IP Library Granted Patent US 10,958,662
Granted Patent B1
US 10,958,662 · App. 16/751,183 · Granted Mar 23, 2021

Access proxy platform

Inventors: Pablo German Sole (Woodside, CA); Jose Luis Ferras Pereira (San Mateo, CA); Sinan Eren (Woodside, CA); Luisa Marina Moya Praca de Araujo Lima (Oporto, PT)
Assignee: Fyde, Inc.
H04L63/105H04L63/0272H04L63/0281H04L63/0853H04L63/107H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,958,662
App. No.
16/751,183
Granted
Mar 23, 2021
Kind
B1
Abstract

An access proxy system is disclosed. A proxy server receives, from a client device, a request to access a protected resource. The protected resource represents a mapping between a user-facing domain and an internal domain that is only accessible from behind a set of one or more proxies that includes the proxy server. In response to receiving a grant of permission by an access policy engine, the proxy server proxies access to the protected resource using a mutual-TLS connection with the client device.

Claims (24)

1. A system, comprising:

a processor configured to:

receive, at a proxy server and from a client device, a request to access a protected resource, wherein the protected resource represents a mapping between a user-facing domain and an internal domain that is only accessible from behind a set of one or more proxies that includes the proxy server, wherein the request is received from the client device in response to an interception, by a VPN stack of an operating system executing on the client device, of a DNS resolution request; and

in response to receiving a grant of permission by an access policy engine, proxy, by the proxy server, access to the protected resource using a mutual-TLS connection with the client device; and

wherein the access policy engine is configured to evaluate a trust level of a device-user, wherein the trust level comprises a named collection of constraints that must be fulfilled to access the resource, wherein evaluating the trust level includes applying a set of rules associated with access to the protected resource to a set of attributes of the client device, and wherein evaluating the trust level includes evaluating historical location data; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 wherein evaluating the trust level further includes applying the set of rules associated with access to the protected resource to a set of attributes of a user.

3. The system of claim 1 wherein evaluating the trust level includes evaluating telemetric data periodically provided by the client device.

4. The system of claim 1 wherein the grant of permission comprises a token issued to the client device by the access policy engine.

5. The system of claim 1 wherein the grant of permission comprises a message transmitted to the proxy server by the access policy engine.

6. The system of claim 1 wherein the grant of permission has an associated length of time.

7. The system of claim 6 wherein the client device is configured to automatically request an additional grant of permission with an additional length of time prior to a lapsing of the associated length of time.

8. The system of claim 1 wherein the request is received from the client device via a publicly accessible domain.

9. A method, comprising:

receiving, at a proxy server and from a client device, a request to access a protected resource, wherein the protected resource represents a mapping between a user-facing domain and an internal domain that is only accessible from behind a set of one or more proxies that includes the proxy server, wherein the request is received from the client device in response to an interception, by a VPN stack of an operating system executing on the client device, of a DNS resolution request; and

in response to receiving a grant of permission by an access policy engine, proxying, by the proxy server, access to the protected resource using a mutual-TLS connection with the client device;

wherein the access policy engine is configured to evaluate a trust level of a device-user, wherein the trust level comprises a named collection of constraints that must be fulfilled to access the resource, wherein evaluating the trust level includes applying a set of rules associated with access to the protected resource to a set of attributes of the client device, and wherein evaluating the trust level includes evaluating historical location data.

10. The method of claim 9 wherein evaluating the trust level further includes applying the set of rules associated with access to the protected resource to a set of attributes of a user.

11. The method of claim 9 wherein evaluating the trust level includes evaluating telemetric data periodically provided by the client device.

12. The method of claim 9 wherein the grant of permission comprises a token issued to the client device by the access policy engine.

13. The method of claim 9 wherein the grant of permission comprises a message transmitted to the proxy server by the access policy engine.

14. The method of claim 9 wherein the grant of permission has an associated length of time.

15. The method of claim 14 wherein the client device is configured to automatically request an additional grant of permission with an additional length of time prior to a lapsing of the associated length of time.

16. The method of claim 9 wherein the request is received from the client device via a publicly accessible domain.

Assignments (5)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2021
From: FYDE, INC.
To: BARRACUDA NETWORKS, INC.
Reel/Frame 056343/0623 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2020
From: SOLE, PABLO GERMAN; FERRAS PEREIRA, JOSE LUIS; EREN, SINAN; MOYA PRACA DE ARAUJO LIMA, LUISA MARINA
To: FYDE, INC.
Reel/Frame 052530/0666 →
Cited By (15)
US 12,375,475 US 12,388,829 US 12,425,375 US 12,452,253 US 12,474,945 US 12,476,972 US 12,504,893 US 12,513,147 US 12,519,775 US 12,574,447 US 12,580,894 US 12,609,934 US 12,627,523 US 12,652,247 US 12,684,349