IP Library Granted Patent US 12706883
Granted Patent B2
US 12706883 · App. 18/800,290 · Granted Aug 11, 2026

Obscuring private network topologies for P2P group configuration using on-premises proxy services

Inventors: Alexander Schäfer (Duesseldorf, DE); Christopher Probst-Ranly (Solingen, DE); Stefan Lindmark (Östhammar, SE)
Assignee: Google LLC
H04L63/0281H04L63/0407H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706883
App. No.
18/800,290
Granted
Aug 11, 2026
Kind
B2
Abstract

A data item is provided to an on-premises proxy service by a peer-to-peer (P2P) client device associated with a video conferencing platform. The P2P client device and the on-premises proxy service are associated with a private network. The data item comprises topological information corresponding to the private network. A transformed version of the data item is received from the on-premises proxy service. The transformed version of the data item obscures the topological information corresponding to the private network. The transformed version of the data item is provided to an external tracking service for a P2P configuration operation. The external tracking service is associated with the video conferencing platform and is external to the private network.

Claims (45)

1 . A method comprising:

requesting, from an external service associated with a video conferencing platform, an address of an on-premises proxy service, wherein the address corresponds to a private address range of a private network, and wherein the external service is external to the private network;

providing, by a peer-to-peer (P2P) client device associated with the video conferencing platform, a data item to the on-premises proxy service, wherein the P2P client device and the on-premises proxy service are part of the private network, and wherein the data item comprises topological information corresponding to the private network;

receiving, from the on-premises proxy service, a transformed version of the data item, wherein the transformed version of the data item obscures the topological information corresponding to the private network; and

providing the transformed version of the data item to the external tracking service for a P2P configuration operation.

2 . The method of claim 1 , wherein the data item is an IP address of a private IP address range associated with the private network, wherein the IP address is provided to the on-premises proxy service in association with an IP address resolution request, and wherein the transformed version of the data item is a peering group ID corresponding to a set of peers in the private network.

3 . The method of claim 2 , wherein a correspondence between the private IP address range and the peering group ID is defined in a configuration table stored within the private network.

4 . The method of claim 1 , wherein the data item is a Session Description Protocol (SDP) offer for a second P2P client device in the private network, and wherein the transformed version of the data item is an encrypted SDP offer.

5 . The method of claim 4 , further comprising:

receiving, from the external service, an encrypted SDP answer associated with the second P2P client device;

providing the encrypted SDP answer to the on-premises proxy service; and

receiving a decrypted SDP answer from the on-premises proxy service.

6 . The method of claim 1 , wherein providing the data item to the on-premises proxy service comprises using an API associated with the external service, wherein the on-premises proxy service conforms to the API.

7 . The method of claim 6 , wherein:

requesting the address of the on-premises proxy service is performed prior to providing the data item to the on-premises proxy service.

8 . A system comprising:

a memory device; and

a processing device coupled to the memory device, the processing device to perform operations comprising:

requesting, from an external service associated with a video conferencing platform, an address of an on-premises proxy service, wherein the address corresponds to a private address range of a private network, and wherein the external service is external to the private network;

providing, by a peer-to-peer (P2P) client device associated with the video conferencing platform, a data item to the on-premises proxy service, wherein the P2P client device and the on-premises proxy service are are part of the private network, and wherein the data item comprises topological information corresponding to the private network;

receiving, from the on-premises proxy service, a transformed version of the data item, wherein the transformed version of the data item obscures the topological information corresponding to the private network; and

providing the transformed version of the data item to the external tracking service for a P2P configuration operation.

9 . The system of claim 8 , wherein the data item is an IP address of a private IP address range associated with the private network, wherein the IP address is provided to the on-premises proxy service in association with an IP address resolution request, and wherein the transformed version of the data item is a peering group ID corresponding to a set of peers in the private network.

10 . The system of claim 9 , wherein a correspondence between the private IP address range and the peering group ID is defined in a configuration table stored within the private network.

11 . The system of claim 8 , wherein the data item is a Session Description Protocol (SDP) offer for a second P2P client device in the private network, and wherein the transformed version of the data item is an encrypted SDP offer.

12 . The system of claim 11 , the operations further comprising:

receiving, from the external tracking service, an encrypted SDP answer associated with the second P2P client device;

providing the encrypted SDP answer to the on-premises proxy service; and

receiving a decrypted SDP answer from the on-premises proxy service.

13 . The system of claim 8 , wherein providing the data item to the on-premises proxy service comprises using an API associated with the external service, wherein the on-premises proxy service conforms to the API.

14 . The system of claim 13 , wherein:

requesting the address of the on-premises proxy service is performed prior to providing the data item to the on-premises proxy service.

15 . A non-transitory computer-readable medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

requesting, from an external service associated with a video conferencing platform, an address of an on-premises proxy service, wherein the address corresponds to a private address range of a private network, and wherein the external service is external to the private network;

providing, by a peer-to-peer (P2P) client device associated with the video conferencing platform, a data item to the on-premises proxy service, wherein the P2P client device and the on-premises proxy service are part of the private network, and wherein the data item comprises topological information corresponding to the private network;

receiving, from the on-premises proxy service, a transformed version of the data item, wherein the transformed version of the data item obscures the topological information corresponding to the private network; and

providing the transformed version of the data item to the external tracking service for a P2P configuration operation.

16 . The non-transitory computer-readable medium of claim 15 , wherein the data item is an IP address of a private IP address range associated with the private network, wherein the IP address is provided to the on-premises proxy service in association with an IP address resolution request, and wherein the transformed version of the data item is a peering group ID corresponding to a set of peers in the private network.

17 . The non-transitory computer-readable medium of claim 16 , wherein a correspondence between the private IP address range and the peering group ID is defined in a configuration table stored within the private network.

18 . The non-transitory computer-readable medium of claim 15 , wherein the data item is a Session Description Protocol (SDP) offer for a second P2P client device in the private network, and wherein the transformed version of the data item is an encrypted SDP offer.

19 . The non-transitory computer-readable medium of claim 18 , the operations further comprising:

receiving, from the external service, an encrypted SDP answer associated with the second P2P client device;

providing the encrypted SDP answer to the on-premises proxy service; and

receiving a decrypted SDP answer from the on-premises proxy service.

20 . The non-transitory computer-readable medium of claim 15 , wherein providing the data item to the on-premises proxy service comprises using an API associated with the external service, wherein the on-premises proxy service conforms to the API.