IP Library › Granted Patent US 12,712,847
Granted Patent B2
US 12,712,847 · App. 18/587,433 · Granted Aug 18, 2026

System and method of secure network management using a reverse proxy server

Inventors: Anish Paranjpe (Bellevue, WA); Seth Girouard Reisinger (Snoqualmie, WA); Roberto Yeriel Guzman-Ortiz (Bellevue, WA); Nirag Tibdewal (Bothell, WA); Vikram Dadwal (Snohomish, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/0236H04L61/4511H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,847
App. No.
18/587,433
Granted
Aug 18, 2026
Kind
B2
Abstract

A method and system for securely routing traffic in a computing environment via a firewall, the method including configuring a reverse proxy server via a first configuration file and configuring a DNS server via a second configuration file, and routing traffic via the reverse proxy server by looking up addresses in the DNS server. The first configuration file includes a plurality of target IP addresses, each of the plurality of target IP addresses referencing a DNS record in the DNS server and the second configuration file includes a plurality of DNS records, where each of the DNS records is initially set to point to a default IP address. When it is determined that there is a change to an IP address of a resource in the computing environment, the DNS record associated with the resource in the DNS server is automatically updated via an API call to the DNS server by replacing the default IP address with the updated IP address for the resource. The reverse proxy servers refers to the updated DNS record to route traffic to the resource.

Claims (43)

1 . A system for securely routing traffic in a computing environment to a resource system, the system comprising:

a reverse proxy server;

a firewall;

Domain Name System (DNS) server;

a processor; and

a memory storing executable instructions that, when executed, cause the processor alone or in combination with other processors to perform operations of:

configuring the reverse proxy server via a first configuration file that includes a plurality of target IP addresses referencing a plurality of DNS records in the DNS server;

configuring the DNS server via a second configuration file that includes the plurality of DNS records previously configured to point to a default IP address;

detecting a change to an IP address of a resource element in the resource system;

upon detecting the change, updating a DNS record associated with the resource element in the DNS server via an Application Programming Interface (API) call to the DNS server, wherein updating the DNS record includes replacing the default IP address in the DNS record with an updated IP address for the resource element;

utilizing, by the reverse proxy server, the DNS record to route the traffic to the firewall; and

routing, by the firewall, the traffic from the reverse proxy server to the resource element, wherein the firewall is statically configured with Network Address Translation (NAT) rules.

2 . The system of claim 1 , wherein the reverse proxy server is a static reverse proxy server.

3 . The system of claim 1 , wherein the DNS server is a private DNS server.

4 . The system of claim 1 , wherein the resource element comprises a virtual machine.

5 . The system of claim 1 , further comprising a network security group (NSG) element coupled to the reverse proxy server that filters the traffic by determining whether a user is allowed access to the resource element.

6 . The system of claim 1 , wherein the plurality of DNS records in the second configuration file are previously configured to point to the default IP address of 0.0.0.0.

7 . The system of claim 1 , wherein when the change to the IP address of the resource element in the computer environment is needed, the DNS record for the resource in the configuration file is updated to point to the updated IP address for the resource element.

8 . The system of claim 1 , wherein the firewall includes a static number of the NAT rules.

9 . The system of claim 8 , wherein when there is the change in the computing environment that requires updating of records, no updates to the NAT rules in the firewall are needed.

10 . The system of claim 1 , wherein when there is the change in the computing environment that requires updating of records, no updates to the reverse proxy server are needed to correctly route the traffic.

11 . A method for securely routing traffic in a computing environment to a resource system, comprising:

configuring a reverse proxy server via a first configuration file that includes a plurality of target IP addresses referencing a plurality of Domain Name System (DNS) records in a DNS server;

configuring the DNS server via a second configuration file that includes the plurality of DNS records previously configured to point to a default IP address;

detecting a change to an IP address of a resource element in the resource system;

upon detecting the change, updating a DNS record associated with the resource element in the DNS server via an Application Programming Interface (API) call to the DNS server, wherein updating the DNS record includes replacing the default IP address in the DNS record with an updated IP address for the resource element;

utilizing, by the reverse proxy server, the DNS record to route the traffic to a firewall; and

routing, by the firewall, the traffic from the reverse proxy server to the resource element, wherein the firewall is statically configured with Network Address Translation (NAT) rules.

12 . The method of claim 11 , wherein the default IP address is 0.0.0.0.

13 . The method of claim 11 , wherein the firewall includes a static number of the NAT rules.

14 . The method of claim 13 , wherein when there is the change in the computing environment that requires updating of records, no updates to the NAT rules in the firewall are needed to correctly route the traffic via the firewall.

15 . The method of claim 11 , wherein when there is the change in the computing environment that requires updating of records, no updates to the reverse proxy server are needed to correctly route the traffic via the firewall.

16 . The method of claim 12 , wherein the resource element is a virtual machine.

