IP Library Granted Patent US 12,200,080
Granted Patent B2
US 12,200,080 · App. 17/719,787 · Granted Jan 14, 2025

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Inventors: Vincent E. Parla (North Hampton, NH); Kyle Andrew Donald Mestery (Woodbury, MN)
Assignee: Cisco Technology, Inc.
H04L67/561H04L12/4633H04L12/4641H04L45/42H04L45/66H04L61/103H04L61/4511H04L63/0236H04L63/0281H04L63/029H04L63/0435H04L67/02H04L67/101H04L67/1012H04L67/141H04L67/562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,080
App. No.
17/719,787
Granted
Jan 14, 2025
Kind
B2
Abstract

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise/private application resource executing on an application node and hosted in an enterprise/application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.

Claims (74)

1. A method comprising:

receiving, at one or more nodes executing a multiplexed application substrate over QUIC encryption (MASQUE) proxy service and from a client device, a hypertext transfer protocol (HTTP) request;

identifying, by the MASQUE proxy service, an endpoint identifier in a header field of the HTTP request;

sending, by the MASQUE proxy service and to a domain name service (DNS) server, a DNS resolution request including the endpoint identifier;

receiving, by the MASQUE proxy service and from the DNS server, an address associated with an application node associated with an enterprise network that is remote from the client device; and

establishing, at least partly by the MASQUE proxy service, a tunneled connection between the one or more nodes and the application node, wherein the tunneled connection is configured to transmit a data stream between the client device and the application node.

2. The method of claim 1 , wherein:

the MASQUE proxy service is a first MASAQUE proxy service executing on a first node of the one or more nodes, the first node being deployed at a first network edge of an enterprise network; and

the one or more nodes include a second node executing a second MASQUE proxy service, the second node being deployed at a second network edge of a cloud computing network, the cloud computing network being remote from the enterprise network.

3. The method of claim 2 , wherein the tunneled connection comprises:

a first tunneled connection communicatively coupling the first node and the second node;

a second tunneled connection communicatively coupling the first node and the application node; and

a third tunneled connection communicatively coupling the second node and the client device.

4. The method of claim 3 , wherein the enterprise network comprises a firewall service configured to apply one or more enterprise firewall rules to the data stream at the first tunneled connection.

5. The method of claim 1 , wherein establishing the tunneled connection is based at least in part on receiving, by the MASQUE proxy service and from an authentication service associated with the enterprise network, an authentication token associated with at least one of the client device or an enterprise account associated with the client device.

6. The method of claim 5 , wherein the HTTP request is a first HTTP request generated by a first application executing on the client device, the endpoint identifier is a first endpoint identifier, the address is a first address, the application node is a first application node, and the method further comprising:

receiving, by the MASQUE proxy service and from a second application executing on the client, a second HTTP request, the second application being different from the first application;

identifying, by the MASQUE proxy service, a second endpoint identifier in the header field of the second HTTP request;

sending, by the MASQUE proxy service and to a domain name service (DNS) server, an additional DNS resolution request including the second endpoint identifier;

receiving, by the MASQUE proxy service and from the DNS server, a second address associated with a second application node;

determining, by the MASQUE proxy service and based at least in part on the second address, that the second application node is associated with the enterprise network; and

establishing, by the MASQUE proxy service and based at least in part on the authentication token, an additional tunneled connection between the client device and the second application node.

7. The method of claim 1 , wherein:

the MASQUE proxy service is executing on a first node of the one or more nodes, the first node being deployed in a cloud computing network; and

the one or more nodes include a second node executing a secure access service edge (SASE) service deployed in the cloud computing network, the SASE service being configured to apply one or more cloud-based security services to the data stream.

8. The method of claim 1 , wherein:

the MASQUE proxy service is executing on a first node of the one or more nodes, the first node being deployed in a cloud computing network; and

the application node is communicatively coupled to the first node via an internet protocol secure (IPSec) connection or a point-to-point virtual private network (VPN) connection.

9. A system comprising:

one or more processors; and

one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, at a multiplexed application substrate over QUIC encryption (MASQUE) proxy service and from a client device, a hypertext transfer protocol (HTTP) request;

identifying, by the MASQUE proxy service, an endpoint identifier in a header field of the HTTP request;

sending, by the MASQUE proxy service and to a domain name service (DNS) server, a DNS resolution request including the endpoint identifier;

receiving, by the MASQUE proxy service and from the DNS server, an address associated with an application node; and

establishing, at least partly by the MASQUE proxy service, a tunneled connection between the MASQUE proxy service and the application node, wherein the tunneled connection is configured to transmit a data stream between the client device and the application node.

10. The system of claim 9 , wherein:

the MASQUE proxy service is a first instance of the MASQUE proxy service executing on a first proxy node of one or more nodes, the first proxy node being deployed at a first network edge of an enterprise network;

the one or more nodes include a second proxy node executing a second instance of the MASQUE proxy service, the second proxy node being deployed at a second network edge of a cloud computing network; and

the application node is associated with the enterprise network.

