IP Library Granted Patent US 11,677,718
Granted Patent B1
US 11,677,718 · App. 17/459,122 · Granted Jun 13, 2023

File sharing over secure connections

Inventors: Alexey Petrukhin (Tallinn, EE); Grigory Nikolaenko (Moscow, RU); Nikolay Dobrovolskiy (Moscow, RU); Serguei Beloussov (Singapore, SG)
Assignee: Parallels International GmbH
H04L63/0254G06F11/1402H04L63/0281H04L63/04H04L63/061H04L63/166H04L67/01H04L67/06H04L67/1097H04L67/56G06F2201/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,718
App. No.
17/459,122
Granted
Jun 13, 2023
Kind
B1
Abstract

Systems and methods for file sharing over secure connections. An example method comprises: receiving a client request identifying a file sharing host and a file residing on the file sharing host; establishing a secure client connection; responsive to identifying a management connection with the file sharing host, transmitting an identifier and a parameter of the secure client connection via the management connection; receiving a host request to establish a secure host connection, the host request comprising the identifier of the secure client connection; establishing the secure host connection using the parameter of the secure client connection identified by the received identifier; forwarding, over the secure host connection, a first data packet received over the secure client connection, the first data packet comprising at least part of the client request; and forwarding, over the secure client connection, a second data packet received over the secure host connection, the second data packet comprising at least part of the file identified by the client request.

Claims (103)

1. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection and the second secure connection are established by a process including:

establishing with the client computing device a browser based session with the file sharing proxy server;

establishing the second secure connection between the client computing device and the file sharing proxy server;

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator;

parsing the resource locator to identify the file sharing host of the plurality of file sharing hosts as being a storage location of the file;

determining whether a management connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts exists;

upon a positive determination that the management connection to the file sharing host of the plurality of file sharing hosts exists transmitting a message over the management connection to the file sharing host of the plurality of file sharing hosts, the message comprising at least a client session identifier of the browser based session and an element of a connection state of the second secure connection;

establishing by the file sharing host of the plurality of file sharing hosts a new unsecured connection with the file sharing proxy server where in establishing the new unsecured connection the file sharing host of the plurality of file sharing hosts transmits an identifier to the file sharing proxy server allowing it to associate the new unsecured connection with the client computing device and the browser based session; and

responsive to a response from the file sharing proxy server to the file sharing host of the plurality of file sharing hosts establishing the first secure connection over the new unsecured connection where the first secure connection is established using the element of the connection state of the second secure connection such that the first secure connection and second secure connection share at least the element of the connection state of the second secure connection.

2. The method according to claim 1 , wherein

when messages to the client computing device from the file sharing host of the plurality of file sharing hosts are encrypted the client computing device decrypts the messages transmitted from the file sharing host of the plurality of file sharing hosts; and

when other messages to the file sharing host of the plurality of file sharing hosts from the client computing device are encrypted the file sharing host of the plurality of file sharing hosts decrypts the other messages transmitted from the client computing device.

3. The method according to claim 1 , wherein

the message further comprises a part of the request and other elements of the connection state of the second secure connection.

4. The method according to claim 1 , wherein

the message further comprises a part of the request and one or more other elements of the connection state of the second secure connection; and

each other elements of the connection state is selected from the group comprising a cipher type, a master key, a secure session identifier of the second secure connection, and an initialization vector value.

5. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection and the second secure connection are established by a process comprising:

establishing an initial connection between the client computing device and the file sharing proxy server;

identifying the file sharing host of the plurality of file sharing hosts;

establishing a new unsecured connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts; and

establishing the second secure connection over the new unsecured connection such that the first secure connection and second secure connection share at least an element of a connection state of the second secure connection.

6. The method according to claim 5 , wherein

establishing an initial connection between the client computing device and the file sharing proxy server comprises:

establishing with the client computing device a browser based session with the file sharing proxy server;

establishing the second secure connection between the client computing device and the file sharing proxy server; and

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator.

7. The method according to claim 5 , wherein

identifying the file sharing host of the plurality of file sharing hosts comprises parsing a resource locator to identify the file sharing host of the plurality of file sharing hosts as being a storage location of a file; and

the resource locator is received by the file sharing proxy server as part of a file access request for the file from the client computing device.

8. The method according to claim 4 , wherein

establishing the new unsecured connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts comprises:

determining whether a management connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts exists;

upon a positive determination that the management connection to the file sharing host of the plurality of file sharing hosts exists transmitting a message over the management connection to the file sharing host of the plurality of file sharing hosts, the message comprising at least a client session identifier of the browser based session and an element of a connection state of the second secure connection; and

establishing by the file sharing host of the plurality of file sharing hosts the new unsecured connection with the file sharing proxy server where in establishing the new unsecured connection the file sharing host of the plurality of file sharing hosts transmits an identifier to the file sharing proxy server allowing it to associate the new unsecured connection with the client computing device and the browser based session.

