IP Library Granted Patent US 12,556,579
Granted Patent B2
US 12,556,579 · App. 17/957,159 · Granted Feb 17, 2026

Using a websocket connection to send messages from an off-premises node to an on-premises node

Inventors: Alexandru Cozma (Bucharest, RO); Jeffery J Van Heuklon (Rochester, MN)
H04L63/168H04L63/0236H04L63/029H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,579
App. No.
17/957,159
Granted
Feb 17, 2026
Kind
B2
Abstract

A method includes establishing a WebSocket connection between an on-premises WebSocket application hosted on a first on-premises compute node and an off-premises WebSocket application hosted on a first off-premises compute node, wherein the first on-premises compute node is in an on-premises network having a firewall that prevents the first off-premises compute node from initiating a connection with the first on-premises compute node, and wherein the on-premises WebSocket application hosted on the first on-premises compute node initiates the establishing of the WebSocket connection with the off-premises WebSocket application hosted on the first off-premises compute node. The method further includes sending a message from a client application hosted on a second off-premises compute node to a server application hosted on a second on-premises compute node through the WebSocket connection, wherein the second off-premises compute node initiates the sending of the message to the second on-premises compute node.

Claims (38)

1 . A computer program product comprising a non-transitory computer readable medium and program instructions embodied therein, the program instructions being configured to be executable by a processor on an on-premises compute node to cause the processor to perform operations comprising:

hosting an on-premises WebSocket application;

initiating establishment of a WebSocket connection from the on-premises WebSocket application to an off-premises WebSocket application hosted on a first off-premises compute node, wherein the on-premises compute node is in an on-premises network having a firewall that prevents off-premises compute nodes from initiating a connection with the on-premises compute node;

the on-premises WebSocket application receiving a first application layer message from the off-premises WebSocket application through the WebSocket connection, where the first application layer message encapsulates a first transport layer segment sent from a client application hosted on the first off-premises compute node or a second off-premises compute node and directed to an on-premises server application; and

forwarding the first transport layer segment from a transport layer client service associated with the on-premises WebSocket application through a transport layer socket to a transport layer server service associated with the on-premises server application.

2 . The computer program product of claim 1 , further comprising:

the transport layer client service associated with the on-premises WebSocket application receiving a second transport layer segment from the transport layer server service associated with the on-premises server application through the transport layer socket, wherein the second transport layer segment is being sent from the on-premises server application to the off-premises client application; and

the on-premises WebSocket application encapsulating the second transport layer segment into a second application layer message and sending the second application layer message to the off-premises WebSocket application through the WebSocket connection.

3 . The computer program product of claim 1 , wherein the transport layer client service and the transport layer server service communicate over the transport layer socket using a protocol selected from Transmission Control Protocol and User Datagram Protocol.

4 . A computer program product comprising a non-transitory computer readable medium and program instructions embodied therein, the program instructions being configured to be executable by a processor on an off-premises compute node to cause the processor to perform operations comprising:

hosting an off-premises WebSocket application that is an endpoint for a WebSocket connection between the off-premises WebSocket application and an on-premises WebSocket application hosted on a first on-premises compute node, wherein the on-premises compute node is in an on-premises network having a firewall that prevents the off-premises compute node from initiating a connection with the on-premises compute node;

a transport layer server service associated with the off-premises WebSocket application receiving a first transport layer segment through a transport layer socket, wherein the transport layer segment is sent from an off-premises client application to an on-premises server application; and

the off-premises WebSocket application encapsulating the first transport layer segment into an application layer message and sending the application layer message to the on-premises WebSocket application through the WebSocket connection.

5 . The computer program product of claim 4 , further comprising:

the off-premises WebSocket application receiving a second application layer message from the on-premises WebSocket application through the WebSocket connection, where the second application layer message encapsulates a second transport layer segment sent from the on-premises server application and directed to the off-premises client application; and

forwarding the second transport layer segment from the transport layer server service associated with the off-premises WebSocket application through the transport layer socket to the transport layer client service associated with the off-premises server application for delivery to the off-premises client application.