11. The system of claim 10 , wherein the tunneled connection comprises:

a first tunneled connection communicatively coupling the first proxy node and the second proxy node;

a second tunneled connection communicatively coupling the first proxy node and the application node; and

a third tunneled connection communicatively coupling the second proxy node and the client device.

12. The system of claim 9 , wherein:

the MASQUE proxy service is executing on a first proxy node of one or more nodes, the first proxy node being deployed in a cloud computing network; and

the application node is associated with an enterprise network, the application node being communicatively coupled to the first proxy node via an internet protocol secure (IPSec) connection or a point-to-point virtual private network (VPN) connection.

13. The system of claim 9 , wherein the MASQUE proxy service is executing on a first proxy node of one or more nodes, the first proxy node being deployed in an enterprise network associated with at least one of the DNS server or the application node.

14. The system of claim 9 , wherein:

the MASQUE proxy service is executing on a first proxy node of one or more nodes, the first proxy node being deployed in a cloud computing network; and

the one or more nodes include a second proxy node executing a secure access service edge (SASE) service deployed in the cloud computing network, the SASE service being configured to apply one or more cloud-based security services to the data stream.

15. A method comprising:

receiving, at a multiplexed application substrate over QUIC encryption (MASQUE) proxy service and from a client device, a hypertext transfer protocol (HTTP) request;

identifying, by the MASQUE proxy service, an endpoint identifier in a header field of the HTTP request;

sending, by the MASQUE proxy service and to a domain name service (DNS) server, a DNS resolution request including the endpoint identifier;

receiving, by the MASQUE proxy service and from the DNS server, an address associated with an application node; and

establishing, at least partly by the MASQUE proxy service, a tunneled connection between the MASQUE proxy service and the application node, wherein the tunneled connection is configured to transmit a data stream between the client device and the application node.

16. The method of claim 15 , wherein the header field of the HTTP request is encrypted using a hybrid public key encryption (HPKE) as an encrypted header field, and the method further comprising:

decrypting, by the MASQUE proxy service, the encrypted header field; and

wherein identifying the endpoint identifier is based at least in part on decrypting the encrypted header field.

17. The method of claim 16 , wherein:

the MASQUE proxy service is a first instance of the MASQUE proxy service executing on a first proxy node of one or more nodes, the first proxy node being deployed at a first network edge of an enterprise network;

the one or more nodes include a second proxy node executing a second instance of the MASQUE proxy service, the second proxy node being deployed at a second network edge of a cloud computing network; and

the encrypted header field is inaccessible by the second instance of the MASQUE proxy service.

18. The method of claim 15 , wherein:

the application node is deployed in an enterprise network; and

establishing the tunneled connection is based at least in part on receiving, by the MASQUE proxy service and from an authentication service associated with the enterprise network, an authentication token associated with at least one of the client device or an enterprise account associated with the client device.

19. The method of claim 15 , wherein the HTTP request is generated by at least one of:

an operating system executing on the client device;

a thick application executing on the client device;

a thin application executing on the client device;

a virtual private network (VPN) client executing on the client device; or

a web browser executing on the client device.

