DEVICE AND METHOD FOR FILTERING NETWORK REQUESTS MADE BY A CLIENT OR END USER
Patent Information
- Application Number
- ARP20220100797
- Authority / Receiving Office
- AR · AR
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-31
- Filing Date
- 2022-03-31
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Existing computing devices lack effective mechanisms to manage and filter data communications, particularly in environments where strict network access policies are required, such as in companies or schools, without creating infinite loops or compromising security.
Implementing a network access application that acts as the remote endpoint of a VPN connection, enabling selective communication management, monitoring, and filtering of data packets, while ensuring all other applications use the VPN except for the network access application itself.
Enables secure and controlled network access by allowing or blocking communications based on policy decisions, ensuring compliance with organizational policies and user safety, particularly effective in environments where children or employees need protection from inappropriate content.
Abstract
Description
Client filter VPN Cross-reference to related applications
[0001] This application claims priority and benefit from U.S. Provisional Patent Application 63 / 168,719, filed March 31, 2021, which is incorporated herein by reference. Field
[0002] This disclosure relates to computer systems and data communications, and in particular to filtering systems. Background
[0003] Computing devices are used for a wide range of data communications. It can be useful to filter or manage data communications. For example, a company may establish rules for employees using company devices. In other examples, schools may want to block certain websites and other content. Summary
[0004] According to one aspect of this disclosure, a device includes memory, a network interface, and a processor connected to the memory and the network interface. The processor is configured to run an operating system to execute a user application and enable access to a remote network resource through the network interface, and to enable a virtual private network (VPN) connection. The operating system enforces the use of the VPN connection by the user application. The processor is configured to run a network access application executed by the operating system. The network access application is configured as the remote endpoint of the VPN connection. The network access application is configured to communicate with the remote network resource on behalf of the user application.
[0005] The network access application can be configured to selectively allow or block communications between the user application and the remote network resource. 1746829 of 15
[0006] The network access application can be configured to control communications between the user application and the remote network resource.
[0007] The network access application can be configured to modify communications between the user application and the remote network resource.
[0008] The network access application may include a proxy configured to communicate with the remote network resource on behalf of the user application.
[0009] The network access application may be configured to maintain a mapping of data packets communicated between the user application and a plurality of remote network resources to network connections provided by the proxy.
[0010] The network access application can be configured to identify a data packet that does not fit the mapping and, in response, open a new network connection on the proxy.
[0011] The network access application may include a filter configured to selectively allow or block communications between the user application and the remote network resource.
[0012] The operating system may require the use of the VPN connection by all applications except the network access application.
[0013] According to one aspect of this disclosure, a method includes running a user application with an operating system. The operating system allows access to a remote network resource through a network interface and permits a virtual private network (VPN) connection. The operating system enforces the use of the VPN connection by the user application. The method further includes establishing the network access application as the remote endpoint of the VPN connection and the network access application communicating with the remote network resource on behalf of the user application.
[0014] The method may further include the network access application selectively allowing or blocking communications between the user application and the remote network resource. 1746829 of 15
[0015] The method may further include the network access application that monitors communications between the user application and the remote network resource.
[0016] The method may also include the network access application modifying communications between the user application and the remote network resource.
[0017] The method may further include the network access application using a proxy to communicate with the remote network resource on behalf of the user application.
[0018] The method may further include the network access application maintaining a mapping of data packets communicated between the user application and a plurality of remote network resources to network connections provided by the proxy.
[0019] The method may further include the network access application identifying a data packet that does not fit the mapping and, in response, opening a new network connection on the proxy.
[0020] The method may also include the operating system enforcing the use of the VPN connection by all applications except the network access application. Brief description of the drawings
[0021] Figure 1 is a block diagram of an example computer system according to this disclosure.
[0022] Figure 2 is a block diagram of another example of a computer system according to this disclosure.
[0023] Figure 3 is an example communications data flow diagram of the example system in Figure 2 when a request is allowed.
