发明名称 Secure access to remote resources over a network
摘要 A client computer hosts a virtual private network tool to establish a virtual private network connection with a remote network. Upon startup, the virtual private network tool collects critical network information for the client computer, and sends this critical network information to an address assignment server in the remote network. The address assignment server compares the critical network information with a pool of available addresses in the remote network, and assigns addresses for use by the client computer that do not conflict with the addresses for local resources. The address assignment server also provides routing information for resources in the remote network to the virtual private network tool. The virtual private network tool will postpone loading this routing information into the routing tables of the client computer until the client computer requests access to a specific resource in the remote network. When the client computer requests access to a specific resource in the remote network, the virtual private network tool will only provide the routing table with the routing information for that specific remote resource.
申请公布号 US9407456(B2) 申请公布日期 2016.08.02
申请号 US201113038340 申请日期 2011.03.01
申请人 AVENTAIL LLC 发明人 Hoover Paul Lawrence;Erickson Rodger Del;Sauve Bryan
分类号 G06F15/173;H04L12/46;G06F21/62;H04L29/12;H04L29/06;H04L29/08 主分类号 G06F15/173
代理机构 Polsinelli LLP 代理人 Polsinelli LLP
主权项 1. A method for securely accessing a remote resource on a private network, the method comprising: storing in a memory of a client computing device a routing rule for accessing a remote resource; and executing instructions stored in the memory of the client computing device, wherein execution of the instructions by a processor: provides to a routing table stored in the memory of the client computing device one or more initial routing rules for accessing a name server in the network, wherein the one or more initial routing rules are limited to one or more routing rules necessary for accessing the name server;requests access to the remote resource by a client application stored in the memory of the client computing device using the name of the remote resource;transmits to the name server an address resolution query for the name of the remote resource based on the one or more initial routing rules;intercepts a reply from the name server intended for the client application, the reply including a network address corresponding to the name of the resource;obtains from the memory the routing rule corresponding to the name of the requested resource;determines that the client computing device is permitted to access the requested resource based on the routing rule;generates a routing rule for the network address identified in the reply;provides to the client application the routing rule for the network address generated from the intercepted reply; andopens by the client application a secure connection with the remote network based on the routing rule.
地址 San Jose CA US