IP Library Granted Patent US 12,261,833
Granted Patent B2
US 12,261,833 · App. 18/047,878 · Granted Mar 25, 2025

System and method for safely relaying and filtering Kerberos authentication and authorization requests across network boundaries

Inventors: David Forrest McNeely (San Jose, CA); Peter Gerardus Jansen (Goirle, NL); Clifford Van Slimming (Almere, NL); Bob Janssen (Bonaire CN, NL)
Assignee: DELINEA INC.
H04L63/0807H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,833
App. No.
18/047,878
Granted
Mar 25, 2025
Kind
B2
Abstract

A system and method for providing secure access to an organization's internal resources by an application running on an external network. An agent accepts queries from the application which are passed to a relay with a dynamic filter. The relay establishes a secure connection with a connector through the organization's firewall and passes requests from the application to an authentication service running on the internal network to confirm that a user of the application is authorized and issue an authentication ticket which is returned to the application. The application then sends a request to access a specific internal resource based on the authentication ticket, which is passed to a ticket granting service running on the internal network, to verify that said user is authorized to access the specific internal resource, and, if so, issue a service ticket to grant access the application for that resource.

Claims (13)

1. A system for providing secure access to an organization's internal server resources on an internal network by an application running on an external network comprising:

an agent configured to accept queries from the application running on said external network and pass said queries to a relay with a dynamic filter running on said external network;

said relay configured to i) establish a secure connection with a local connector through a firewall to protect said organization's internal server resources running on said internal network, and ii) pass requests from said application via said agent to a cloud authentication service running on said external network, said cloud authentication service to confirm that a user of said application is authorized to access said internal network and if authorized, issue an authentication ticket,

a cloud connector running on said external network configured to receive said issued authentication ticket and pass said issued authentication ticket via said relay for receipt by said application via said agent;

said relay further configured to receive from said application via said agent a request to access a specific internal server resource based on said issued authentication ticket, and pass said request through said secure connection to said connector if said user is authenticated, said connector further configured to pass said request to a ticket granting service running on said internal network, said ticket granting service to verify that said user is authorized to access the specific internal server, and if authorized to issue a service ticket provided to said connector to pass said service ticket via said relay and said agent to said application, wherein said application, based on said service ticket, is granted access to said specific internal server.

2. The system defined by claim 1 wherein said ticket granting service verifies that said user is authorized to access the specific internal server by checking a database on said internal network to check if said user exists in said database and is allowed access to the local resource, or said request received by said ticket granting service originates from a trusted realm.

3. The system defined by claim 1 wherein said dynamic filter uses rules wherein at least a username of said user and a realm from which said queries originate are checked.

4. The system defined by claim 1 wherein said relay routes to said connector based on a realm from which said queries originate.

5. A method for providing secure access to an organization's internal server resources on an internal network by an application running on an external network comprising:

accepting by an agent queries from the application running on said external network and passing said queries to a relay with a dynamic filter running on said external network;

establishing by said relay a secure connection with a local connector through a firewall to protect said organization's internal server resources running on said internal network, and ii) passing requests from said application via said agent to a cloud authentication service running on said external network;

confirming by said cloud authentication service that a user of said application is authorized to access said internal network and if authorized, issuing an authentication ticket, receiving by a cloud connector running on said external network said issued authentication ticket and passing said issued authentication ticket via said relay for receipt by said application via said agent;

said relay further receiving from said application via said agent a request to access a specific internal server resource based on said issued authentication ticket, and passing said request through said secure connection to said connector if said user is authenticated, said connector passing said request to a ticket granting service running on said internal network, verifying by said ticket granting service that said user is authorized to access the specific internal server, and if authorized issuing a service ticket provided to said connector to pass said service ticket via said relay and said agent to said application, granting access by said application based on said service ticket to said specific internal server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: MCNEELY, DAVID FORREST; JANSEN, PETER GERARDUS; VAN SLIMMING, CLIFFORD; JANSSEN, BOB
To: DELINEA INC.
Reel/Frame 065144/0640 →
Continuity (2)
Related Publication 20240137355A1 · Apr 25, 2024
Related Publication 20240236069A9 · Jul 11, 2024
References Cited (16)
US 8510818B2 · Garg et al. · 2013 [cited by applicant]
US 9450944B1 · Sousley et al. · 2016 [cited by applicant]
US 11394710B1 · Royal et al. · 2022 [cited by applicant]
US 20050108575A1 · Yung · 2005 [cited by applicant]
US 20160164869A1 · Young · 2016 [cited by examiner]
US 20180159856A1 · Gujarathi · 2018 [cited by examiner]
US 20180219862A1 · Young · 2018 [cited by examiner]
US 20180255021A1 · Pellizzer · 2018 [cited by examiner]
US 20220150703A1 · Raju · 2022 [cited by examiner]
US 20240137355A1 · McNeely · 2024 [cited by examiner]
US 20240236069A9 · McNeely · 2024 [cited by examiner]
WO 2019000092A1 · 2019 [cited by applicant]
Anonymous: “Ivanti Cloud Relay”, The Wayback Machine Retrieved from URL:https://web.archive.org/web/20211208220658/https://help.ivanti.com/res/help/en_US/IWC/2021/Help/Content/10025.htm, Dec. 8, 2021, 1 page. [cited by applicant]
Db Tech: “Restrict Access to Your Cloudflare Tunnel Applications”, Retrieved from the Internet URL: https://www.youtube.com/watch?v=65FdHRs0axE, XP093099345 , Oct. 18, 2022, 2 pages. [cited by applicant]
European Search Report and Search Opinion received for EP Application No. 23204486.7, mailed on Nov. 30, 2023, 19 pages. [cited by applicant]
Fulvio, R., et al., “MIT Kerberos Consortium—Protocol Tutorial”, Retrieved from the Internet: URL:http://www.kerberos.org/software/tutorial.html, XP055338186, Nov. 27, 2007, 10 pages. [cited by applicant]