9. The method according to claim 5 , wherein

establishing the second secure connection over the new unsecured connection such that the first secure connection employs at least an element of a connection state of the second secure connection comprises:

transmitting a request over the new unsecured connection from the file sharing hose of the plurality of file sharing hosts where the request identifies a client session identifier; and

the client session identifier was transmitted to the file sharing hose of the plurality of file sharing hosts by the file sharing proxy server as part of a message to establish the new unsecured connection; and

the element of a connection state of the second secure connection was communicated as part of an initial request from the client computing device for the file.

10. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission;

the first secure connection is established by a process which comprises:

establishing the second secure connection between the client computing device and the file sharing proxy server;

determining whether a management connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts exists;

upon a positive determination that the management connection to the file sharing host of the plurality of file sharing hosts exists transmitting a message over the management connection to the file sharing host of the plurality of file sharing hosts, the message comprising at least a client session identifier of a browser based session and an element of a connection state of the second secure connection; and

upon a negative determination that the management connection to the file sharing host of the plurality of file sharing hosts exists establishing a connection recover procedure with respect to the file sharing host of the plurality of file sharing hosts; and

the browser based session is employed to generate a file access request for the file which a identifies the file by a resource locator.

11. The method according to claim 10 , wherein

the connection recover procedures comprises:

transmitting another message to an address associated with a user of the file sharing host of the plurality of file sharing hosts; and

the user at least one of power the file sharing host of the plurality of file sharing hosts on and establish the management connection between the file sharing host of the plurality of file sharing hosts and the file sharing proxy server; and

the file sharing proxy server subsequently seeks to determine again whether the management connection between the file sharing proxy server and the file sharing a host of the plurality of file sharing hosts exist.

12. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file;

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator;

parsing the resource locator to identify the file sharing host of the plurality of file sharing hosts as being a storage location of the file;

retrieving data from a file sharing host information record from a database accessible to the file sharing proxy server associated with the file sharing host of the plurality of file sharing hosts; and

employing the data to cause an awakening of the file sharing host of the plurality of file sharing hosts by at least one of an active peer of the file sharing host of the plurality of file sharing hosts, an active device in a home network with the file sharing host of the plurality of file sharing hosts forms, and an active device in close proximity of the file sharing host of the plurality of file sharing hosts; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the file sharing host information record comprises one or more fields describing the configuration of the home network where the home network is at least one of a local area network or a wireless network.

13. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file;

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator; and

identifying the file sharing host of the plurality of file sharing hosts as being an active storage location of the file through a process comprising the steps of:

parsing the resource locator to identify the file;

identifying a subset of the plurality of file sharing hosts storing the file in dependence upon parsing a database accessible to the file sharing proxy server storing metadata relating to file system objects stored by each of the plurality of file sharing hosts to match the file to these file system objects;

identifying an active file sharing host of the subset of the plurality of file sharing hosts in dependence upon parsing another database accessible to the file sharing proxy server storing one or more fields describing availability of each file sharing host of the plurality of file sharing hosts where the active file sharing host is currently available; and

establishing the active file sharing host as the file sharing host of the plurality of file sharing hosts; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-a encrypting it for transmissions.

14. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file;

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator;

identifying the file sharing host of the plurality of file sharing hosts as being an active storage location of the file through a process comprising the steps of:

parsing the resource locator to identify the file;

identifying a subset of the plurality of file sharing hosts storing the file in dependence upon parsing a database accessible to the file sharing proxy server storing metadata relating to file system objects stored by each of the plurality of file sharing hosts to match the file to these file system objects;

selecting the file sharing host of the plurality of file sharing hosts from subset of the plurality of file sharing hosts;

establishing a status of the file sharing host of the plurality of file sharing hosts in dependence upon parsing another database accessible to the file sharing proxy server storing one or more fields describing availability of the file sharing host of the plurality of file sharing hosts;

upon establishing the status of the file sharing host of the plurality of file sharing hosts as active the file sharing proxy server executes another process in conjunction with the file sharing host of the plurality of file sharing hosts to establish the first secure connection; and

upon establishing the status of the file sharing host of the plurality of file sharing hosts as not active the file sharing proxy server executes a further process comprising the steps of:

retrieving data from a file sharing host information record from the another database associated with the file sharing host of the plurality of file sharing hosts; and

employing the data to cause an awakening of the file sharing host of the plurality of file sharing hosts by at least one of an active peer of the file sharing host of the plurality of file sharing hosts, an active device in a home network with the file sharing host of the plurality of file sharing hosts forms, and an active device in close proximity of the file sharing host of the plurality of file sharing hosts; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the file sharing host information record comprises one or more fields describing the configuration of the home network where the home network is at least one of a local area network or a wireless network.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded May 1, 2023
From: PARALLELS IP HOLDINGS GMBH; PARALLELS INTERNATIONAL GMBH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 063491/0095 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: PETRUKHIN, ALEXEY; NIKOLAENKO, GRIGORY; DOBROVOLSKIY, NIKOLAY; BELOUSSOV, SERGUEI
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 063480/0639 →
Continuity (2)
Continuation 16458912 · Jul 1, 2019
Continuation 15056435 · Feb 29, 2016