IP Library Granted Patent US 9,100,369
Granted Patent B1
US 9,100,369 · App. 13/595,938 · Granted Aug 4, 2015

Secure reverse connectivity to private network servers

Inventors: John R. Fallows (Palo Alto, CA); Christopher M. E. Barrow (San Mateo, CA)
Assignee: Kaazing Corporation
H04L63/0281H04L63/029H04L67/2876H04L63/0815H04L63/20H04L67/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,100,369
App. No.
13/595,938
Granted
Aug 4, 2015
Kind
B1
Abstract

Establishing a connection is disclosed. A first communication link with a perimeter gateway located external to a private network firewall but behind a perimeter network firewall is initiated. A request to allow the connection from a requestor that has requested the connection to an internal server via the perimeter gateway is received. A second communication link with the internal server protected by the private network firewall is initiated. The connection is allowed at least in part by associating together the first communication link with the second communication link.

Claims (42)

1. A system for establishing a connection, comprising:

a communication interface configured to:

initiate a first communication link with a perimeter gateway located external to a private network firewall but behind a perimeter network firewall, wherein initiating the first communication link with the perimeter gateway includes providing to the perimeter gateway an internal gateway identifier of a service offered by an internal server, the internal gateway identifier includes a network location address of an internal gateway system location where the service offered by the internal server may be accessed, and the internal gateway identifier includes a protocol identifier of a protocol to be utilized between the perimeter gateway and the system;

receive a request to allow the connection from a requestor that has requested the connection to the internal server via the perimeter gateway, wherein the requestor has requested the connection using a perimeter gateway identifier of the service offered by the internal server, the perimeter gateway identifier includes a network location address of the perimeter gateway where the service offered by the internal server may be accessed, and the perimeter gateway has determined that the perimeter gateway identifier of the service corresponds to the internal gateway identifier of the service and provided the request using the internal gateway identifier of the service; and

initiate a second communication link with the internal server protected by the private network firewall, wherein initiating the second communication link includes determining that the internal gateway identifier of the service offered by the internal server corresponds to an internal server identifier of the service offered by the internal server; and

a processor configured to:

allow the connection at least in part by binding the first communication link with the second communication link.

2. The system of claim 1 , wherein the communication interface is further configured to initialize a new communication link with the perimeter gateway after the first communication link and the second communication link are associated together.

3. The system of claim 1 , wherein the communication interface is further configured to receive an identifier associated with a number of pending connections to be bound.

4. The system of claim 3 , wherein the communication interface is further configured to initialize together a plurality of new communication links associated with the received identifier.

5. The system of claim 1 , wherein the requestor requested the connection via a public network external to perimeter network firewall.

6. The system of claim 1 , wherein the first communication link and the second communication link are encrypted.

7. The system of claim 1 , wherein the first communication link is associated with a reverse proxy.

8. The system of claim 1 , wherein the first communication link is associated with a reverse SOCKS proxy.

9. The system of claim 1 , wherein the first communication link is associated with a logical connection included in a plurality of logical connections multiplexed on a network connection.

10. The system of claim 1 , wherein a communication protocol utilized on the first communication link is dynamically determined.

11. The system of claim 1 , wherein initiating the first communication link includes mutually authenticating the perimeter gateway and the system.

12. The system of claim 1 , wherein the request is received via the first communication link.

13. The system of claim 1 , wherein the request is received via a third communication link.

14. The system of claim 1 , wherein the internal server is not directly accessible by the requestor.

15. The system of claim 1 , wherein the first communication link with the second communication link are utilized to proxy communications between the perimeter gateway and the internal server.

