IP Library Granted Patent US 12,418,513
Granted Patent B2
US 12,418,513 · App. 17/855,764 · Granted Sep 16, 2025

Internet protocol based security over port forwarding tunnels

Inventors: Fan Du (Santa Clara, CA); Jiangbin Luo (Cupertino, CA); Pradeep Bansal (Portland, OR); Keon Jang (Los Altos, CA)
Assignee: Rubrik, Inc.
H04L63/029H04L63/0236H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,513
App. No.
17/855,764
Granted
Sep 16, 2025
Kind
B2
Abstract

An application server host may receive, via a port forwarding tunnel, a connection request that includes an indication of a client internet protocol (IP) address for a client host. The application server host may identify based at least in part on the client IP address and using a mapping maintained for a plurality of client hosts, a virtual IP address that is associated with the client IP address and a client network identifier associated with the port forwarding tunnel from which the connection request is received. The application server host may open a connection between an application server hosted by the application server host and the client host using the identified virtual IP address.

Claims (56)

1. A method for data management comprising:

receiving, at an application server host and via a port forwarding tunnel, a connection request that includes an indication of a client internet protocol (IP) address for a client host;

identifying, based at least in part on the client IP address and using a mapping maintained for a plurality of client hosts, a virtual IP address that is assigned to both the client IP address and a client network identifier, wherein the client network identifier is mapped to the port forwarding tunnel from which the connection request is received; and

opening a connection between an application server hosted by the application server host and the client host using the identified virtual IP address.

2. The method of claim 1 , wherein identifying the virtual IP address comprises:

identifying, based at least in part on the client IP address and the client network identifier, the virtual IP address from a file including the mapping and maintained at the application server host.

3. The method of claim 1 , wherein identifying the virtual IP address comprises:

transmitting, via an application programming interface (API), a request for the virtual IP address, wherein the request includes the client IP address and the client network identifier; and

receiving, in response to the request, an indication of the virtual IP address.

4. The method of claim 1 , further comprising:

receiving, at the application server host and via a second port forwarding tunnel, a second connection request that includes an indication of a second client IP address for a second client host, wherein the second client IP address has a same value as the client IP address;

identifying, based at least in part on the second client IP address and using the mapping, a second virtual IP address that is assigned to both the second client IP address and a second client network identifier, wherein the client network identifier is mapped to the second port forwarding tunnel from which the connection request is received, wherein the second client network identifier is used to differentiate between the second client IP address and the client IP address that have the same value; and

opening a second connection between the application server hosted and the second client host using the identified second virtual IP address.

5. The method of claim 1 , wherein receiving the connection request comprises:

receiving the connection request via a tunnel endpoint for the port forwarding tunnel, wherein the tunnel endpoint is provisioned for access by a second plurality of client hosts associated with the client network identifier.

6. The method of claim 1 , wherein the plurality of client hosts are associated with a plurality of loopback IP addresses in the mapping.

7. The method of claim 1 , wherein the application server host is configured to enforce security policies based at least in part on the identified virtual IP address.

8. The method of claim 1 , further comprising:

receiving, via the connection, a packet that is to be received at the application server, wherein the packet includes an IP address associated with the port forwarding tunnel;

replacing the IP address associated with the port forwarding tunnel with the virtual IP address associated with the client host based at least in part on the connection via which the packet is received; and

forwarding the packet to the application server.

9. An apparatus, comprising:

a processor;

memory coupled with the processor; and

instructions stored in the memory and executable by the processor to cause the apparatus to:

receive, at an application server host and via a port forwarding tunnel, a connection request that includes an indication of a client internet protocol (IP) address for a client host;

identify, based at least in part on the client IP address and using a mapping maintained for a plurality of client hosts, a virtual IP address that is assigned to both the client IP address and a client network identifier, wherein the client network identifier is mapped to the port forwarding tunnel from which the connection request is received; and

open a connection between an application server hosted by the application server host and the client host using the identified virtual IP address.

10. The apparatus of claim 9 , wherein the instructions to identify the virtual IP address are executable by the processor to cause the apparatus to:

identify, based at least in part on the client IP address and the client network identifier, the virtual IP address from a file including the mapping and maintained at the application server host.