[0024] Figure 4 is an example communications data flow diagram of the example system in Figure 2 when a request is denied.
[0025] Figure 5 is a flow diagram of an example method according to this disclosure. 1746829 of 15
[0026] Figure 6 is a block diagram showing an example mapping according to this disclosure Detailed description
[0027] This disclosure describes techniques for filtering network requests made by a client or end user using a computing device, such as a smartphone, tablet, or laptop. The device may run a network access application that uses a virtual private network (VPN) software development kit (SDK) to redirect traffic through a filtering application. The filtering application does not create a VPN connection and does not send traffic to a remote server. All communication between the device and the network may pass through the filtering application. A remote VPN endpoint is not used. Rather, the VPN SDK is used to consume packets and redirect them for filtering purposes, and then send broadcast packets out of the device.The VPN can be configured by a mobile device management (MDM) system or installed by the user or client using the mobile computing device. The network access application has full access to all traffic communicated through the VPN. The network access application can filter network requests made by any other application on the device. It can perform this filtering by sending network requests to a remote server or system, receiving allow / deny decisions, and blocking or redirecting denied requests.
[0028] As shown in Figure 1, an electronic device 10 connects to a network 12 to communicate with a remote network resource 14. The device 10 can be a smartphone, laptop, or similar electronic device with a controlled or closed operating system, such as Android™ or iOS™. The remote network resource 14 can be a server, such as a website server, social media server, application server, or similar. The remote network resource 14 can include any number and type of servers and can be referred to as a server cluster or cloud. 1746829 of 15 Network 12 can be a wide area computer data network, such as the Internet, and may also include a connected wide area network (WAN) or local area network (LAN). Communication between device 10 and remote network resource 14 can be unidirectional or bidirectional, and bidirectional communication is typically expected. Any number of different devices 10 and remote network resources 14 can be provided for any number of users and services.
[0029] Device 10 includes memory 20, a network interface 22, and a processor 26 connected to memory 20 and network interface 22.
[0030] Memory 20 may include any suitable non-transient, computer-readable storage medium, such as read-only memory (ROM), random-access memory (RAM), flash memory, electrically erasable programmable read-only memory (EEPROM), a solid-state drive (SSD), and a combination thereof. Memory 20 may include both volatile and non-volatile components.
[0031] Network interface 22 may include a network adapter and controller suitable for communicating data across computer network 12, such as a local area network (LAN), a wide area network (WAN), the Internet, or a combination thereof. Computer network 12 may be wired, wireless, or a combination thereof, and network interface 22 may be configured accordingly.
[0032] The processor 26 may include a central processing unit (CPU), a microprocessor, a programmable gate array (FPGA), or an application-specific integrated circuit (ASIC) configurable by hardware, firmware, and / or software.
[0033] Instructions can be provided to memory 20 for execution by the processor 26 to perform the functionality discussed herein, such as implementing a network access application, an operating system, a user application, etc. The instructions can be executed directly, as binary or machine code, and / or can include code 1746829 of 15 interpretable, byte code, source code or similar instructions that may be subjected to further processing in order to execute.
[0034] Device 10 may further include a user interface 24. The user interface 24 may include any device suitable for processing user input / output, such as a display, a touchscreen, a button, a speaker, a microphone, and a suitable combination thereof. Examples of a device 10 that omits a user interface (or has a very limited user interface) include Internet of Things (IoT) devices, such as network cameras.
[0035] Memory 20 can store an operating system (OS) 30, a user application 32, and a network access application 34, as well as data related to these. The processor 26 cooperates with memory 20 to execute the code that implements the operating system 30, the user application 32, and the network access application 34. The applications 32 and 34 are executed by the OS 30, which can provide and manage resources for the applications 32 and 34, such as processor time and memory allocation.
