IP Library Granted Patent US 10,332,090
Granted Patent B2
US 10,332,090 · App. 15/247,372 · Granted Jun 25, 2019

Providing secure remote access to a device at a merchant location

Inventor: Brett B. Stewart (Austin, TX)
Assignee: Acumera, Inc.
G06Q20/206H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,332,090
App. No.
15/247,372
Granted
Jun 25, 2019
Kind
B2
Abstract

System and method for providing secure connections between a point of sale (POS) system and a datacenter. Upon initiation of a support event associated with the POS system, a gateway device may determine an available block of internet protocol (IP) addresses for the merchant location, e.g., by accessing information stored in a shared storage location. The gateway device may determine a local IP address of the POS system and establish an apparent IP address of the POS system, selected from the available block of IP addresses. The gateway device may initiate a virtual private network (VPN) tunnel to the datacenter using at least a subset of the available block of IP addresses. The gateway device may securely store a descriptive document in the shared storage location identifying the available block of IP addresses for the merchant location. The gateway device may performing IP address translation during the support event.

Claims (60)

1. A gateway device for providing secure connections between a point of sale (POS) system located at a merchant location and a datacenter, the gateway device comprising:

a functional unit coupled to a network interface, wherein the network interface is configured to communicate with the datacenter over a network;

wherein the functional unit is configured to:

upon initiation of a support event associated with the POS system, determine an available block of internet protocol (IP) addresses for the merchant location, wherein determining the available block of IP addresses is performed by accessing information stored in a shared storage location;

determine a local IP address of the POS system;

establish an apparent IP address of the POS system that is different than the local IP address, wherein the apparent IP address is selected from the available block of IP addresses;

initiate a secure virtual private network (VPN) tunnel from the gateway device to the datacenter, wherein the VPN tunnel uses at least a subset of the available block of IP addresses;

securely store a descriptive document in the shared storage location, wherein the descriptive document identifies the available block of IP addresses for the merchant location, and wherein the descriptive document is configured to enable the datacenter to communicate with the POS system using the apparent IP address during the support event;

during the support event, receive one or more communications from the data center addressed to the apparent IP address and translate the received one or more communications to be addressed to the local IP address; and

terminate the support event.

2. The gateway device of claim 1 , wherein the merchant location comprises a plurality of devices, wherein the functional unit is further configured to establish an apparent IP address for each of the plurality of devices, wherein each apparent IP address is selected from the available block of IP addresses.

3. The gateway device of claim 1 , wherein determining the available block of addresses comprises:

accessing one or more descriptive documents stored in the shared storage location, wherein each of the one or more descriptive documents identifies a respective block of IP addresses in use; and

determining an unused block of IP addresses different from each of the respective blocks of IP addresses in use.

4. The gateway device of claim 3 , wherein each respective block of IP addresses in use are associated with a respective merchant location, wherein the number of possible merchant locations exceeds the number of available blocks of IP addresses.

5. The gateway device of claim 1 , wherein the descriptive document is accessible only by the gateway device, and is securely readable over the network by the datacenter via use of a shared cryptographic key.

6. The gateway device of claim 1 , wherein said terminating the support event is performed automatically in response to a specified period of inactivity.

7. The gateway device of claim 1 , wherein said terminating the support event is performed in response to:

termination of the support event;

a command from the POS system; or

a command from the datacenter.

8. The gateway device of claim 1 , wherein the initiation of the support event is performed in response to:

input to the POS system; or

a command from the datacenter.

9. A method for providing secure connections between a point of sale (POS) system located at a merchant location and a datacenter, the method comprising:

by a gateway device at the merchant location:

upon initiation of a support event associated with the POS system, determining an available block of internet protocol (IP) addresses for the merchant location, wherein determining the available block of IP addresses is performed by accessing information stored in a shared storage location;

determining a local IP address of the POS system;

establishing an apparent IP address of the POS system that is different than the local IP address, wherein the apparent IP address is selected from the available block of IP addresses;

initiating a secure virtual private network (VPN) tunnel from the gateway device to the datacenter, wherein the VPN tunnel uses at least a subset of the available block of IP addresses;

securely storing a descriptive document in the shared storage location, wherein the descriptive document identifies the available block of IP addresses for the merchant location, and wherein the descriptive document is configured to enable the datacenter to communicate with the POS system using the apparent IP address during the support event;

during the support event, receiving one or more communications from the data center addressed to the apparent IP address and translating the received one or more communications to be addressed to the local IP address; and

terminating the support event.

