IP Library Granted Patent US 11,362,987
Granted Patent B2
US 11,362,987 · App. 16/988,022 · Granted Jun 14, 2022

Fully qualified domain name-based traffic control for virtual private network access control

Inventors: Shanavas Kottikal Saidumuhamed (Thrisssur, IN); Prabhath Thankappan (Kottayam, IN); John Alappattu Varudunny (Thrissur, IN); George Mathew Koikara (Bangalore, IN)
Assignee: Pulse Secure, LLC
H04L61/1552H04L12/4633H04L12/4641H04L12/66H04L61/1511H04L63/101H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,362,987
App. No.
16/988,022
Granted
Jun 14, 2022
Kind
B2
Abstract

A system includes a virtual private network (VPN) gateway and a client device. The VPN gateway receives a domain name system response through a physical coding sublayer. The VPN gateway fetches a fully qualified domain name corresponding to the domain name system response, and fetches one or more access control list rules from an access control list table for a specific user account. The VPN gateway installs an Internet protocol (IP) address in the access control list table for each access control list rule and handles requested data traffic to the IP address. The client device creates a virtual tunnel interface route with a port of a transmission control protocol (TCP) listener device and parses the domain name system response. The client device updates a domain name system cache with the fully qualified domain name and the IP address and sends unencrypted network traffic over the virtual tunnel interface route.

Claims (32)

1. A system for controlling network traffic, the system comprising:

an access control table including a list of entries, wherein each entry includes a fully qualified domain name (FQDN), one or more IP addresses corresponding with each FQDN, and permissions and policies associated with the FQDN;

a mobile computing device, including at least one processor and a memory configured to execute a user application and a virtual private network (VPN) handler on the mobile computing device, wherein:

the user application is configured to establish a communications session with a transmission control protocol (TCP) listener device; and

the VPN handler is configured to:

split TCP network traffic and user datagram protocol (UDP) network traffic exiting the mobile computing device between a VPN tunnel and an external socket;

route the TCP network traffic either over the VPN tunnel or over the external socket in response to:

obtaining a FQDN corresponding with an IP address synchronization (SYN) packet used to initiate the communication session; and

determining whether the FQDN is associated with a public or a private network;

identify entries of the access control table that lack the permissions and policies associated with the FQDN;

send the entries to a VPN gateway through which the mobile computing device establishes the VPN tunnel; and

receive new entries the VPN gateway returns that include the permissions and policies associated with the FQDN for updating the identified entries.

2. The system of claim 1 , wherein the VPN handler encrypts and routes the TCP network traffic over the VPN tunnel in response to determining that the FQDN is associated with a private network.

3. The system of claim 1 , wherein the VPN handler routes an unencrypted version of the TCP network traffic over the external socket in response to determining that the FQDN is associated with a public network.

4. The system of claim 1 , wherein the VPN handler:

extracts information from the UDP network traffic including an IP address, a source port, and a destination port,

encrypts and routes the UDP network traffic over the VPN tunnel in response to determining that any of the extracted information is associated with a private network, and

routes an unencrypted version of the UDP network traffic over the external socket in response to determining that any of the extracted information is associated with a public network.

5. The system of claim 1 , further comprising the VPN gateway through which the mobile computing device establishes the VPN tunnel, wherein the access control table is stored on the VPN gateway.

6. The system of claim 1 , wherein the access control table is stored within the mobile computing device.

7. The system of claim 1 , wherein the VPN handler:

determines whether to route the TCP network traffic either over the VPN tunnel or over the external socket by matching an IP address of the SYN packet associated with the TCP network traffic to the entries in the access control table, and

processes data packets of the TCP network traffic according to the permissions and policies of the matched entries.

8. The system of claim 1 , wherein the VPN handler:

determines whether to route the UDP network traffic either over the VPN tunnel or over the external socket by matching any of a source port, a destination port, or an IP address of the UDP network traffic to the entries in the access control table, and

processes data packets of the UDP network traffic according to the permissions and policies of the matched entries.

9. The system of claim 1 , further comprising a domain name service (DNS) cache that maps IP addresses to FQDNs, wherein the VPN handler:

obtains the FQDNs corresponding to the IP addresses using the DNS cache; and

populates the FQDNs in the entries of the access control table when the entries are lacking FQDNs corresponding to the IP addresses.

10. The system of claim 9 , wherein the VPN handler:

issues a reverse DNS query to the DNS cache to reverse resolve the IP addresses to the FQDNs when IP addresses associated with the network traffic are known but no entries for the IP addresses exist in the access control table; and

adds entries to the access control table.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
Priority Claims (1)
IN 201841015035 · Apr 20, 2018 · national
Continuity (2)
Continuation 16388719 · Apr 18, 2019
Related Publication 20200366639A1 · Nov 19, 2020
Cited By (1)
US 12,531,836