[0036] OS 30 also allows access to remote network resource 14 through network interface 22, which may include providing a network application programming interface (API) for applications 32, 34 to reference. OS 30 can enable VPN connections over network 12. OS 30 can be Android™, iOS™, or similar. For Android, the public class VpnService can be used (see https: / / developer.android.com / reference / android / net / VpnService). For iOS, a VPN extension point, such as NEAppProxyProvider and NEPacketTunnelProvider, can be used (see https: / / developer.apple.com / documentation / networkextension / nepackettunnelprovider).
[0037] OS 30 can be configured to enforce the use of a VPN connection by the user application 32. This can be done with a 1746829 of 15 MDM application used with device 10 or by manually configuring a VPN configuration profile through OS 30. OS 30 can enforce the use of the VPN connection by all applications where this is possible, except for the network access application 34. Not enforcing the VPN connection on the network access application 34 prevents an infinite loop.
[0038] User Application 32 can be an application specifically configured to communicate with Remote Network Resource 14. For example, Remote Network Resource 14 might provide a website, and User Application 32 might be a web browser or other user agent. In another example, Remote Network Resource 14 might accept and provide image data and text data, and User Application 32 might be a social media application, such as Twitter™, Facebook™, or similar. In yet another example, Remote Network Resource 14 might accept and provide data in a proprietary or custom format / protocol, and User Application 32 might be specifically written to communicate using that format / protocol. In some examples, User Application 32 might be part of the operating system 30, such as a web browser that is tightly integrated with the operating system 30, such as through the use of a non-public API.
[0039] Network Access Application 34 is configured as a remote endpoint of the VPN connection that OS 30 forces Application 32 to use. Network Access Application 34 is configured to communicate with Remote Network Resource 14 on behalf of User Application 32. Because it is the VPN endpoint, Network Access Application 34 can inspect the contents of the data packets it handles. Accordingly, Network Access Application 34 can be configured to selectively allow or block communications between User Application 32 and Remote Network Resource 14, monitor communications between User Application 32 and Remote Network Resource 14, modify communications between User Application 32 and Remote Network Resource 14, or a combination thereof. 1746829 of 15
[0040] In several examples, the network access application 34 is configured as a remote endpoint of the VPN connection by means of an API exposed by OS 30. Such an API can allow the network access application 34 to obtain callbacks for the network traffic packet by packet. That is, the network access application 34 can receive a callback for each packet communicated to / from device 10, and that callback can provide the contents of the packet. An API can, additionally or alternatively, provide a virtual interface for the network access application 34. Furthermore, the API can allow the registration of the network access application 34. An example of registration of the network access application 34 includes the network access application 34 extending a programmatic object and implementing any function callbacks required to process VPN data.OS 30 can abstract low-level implementation details that the API exposes to the network access application 34.
[0041] As shown in Figure 2, another device 50 includes another example of a network access application 52 that includes a proxy 54 to communicate with the remote network resource 14 on behalf of the user application 32. In the examples discussed herein, the proxy 54 is a transparent proxy. The proxy 54 can manage the relationship between the network data packets known to the OS 30 and the user application 32 and the network data packets known to the network 12 and the remote network resource 14.
[0042] The proxy 54 or another component of the network access application 52 can maintain a mapping of data packets communicated between the user application 32 and a plurality of remote network resources 14 to network connections provided by the proxy 54. That is, the proxy can maintain a connection (or socket) for each data flow between an endpoint user application 32 and a remote network resource 14. When a data packet is identified that does not fit the mapping, a new network connection can be opened on the proxy 54. 1746829 of 15
[0043] The network access application 52 further includes a filter 56 to selectively permit, block, or modify communications between the user application 32 and the remote network resource 14. The filter 56 can inspect data packets and communicate information about those packets to a policy service 60 over the network 12. In other examples, the policy service 60 can be provided to the memory 20 of the device 50.
