOND LIEN SECURITY AGREEMENT Recorded Dec 12, 2022
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 062953/0499 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 12, 2022
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 062115/0761 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2022
From: NIRANJAN, RAGHAVENDRA SINGH
To: INFOBLOX INC.
Reel/Frame 060623/0792 →
Continuity (1)
Related Publication 20230379304A1 · Nov 23, 2023
References Cited (7)
US 20180309658A1 · Parla · 2018 [cited by examiner]
US 20220385474A1 · Helfinstine · 2022 [cited by examiner]
Damas et al., Extension Mechanisms for DNS (EDNS(0)), RFC 6891—Extension Mechanisms for DNS (EDNS(0)), Apr. 2013. [cited by applicant]
Gentile et al., A Survey on the Implementation and Management of Secure Virtual Private Networks (VPNs) and Virtual LANs (VLANs) in Static and Mobile Scenarios, Telecom 2021, vol. 2, pp. 430-445. [cited by applicant]
Harchay et al., An Enhanced Traffic Split Routing Heuristic for Layer 2 and Layer 1 Services, (IJACSA) International Journal of Advanced Computer Science and Applications, vol. 13, No. 1, 2022 (downloaded May 5, 2022). [cited by applicant]
Lana Ibrahim, Virtual Private Network (VPN) Management and IPSec Tunneling Technology, Middle East Comprehensive Journal For Education and Science Publications ( MECSJ ), Issue (1), Jan. 2017, pp. 76-87. [cited by applicant]
Liu et al., Avoiding VPN Bottlenecks: Exploring Network-Level Client Identity Validation Options, 2021. [cited by applicant]
Cited By (2)
US 12,683,934 US 12,712,911