6 . A method, comprising:

establishing a WebSocket connection between an on-premises WebSocket application hosted on a first on-premises compute node and an off-premises WebSocket application hosted on a first off-premises compute node, wherein the first on-premises compute node is in an on-premises network having a firewall that prevents the first off-premises compute node from initiating a connection with the first on-premises compute node, and wherein the on-premises WebSocket application hosted on the first on-premises compute node initiates the establishing of the WebSocket connection with the off-premises WebSocket application hosted on the first off-premises compute node; and

sending a message from a client application hosted on a second off-premises compute node to a server application hosted on a second on-premises compute node through the WebSocket connection, wherein the second off-premises compute node initiates the sending of the message to the second on-premises compute node.

7 . The method of claim 6 , wherein the first and second on-premises compute nodes are the same on-premises compute node and/or the first and second off-premises compute nodes are the same off-premises compute node.

8 . The method of claim 6 , wherein the WebSocket connection traverses through the firewall and a web proxy server between the first on-premises compute node and the first off-premises compute node.

9 . The method of claim 8 , further comprising:

the first on-premises node maintaining the WebSocket connection in an active state.

10 . The method of claim 6 , further comprising:

the first on-premises compute node receiving an instruction from an on-premises user, wherein the instruction identifies a network address for the first off-premises compute node and causes the on-premises WebSocket application hosted on the first on-premises compute node to initiate the establishing of the WebSocket connection with the off-premises WebSocket application hosted on the first off-premises compute node.

11 . The method of claim 6 , further comprising:

allowing messages sent from the second off-premises compute node to the second on-premises compute node to reach the second on-premises compute node only if the messages are sent through the WebSocket connection.

12 . The method of claim 6 , further comprising:

sending a second message from the server application to the client application through the WebSocket connection.

13 . The method of claim 6 , further comprising:

sending messages from an additional client application hosted on an off-premises compute node through the WebSocket connection to the server application, from an additional server application hosted on an on-premises compute node through the WebSocket connection to the client application, and/or between the additional client application and the additional server application.

14 . The method of claim 6 , further comprising:

establishing an off-premises transport layer socket between an off-premises transport layer client service associated with the client application hosted on the second off-premises compute node and an off-premises transport layer server service associated with the off-premises WebSocket application hosted on the first off-premises compute node; and

establishing an on-premises transport layer socket between an on-premises transport layer server service associated with a server application hosted on the second on-premises compute node and an on-premises transport layer client service associated with the on-premises WebSocket application hosted on the first off-premises compute node.

15 . The method of claim 14 , wherein the off-premises transport layer client services and the off-premises transport layer server service communicate over the off-premises transport layer socket using a protocol selected from Transmission Control Protocol and User Datagram Protocol, and wherein the on-premises transport layer client services and the on-premises transport layer server service communicate over the on-premises transport layer socket using a protocol selected from Transmission Control Protocol and User Datagram Protocol.

16 . The method of claim 14 , wherein the message sent from the client application to the server application is initiated by the client application and directed to the server application, sent over the off-premises transport layer socket from the off-premises transport layer client service associated with the client application to the off-premises transport layer server service associated with the off-premises WebSocket application, sent over the WebSocket connection from the off-premises WebSocket application to the on-premises WebSocket application, and sent over the on-premises transport layer socket from the on-premises transport layer client service associated with the on-premise WebSocket application to the on-premises transport layer server service associated with the server application.

17 . The method of claim 16 , wherein the message forms at least one transport layer segment, and wherein the message is encapsulated in an Internet Protocol datagram.

18 . The method of claim 16 , wherein the transport layer server service associated with the off-premises WebSocket application uses a first destination port having the same port number as a second destination port used by the transport layer server service associated with the server application hosted by the on-premises compute node.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2023
From: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
Reel/Frame 064298/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2022
From: COZMA, ALEXANDRU; VAN HEUKLON, JEFFERY J
To: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
Reel/Frame 061559/0282 →
Continuity (1)
Related Publication 20240114054A1 · Apr 4, 2024
References Cited (7)
US 20140237585A1 · Khan · 2014 [cited by examiner]
US 20160241633A1 · Overby, Jr. · 2016 [cited by examiner]
US 20170171289A1 · Fausak · 2017 [cited by examiner]
Firewall—Wikipedia (Year: 2020). [cited by examiner]
Virtual Private Network & Tunneling—Wikipedia (Year: 2020). [cited by examiner]
WebSocket—Wikipedia (Year: 2020). [cited by examiner]
Feng, “Windows Firewall Blocks All Incoming Traffic by Default” (Year: 2020). [cited by examiner]