[0044] For example, filter 56 can scan outgoing packets for new Hypertext Transfer Protocol (HTTP) or Secure HTTP (HTTPS) requests to Uniform Resource Locators (URLs) from user application 32 (e.g., a web browser). If a URL is detected, filter 56 can provide that URL to policy service 60 for a policy decision (e.g., can the device user access this URL?). Filter 56 can also provide information related to device 50 and the person operating the device, such as user group, age, job / role, employer, school, etc. Policy service 60 responds to filter 56 with a command to allow or block the requested URL. A block command can identify a URL to which the filter should redirect user application 32.In some examples, the policy service 60 responds with the requested URL, if permitted, or with a redirect URL, if the requested URL is blocked. A redirect URL can be provided to the browser as an HTTP / HTTPS redirect, which can go through the same policy decision process discussed above and not be blocked. A server at the redirect URL can respond with a warning message informing the user that the requested URL has been blocked. An example policy service is described in published PCT patent application WO2011004258, which is incorporated herein by reference.
[0045] Figure 3 shows an example of data flow in the system depicted in Figure 2, in which communication is permitted between a user application 32 and a remote network resource 14. Note that 1746829 of 15 Some communications are omitted for the sake of clarity, such as communications between a proxy 54 and / or filter 56 and OS 30. It should be understood that, in several examples, proxy 54 and / or filter 56 may carry out their network communications through OS 30.
[0046] In communication 72, a user application 32 makes a request to a remote network resource 14 by first calling a function provided by the OS 30.
[0047] In communication 74, OS 30 determines that a VPN configuration 70 is in effect for application 32.
[0048] In communication 76, from VPN configuration 70, OS 30 determines that the VPN endpoint is a network access application 52 and a proxy 54 on the same device as application 32 and OS 30.
[0049] In communication 78, the network access application 52 determines that the request is subject to policy. This may include communication between proxy 54 and a filter 56 associated with the network access application 52.
[0050] In communication 80, filter 56 requests a policy decision from a policy service 60.
[0051] In communication 82, policy service 60 responds, in this example, with an indication that the original request from user application 32 should be allowed.
[0052] In communication 84, the filter and the proxy can share knowledge of the policy decision.
[0053] In communication 86, proxy 54 makes the original request to remote network resource 14 on behalf of user application 32.
[0054] In communication 88, remote network resource 14 responds to proxy 54, which then provides the response to operating system 30 via VPN configuration 70, in communications 90 and 92.
[0055] In communication 94, OS 30 then provides the data to user application 32 that was originally requested in communication 72. 1746829 of 15
[0056] Figure 4 shows an example of data flow in the system depicted in Figure 2, in which communication between a user application 32 and a remote network resource 14 is blocked. Note that some communications are omitted for clarity, such as communications between a proxy 54 and / or filter 56 and OS 30. It should be understood that, in several examples, the proxy 54 and / or filter 56 may perform their network communications through OS 30.
[0057] In communications 72-78, as mentioned above, a user application 32 makes a request that is processed by a VPN endpoint on the same device as the user application, i.e., by a network access application 54.
[0058] In communication 80, filter 56 requests a policy decision from a policy service 60.
[0059] In communication 100, policy service 60 responds, in this example, with an indication that the original request from user application 32 is not permitted and should be blocked.
[0060] In communication 102, the filter and the proxy can share knowledge of the policy decision.
[0061] In communication 104 and 106, proxy 54 provides an indication of the policy decision to block the request to OS 30 through VPN configuration 70.
[0062] In communication 108, OS 30 informs user application 32 of the blocking of the original request in communication 72.
[0063] In several examples, in communication 100, policy service 60 may provide a redirect address (e.g., a URL) indicating that the original request is blocked. User application 32 may receive the redirect address, via communications 104 and 106, and may make a new request for a resource at the redirect address. The processing of the new request may occur as shown in Figure 3 (i.e., it is allowed) with a response from a 1746829 of 15 different remote network resource 14 in the redirection address which is a denial page or other warning message that application 32 may display or otherwise process.
