IP Library Granted Patent US 10,701,034
Granted Patent B2
US 10,701,034 · App. 16/175,680 · Granted Jun 30, 2020

Intelligent sorting for N-way secure split tunnel

Inventors: Carl Steven Mower (Sunnyvale, CA); Matthew Alan Palmer (Menlo Park, CA)
Assignee: Extreme Networks, Inc.
H04L63/0236H04L12/6418H04L45/44H04L49/70H04L63/029H04L63/0227H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,701,034
App. No.
16/175,680
Granted
Jun 30, 2020
Kind
B2
Abstract

A method of intelligently sorting packets/datagrams for sending through appropriate branches of a N-way split VPN tunnel according to embodiments of the present invention allow for efficient movement of network traffic to and from a remote network location. Intelligent sorting may be based on a wide range of criteria in order to implement different policies. For example, datagrams may be sorted for sending through the branches of a 3-way split tunnel so that all traffic from a remote network location ultimately destined to servers at a central location may be sent via a secure VPN tunnel, all traffic that matches a “white-list” of trusted external sites may be sent directly to and from these sites to the remote network location, and all other traffic may be redirected through a Web service that scrubs and filters the traffic to/from questionable sites. Furthermore, the VPN tunnel may be chosen to minimize latency, to detour around network failures, or to conserve energy by minimizing the number of routers a datagram passes through.

Claims (31)

1. A method, comprising:

sending a first category of datagrams from among a plurality of categories of datagrams to a central network location along an N-way split virtual private network tunnel;

sending a second category of datagrams from among the plurality of categories of datagrams to destinations on a white list along the N-way split virtual private network tunnel; and

sending a third category of datagrams from among the plurality of categories of datagrams to a scanning service website along the N-way split virtual private network tunnel, the scanning service website configured to at least one of scrub or filter the third category of datagrams.

2. The method of claim 1 , wherein sending the third category of datagrams to the scanning service website comprises selecting the scanning service website from among a plurality of scanning service websites based on a user identification attached to each datagram of the plurality of types of datagrams.

3. The method of claim 1 , wherein N is a multiple of three.

4. The method of claim 1 , further comprising determining whether to categorize a datagram in the first, second, or third category of datagrams based on a device type transmitting the datagram.

5. The method of claim 1 , further comprising periodically updating the white list.

6. The method of claim 1 , further comprising determining whether to sort each datagram of the plurality of datagrams based on a destination address of the datagram.

7. The method of claim 1 , further comprising determining which tunnel of the N-way tunnel to send the first category of datagrams, the second category of datagrams, and the third category of datagrams through based on at least one criterion.

8. The method of claim 7 , wherein the at least one criterion comprises network latency, network failures, a hop count, or energy usage.

9. A system, comprising:

a memory storing computer instructions for sending a plurality of categories of datagrams along an N-way split virtual private network tunnel;

a processor configured to execute the instructions, the instructions causing the processor to:

send a first category of datagrams from among the plurality of categories of datagrams to a central network location along the N-way split virtual private network tunnel;

send a second category of datagrams from among the plurality of categories of datagrams to destinations on a white list along the N-way split virtual private network tunnel; and

send a third category of datagrams from among the plurality of categories of datagrams to a scanning service website along the N-way split virtual private network tunnel, the scanning service website configured to at least one of scrub or filter the third category of datagrams.

10. The system of claim 9 , wherein, to send the third category of datagrams to the scanning service website, the instructions further cause the processor to select the scanning service website from among a plurality of scanning service websites based on a user identification attached to each datagram of the plurality of types of datagrams.

11. The system of claim 9 , wherein N is a multiple of three.

12. The system of claim 9 , wherein the instructions further cause the processor to determine whether to categorize a datagram in the first, second, or third category of datagrams based on a device type transmitting the datagram.

13. The system of claim 9 , wherein the instructions further cause the processor to periodically update the white list.

14. The system of claim 9 , wherein the instructions further cause the processor to determine whether to sort each datagram of the plurality of datagrams based on a destination address of the datagram.

15. The system of claim 9 , wherein the instructions further cause the processor to determine which tunnel of the N-way tunnel to send the first category of datagrams, the second category of datagrams, and the third category of datagrams through based on at least one criterion.

16. The system of claim 15 , wherein the at least one criterion comprises network latency, network failures, a hop count, or energy usage.

17. A non-transitory, tangible computer-readable device having instructions stored thereon for sending a plurality of categories of datagrams along an N-way split virtual private network tunnel that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

sending a first category of datagrams from among the plurality of categories of datagrams to a central network location along the N-way split virtual private network tunnel;

sending a second category of datagrams from among the plurality of categories of datagrams to destinations on a white list along the N-way split virtual private network tunnel; and

sending a third category of datagrams from among the plurality of categories of datagrams to a scanning service website along the N-way split virtual private network tunnel, the scanning service website configured to at least one of scrub or filter the third category of datagrams.

18. The device of claim 17 , wherein the operations further comprise periodically updating the white list.

19. The device of claim 17 , wherein the operations further comprise determining which tunnel of the N-way tunnel to send the first category of datagrams, the second category of datagrams, and the third category of datagrams through based on at least one criterion.

20. The device of claim 19 , wherein the at least one criterion comprises network latency, network failures, a hop count, or energy usage.

Assignments (5)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2020
From: AEROHIVE NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 052473/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2020
From: PARETO NETWORKS, INC.
To: AEROHIVE NETWORKS, INC.
Reel/Frame 052346/0760 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2020
From: MOWER, CARL STEVEN; PALMER, MATTHEW ALAN
To: PARETO NETWORKS, INC.
Reel/Frame 052349/0870 →
SECURITY INTEREST Recorded Aug 12, 2019
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 050023/0001 →
Continuity (6)
Continuation 15682322 · Aug 21, 2017
Continuation 14860651 · Sep 21, 2015
Continuation 13849278 · Mar 22, 2013
Continuation 12649134 · Dec 29, 2009
Provisional Application 61152583 · Feb 13, 2009
Related Publication 20190132287A1 · May 2, 2019