IP Library Granted Patent US 11,778,039
Granted Patent B1
US 11,778,039 · App. 17/744,819 · Granted Oct 3, 2023

Systems and methods for establishing discrete connection to a network endpoint

Inventors: Christopher Edward Delaney (Front Royal, VA); Chava Louis Jurado (Leesburg, VA); Carl Bailey Jacobs (Fredericksburg, VA)
Assignee: Cyber IP Holdings, LLC
H04L67/141H04L67/02H04L67/147H04L67/2895H04L67/561
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,778,039
App. No.
17/744,819
Granted
Oct 3, 2023
Kind
B1
Abstract

Systems and methods are provided for connecting a client to a desired network endpoint. Example systems and methods include receiving, at a server, a request identifying a network endpoint to be accessed, configuring a proxy instance, the proxy instance being configured to receive a connection from a client to forward that client connection to the identified network endpoint, and deleting the proxy instance upon occurrence of a session end criteria. In some embodiments, the request identifying a network endpoint to the server is received from the network endpoint. In some embodiments, the request identifying a network endpoint to the server is received from the client. In some embodiments, a platform as a service is used to configure the proxy instance. In some embodiments, the request identifying a network endpoint is made to the platform as a service rather than to the server, which is not included in the embodiment.

Claims (39)

1. A computer-implemented method of connecting a client to a desired network endpoint, comprising:

receiving, at a server, a request identifying a network endpoint to be accessed;

configuring a proxy instance, the proxy instance being configured to receive a connection from a client and to forward that client connection to the identified network endpoint, wherein the proxy instance is implemented by:

configuring a first reverse proxy connection and a second reserve proxy connection, each configured to receive a connection from the client to set up a discreet connection; and

sending access credentials to the client over the first reverse proxy connection including an address for accessing the second reverse proxy connection, wherein the second reverse proxy connection is associated with the proxy instance; and

deleting the proxy instance upon occurrence of a session end criteria.

2. The method of claim 1 , wherein the request identifying a network endpoint to the server is received from the network endpoint.

3. The method of claim 2 , wherein the server requests a platform as a service to create a pool of proxy instances.

4. The method of claim 3 , wherein the server allocates one proxy instance from the pool of proxy instances to the client upon the client entering a URL corresponding to the network endpoint.

5. The method of claim 4 , wherein the server requests the platform as a service to create a new proxy instance upon the server allocating one proxy instance from the pool of proxy instances to the client.

6. The method of claim 4 , wherein the server issues an HTTP 302 (Resource Temporarily Moved) response code to the client containing a URL of the proxy instance that was allocated to the client.

7. The method of claim 1 , wherein the proxy instance is further implemented by:

sending an invitation indicating a mechanism for accessing the first reverse proxy connection to the client;

deleting the first reverse proxy connection upon delivery of the access credentials for the second reverse proxy connection; and

facilitating the discreet connection between the client and the network endpoint without any detectable direct contact with the network endpoint using the second reverse proxy connection.

8. The method of claim 1 , wherein the session end criteria comprises the client terminating a connection to the network endpoint, an expiration of a pre-determined period of time, or inactivity for more than a threshold period of time.

9. The method of claim 1 , wherein the request identifying a network endpoint to the server is received from the client.

10. The method of claim 9 , wherein the proxy instance is configured with an IP address whitelist limiting connections to the proxy instance to connections from the client.

11. The method of claim 1 , wherein the server sends a request to a platform as a service to configure the proxy instance.

12. The method of claim 11 , wherein the server requests the platform as a service to delete the proxy instance upon occurrence of session end criteria.

13. The method of claim 11 , wherein the server receives a URL to the proxy instance from the platform as a service and transmits the URL to the proxy instance to the client, the client establishing a connection to the proxy instance using the URL to the URL to the proxy instance.

14. The method of claim 13 , wherein the desired endpoint is the public IP address of an inbound proxy node comprising a hub device of an on-demand computing network configured to comprise one or more rim devices, which can only be contacted by the client through the hub device wherein the network endpoint is configured to be a rim device.

15. A computer-implemented system for connecting a client to a desired network endpoint, comprising:

a server comprising:

one or more data processors; and

a non-transitory computer-readable medium encoded with instructions to command one or more data processors to:

receive a request identifying a network endpoint to be accessed;

make a request to a platform as a service provider to configure a proxy instance, the proxy instance being configured to receive a connection from a client and to forward that client connection to the identified network endpoint, wherein the proxy instance is implemented by:

configuring a first reverse proxy connection and a second reserve proxy connection, each configured to receive a connection from the client to set up a discreet connection; and

sending access credentials to the client over the first reverse proxy connection including an address for accessing the second reverse proxy connection, wherein the second reverse proxy connection is associated with the proxy instance; and

delete the proxy instance upon occurrence of a session end criteria.

16. The computer-implemented system of claim 15 , wherein the request identifying a network endpoint to the server is made by a client.

17. The computer-implemented system of claim 16 , wherein the request identifying a network endpoint to the server is made by the network endpoint.

18. The computer-implemented system of claim 17 , wherein the server requests a platform as a service to create a pool of proxy instances.

19. The computer-implemented system of claim 18 , wherein the server allocates one proxy instance from the pool of proxy instances to the client upon the client entering a URL corresponding to the network endpoint.

20. A computer-implemented system for connecting a client to a desired network endpoint, comprising:

a processor-implemented platform as a service provider receiving a request from a client to configure a proxy instance, wherein the proxy instance is configured to receive a connection from the client and to forward that client connection to an identified network endpoint, and to delete the proxy instance upon occurrence of a session end criteria and, wherein the proxy instance is implemented the provider via instructions stored on a computer-readable medium that command the processor-implemented platform to execute steps comprising:

configuring a first reverse proxy connection and a second reserve proxy connection, each configured to receive a connection from the client to set up a discreet connection; and

sending access credentials to the client over the first reverse proxy connection including an address for accessing the second reverse proxy connection, wherein the second reverse proxy connection is associated with the proxy instance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: DELANEY, CHRISTOPHER EDWARD; JURADO, CHAVA LOUIS; JACOBS, CARL BAILEY
To: CYBER IP HOLDINGS, LLC
Reel/Frame 059914/0488 →
Continuity (1)
Provisional Application 63190262 · May 19, 2021
Cited By (2)
US 12,407,725 US 12,609,991