IP Library › Granted Patent US 12,549,518
Granted Patent B2
US 12,549,518 · App. 18/359,543 · Granted Feb 10, 2026

System and method for client-based traffic control utilizing domain catalog

Inventors: Natan Elul (Tel Aviv, IL); Daniel Reisel (Tel Aviv, IL); Guy Sviry (Tel Aviv, IL); Gil Azrielant (Tel Aviv, IL); Yehoshua Haim Chen (Tel Aviv, IL)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/0236H04L63/083H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,518
App. No.
18/359,543
Granted
Feb 10, 2026
Kind
B2
Abstract

A system and method for directing network traffic in a client device based on a domain catalog. The method includes generating a virtual network interface having a namespace with a plurality of names, wherein a first name of the namespace is assigned to a client device; assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment; configuring the client device to communicate only through the virtual network interface; and sending network traffic to the resource, in response to determining that the resource is allowed based on a domain catalog.

Claims (54)

1 . A method comprising:

generating a virtual network interface having a namespace comprising a plurality of names, wherein a first name of the namespace is assigned to a client device;

assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment;

configuring the client device to communicate through the virtual network interface to access the resource;

inspecting network traffic received from the client device through the virtual network interface;

determining a destination of the network traffic; and

sending the network traffic to the destination based on determining that the network traffic is allowable according to a policy of the zero trust network environment, the policy being related to an entry of a domain catalog for the network traffic.

2 . The method of claim 1 , wherein the entry of the domain catalog contains a domain name and an attribute of the domain name, the method comprising:

matching information of the network traffic to the entry in the domain catalog.

3 . The method of claim 2 , comprising:

identifying the policy based on the attribute in the entry matched to the network traffic, wherein the network traffic is allowed or blocked using the policy.

4 . The method of claim 1 , wherein the virtual network interface has a routing table having a first address of the resource that is different from a second address of the resource in a private network, and wherein the virtual network interface exposes the resource through a local network of the virtual network interface, the local network being different from the private network.

5 . The method of claim 1 , wherein the virtual network interface is generated at the client device by agent software provided by a system in the zero trust network environment to the client device.

6 . The method of claim 5 , further comprising:

receiving, at the system, credentials of a user account associated with the client device; and

providing the agent software from the system to the client device based on the system authenticating the credentials.

7 . The method of claim 1 , further comprising:

altering a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.

8 . A non-transitory computer readable medium comprising instructions that upon execution cause a system to:

send, from the system to a client device, agent software that when executed at the client device generates a virtual network interface having a namespace comprising a plurality of names, wherein a first name of the namespace is assigned to the client device, and a second name of the namespace is assigned to a resource accessible to the client device through a zero trust network environment;

receive, at the system from the client device, network traffic sent by the client device to the resource through the virtual network interface;

inspect the network traffic received from the client device;

determine, at the system, a destination of the network traffic; and

send, from the system, the network traffic to the destination based on determining that the network traffic is allowable according to a policy of the zero trust network environment, the policy being related to an entry of a domain catalog for the network traffic.

9 . The non-transitory computer readable medium of claim 8 , wherein the instructions upon execution cause the system to:

receive a credential from the client device;

authenticate the credential; and

send the agent software from the system to the client device based on authenticating the credential.

10 . The non-transitory computer readable medium of claim 8 , wherein the system is part of the zero trust network environment, the resource is part of a private network, and the zero trust network environment is between the client device and the private network.

11 . The non-transitory computer readable medium of claim 10 , wherein the virtual network interface generated at the client device has a routing table having a first address of the resource that is different from a second address of the resource in the private network, and wherein the virtual network interface exposes the resource through a local network of the virtual network interface, the local network being different from the private network.

12 . The non-transitory computer readable medium of claim 8 , wherein the entry of the domain catalog contains a domain name and an attribute of the domain name, and wherein the instructions upon execution cause the system to:

match information of the network traffic to the entry in the domain catalog.

13 . The non-transitory computer readable medium of claim 12 , wherein the instructions upon execution cause the system to:

identify the policy based on the attribute in the entry matched to the network traffic.

