IP Library Granted Patent US 12,058,109
Granted Patent B2
US 12,058,109 · App. 18/103,898 · Granted Aug 6, 2024

VPN deep packet inspection

Inventors: Steven C. Work (Seattle, WA); Prakash N. Masanagi (Seattle, WA); Christopher D. Peterson (Seattle, WA)
Assignee: SonicWALL Inc.
H04L63/0272H04L63/0281H04L63/164H04L63/166H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,058,109
App. No.
18/103,898
Granted
Aug 6, 2024
Kind
B2
Abstract

Policy enforcement previously available for web proxy access methods is extended and applied to layer 3 packets flowing through VPN channels. With these extensions, a common security policy is possible that is enforceable between VPN proxied access and VPN tunneled access. Equivalent security policy to tunnel based VPN access without comprising the inherent performance, scalability and application compatibility advantages tunne based VPNs have over their proxy based VPN counterparts.

Claims (38)

1. A method for securing a virtual private network (VPN), the method comprising:

receiving a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

accessing authentication data from a data store, wherein the authentication data includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session;

identifying that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allowing the proxied VPN session with the originating device based on the identified session type; and

passing to a proxy server a connection identifier that allows the proxy server to provide policy server requests for the proxied VPN session with the originating device.

2. The method of claim 1 , wherein the policy server requests by the proxy server correspond to a response to the connection request from the originating device.

3. The method of claim 1 , wherein allowing the proxied VPN session including identifying a proxy server to receive communications associated with the VPN session.

4. The method of claim 1 , further comprising sending application-level information by spoofing a protocol exchange with the originating device, wherein the application-level information is included in the connection request.

5. The method of claim 1 , further comprising supplying one or more tunnels of the VPN with a list corresponding to a port.

6. The method of claim 5 , wherein the list is associated with access rules specifying application-level information associated with allowing the proxied VPN session.

7. The method of claim 1 , wherein allowing the proxied VPN session is allowed or proxied based on identifying that the authentication information of the originating device matches the authentication data in the data store and the session type.

8. A apparatus for securing a virtual private network (VPN), the apparatus comprising:

a transceiver; and

a processor configured to execute instructions and cause the processor to:

receive a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

access authentication data from a data store, wherein the authentication data includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session;

identify that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allow the proxied VPN session with the originating device based on the identified session type; and

pass to a proxy server a connection identifier that allows the proxy server to provide policy server requests for the proxied VPN session with the originating device.

9. The apparatus of claim 8 , the policy server requests by the proxy server correspond to a response to the connection request from the originating device.

10. The apparatus of claim 8 , allowing the proxied VPN session including identifying a proxy server to receive communications associated with the VPN session.

11. The apparatus of claim 8 , wherein the instructions further cause the processor to:

send application-level information by spoofing a protocol exchange with the originating device, wherein the application-level information is included in the connection request.

12. The apparatus of claim 8 , wherein the instructions further cause the processor to: supply one or more tunnels of the VPN with a list corresponding to a port.

13. The apparatus of claim 12 , the list is associated with access rules specifying application-level information associated with allowing the VPN session.

14. The apparatus of claim 8 , allowing the proxied VPN session is allowed or proxied based on identifying that the authentication information of the originating device matches the authentication data in the data store and the session type.

15. A non-transitory computer-readable medium comprising instructions executable by a computing system to perform a method for securing a virtual private network (VPN), the method comprising:

receiving a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

accessing authentication data from a data store, wherein the authentication data includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session;

identifying that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allowing the proxied VPN session with the originating device based on the identified session type; and

passing to a proxy server a connection identifier that allows the proxy server to provide policy server requests for the proxied VPN session with the originating device.

16. The non-transitory computer-readable medium of claim 15 , the policy server requests by the proxy server correspond to a response to the connection request from the originating device.

17. The non-transitory computer-readable medium of claim 15 , wherein allowing the proxied VPN session includes identifying a proxy server to receive communications associated with the VPN session.

18. The non-transitory computer-readable medium of claim 15 , wherein the computer-readable medium further comprises instructions executable by the computing system to send application-level information by spoofing a protocol exchange with the originating device, wherein the application-level information is included in the connection request.

19. The non-transitory computer-readable medium of claim 15 , wherein the computer- readable medium further comprises instructions executable by the computing system to supply one or more tunnels of the VPN with a list corresponding to a port.

20. The non-transitory computer-readable medium of claim 15 , wherein allowing the proxied VPN session is allowed or proxied based on identifying that the authentication information of the originating device matches the authentication data in the data store and the session type.

Assignments (4)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2024
From: PETERSON, CHRISTOPHER
To: SONICWALL US HOLDINGS INC.
Reel/Frame 066491/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2024
From: WORK, STEVEN C.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 066526/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: MASANAGI, PRAKASH NAGAPPA
To: AVENTAIL LLC
Reel/Frame 066187/0374 →
Continuity (4)
Continuation 16590253 · Oct 1, 2019
Continuation 13773475 · Feb 21, 2013
Provisional Application 61601318 · Feb 21, 2012
Related Publication 20230254286A1 · Aug 10, 2023
Cited By (1)
US 12,695,725