IP Library Granted Patent US 9,130,936
Granted Patent B2
US 9,130,936 · App. 12/572,656 · Granted Sep 8, 2015

Method and system for providing secure access to private networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,130,936
App. No.
12/572,656
Granted
Sep 8, 2015
Kind
B2
Abstract

Improved approaches for providing secure remote access to resources maintained on private networks are disclosed. According to one aspect, predetermined elements, such as applets, can be modified to redirect all communications to and from an application server through an intermediate server. The intermediate server in turn communicates with the application servers. According to another aspect, a communication framework can be provided to funnel communication between an applet and a server through a communication layer so as to provide managed and/or secured communications there between.

Claims (39)

1. A system for communicating between a client and a server through an intermediate server, said system comprising:

a non-transitory computer-readable storage medium storing code that is executable to implement:

a communication layer to transform one or more socket connections into a pair of unidirectional secure URL connections with the intermediate server; and

an applet to create at least one socket connection with the communication layer to enable communication between the applet and the server via the pair of unidirectional secure URL connections with the intermediate server, the applet including applet bytecode having been modified by the intermediate server to redirect applet communications with the server through the intermediate server.

2. The system as recited in claim 1 , where the applet communicates with the intermediate server using packets of data.

3. The system as recited in claim 2 , where the packets include a header and data, and where the header includes at least a browser identifier and a socket identifier.

4. The system as recited in claim 1 , where said communication layer comprises:

an outgoing queue to buffer outgoing packets of data received from the at least one socket connection with said applet; and

a sender thread that sends the packets of data stored in said outgoing queue to said intermediate server.

5. The system as recited in claim 1 , where said communication layer comprises:

a reader thread that receives packets of data sent from said intermediate server to said applet via said communication layer; and

at least one incoming queue to buffer incoming packets of data received from said intermediate server.

6. The system as recited in claim 5 , where said at least one incoming queue operatively connects with the at least one socket connection of said applet.

7. The system as recited in claim 1 , where flow control messages are sent between said communication layer and said intermediate server.

8. The system as recited in claim 1 , where said communication layer is to send acknowledgment messages to said intermediate server.

9. The system as recited in claim 1 , where one of the pair of the unidirectional secure URL connections includes an outgoing unidirectional secure URL connection, and the other of the pair of the unidirectional secure URL connections includes an incoming unidirectional secure URL connection.

10. The system as recited in claim 9 , where the outgoing unidirectional secure URL connection includes a transient connection.

11. The system as recited in claim 9 , where the incoming unidirectional secure URL connection includes a persistent connection.

12. The system as recited in claim 1 , where said communication layer includes an applet communication layer.

13. A system for communicating between a client and a server via an intermediate server, said system comprising:

a non-transitory computer-readable storage medium storing code that is executable to implement:

a communication layer, and

one or more applets to create at least one socket connection with the communication layer, the one or more applets including applet bytecode having been modified by the intermediate server to redirect applet communications with the server through the intermediate server, where

the communication layer is to transform the at least one socket connection into a pair of unidirectional URL connections with the intermediate server to enable the one or more applets to communicate with the server via the pair of unidirectional URL connections with the intermediate server.

14. The system as recited in claim 13 , where the pair of unidirectional URL connections include secure connections.

15. The system as recited in claim 13 , where the pair of unidirectional URL connections include HTTPS connections.

16. The system as recited in claim 13 , where one of the pair of unidirectional URL connections includes a transient connection, and the other of the pair of unidirectional URL connections includes a persistent connection.

17. A system for communicating between a client and a server via an intermediate server, said system comprising:

a non-transitory computer-readable storage medium storing code that is executable to implement:

a communication layer, and

one or more applets to create at least one socket connection with the communication layer, the one or more applets including applets bytecode having been modified by the intermediate server to redirect applet communications with the server through the intermediate server, where

the communication layer is to:

establish an intermediate socket connection with the intermediate server to enable communication between the one or more applets and the server over the intermediate socket connection when the intermediate socket connection can be established and to transform said at least one socket connection into a pair of unidirectional URL connections with the intermediate server to enable communication between the one or more applets and the server over the pair of unidirectional URL connections when the intermediate socket connection cannot be established.

18. A method for communicating between a client and a server via an intermediate server, said method comprising:

creating at least one socket connection between one or more applets and a communication layer, the one or more applets including applet bytecode having been modified by the intermediate server to redirect applet communications with the server through the intermediate server; and

transforming the at least one socket connection into a pair of unidirectional URL connections with the intermediate server to enable the one or more applets to communicate with the server via the pair of unidirectional URL connections with the intermediate server.

19. The method of claim 18 , wherein the pair of unidirectional URL connections include secure connections.

20. The method of claim 18 , wherein the pair of unidirectional URL connections include HTTPS connections.

21. The method of claim 18 , where one of the pair of unidirectional URL connections includes a transient connection, and the other of the pair of unidirectional URL connections includes a persistent connection.

Assignments (12)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
SECURITY INTEREST Recorded Dec 30, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034713/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034045/0717 →