14 . A system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

send, from the system to a client device, agent software that when executed at the client device generates a virtual network interface having a namespace comprising a plurality of names, wherein a first name of the namespace is assigned to the client device, and a second name of the namespace is assigned to a resource accessible to the client device through a zero trust network environment;

receive, at the system from the client device, network traffic sent by the client device to the resource through the virtual network interface;

inspect, at the system, the network traffic received from the client device;

determine a destination of the network traffic; and

send, from the system, the network traffic to the destination based on determining that the network traffic is allowable according to a policy of the zero trust network environment, the policy being related to an entry of a domain catalog for the network traffic.

15 . The system of claim 14 , wherein the entry of the domain catalog contains a domain name and an attribute of the domain name, wherein the instructions are executable on the processor to:

match information of the network traffic to the entry in the domain catalog.

16 . The system of claim 15 , wherein the instructions are executable on the processor to:

identify the policy based on the attribute in the entry matched to the network traffic.

17 . The system of claim 14 , wherein the instructions are executable on the processor to:

alter a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.

18 . The system of claim 14 , wherein the instructions are executable on the processor to:

receive a credential from the client device;

authenticate the credential; and

send the agent software from the system to the client device based on authenticating the credential.

19 . The system of claim 14 , wherein the system is part of the zero trust network environment, the resource is part of a private network, and the zero trust network environment is between the client device and the private network.

20 . The system of claim 19 , wherein the virtual network interface generated at the client device has a routing table having a first address of the resource that is different from a second address of the resource in the private network, and wherein the virtual network interface exposes the resource through a local network of the virtual network interface, the local network being different from the private network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2024
From: ELUL, NATAN; REISEL, DANIEL; SVIRY, GUY; AZRIELANT, GIL; HAIM CHEN, YEHOSHUA
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 068086/0430 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 067407/0542 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 066846/0681 →
Continuity (1)
Related Publication 20250039131A1 · Jan 30, 2025
References Cited (34)
US 9525672B2 · Cignetti et al. · 2016 [cited by applicant]
US 10205657B2 · Chang · 2019 [cited by applicant]
US 11074091B1 · Nayakbomman et al. · 2021 [cited by applicant]
US 11159366B1 · Gawade et al. · 2021 [cited by applicant]
US 11240242B1 · Celik · 2022 [cited by applicant]
US 11316822B1 · Gawade et al. · 2022 [cited by applicant]
US 11470100B1 · Christian · 2022 [cited by applicant]
US 11588859B2 · Keiser, Jr. · 2023 [cited by examiner]
US 11843577B2 · Singh · 2023 [cited by examiner]
US 11902145B2 · Laplante · 2024 [cited by examiner]
US 11943260B2 · Narayanaswamy · 2024 [cited by examiner]
US 12034652B2 · Henkel · 2024 [cited by examiner]
US 12068958B1 · Henkel · 2024 [cited by examiner]
US 12101296B2 · Vemulpali · 2024 [cited by examiner]
US 20160182473A1 · Cignetti et al. · 2016 [cited by applicant]
US 20160261496A1 · Chang · 2016 [cited by applicant]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190238365A1 · Sudhakaran et al. · 2019 [cited by applicant]
US 20200236112A1 · Pularikkal et al. · 2020 [cited by applicant]
US 20200336466A1 · Goldschlag et al. · 2020 [cited by applicant]
US 20220075889A1 · Friedman · 2022 [cited by applicant]
US 20220158926A1 · Wennerstrom et al. · 2022 [cited by applicant]
US 20220278926A1 · Sharma et al. · 2022 [cited by applicant]
US 20220278927A1 · Mariappan et al. · 2022 [cited by applicant]
US 20220334864A1 · Kn et al. · 2022 [cited by applicant]
US 20230104568A1 · Miriyala · 2023 [cited by examiner]
US 20230107891A1 · Miriyala et al. · 2023 [cited by applicant]
US 20230123781A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230224167A1 · Wang et al. · 2023 [cited by applicant]
US 20230224302A1 · Sviri et al. · 2023 [cited by applicant]
US 20230224303A1 · Sviri et al. · 2023 [cited by applicant]
US 20230291726A1 · Dekel et al. · 2023 [cited by applicant]
US 20230388271A1 · Chen et al. · 2023 [cited by applicant]
US 20240422107A1 · Sharma et al. · 2024 [cited by applicant]