10. The method of claim 9 , wherein the merchant location comprises a plurality of devices, wherein the functional unit is further configured to establish an apparent IP address for each of the plurality of devices, wherein each apparent IP address is selected from the available block of IP addresses.

11. The method of claim 9 , wherein determining the available block of addresses comprises:

accessing one or more descriptive documents stored in the shared storage location, wherein each of the one or more descriptive documents identifies a respective block of IP addresses in use; and

determining an unused block of IP addresses different from each of the respective blocks of IP addresses in use.

12. The method of claim 11 , wherein each respective block of IP addresses in use are associated with a respective merchant location, wherein the number of possible merchant locations exceeds the number of available blocks of IP addresses.

13. The method of claim 9 , wherein the descriptive document is accessible only by the gateway device, and is securely readable over the network by the datacenter via use of a shared cryptographic key.

14. The method of claim 9 , wherein said terminating the support event is performed automatically in response to a specified period of inactivity.

15. The method of claim 9 , wherein said terminating the support event is performed in response to:

termination of the support event;

a command from the POS system; or

a command from the datacenter.

16. The method of claim 9 , wherein the initiation of the support event is performed in response to:

input to the POS system; or

a command from the datacenter.

17. A non-transitory memory medium storing program instructions for providing secure connections between a point of sale (POS) system located at a merchant location and a datacenter, wherein the program instructions are executable by a processor of a gateway device at the merchant location to:

upon initiation of a support event associated with the POS system, determine an available block of internet protocol (IP) addresses for the merchant location, wherein determining the available block of IP addresses is performed by accessing information stored in a shared storage location;

determine a local IP address of the POS system;

establish an apparent IP address of the POS system that is different than the local IP address, wherein the apparent IP address is selected from the available block of IP addresses;

initiate a secure virtual private network (VPN) tunnel from the gateway device to the datacenter, wherein the VPN tunnel uses at least a subset of the available block of IP addresses;

securely store a descriptive document in the shared storage location, wherein the descriptive document identifies the available block of IP addresses for the merchant location, and wherein the descriptive document is configured to enable the datacenter to communicate with the POS system using the apparent IP address during the support event;

during the support event, receive one or more communications from the data center addressed to the apparent IP address and translate the received one or more communications to be addressed to the local IP address; and

terminate the support event.

18. The non-transitory memory medium of claim 17 , wherein determining the available block of addresses comprises:

accessing one or more descriptive documents stored in the shared storage location, wherein each of the one or more descriptive documents identifies a respective block of IP addresses in use; and

determining an unused block of IP addresses different from each of the respective blocks of IP addresses in use.

19. The non-transitory memory medium of claim 18 , wherein each respective block of IP addresses in use are associated with a respective merchant location, wherein the number of possible merchant locations exceeds the number of available blocks of IP addresses.

20. The non-transitory memory medium of claim 17 , wherein said terminating the support event is performed automatically in response to a specified period of inactivity.

Assignments (9)
SECURITY INTEREST Recorded Jan 29, 2026
From: SCALE COMPUTING, LLC
To: TORONTO DOMINION (TEXAS) LLC
Reel/Frame 073633/0710 →
CHANGE OF NAME Recorded Sep 9, 2025
From: ACUMERA, INC.
To: SCALE COMPUTING, INC.
Reel/Frame 073133/0138 →
RELEASE OF SECURITY INTEREST Recorded Jul 2, 2024
From: ALTER DOMUS (US) LLC
To: ACUMERA, INC.
Reel/Frame 067896/0535 →
RELEASE OF SECURITY INTEREST Recorded Jun 9, 2023
From: CAPITAL FINANCE ADMINISTRATION, LLC
To: ACUMERA, INC.
Reel/Frame 063909/0794 →
SECURITY INTEREST Recorded Jun 9, 2023
From: ACUMERA, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 063912/0619 →
RELEASE OF SECURITY INTEREST Recorded Feb 22, 2023
From: COMERICA BANK
To: ACUMERA, INC.
Reel/Frame 062773/0454 →
SECURITY INTEREST Recorded Oct 5, 2021
From: ACUMERA, INC.
To: CAPITAL FINANCE ADMINISTRATION, LLC
Reel/Frame 057705/0083 →
SECURITY INTEREST Recorded Mar 17, 2017
From: ACUMERA, INC.
To: COMERICA BANK
Reel/Frame 041609/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2016
From: STEWART, BRETT B.
To: ACUMERA, INC.
Reel/Frame 039543/0105 →
Continuity (2)
Provisional Application 62210862 · Aug 27, 2015
Related Publication 20170061415A1 · Mar 2, 2017
Cited By (2)
US 12,294,567 US 12,337,232