20. The method of claim 15 , wherein the application node is configured as an enterprise application deployed in an enterprise network or a software as a service (SaaS) application associated with the enterprise network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2022
From: PARLA, VINCENT E.; MESTERY, KYLE ANDREW DONALD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059586/0481 →
Continuity (5)
Provisional Application 63273306 · Oct 29, 2021
Provisional Application 63272985 · Oct 28, 2021
Provisional Application 63271437 · Oct 25, 2021
Provisional Application 63244599 · Sep 15, 2021
Related Publication 20230079444A1 · Mar 16, 2023
References Cited (61)
US 9923961B2 · Hentunen · 2018 [cited by applicant]
US 11516185B2 · Scali · 2022 [cited by applicant]
US 11563772B2 · Doron et al. · 2023 [cited by applicant]
US 11785523B1 · Di Dio · 2023 [cited by examiner]
US 20060193335A1 · Nanji · 2006 [cited by applicant]
US 20100077064A1 · Viger et al. · 2010 [cited by applicant]
US 20130014206A1 · Rao et al. · 2013 [cited by applicant]
US 20150365412A1 · Innes et al. · 2015 [cited by applicant]
US 20170104851A1 · Arangasamy et al. · 2017 [cited by applicant]
US 20170353386A1 · Wang et al. · 2017 [cited by applicant]
US 20180183794A1 · Desai et al. · 2018 [cited by applicant]
US 20180375967A1 · Pithawala et al. · 2018 [cited by applicant]
US 20190199835A1 · Deval et al. · 2019 [cited by applicant]
US 20190268305A1 · Xu et al. · 2019 [cited by applicant]
US 20190268797A1 · Pang et al. · 2019 [cited by applicant]
US 20190319873A1 · Shelar et al. · 2019 [cited by applicant]
US 20190386961A1 · Kupisiewicz et al. · 2019 [cited by applicant]
US 20200067634A1 · Medard et al. · 2020 [cited by applicant]
US 20200120015A1 · Boucadair et al. · 2020 [cited by applicant]
US 20200120555A1 · Patil et al. · 2020 [cited by applicant]
US 20210045186A1 · Fu et al. · 2021 [cited by applicant]
US 20210250333A1 · Negrea et al. · 2021 [cited by applicant]
US 20210312366A1 · Dhanabalan · 2021 [cited by applicant]
US 20220116327A1 · Salkintzis · 2022 [cited by applicant]
US 20220174044A1 · Konda · 2022 [cited by applicant]
US 20220386166A1 · Sarker et al. · 2022 [cited by applicant]
US 20220407799A1 · Amend · 2022 [cited by applicant]
US 20230074934A1 · Li et al. · 2023 [cited by applicant]
US 20230081782A1 · Parla · 2023 [cited by applicant]
US 20230083582A1 · Paria · 2023 [cited by applicant]
US 20230085513A1 · Mestery · 2023 [cited by applicant]
CN 111885093A · 2020 [cited by applicant]
CN 11260095 · 2021 [cited by applicant]
CN 11265374 · 2021 [cited by applicant]
CN 112600953 · 2021 [cited by applicant]
CN 112653740 · 2021 [cited by applicant]
WO WO2014161408A1 · 2014 [cited by applicant]
WO WO2021009553 · 2021 [cited by applicant]
WO WO2021084326A1 · 2021 [cited by applicant]
WO 2021163684 · 2021 [cited by applicant]
WO WO20211636 · 2021 [cited by applicant]
WO WO2021170248A1 · 2021 [cited by applicant]
WO WO2022083897A1 · 2022 [cited by examiner]
WO WO2022194397A1 · 2022 [cited by examiner]
WO WO2023043727A1 · 2023 [cited by applicant]
WO WO2023044174A1 · 2023 [cited by applicant]
Kuhlewind Mirja Mirja [email protected] et al: “Evaluation of QUIC-based Masque proxying”, Proceedings of the 2nd ACM International Workshop on Distributed Machine Learning, ACMPUB27, New York, NY, USA, Dec. 7, 202… [cited by applicant]
The PCT Search Report and Written Opinion mailed Nov. 25, 2022 for PCT application No. PCT/US2022/043336, 16 pages. [cited by applicant]
The PCT Search Report and Written Opinion mailed Feb. 20, 2023 for PCT application No. PCT/US2022/04 7765, 15 pages. [cited by applicant]
Tthe PCT Search Report and Written Opinion mailed Feb. 20, 2023 for PCT application No. PCT/US2022/047826, 17 pages. [cited by applicant]
The PCT Search Report and Written Opinion mailed Jun. 5, 2023 for PCT application No. PCT/US23/17934, 32 pgs. [cited by applicant]
Iyengar, et al, “QUIC: a UDP-Based Mulitplexed and Secure Transport”, Internet Engineering Task Force, May 2021, 95 pgs. [cited by applicant]
Kuehlewind, et al, “Applicability of the QUIC Transport Protocol draft-ietf-quic-applicability-13”, Network Working Group, Internet-Draft, Sep. 2, 2021, 28 pgs. [cited by applicant]
Kuehlewind, et al, “Discovery Mechanism for QUIC-based, Non-transparent Proxy Services draft-Kuehlewind-quic-proxy-discovery-01”, Network Working Group, Internet Draft, Jan. 27, 2020, 12 pgs. [cited by applicant]
Office Action for U.S. Appl. No. 17/719,829, mailed on Jun. 2, 2023, Kyle Andrew Donald Mestery, “QUIC and Anycast Proxy Resiliency”, 15 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/719,867, mailed on Sep. 18, 2023, Vincent E. Parla, “Policy Expressions Using QUIC Connection Identifiers”, 10 pages. [cited by applicant]
Pauly, er al, “QUIC-Aware Proxying Using HTTP draft-pauly-masque-quic-proxy-03”, Masque, Internet draft, Jun. 30, 2023, 20 pgs. [cited by applicant]
Schinazi, et al, “The MASQUE Protocol draft-schinazi-masque-protocol-01”, Network Working Group, Internet-Draft, Mar. 12, 2020. 14 pgs. [cited by applicant]
Sy,et al, “Accelerating QUIC's Connection Establishment on High-Latency Access Networks”, Institute of Electrical and Electronics Engineers, Internet article, Published in: https://ieeexplore.ieee.org/xpl/conhome/895547… [cited by applicant]
Piraux et al. “Tunneling Inernet Protocols Inside QUIC” ; draft-piraux-quic-tunnel-03.txt, Tunneling Internet Protocols Inside QUIC; Draft-Piraux-QUIC-Tunnel-03.TXT; Internet-Draft: QUIC Working Group, Internet Engineer… [cited by applicant]
The PCT Search Report and Written Opinion mailed Feb. 20, 2023 for PCT application No. PCT/US2022/047826, 17 pages. [cited by applicant]