[0064] Figure 5 shows a flowchart of an example method 120. Method 120 can be implemented by a network access application, an operating system, or other programmatic instructions executable by a processor.
[0065] In block 122, a user application is running with an operating system. The operating system allows access to a remote network resource through a network interface. The operating system further enables a virtual private network (VPN) connection and enforces the use of the VPN connection by the user application.
[0066] In block 124, a network access application is configured as the remote endpoint of the VPN connection. This can be done before or during the user application startup. The operating system can require all applications except the network access application to use the VPN connection.
[0067] In block 126, the network access application communicates with the remote network resource on behalf of the user application. A mapping of data packets to network connections can be referenced. If a data packet does not match the mapping, a new network connection can be opened.
[0068] The network access application can monitor communications between the user application and the remote network resource, and can also selectively allow or block communications between the user application and the remote network resource. The network access application can use deep packet inspection (DPI). In various examples, the network access application can modify communications between the user application and the remote network resource, for example, to insert messages to the user of the user application, delete content, etc. 1746829 of 15 example, a message can be inserted to indicate that certain content was deleted.
[0069] Method 120 can terminate when the application execution ends, via block 128. Method 120 can be performed continuously and in parallel for several different applications.
[0070] Figure 6 shows further details of a sample network access application 52. The network access application 52 can maintain a mapping 140 of data packets 144 and connection identifiers 146 for network connections provided by the proxy 54. The proxy 54 can maintain a connection identifier (or socket) 146 for each data flow between an endpoint user application and a remote network resource. The mapping 140 associates data packets 144 to connection identifiers 146 and further associates user applications to data packets 144 through user application identifiers 142. Each user application identifier 142 can be associated with multiple data packets 144. Each connection identifier 146 can be associated with multiple data packets 144.A data packet 144 can be provided with a connection identifier 146 when, for example, a user application sends an outgoing data packet 144. A remote network resource can maintain such connection identifiers 146 when it responds with incoming data packets 144. Therefore, proxy 54 can use mapping 140 to associate incoming data packets with the correct user application. When a data packet 144 is identified that does not fit mapping 140, a new network connection 146 can be opened on proxy 54, and a corresponding connection identifier 146 can be generated. This can occur when a user application initiates a new communication with a remote resource.
[0071] In view of the above, it should be evident that a client device can enable network access policy decisions, traffic monitoring, and alteration of communications by using an application on the client device as the endpoint of a VPN created on the client device. 1746829 of 15 restrictions that an operating system imposes on the inspection, analysis, and manipulation of network traffic can be bypassed, so that most or all significant network traffic to / from the device can be known at the application level. This allows an application to provide security features, such as blocking harmful websites and search results, to be deployed on client devices, particularly where such devices are used by children or others who do not wish to be exposed to such content.
[0072] It should be recognized that the features and aspects of the various examples provided above may be combined in other examples that also fall within the scope of this disclosure. In addition, the figures are not to scale and may be exaggerated in size and shape for illustrative purposes.
Claims
1. A device for filtering network requests made by a client or end user, characterized in that it comprises: a memory; a network interface; and a processor connected to the memory and the network interface, the processor being configured to run: an operating system to run a user application, enable access to a remote network resource through the network interface and enable a virtual private network (VPN) connection, wherein the operating system enforces the use of the VPN connection by the user application; and a network access application run by the operating system, on a client device, the network access application being configured as the remote endpoint of the VPN connection;wherein the network access application comprises: a proxy configured to communicate with the remote network resource on behalf of the user application by managing the relationship between network data packets as known to the user application and the remote network resource; and a filter configured to selectively permit, block, or modify communications between the user application and the remote network resource in accordance with policy decisions received from a policy service; and wherein the network access application creates the VPN on the device to enable inspection, filtering, and modification of traffic by the proxy and the filter. Sixteen claims follow;