IP Library Granted Patent US 10,264,078
Granted Patent B2
US 10,264,078 · App. 15/477,348 · Granted Apr 16, 2019

System and method of providing secure data transfer

Inventors: Ian Kennedy Hamilton (Ottawa, CA); Anthony Vasile (Ottawa, CA)
Assignee: Signiant Inc.
H04L67/141H04L12/2856H04L12/4633H04L45/64H04L47/125H04L61/1511H04L63/029H04L63/0428H04L63/166H04L67/02H04L67/06H04L67/10H04L69/326H04L61/2592H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,264,078
App. No.
15/477,348
Granted
Apr 16, 2019
Kind
B2
Abstract

A system and method is provided for providing secure accelerated data transfer. The system may transparently provide accelerated data transfer between a client and a remote system. The system may provide a method for determining a mapped domain name for identifying an ingress server. The system may provide a method for determining a tunnel route to an egress server selected for establishing a connection with the remote system. The system may provide a method of exchanging data between the client system and the remote system via the ingress server and the egress server.

Claims (64)

1. A computer implemented method of facilitating data transfers between a client system and a remote system, the method being implemented in a cloud-based computer system comprising a mapping service, an ingress system and an egress system, the method comprising:

receiving, by the mapping service, a domain name for the remote system;

mapping, by the mapping service, the domain name to a mapped domain name for the remote system, wherein requests to the mapped domain name are directed to an ingress system for establishing a connection with the remote system;

receiving, by the ingress system, a request to establish communication with the remote system, the request directed from the mapped domain name;

establishing, by the ingress system, a first data transfer connection with the client system;

transmitting, by the ingress system to a tunnel routing service, a request to identify an egress system from among multiple egress systems for communicating with the remote system;

receiving, by the ingress system from the tunnel routing service, an address of the egress system selected from among the multiple egress systems;

establishing, by the ingress system, a data tunnel comprising a second data transfer connection with the egress system based on the address of the egress system received from the tunnel routing service;

establishing, by the egress system, a third data transfer connection between the remote system and the egress system; and

facilitating, by the ingress system and the egress system, data exchange between the client system and the remote system via the first data transfer connection, the data tunnel, and the third data transfer connection.

2. The computer implemented method of claim 1 , wherein establishing the first data transfer connection includes establishing a transport layer security data connection.

3. The computer implemented method of claim 1 , further comprising establishing a transport layer security data connection between the ingress system and the remote system across the second data transfer connection and the third data transfer connection.

4. The computer implemented method of claim 1 , wherein the cloud-based computer system is further programmed with instructions that implement a second ingress system and a second egress system; and the method further comprises:

establishing, by the second ingress system and the second egress system, a second data tunnel between the client system and the remote system via the second ingress system and the second egress system.

5. The computer implemented method of claim 1 , further comprising establishing, by the ingress system, one or more fourth data transfer connections between the egress system and the ingress system in response to an increased traffic load.

6. The computer implemented method of claim 1 , further comprising determining the mapped domain name corresponding to the ingress system and the client system, based on at least one of data transfer rates, overall data throughput, and latency times between the client system and the ingress system.

7. The method of claim 1 , wherein obtaining the destination domain name corresponding to the remote system comprises:

obtaining, by the ingress system, the destination domain name from a predefined mapping of the destination domain name to a mapped domain name that corresponds to the destination domain name.

8. The method of claim 1 , wherein facilitating the data exchange between the client system and the remote system comprises:

receiving, by the ingress system, one or more data packets from the client system via the first data transfer connection; and

transmitting, by the ingress system, the one or more data packets to the egress system via the data tunnel.

9. The method of claim 8 , wherein receiving the one or more data packets from the client system comprises:

receiving, by the ingress system, the one or more data packets from the client system via a hypertext transfer protocol.

10. The method of claim 8 , wherein facilitating the data exchange between the client system and the remote system comprises:

receiving, by the egress system, one or more second data packets from the remote system via the third data transfer connection; and

transmitting, by the ingress system, the one or more second data packets to the ingress system via the data tunnel.

11. The method of claim 10 , wherein receiving the one or more second data packets from the remote system comprises:

receiving, by the egress system, the one or more second data packets from the remote system via a transmission control protocol.

