IP Library Granted Patent US 9,444,791
Granted Patent B2
US 9,444,791 · App. 14/814,417 · Granted Sep 13, 2016

Method and system for providing secure access to private networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,444,791
App. No.
14/814,417
Granted
Sep 13, 2016
Kind
B2
Abstract

Improved approaches for providing secure remote access to resources maintained on private networks are disclosed. According to one aspect, predetermined elements, such as applets, can be modified to redirect all communications to and from an application server through an intermediate server. The intermediate server in turn communicates with the application servers. According to another aspect, a communication framework can be provided to funnel communication between an applet and a server through a communication layer so as to provide managed and/or secured communications there between.

Claims (64)

1. A method of operation in an intermediate server, said method comprising:

receiving, from a client, an applet code request for an applet;

requesting applet code for the applet from a remote server via a network;

receiving the applet code from the remote server in response to said requesting of the applet code;

modifying the applet code to redirect external communications from the applet through the intermediate server; and

sending the modified applet code to the client.

2. The method of claim 1 , wherein modifying the applet code comprises:

replacing a class descriptor for a class in the applet code with a modified version of the class to redirect external communications from the applet through the intermediate server.

3. The method of claim 1 , wherein modifying the applet code comprises:

replacing a method in the applet code with a static method call to redirect external communications from the applet through the intermediate server.

4. The method of claim 1 , wherein modifying the applet code comprises:

replacing a creation of an object class in the applet code with a static method to redirect external communications from the applet through the intermediate server.

5. The method of claim 1 , wherein modifying the applet code comprises:

replacing a class string in the applet code with a wrapper class to redirect external communications from the applet through the intermediate server.

6. The method of claim 1 , wherein the applet code is bytecode for the applet.

7. The method of claim 1 , further comprising:

receiving a resource request for a particular resource, the resource request being provided to the intermediate server from the client via the network;

extracting an identifier associated with a destination server from the resource request;

requesting, based on the identifier, the particular resource from the destination server;

receiving, in response to the request, the particular resource from the destination server;

modifying the particular resource to redirect internal resource requests to the intermediate server, where the modifying of the particular resource modifies at least one source file address within the particular resource, the at least one source file address pertaining to the applet;

sending the modified particular resource to the client,

wherein the applet code request is received after sending the modified particular resource to the client.

8. The method of claim 7 , wherein the remote server is the destination server.

9. The method of claim 7 , wherein said modifying of the particular resource comprises:

identifying, within the particular resource, a predetermined element that includes at least a first network address; and

modifying the first network address within the predetermined element of the particular resource to a second network address that pertains to the intermediate server.

10. The method of claim 7 , wherein modifying the particular resource includes:

identifying at least one element that specifies the applet within the particular resource;

determining whether the at least one element includes a codebase attribute;

inserting a default codebase attribute into the at least one element when it is determined that the at least one element does not include a codebase attribute; and

modifying the codebase attribute of the at least one element.

11. A non-transitory computer readable medium storing computer readable code, the code when executed by an intermediate server causes the intermediate server to:

receive, from a client, an applet code request for an applet;

request applet code for the applet from a remote server via a network;

receive the applet code from the remote server in response to said requesting of the applet code;

modify the applet code to redirect external communications from the applet through the intermediate server; and

send the modified applet code to the client.

12. The non-transitory computer readable medium of claim 11 , wherein the code causing the intermediate server to modify the applet code comprises code causing the intermediate server to:

replace a class descriptor for a class in the applet code with a modified version of the class to redirect external communications from the applet through the intermediate server.

13. The non-transitory computer readable medium of claim 11 , wherein the code causing the intermediate server to modify the applet code comprises code causing the intermediate server to:

replace a method in the applet code with a static method call to redirect external communications from the applet through the intermediate server.

14. The non-transitory computer readable medium of claim 11 , wherein the code causing the intermediate server to modify the applet code comprises code causing the intermediate server to:

replace a creation of an object class in the applet code with a static method to redirect external communications from the applet through the intermediate server.

15. The non-transitory computer readable medium of claim 11 , wherein the code causing the intermediate server to modify the applet code comprises code causing the intermediate server to:

replace a class string in the applet code with a wrapper class to redirect external communications from the applet through the intermediate server.

16. The non-transitory computer readable medium of claim 11 , wherein the applet code is bytecode for the applet.

17. The non-transitory computer readable medium of claim 11 , wherein the code further causes the intermediate server to:

receive a resource request for a particular resource, the resource request being provided to the intermediate server from the client via the computer network;

extract an identifier associated with a destination server from the resource request;

request, based on the identifier, the particular resource from the destination server;

receive, in response to the request, the particular resource from the destination server;

modify the particular resource to redirect internal resource requests to the intermediate server, where the modifying of the particular resource modifies at least one source file address within the particular resource, the at least one source file address pertaining to the applet;

send the modified particular resource to the client,

wherein the applet code request is received after sending the modified particular resource to the client.

18. The non-transitory computer readable medium of claim 17 , wherein the remote server is the destination server.

19. The non-transitory computer readable medium of claim 17 , wherein the code causing the intermediate server to modify the particular resource comprises code causing the intermediate server to:

identify, within the particular resource, a predetermined element that includes at least a first network address; and

modify the first network address within the predetermined element of the particular resource to a second network address that pertains to the intermediate server.

20. The non-transitory computer readable medium of claim 17 , wherein the code causing the intermediate server to modify the particular resource comprises code causing the intermediate server to:

identify at least one element that specifies the applet within the particular resource;

determine whether the at least one element includes a codebase attribute;

insert a default codebase attribute into the at least one element when it is determined that the at least one element does not include a codebase attribute; and

modify the codebase attribute of the at least one element.

Assignments (14)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2015
From: TOCK, THERON; XIA, ZEQING
To: NEOTERIS, INC.
Reel/Frame 036233/0662 →
MERGER AND CHANGE OF NAME Recorded Aug 1, 2015
From: NEOTERIS, INC.; NEOTERIS, INC.
To: NETSCREEN SSL, INC.
Reel/Frame 036233/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2015
From: NETSCREEN SSL, INC.
To: NETSCREEN TECHNOLOGIES, INC.
Reel/Frame 036233/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2015
From: NETSCREEN TECHNOLOGIES, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 036233/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2015
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 036233/0703 →