IP Library › Granted Patent US 12,695,725
Granted Patent B2
US 12,695,725 · App. 18/796,053 · Granted Jul 28, 2026

VPN deep packet inspection

Inventors: Steven C. Work (Seattle, WA); Prakash N. Masanagi (Seattle, WA); Christopher D. Peterson (Seattle, WA)
Assignee: SONICWALL US HOLDINGS INC.
H04L63/0272H04L63/0281H04L63/164H04L63/166H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,725
App. No.
18/796,053
Filed
Aug 6, 2024
Granted
Jul 28, 2026
Kind
B2
Art Unit
2498
USPC
726/15
Abstract

Policy enforcement previously available for web proxy access methods is extended and applied to layer 3 packets flowing through VPN channels. With these extensions, a common security policy is possible that is enforceable between VPN proxied access and VPN tunneled access. Equivalent security policy to tunnel based VPN access without comprising the inherent performance, scalability and application compatibility advantages tunnel based VPNs have over their proxy based VPN counterparts.

Claims (34)

1 . A method for securing a virtual private network (VPN), the method comprising:

receiving a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

accessing authentication data from a data store, wherein the authentication data includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session;

identifying that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allowing the proxied VPN session with the originating device based on the identified session type, wherein data traveling through the proxied VPN session is subjected to packet inspection; and

passing to a proxy server a connection identifier that allows the proxy server to provide policy server requests correlating to the packet inspected data for the proxied VPN session with the originating device.

2 . The method of claim 1 , further comprising tracking a state of the proxied VPN session, and storing the state of the proxied VPN session tracked in the data store.

3 . The method of claim 1 , wherein the policy server requests made by the proxy server correspond to a response to the connection request from the originating device.

4 . The method of claim 1 , wherein allowing the proxied VPN session includes identifying the proxy server for receiving communications associated with the proxied VPN session.

5 . The method of claim 1 , further comprising sending application-level information by spoofing a protocol exchange with the originating device, wherein the application-level information is included in the connection request.

6 . The method of claim 1 , further comprising supplying one or more tunnels of the VPN with a list corresponding to a port.

7 . The method of claim 6 , wherein the list is associated with one or more access rules specifying application-level information associated with allowing the proxied VPN session.

8 . The method of claim 1 , wherein allowing the proxied VPN session is further based on identifying that the authentication information of the originating device matches the authentication data in the data store and the session type.

9 . An apparatus for securing a virtual private network (VPN), the apparatus comprising:

a transceiver that receives a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

a data store that stores authentication data that includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session; and

a processor that executes instructions stored in memory, wherein the processor executes the instructions to:

access the authentication data from the data store;

identify that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allow the proxied VPN session with the originating device based on the identified session type, wherein data traveling through the proxied VPN session is subjected to packet inspection; and

pass to a proxy server a connection identifier that allows the proxy server to provide policy server requests correlating to the packet inspected data for the proxied VPN session with the originating device.

10 . The apparatus of claim 9 , wherein the processor executes further instructions to track a state of the proxied VPN session, and wherein the data store further stores the state of the proxied VPN session.

11 . The apparatus of claim 9 , wherein the policy server requests made by the proxy server correspond to a response to the connection request from the originating device.

12 . The apparatus of claim 9 , wherein the processor allows the proxied VPN session by identifying the proxy server for receiving communications associated with the proxied VPN session.

13 . The apparatus of claim 9 , wherein the transceiver further sends application-level information by spoofing a protocol exchange with the originating device, wherein the application-level information is included in the connection request.

14 . The apparatus of claim 9 , wherein the processor executes further instructions to supply one or more tunnels of the VPN with a list corresponding to a port.

15 . The apparatus of claim 14 , wherein the list is associated with one or more access rules specifying application-level information associated with allowing the proxied VPN session.

16 . The apparatus of claim 9 , wherein the processor allows the proxied VPN session further based on identifying that the authentication information of the originating device matches the authentication data in the data store and the session type.

17 . A non-transitory, computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for securing a virtual private network (VPN), the method comprising:

receiving a connection request from an originating device for a VPN session, wherein the connection request is associated with authentication information including a user identifier and a hardware identifier of the originating device;

accessing authentication data from a data store, wherein the authentication data includes a plurality of user identifiers and hardware identifiers associated with access to the VPN session;

identifying that the authentication information of the originating device matches the authentication data in the data store and a session type corresponding to a proxied VPN session;

allowing the proxied VPN session with the originating device based on the identified session type, wherein data traveling through the proxied VPN session is subjected to packet inspection; and

passing to a proxy server a connection identifier that allows the proxy server to provide policy server requests correlating to the packet inspected data for the proxied VPN session with the originating device.