12. The computer implemented method of claim 1 , further comprising:

selecting, by the tunnel routing service, the egress system to correspond to the mapped domain name.

13. The computer implemented method of claim 12 , wherein selecting the egress system to correspond to the mapped domain name includes selecting the egress system based on at least one of data transfer rates, overall data throughput, and latency times.

14. A system for establishing a secure data transfer connection between a client system and a remote system via an ingress system and an egress system, the system comprising:

a cloud-based computer system comprising one or more physical processors programmed to:

receive a domain name for the remote system;

map the domain name to a mapped domain name for the remote system, wherein requests to the mapped domain name are directed to an ingress system for establishing a connection with the remote system;

receive a request to establish communication with the remote system, the request directed from the mapped domain name;

establish a first data transfer connection with the client system;

transmit, to a tunnel routing service, a request to identify an egress system from among multiple egress systems for communicating with the remote system;

receive, from the tunnel routing service, an address of the egress system selected from among the multiple egress systems;

establish a data tunnel comprising a second data transfer connection with the egress system based on the address of the egress system received from the tunnel routing service;

wherein the egress system is programmed to:

establish a third data transfer connection between the remote system and the egress system; and

wherein the ingress system and the egress system facilitate data exchange between the client system and the remote system via the first data transfer connection, the data tunnel, and the third data transfer connection.

15. The system of claim 14 , wherein the ingress system is further configured to establish the first data transfer connection as a cryptographically secure TSL data connection.

16. The system of claim 14 , wherein the egress system is further configured to establish the third data transfer connection includes as a cryptographically secure TSL data connection.

17. The system of claim 14 , wherein the cloud-based computer system is further programmed to implement a second ingress system and a second egress system;

the second ingress system and the second egress system are configured to establish a second data tunnel between the client system and the remote system via the second ingress system and the second egress system.

18. The system of claim 14 , wherein the ingress system is further configured to establish one or more fourth data transfer connections between the egress system and the ingress system in response to an increased traffic load.

19. The system of claim 14 , wherein the mapping service is further programmed to:

determine the mapped domain name corresponding to the ingress system and the local client, based on at least one of data transfer rates, overall data throughput, and latency times between the local client and the ingress system.

20. The system of claim 14 , wherein to obtain the destination domain name corresponding to the remote system, the ingress system is further programmed to:

obtain the destination domain name from a predefined mapping of the destination domain name to a mapped domain name that corresponds to the destination domain name.

21. The system of claim 14 , wherein to facilitate the data exchange between the client system and the remote system, the ingress system is further programmed to:

receive one or more data packets from the client system via the first data transfer connection; and

transmit the one or more data packets to the egress system via the data tunnel.

22. The system of claim 21 , wherein to receive the one or more data packets from the client system, the ingress system is further programmed to:

receive the one or more data packets from the client system via a hypertext transfer protocol.

23. The system of claim 21 , wherein to facilitate the data exchange between the client system and the remote system, the egress system is further programmed to:

receive one or more second data packets from the remote system via the third data transfer connection; and

transmit the one or more second data packets to the ingress system via the data tunnel.

24. The system of claim 16 , wherein to receive the one or more second data packets from the remote system, the egress system is further programmed to:

receive the one or more second data packets from the remote system via a transmission control protocol.

25. The system of claim 14 , wherein the tunnel routing service is further configured to select the egress system to correspond to the mapped domain name.

26. The system of claim 25 , wherein the tunnel routing service is further configured to select the egress system to correspond to the mapped domain name based on at least one of data transfer rates, overall data throughput, and latency times.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Dec 24, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: SIGNIANT INC.
Reel/Frame 069674/0329 →
SECURITY INTEREST Recorded Dec 23, 2024
From: SIGNIANT INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069662/0739 →
SECURITY INTEREST Recorded Aug 18, 2021
From: SIGNIANT INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 057209/0893 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 17, 2019
From: SIGNIANT INC.
To: SILICON VALLEY BANK
Reel/Frame 051325/0565 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2017
From: HAMILTON, IAN KENNEDY; VASILE, ANTHONY
To: SIGNIANT INC.
Reel/Frame 041825/0503 →
Continuity (2)
Continuation 15332215 · Oct 24, 2016
Related Publication 20180115615A1 · Apr 26, 2018