17 . A non-transitory computer readable medium on which are stored instructions that when executed cause a programmable device for securely routing traffic in a computing environment to a resource system to perform functions of:

configuring a reverse proxy server via a first configuration file that includes a plurality of target IP addresses referencing a plurality of Domain Name System (DNS) records in a DNS server;

configuring the DNS server via a second configuration file that includes the plurality of DNS records previously configured to point to a default IP address;

detecting a change to an IP address of a resource element in the resource system;

upon detecting the change, updating a DNS record associated with the resource element in the DNS server via an Application Programming Interface (API) call to the DNS server, wherein updating the DNS record includes replacing the default IP address in the DNS record with an updated IP address for the resource element;

utilizing, by the reverse proxy server, the DNS record to route the traffic to a firewall; and

routing, by the firewall, the traffic from the reverse proxy server to the resource element, wherein the firewall is statically configured with Network Address Translation (NAT) rules.

18 . The non-transitory computer readable medium of claim 17 , wherein the firewall includes a static number of Network Address Translation (NAT) rules.

19 . The non-transitory computer readable medium of claim 18 , wherein when there is the change in the computing environment that requires updating of records, no updates to the NAT rules in the firewall are needed to correctly route the traffic via the firewall.

20 . The non-transitory computer readable medium of claim 17 , wherein when there is the change in the computing environment that requires updating of records, no updates to the reverse proxy server are needed to correctly route the traffic via the firewall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2024
From: PARANJPE, ANISH; REISINGER, SETH GIROUARD; GUZMAN-ORTIZ, ROBERTO YERIEL; TIBDEWAL, NIRAG; DADWAL, VIKRAM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 066563/0669 →
Continuity (1)
Related Publication 20250274432A1 · Aug 28, 2025
References Cited (35)
US 11863528B1 · Chung · 2024 [cited by examiner]
US 12212635B2 · Ayyadevara · 2025 [cited by examiner]
US 20020065938A1 · Jungck · 2002 [cited by examiner]
US 20060101026A1 · Fukushima · 2006 [cited by applicant]
US 20110153697A1 · Nickolov · 2011 [cited by examiner]
US 20150058488A1 · Backholm · 2015 [cited by examiner]
US 20150135302A1 · Cohen · 2015 [cited by examiner]
US 20150229629A1 · Ishaya · 2015 [cited by examiner]
US 20150326640A1 · Jellick · 2015 [cited by examiner]
US 20160112375A1 · Cohen · 2016 [cited by examiner]
US 20160261502A1 · Donovan · 2016 [cited by examiner]
US 20170295131A1 · Dyszynski · 2017 [cited by examiner]
US 20180077121A1 · Gordon · 2018 [cited by examiner]
US 20190132280A1 · Meuninck · 2019 [cited by examiner]
US 20190158353A1 · Johnson · 2019 [cited by examiner]
US 20200322374A1 · Holloway · 2020 [cited by applicant]
US 20210250330A1 · Gurney · 2021 [cited by examiner]
US 20220263793A1 · Baker · 2022 [cited by examiner]
US 20220417053A1 · Wright · 2022 [cited by examiner]
US 20230133809A1 · Ayyadevara · 2023 [cited by examiner]
US 20250158989A1 · Howe · 2025 [cited by examiner]
US 20250158990A1 · Howe · 2025 [cited by examiner]
US 20250159022A1 · Howe · 2025 [cited by examiner]
US 20250159023A1 · Howe · 2025 [cited by examiner]
US 20250184221A1 · Marques · 2025 [cited by examiner]
WO 2002039699A1 · 2002 [cited by applicant]
Aung, Si Thu, and Thandar Thein. “Comparative analysis of site-to-site layer 2 virtual private networks.” 2020 IEEE Conference on Computer Applications (ICCA). IEEE, 2020. (Year: 2020). [cited by examiner]
Penaflor Rey, William, and Kieth Wilhelm Jan Dugang Rey. “Designing secure and scalable end-to-end private network connections between sites via overlay tunnels.” Proceedings of the 2022 5th International Conference on … [cited by examiner]
“Create Hardware Firewall”, Retrieved From: https://cloud.ibm.com/netsec/firewalls/single-server/provision#about, Retrieved on Feb. 24, 2021, 3 Pages. [cited by applicant]
“HAProxy as a TCP reverse proxy with DDNS target discovery and load balancing”, Retrieved From: https://blog.jitdor.com/2020/06/17/haproxy-as-a-tcp-reverse-proxy-with-ddns-target-discovery-and-load-balancing/2/#:~:text=… [cited by applicant]
“Quotas and limits”, Retrieved From https://cloud.google.com/vpc/docs/quota#per_network, Retrieved on Feb. 22, 2024, 19 Pages. [cited by applicant]
Assmann, Baptiste, “DNS for Service Discovery in HAProxy”, Retrieved From: https://www.haproxy.com/blog/dns-service-discovery-haproxy, Jun. 14, 2019, 14 Pages. [cited by applicant]
Benomar, et al., “A Cloud-Based and Dynamic DNS Approach to Enable the Web of Things”, IEEE Transactions on Network Science and Engineering, vol. 09, Issue No. 06, Sep. 8, 2021, pp. 3968-3978. [cited by applicant]
Extended European Search Report received for EP Application No. 251590899, mailed on Jul. 10, 2025, 12 pages. [cited by applicant]
Raza, et al., “URL fonNarding for NAT traversal”, 2015 IFIP/IEEE International Symposium on Integrated Network Management (IM), May 2015, pp. 599-605. [cited by applicant]