IP Library Granted Patent US 12,034,699
Granted Patent B1
US 12,034,699 · App. 18/316,397 · Granted Jul 9, 2024

File sharing over secure connections

Inventors: Alexey Petrukhin (Tallinn, EE); Grigory Nikolaenko (Moscow, RU); Nikolay Dobrovolskiy (Moscow, RU); Serguei Beloussov (Singapore, SG)
Assignee: Parallels International GmbH
H04L63/0254G06F11/1402H04L63/0281H04L63/04H04L63/061H04L63/166H04L67/01H04L67/06H04L67/1097H04L67/56G06F2201/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,699
App. No.
18/316,397
Granted
Jul 9, 2024
Kind
B1
Abstract

Systems and methods for file sharing over secure connections. An example method comprises: receiving a client request identifying a file sharing host and a file residing on the file sharing host; establishing a secure client connection; responsive to identifying a management connection with the file sharing host, transmitting an identifier and a parameter of the secure client connection via the management connection; receiving a host request to establish a secure host connection, the host request comprising the identifier of the secure client connection; establishing the secure host connection using the parameter of the secure client connection identified by the received identifier; forwarding, over the secure host connection, a first data packet received over the secure client connection, the first data packet comprising at least part of the client request; and forwarding, over the secure client connection, a second data packet received over the secure host connection, the second data packet comprising at least part of the file identified by the client request.

Claims (66)

1. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection; and

the file sharing proxy server does not decrypt data received over the first secure connection from the file sharing host of the plurality of file sharing hosts intended for the client computing device and re-encrypt it for forwarding to the client computing device over the second secure connection;

transmitting first messages to the file sharing host of the plurality of file sharing hosts from the client computing device via the file sharing proxy server over the first secure connection and then the second secure connection;

transmitting second messages to the client computing device from the file sharing host of the plurality of file sharing hosts via the file sharing proxy server over the second secure connection and then the first secure connection;

the client computing device supports decryption of the second messages transmitted from the file sharing host of the plurality of file sharing hosts;

the file sharing host of the plurality of file sharing hosts supports decryption of the first messages transmitted from the client computing device; and

the file sharing proxy server cannot decrypt either the second messages from the file sharing host of the plurality of file sharing hosts which it transmits to the client computing device or the first messages from the client computing device which it transmits to the file sharing host of the plurality of file sharing hosts.

2. The method according to claim 1 , wherein

the first secure connection and the second secure connection employ a common session key such that traffic flowing over both connections is encrypted by the same encryption key.

3. The method according to claim 1 , wherein

the first secure connection is established upon a management connection established between the file sharing host of the plurality of file sharing hosts and the file sharing proxy server independent of a request from the client computing device for the file and the establishment of the first secure connection; and

the management connection is kept alive either indefinitely or for a certain period of time.

4. The method according to claim 1 , wherein

the first secure connection is associated with a first socket associated with the file sharing proxy server;

the second secure connection is associated with a second socket associated with the file sharing proxy server; and

the file sharing proxy server writes to the second socket all that that has been read from the first socket and writes to the first socket all data that has been read from the second socket.

5. The method according to claim 1 , wherein

the first secure connection and the second secure connection share at least one of a secure session key and one or more elements of a secure connection state; and

each element of the connection state is selected from the group comprising a cipher type, a master key, a secure session identifier of the second secure connection, and an initialization vector value.

6. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection and the second secure connection are established by a process comprising:

establishing with the client computing device a browser based session with the file sharing proxy server;

establishing the second secure connection between the client computing device and the file sharing proxy server;

transmitting to the file sharing proxy server from the client computing device a request encoding a file access request for the file which is identified by a resource locator;

parsing the resource locator to identify the file sharing host of the plurality of file sharing hosts as being a storage location of the file; and

responsive to a response from the file sharing proxy server to the file sharing host of the plurality of file sharing hosts establishing the first secure connection over the new unsecured connection where the first secure connection is established using the element of the connection state of the second secure connection such that the first secure connection and second secure connection share at least the element of the connection state of the second secure connection.

7. The method according to claim 6 , wherein

the process establishing the first secure connection and the second secure connection further comprises:

establishing by the file sharing host of the plurality of file sharing hosts a new unsecured connection with the file sharing proxy server where in establishing the new unsecured connection the file sharing host of the plurality of file sharing hosts transmits an identifier to the file sharing proxy server allowing it to associate the new unsecured connection with the client computing device and the browser based session.

8. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection and the second secure connection are established by a process comprising:

establishing an initial connection between the client computing device and the file sharing proxy server;

identifying the file sharing host of the plurality of file sharing hosts;

establishing a new unsecured connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts; and

establishing the second secure connection over the new unsecured connection such that the first secure connection and second secure connection share at least an element of a connection state of the second secure connection.

9. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection is established by a process which comprises:

establishing the second secure connection between the client computing device and the file sharing proxy server;

determining whether a management connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts exists; and

upon a negative determination that the management connection to the file sharing host of the plurality of file sharing hosts exists establishing a connection recover procedure with respect to the file sharing host of the plurality of file sharing hosts; and

the browser based session is employed to generate a file access request for the file which identifies the file by a resource locator.

10. A method comprising:

transmitting from a file sharing host of a plurality of file sharing hosts to a client computing device via a file sharing proxy server a file; wherein

the file is initially transmitted to the file sharing proxy server from the file sharing host of the plurality of file sharing hosts over a first secure connection;

the file is then transmitted from the file sharing proxy server to the client computing device over a second secure connection;

the file sharing proxy server determines whether data received over the first secure connection from the file sharing host of the plurality of file sharing hosts is encrypted and intended for the client computing device and upon a positive determination directly forwards the received data to the client computing device over the second secure connection without decrypting the received data and re-encrypting it for transmission; and

the first secure connection is established by a process which comprises:

establishing the second secure connection between the client computing device and the file sharing proxy server;

determining whether a management connection between the file sharing proxy server and the file sharing host of the plurality of file sharing hosts exists;

upon a positive determination that the management connection to the file sharing host of the plurality of file sharing hosts exists transmitting a message over the management connection to the file sharing host of the plurality of file sharing hosts, the message comprising at least a client session identifier of a browser based session and an element of a connection state of the second secure connection; and

the browser based session is employed to generate a file access request for the file which identifies the file by a resource locator.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded May 18, 2023
From: PARALLELS IP HOLDINGS GMBH; PARALLELS INTERNATIONAL GMBH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 063683/0575 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2023
From: PETRUKHIN, ALEXEY; NIKOLAENKO, GRIGORY; DOBROVOLSKIY, NIKOLAY; BELOUSSOV, SERGUEI
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 063655/0292 →
Continuity (3)
Continuation 17459122 · Aug 27, 2021
Continuation 16458912 · Jul 1, 2019
Continuation 15056435 · Feb 29, 2016