IP Library Granted Patent US 9,455,960
Granted Patent B2
US 9,455,960 · App. 14/564,981 · Granted Sep 27, 2016

Secure application delivery system with dynamic stitching of network connections in the cloud

Inventors: Haseeb Siddique Budhani (Santa Clara, CA); Seetharama Sarma Ayyadevara (San Jose, CA); Hanumantharao Kavuluru (San Jose, CA)
Assignee: Soha Systems, Inc.
H04L63/0281H04L63/0218H04L63/0263H04L63/04H04L63/0457H04L63/0815H04L63/0823H04L63/105H04L67/10H04L67/1004H04L67/34H04L63/0428H04L63/10H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,455,960
App. No.
14/564,981
Granted
Sep 27, 2016
Kind
B2
Abstract

A system is provided to deliver an application, hosted by a private application provider, over a network to a user device comprising: an application delivery system that includes a plurality of first network interface instances, a plurality of security interface instances, a plurality of second network interface instances; multiple application agents, disposed within one or more private application provider systems; a first information structure associates first network interface instances with one or more security interface instances; a second information structure associates second network interface instances with one or more security interface instances; wherein first network interface instances are configured to create a network connections with associated security interface instances and to send requests to the associated security interface instances; wherein second network interface instances are configured to have pools of network connections with one or more agents and to have corresponding connections with associated security interface instances; and wherein security interface instance are configured to validate requests received from first network interface instances and to send the validated requests to associated second network interface instances for delivery to agents.

Claims (42)

1. A system to deliver an application, hosted by a private application provider, over a network to a user device comprising:

an application delivery system that includes at least one CPU and at least one non-transitory storage device configured to provide,

a first network interface that includes a plurality of first network interface instances that includes multiple second connection endpoints;

a network security interface that includes a plurality of security interface instances that each includes multiple second connection endpoints and multiple fourth connection endpoints;

a second network interface that includes a plurality of second network interface instances that each includes multiple third connection endpoints; and

multiple application agents, disposed within one or more private application provider systems;

a first information structure in the at least one non-transitory storage device that associates first network interface instances with one or more security interface instances;

a second information structure in the at least one non-transitory storage device that associates second network interface instances with one or more security interface instances;

wherein respective first network interface instances are configured to receive one or more user or device requests for access to a hosted application and in response to each received user or device request, to create a respective second network connection with an associated security interface instance, wherein each respective second connection includes one endpoint within a respective first network interface instance and includes one endpoint within an associated security interface instance, and to send the received user or device request to the associated security interface instance over the respective second network connection;

wherein respective second network interface instances are configured to have respective pools of respective third network connections with one or more agents and to have corresponding respective fourth connections with one or more associated security interface instances, wherein each respective fourth connection includes one endpoint within a respective second network interface instance and includes one endpoint within an associated security interface instance; and

wherein respective security interface instances are configured to receive one or more user or device requests from respective first interface instances and in response to each received user or device request, to determine whether the received user or device request is valid, and in response to determining that the received user or device request is valid, to couple a respective second network connection endpoint to a respective fourth network connection endpoint, and to send the received user or device request over the a respective coupled fourth network connection for delivery to a respective agent over an associated third network connection.

2. The system of claim 1 ,

wherein each respective first network interface instance is configured to, for each of the one or more received user or device requests, create a respective first network connection with the respective requesting user device and to receive the respective user or device request over the respective first network connection and to send the respective user or device request over a respective second network connection to an associated security interface instance.

3. The system of claim 1 ,

wherein each respective application agent is configured to send one or more requests that identify a corresponding application served by the agent to one or more respective second network interface instances to create the respective pools of respective third network connections with one or more agents; and

wherein each respective second network interface instance is configured to send a corresponding request for a fourth connection to a respective associated security interface instance in response to each received request for a third network connection, wherein each corresponding fourth request identifies the application identified in the request for a third network connection that it is sent in response to.

4. The system of claim 1 ,

wherein the first information structure in the non-transitory storage device associates first network interface instances with security interface instances based at least in part upon a respective application identified in a user or device request.

5. The system of claim 1 ,

wherein the first information structure in the non-transitory storage device associates first network interface instances with one or more security interface instances based at least in part upon a respective application identified in a user or device request; and

wherein the second information structure in the non-transitory storage device associates second network interface instances with one or more security interface instances based at least in part upon a respective application identified in an agent request sent over a third network connection.

6. The system of claim 1 ,

wherein each respective security interface instance is configured to, in response to determining that the user or device request is not valid, redirect the user or device request to a login server.

7. The system of claim 1 , further including:

a management system configured to,

monitor first network interface instance load information and to determine based at least in part upon the first network interface instance load information whether to add or to terminate one or more first network interface instances;

monitor security interface instance load information and to determine based at least in part upon the security interface instance load information whether to add or to terminate one or more security interface instances;

monitor second network interface instance load information and to determine based at least in part upon the second network interface instance load information whether to add or to terminate one or more second network interface instances;

wherein the application delivery system is configured to,

add or to terminate one or more first network interface instances in response to the management system determination;

add or to terminate one or more security interface instances in response to the management system determination; and

add or to terminate one or more second network interface instances in response to the management system determination.

8. The system of claim 1 further including:

an information structure that is shared among the plurality of security interface instances that stores user validation information and that is disposed in non-transitory storage device.

9. The system of claim 1 further including:

an information structure that is shared among the plurality of security interface instances that stores user validation information and that is disposed in a non-transitory storage device; and

multiple respective non-transitory cache storage instances, each respectively associated with a respective security interface instance that stores user validity information corresponding to users that have recently requested access to an application associated with the respective security interface instance.

10. The system of claim 1 further including:

a service designation information structure that associates different services with one or more applications based at least in part upon application identity and that is stored in non-transitory storage device;

wherein the security interface instances are configured to provide services to user or device requests based at least in part upon information in the information structure.

11. The system of claim 10 ,

wherein the associated services include one or more of traffic encryption/decryption, end user identity management, end user authorization, end user session state storage, Layer 7 firewalling, intrusion prevention services (IPS), threat detection, anti-virus protection, and analytics and business logic.

Assignments (3)
MERGER Recorded Jan 25, 2017
From: SOHA SYSTEMS, INC.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 041076/0381 →
CHANGE OF NAME Recorded Apr 2, 2015
From: BUBBLEWRAPP, INC.
To: SOHA SYSTEMS, INC.
Reel/Frame 035355/0613 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2015
From: BUDHANI, HASEEB SIDDIQUE; AYYADEVARA, SEETHARAMA SARMA; KAVULURU, HANUMANTHARAO
To: BUBBLEWRAPP, INC.
Reel/Frame 034682/0458 →
Continuity (3)
Provisional Application 62080064 · Nov 14, 2014
Provisional Application 61953044 · Mar 14, 2014
Related Publication 20150264016A1 · Sep 17, 2015