Assignments (6)
SECURITY INTEREST Recorded Jul 9, 2026
From: SONICWALL US HOLDINGS INC.; SONICWALL INC.; BANYAN SECURITY, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 075961/0674 →
SECURITY INTEREST Recorded Jul 9, 2026
From: SONICWALL US HOLDINGS INC.; SONICWALL INC.; BANYAN SECURITY, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 075961/0907 →
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2024
From: PETERSON, CHRISTOPHER
To: SONICWALL US HOLDINGS INC.
Reel/Frame 068916/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2024
From: WORK, STEVEN C.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 068916/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2024
From: MASANAGI, PRAKASH NAGAPPA
To: AVENTAIL LLC
Reel/Frame 069210/0746 →
Continuity (5)
Continuation 18103898 · Jan 31, 2023
Continuation 16590253 · Oct 1, 2019
Continuation 13773475 · Feb 21, 2013
Provisional Application 61601318 · Feb 21, 2012
Related Publication 20250039147A1 · Jan 30, 2025
References Cited (67)
US 5414833A · Hershey et al. · 1995 [cited by applicant]
US 5796942A · Esben · 1998 [cited by applicant]
US 5945933A · Kalkstein · 1999 [cited by applicant]
US 6088803A · Tso et al. · 2000 [cited by applicant]
US 6108782A · Fletcher et al. · 2000 [cited by applicant]
US 6119236A · Shipley · 2000 [cited by applicant]
US 6178448B1 · Gray et al. · 2001 [cited by applicant]
US 6219706B1 · Fan et al. · 2001 [cited by applicant]
US 6449723B1 · Elgressy et al. · 2002 [cited by applicant]
US 6678835B1 · Shah · 2004 [cited by applicant]
US 6708187B1 · Shanumgam · 2004 [cited by applicant]
US 6789203B1 · Belissent · 2004 [cited by applicant]
US 6851061B1 · Holland et al. · 2005 [cited by applicant]
US 6880005B1 · Bell · 2005 [cited by examiner]
US 7032022B1 · Shanumgam · 2006 [cited by applicant]
US 7058821B1 · Parekh et al. · 2006 [cited by applicant]
US 7134143B2 · Stellenberg et al. · 2006 [cited by applicant]
US 7152164B1 · Loukas · 2006 [cited by applicant]
US 7185368B2 · Copeland · 2007 [cited by applicant]
US 7304996B1 · Swenson et al. · 2007 [cited by applicant]
US 7849502B1 · Bloch et al. · 2010 [cited by applicant]
US 7881199B2 · Krstulich · 2011 [cited by applicant]
US 8189468B2 · Bugenhagen · 2012 [cited by applicant]
US 8339959B1 · Moisand et al. · 2012 [cited by applicant]
US 8726007B2 · Chandrika · 2014 [cited by examiner]
US 9191327B2 · Shieh · 2015 [cited by applicant]
US 10432587B2 · Work · 2019 [cited by applicant]
US 11570150B2 · Work · 2023 [cited by applicant]
US 12058109B2 · Work · 2024 [cited by applicant]
US 20030177389A1 · Albert · 2003 [cited by applicant]
US 20040165588A1 · Pandya · 2004 [cited by applicant]
US 20050185647A1 · Rao et al. · 2005 [cited by applicant]
US 20060037072A1 · Rao · 2006 [cited by examiner]
US 20060123074A1 · Yoshimoto et al. · 2006 [cited by applicant]
US 20060229896A1 · Rosen et al. · 2006 [cited by applicant]
US 20070153798A1 · Krsstulich · 2007 [cited by applicant]
US 20070192842A1 · Beaulieu · 2007 [cited by applicant]
US 20080301801A1 · Jothimani · 2008 [cited by examiner]
US 20090225762A1 · Davidson · 2009 [cited by examiner]
US 20090254967A1 · J et al. · 2009 [cited by applicant]
US 20100037311A1 · He et al. · 2010 [cited by applicant]
US 20100223458A1 · McGrew et al. · 2010 [cited by applicant]
US 20110286466A1 · Ge et al. · 2011 [cited by applicant]
US 20120002813A1 · Wei · 2012 [cited by examiner]
US 20120005476A1 · Wei et al. · 2012 [cited by applicant]
US 20120005745A1 · Wei · 2012 [cited by examiner]
US 20120023554A1 · Murgia · 2012 [cited by applicant]
US 20120036244A1 · Ramachandra et al. · 2012 [cited by applicant]
US 20120096548A1 · Riordan et al. · 2012 [cited by applicant]
US 20120144019A1 · Zhu et al. · 2012 [cited by applicant]
US 20120173694A1 · Yan et al. · 2012 [cited by applicant]
US 20130014246A1 · Larson · 2013 [cited by applicant]
US 20130219486A1 · Work · 2013 [cited by applicant]
US 20200106747A1 · Work · 2020 [cited by applicant]
US 20230254286A1 · Work · 2023 [cited by applicant]
EP 1972096B1 · 2006 [cited by applicant]
EP 2007082A1 · 2007 [cited by applicant]
EP 1853013A1 · 2007 [cited by applicant]
EP 2225663B1 · 2008 [cited by applicant]
EP 2568730A1 · 2010 [cited by applicant]
Cascarano, N., Ciminiera, L., Risso, F. (2011). Optimizing deep packet inspection for high-speed traffic analysis. Journal of Network and Systems Management, 19(1), 7-31. doi.http://dx.doi.org/10.1007/s10922-010-9181-x … [cited by applicant]
U.S. Appl. No. 13/773,475; Final Office Action mailed Apr. 16, 2015. [cited by applicant]
U.S. Appl. No. 13/773,475; Office Action mailed Oct. 2, 2014. [cited by applicant]
U.S. Appl. No. 13/773,475; Final Office Action mailed Jun. 16, 2014. [cited by applicant]
U.S. Appl. No. 13/773,475; Office Action mailed Mar. 14, 2014. [cited by applicant]
U.S. Appl. No. 16/590,253; Office Action mailed Sep. 21, 2021. [cited by applicant]
U.S. Appl. No. 18/103,898; Office Action mailed Oct. 13, 2023. [cited by applicant]