11. The apparatus of claim 9 , wherein the instructions to identify the virtual IP address are executable by the processor to cause the apparatus to:

transmit, via an application programming interface (API), a request for the virtual IP address, wherein the request includes the client IP address and the client network identifier; and

receive, in response to the request, an indication of the virtual IP address.

12. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

receive, at the application server host and via a second port forwarding tunnel, a second connection request that includes an indication of a second client IP address for a second client host, wherein the second client IP address has a same value as the client IP address;

identify, based at least in part on the second client IP address and using the mapping, a second virtual IP address that is assigned to both the second client IP address and a second client network identifier, wherein the client network identifier is mapped to the second port forwarding tunnel from which the connection request is received, wherein the second client network identifier is used to differentiate between the second client IP address and the client IP address that have the same value; and

open a second connection between the application server hosted and the second client host using the identified second virtual IP address.

13. The apparatus of claim 9 , wherein the instructions to receive the connection request are executable by the processor to cause the apparatus to:

receive the connection request via a tunnel endpoint for the port forwarding tunnel, wherein the tunnel endpoint is provisioned for access by a second plurality of client hosts associated with the client network identifier.

14. The apparatus of claim 9 , wherein the plurality of client hosts are associated with a plurality of loopback IP addresses in the mapping.

15. The apparatus of claim 9 , wherein the application server host is configured to enforce security policies based at least in part on the identified virtual IP address.

16. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

receive, via the connection, a packet that is to be received at the application server, wherein the packet includes an IP address associated with the port forwarding tunnel;

replace the IP address associated with the port forwarding tunnel with the virtual IP address associated with the client host based at least in part on the connection via which the packet is received; and

forward the packet to the application server.

17. A non-transitory computer-readable medium storing code, the code comprising instructions executable by a processor to:

receive, at an application server host and via a port forwarding tunnel, a connection request that includes an indication of a client internet protocol (IP) address for a client host;

identify, based at least in part on the client IP address and using a mapping maintained for a plurality of client hosts, a virtual IP address that is assigned to both the client IP address and a client network identifier, wherein the client network identifier is mapped to the port forwarding tunnel from which the connection request is received; and

open a connection between an application server hosted by the application server host and the client host using the identified virtual IP address.

18. The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the processor to:

receive, at the application server host and via a second port forwarding tunnel, a second connection request that includes an indication of a second client IP address for a second client host, wherein the second client IP address has a same value as the client IP address;

identify, based at least in part on the second client IP address and using the mapping, a second virtual IP address that is assigned to both the second client IP address and a second client network identifier, wherein the client network identifier is mapped to the second port forwarding tunnel from which the connection request is received, wherein the second client network identifier is used to differentiate between the second client IP address and the client IP address that have the same value; and

open a second connection between the application server hosted and the second client host using the identified second virtual IP address.

19. The non-transitory computer-readable medium of claim 17 , wherein the instructions to receive the connection request are executable by the processor to:

receive the connection request via a tunnel endpoint for the port forwarding tunnel, wherein the tunnel endpoint is provisioned for access by a second plurality of client hosts associated with the client network identifier.

20. The non-transitory computer-readable medium of claim 17 , wherein the plurality of client hosts are associated with a plurality of loopback IP addresses in the mapping.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 64659/0236 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071566/0187 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 21, 2023
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 064659/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2022
From: DU, FAN; LUO, JIANGBIN; BANSAL, PRADEEP; JANG, KEON
To: RUBRIK, INC.
Reel/Frame 061353/0001 →
Continuity (1)
Related Publication 20240007441A1 · Jan 4, 2024
References Cited (12)
US 9143480B2 · Brousseau · 2015 [cited by examiner]
US 9172559B2 · Chen · 2015 [cited by examiner]
US 10375025B2 · Zheng · 2019 [cited by examiner]
US 20020138628A1 · Tingley · 2002 [cited by examiner]
US 20140181248A1 · Deutsch · 2014 [cited by examiner]
US 20170223154A1 · Hammam · 2017 [cited by examiner]
US 20180124198A1 · Petrov · 2018 [cited by examiner]
US 20200213151A1 · Srivatsan · 2020 [cited by examiner]
US 20230283608A1 · Bosch · 2023 [cited by examiner]
JP 2004007671A · 2004 [cited by examiner]
WO WO02061599A1 · 2002 [cited by examiner]
WO WO2009055722A1 · 2009 [cited by examiner]