IP Library Patent Application 14066064
Patent Application
App. No. 14/066,064

Secure mobile access to resources within a private network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/066,064
Abstract

A technique is disclosed that provides a secure end-to-end connection between a mobile station in a public network and a resource server in a private network. First, a virtual private network (VPN) connection is established by the resource server within the private network, to a VPN/socket secure (SOCKS) proxy in the public network. Subsequently, the SOCKS proxy receives an access request from the mobile station and, in response, sets up a Hypertext Transport Protocol Secure (HTTPS) connection between the resource server and mobile station. Then, a reverse proxy service operating at the resource server retrieves data packets from a resource device, such as a webcam, and encrypts and pushes the packets to the mobile station.

Claims (34)

1 . A method comprising:

establishing a first connection between a resource server computer and a second server computer, wherein the resource server computer is assigned a private Internet Protocol (IP) address that is within a private network's address space, wherein the second server computer has a public IP address that is within a public network's address space, and wherein the second server computer provides a socket secure (SOCKS) proxy service;

receiving, by the second server computer, a request to initiate a second connection, wherein the second connection is between an accessing device and the resource server computer, and wherein the initiation request comprises the private IP address assigned to the resource server computer;

routing, by the SOCKS proxy service of the second server computer, the initiation request to the resource server computer via the first connection, wherein the routing is based on the private IP address assigned to the resource server computer; and

establishing the second connection, based on the resource server computer receiving the initiation request.

2 . The method of claim 1 wherein the initiation request specifies communication to be based on a predetermined cryptographic protocol, and wherein the establishing of the second connection comprises the resource server computer and the accessing device performing a handshake with each other based on the predetermined cryptographic protocol.

3 . The method of claim 1 wherein the first connection is a virtual private network (VPN) connection established by a VPN service provided by the second server computer.

4 . The method of claim 3 wherein the establishing of the first connection comprises assigning, by the VPN service, private IP addresses to both ends of the first connection, including the private IP address assigned to the resource server computer.

5 . The method of claim 4 wherein the routing is also based on the private IP address that is assigned to the end of the first connection at which the second server computer is situated.

6 . The method of claim 1 wherein the initiation request is received from the accessing device.

7 . The method of claim 1 further comprising:

requesting, by the resource server computer, one or more data packets from a resource device, in response to the resource server computer receiving the initiation request; and

transmitting, by the resource server computer to the accessing device, the one or more data packets when received from the resource device in response to requesting the packets.

8 . The method of claim 7 wherein the resource server computer and the resource device are within a shared private network.

9 . The method of claim 8 wherein the accessing device is a mobile station that is operating outside of the shared private network.

10 . The method of claim 7 further comprising encrypting the one or more data packets, by the resource server computer and in accordance with a predetermined cryptographic protocol, prior to transmitting the packets.

11 . A telecommunications system comprising:

a resource server computer for providing one or more data packets to an accessing device; and

a second server computer for:

i) establishing a first connection with the resource server computer, wherein the resource server computer is assigned a private Internet Protocol (IP) address that is within a private network's address space, wherein the second server computer has a public IP address that is within a public network's address space, and wherein the second server computer is capable of providing a socket secure (SOCKS) proxy service,

ii) receiving a request to initiate a second connection, wherein the second connection is between the accessing device and the resource server computer, and wherein the initiation request comprises the private IP address assigned to the resource server computer, and

iii) routing, by the SOCKS proxy service of the second server computer, the initiation request to the resource server computer via the first connection, wherein the routing is based on the private IP address assigned to the resource server computer;

wherein the resource server is configured to provide the one or more data packets to the accessing device after the second connection has been established based on the resource server computer receiving the initiation request.

12 . The telecommunications system of claim 11 wherein the initiation request specifies communication to be based on a predetermined cryptographic protocol, and wherein the resource server computer is also for performing a handshake with the accessing device, based on the predetermined cryptographic protocol and as part of the establishing of the second connection.

13 . The telecommunications system of claim 11 wherein the second server computer is also for providing a VPN service, and wherein the first connection is a virtual private network (VPN) connection established by the VPN service.

14 . The telecommunications system of claim 13 wherein the second server computer is for establishing the first connection by assigning, by the VPN service, private IP addresses to both ends of the first connection, including the private IP address assigned to the resource server computer.

15 . The telecommunications system of claim 14 wherein the routing is also based on the private IP address that is assigned to the end of the first connection at which the second server computer is situated.

16 . The telecommunications system of claim 11 wherein the initiation request is received from the accessing device.

17 . The telecommunications system of claim 11 wherein the resource server computer is also for:

requesting one or more data packets from a resource device, in response to the resource server computer receiving the initiation request; and

transmitting, to the accessing device, the one or more data packets when received from the resource device in response to requesting the packets.

18 . The telecommunications system of claim 17 wherein the resource server computer and the resource device are within a shared private network.

19 . The telecommunications system of claim 18 wherein the accessing device is a mobile station that is operating outside of the shared private network.

20 . The telecommunications system of claim 17 wherein the resource server computer is also for encrypting the one or more data packets, in accordance with a predetermined cryptographic protocol, prior to transmitting the packets.

Assignments (5)
CHANGE OF NAME Recorded Jun 3, 2017
From: SEED LABS SP. Z O.O.
To: SILVAIR SP. Z O.O.
Reel/Frame 042682/0883 →
CHANGE OF NAME Recorded Mar 18, 2015
From: ETC SP. Z O.O.
To: SEED LABS SP. Z O.O.
Reel/Frame 035223/0601 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 034340 FRAME: 0573. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 24, 2015
From: HOMERSOFT SP. Z O.O.
To: ETC SP. Z O.O.
Reel/Frame 035072/0479 →
CHANGE OF NAME Recorded Nov 20, 2014
From: HOMERSOFT SP. ZO. O.
To: ETC SP. ZO. O.
Reel/Frame 034340/0573 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2013
From: SLUPIK, SZYMON; BIS, MARCIN; NOWAK, LUKASZ
To: HOMERSOFT SP. ZO.O.
Reel/Frame 031501/0763 →