16. A system for establishing a connection, comprising:

a communication interface configured to:

receive a communication link from an internal gateway located behind a private network firewall, wherein receiving the communication link includes receiving from the internal gateway an internal gateway identifier of a service offered by an internal server, the internal gateway identifier includes a network location address of the internal gateway where the service offered by the internal server may be accessed, and the internal gateway identifier includes a protocol identifier of a protocol to be utilized between the system and the internal gateway;

establish a reverse proxy connection with the internal gateway using the communication link; and

receive a request to establish the connection with the internal server protected by the private network firewall, wherein the request includes a perimeter gateway identifier of the service offered by the internal server and the perimeter gateway identifier includes a network location address of a perimeter gateway system location where the service offered by the internal server may be accessed; and

a processor configured to:

determine that the request is associated with the reverse proxy connection; and

establish the connection using the reverse proxy connection, wherein the connection is bound to the reverse proxy connection, wherein establishing the connection includes determining that the perimeter gateway identifier of the service corresponds to the internal gateway identifier of the service and utilizing the internal gateway identifier of the service;

wherein the internal gateway determines that the internal gateway identifier of the service offered by the internal server corresponds to an internal server identifier of the service offered by the internal server.

17. A method for establishing a connection, comprising:

initiating a first communication link with a perimeter gateway located external to a private network firewall but behind a perimeter network firewall, wherein initiating the first communication link with the perimeter gateway includes providing to the perimeter gateway an internal gateway identifier of a service offered by an internal server, the internal gateway identifier includes a network location address of an internal gateway where the service offered by the internal server may be accessed, and the internal gateway identifier includes a protocol identifier of a protocol to be utilized between the perimeter gateway and the internal gateway;

receiving a request to allow the connection from a requestor that has requested the connection to the internal server via the perimeter gateway, wherein the requestor has requested the connection using a perimeter gateway identifier of the service offered by the internal server, the perimeter gateway identifier includes a network location address of the perimeter gateway where the service offered by the internal server may be accessed, and the perimeter gateway has determined that the perimeter gateway identifier of the service corresponds to the internal gateway identifier of the service and provided the request using the internal gateway identifier of the service;

initiating a second communication link with the internal server protected by the private network firewall, wherein initiating the second communication link includes determining that the internal gateway identifier of the service offered by the internal server corresponds to an internal server identifier of the service offered by the internal server; and

using a processor to allow the connection at least in part by binding the first communication link with the second communication link.

18. A method for establishing a connection, comprising:

receiving a communication link from an internal gateway located behind a private network firewall, wherein receiving the communication link includes receiving from the internal gateway an internal gateway identifier of a service offered by an internal server, the internal gateway identifier includes a network location address of the internal gateway where the service offered by the internal server may be accessed, and the internal gateway identifier includes a protocol identifier of a protocol to be utilized between a perimeter gateway and the internal gateway;

establishing a reverse proxy connection with the internal gateway using the communication link;

receiving a request to establish the connection with the internal server protected by the private network firewall, wherein the request includes a perimeter gateway identifier of the service offered by the internal server and the perimeter gateway identifier includes a network location address of the perimeter gateway where the service offered by the internal server may be accessed;

determining that the request is associated with the reverse proxy connection; and

establishing the connection using the reverse proxy connection, wherein the connection is bound to the reverse proxy connection, wherein establishing the connection includes determining that the perimeter gateway identifier of the service corresponds to the internal gateway identifier of the service and utilizing the internal gateway identifier of the service;

wherein the internal gateway determines that the internal gateway identifier of the service offered by the internal server corresponds to an internal server identifier of the service offered by the internal server.

Assignments (4)
SECURITY INTEREST Recorded Mar 7, 2017
From: KAAZING CORPORATION
To: COMERICA BANK
Reel/Frame 041485/0708 →
SECURITY INTEREST Recorded Jun 15, 2016
From: KAAZING CORPORATION
To: US VC PARTNERS, L.P.
Reel/Frame 038915/0452 →
SECURITY INTEREST Recorded Jun 3, 2016
From: KAAZING CORPORATION
To: SQN VENTURE INCOME FUND, LP
Reel/Frame 038799/0524 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2012
From: FALLOWS, JOHN R.; BARROW, CHRISTOPHER M. E.
To: KAAZING CORPORATION
Reel/Frame 029274/0573 →