IP Library Granted Patent US 11,665,171
Granted Patent B2
US 11,665,171 · App. 17/863,998 · Granted May 30, 2023

Secure access to a corporate web application with translation between an internal address and an external address

Inventors: David Patimer (Tel Aviv, IL); Lior Lev-Tov (Tel Aviv, IL); Eldad Rudich (Tel Aviv, IL); Leonid Belkind (Tel Aviv, IL)
Assignee: CA, Inc.
H04L63/102G06F9/452G06F21/305G06F21/33H04L63/02H04L63/0281H04L63/0853H04L63/20H04L63/0272H04L63/0428H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,171
App. No.
17/863,998
Granted
May 30, 2023
Kind
B2
Abstract

Secure access to a corporate application with translation between an internal address and an external address. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate web application. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate web application by translating between an internal address of the corporate web application and an external address of the corporate web application.

Claims (28)

1. A computer-implemented method comprising:

receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter, wherein the secure access cloud PoD is deployed outside of the corporate datacenter;

brokering, by a connector deployed in the corporate datacenter and the secure access cloud PoD, a secure communication session between the client application and the corporate web application, wherein brokering the secure communication session further comprises translating between an internal address of the corporate web application and an external address of the corporate web application, wherein communication from the client application addressed to the external address of the corporate web application is translated, via the secure access cloud PoD, to the internal address of the corporate web application, wherein the client application is unaware that the secure communication session is brokered by the connector and the secure access cloud PoD.

2. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed in request headers by replacing the external address of the corporate web application with the internal address of the corporate web application.

3. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed in request bodies by replacing the external address of the corporate web application with the internal address of the corporate web application.

4. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed in response headers by replacing the internal address of the corporate web application with the external address of the corporate web application.

5. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed in response bodies by replacing the internal address of the corporate web application with the external address of the corporate web application.

6. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is completely transparent to the client application.

7. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is completely transparent to the corporate web application.

8. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed automatically.

9. The method of claim 1 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed on a chunked stream.

10. The method of claim 9 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application performed on the chunked stream employs a virtual window of content with searches and replaces of the internal address and the external address being performed while reconstructing chunks in the chunked stream.

11. A computer-implemented method comprising:

receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a first corporate web application that is deployed in a corporate datacenter;

brokering, by a connector deployed in the corporate data center and the secure access cloud PoD, a secure communication session between the client application and the first corporate web application, wherein the client application is unaware that the secure communication session is brokered by the connector and the secure access cloud PoD, wherein brokering the secure communication session further comprises:

translating between an internal address of the corporate web application and an external address of the corporate web application, wherein communication from the client application addressed to the external address of the first corporate web application is translated, via the secure access cloud PoD, to the internal address of the first corporate web application; and

linking to a second corporate web application that is referenced by an internal domain of the second corporate web application in the first corporate web application.

12. The method of claim 11 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is performed:

in request headers and bodies by replacing the external address of the corporate web application with the internal address of the corporate web application; and

in response headers and bodies by replacing the internal address of the corporate web application with the external address of the corporate web application.

13. The method of claim 11 , wherein the translating between the internal address of the corporate web application and the external address of the corporate web application is completely transparent to the client application and to the corporate web application.

14. The method of claim 11 , wherein the linking to the second corporate web application that is referenced by the internal domain of the second corporate web application in the first corporate web application comprises automatically translating the internal domain of the second corporate web application to an external domain of the second corporate web application in response headers and bodies.

15. The method of claim 11 , wherein the linking to the second corporate web application that is referenced by the internal domain of the second corporate web application in the first corporate web application comprises automatically translating the internal domain of the second corporate web application to an external domain of the second corporate web application in request headers and bodies.

16. The method of claim 11 , wherein access permissions to both the first corporate web application and the second corporate web application are aligned.

17. The method of claim 11 , wherein the linking to the second corporate web application that is referenced by the internal domain of the second corporate web application in the first corporate web application comprises automatically masking the existence of the second corporate web application from the client application.

18. The method of claim 17 , wherein the automatically masking the existence of the second corporate web application from the client application comprises generating, by the secure access cloud PoD, ad-hoc Unique Resource Identifiers (URIs) for the second corporate web application that appear to the client application to correspond to the first corporate web application.

19. The method of claim 18 , wherein the URIs appear in content and/or metadata delivered to the client application.

20. The method of claim 17 , wherein the automatically masking the existence of the second corporate web application from the client application is completely transparent to the client application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2022
From: PATIMER, DAVID; LEV-TOV, LIOR; RUDICH, ELDAD; BELKIND, LEONID
To: SYMANTEC CORPORATION
Reel/Frame 060553/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2022
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 060553/0280 →
Continuity (3)
Continuation 16591347 · Oct 2, 2019
Provisional Application 62832038 · Apr 10, 2019
Related Publication 20220345462A1 · Oct 27, 2022