IP Library Granted Patent US 12,289,295
Granted Patent B1
US 12,289,295 · App. 18/420,166 · Granted Apr 29, 2025

Trusted tunnel bridge

Inventors: Jesse Chor (Saratoga, CA); Michael Emery (Scotts Valley, CA)
Assignee: SPLUNK INC.
H04L63/029G06F16/27G06F16/951H04L9/30H04L12/4633H04L63/0442H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,295
App. No.
18/420,166
Granted
Apr 29, 2025
Kind
B1
Abstract

Various embodiments of the present application set forth a computer-implemented method that includes receiving, by a trusted tunnel bridge and from a first application executing in a first network, a first encrypted data packet, where the first encrypted data packet includes an encrypted portion of data, and a destination device identifier (DDI). The method further includes determining, by the trusted tunnel bridge, a particular device in a second network and associated with the DDI included in the first encrypted data packet. The method further includes sending, by the trusted tunnel bridge directly to the particular device, the first encrypted data packet.

Claims (37)

1. A computer-implemented method, comprising:

establishing, by a trusted tunnel bridge, a first authenticated communication channel with a first application executing in a first network, wherein the trusted tunnel bridge is outside of the first network;

receiving, by the trusted tunnel bridge and from the first application via the first authenticated communication channel, a first data packet;

determining, by the trusted tunnel bridge and based on the first data packet, a first device in a second network to which the first data packet should be routed; and

sending, by the trusted tunnel bridge to the first device, the first data packet.

2. The computer-implemented method of claim 1 , wherein sending the first data packet comprises sending the first data packet directly to the first device.

3. The computer-implemented method of claim 1 , wherein the first network is protected by a firewall.

4. The computer-implemented method of claim 1 , further comprising establishing, by the trusted tunnel bridge, a second authenticated communication channel with the first device.

5. The computer-implemented method of claim 1 , further comprising establishing, by the trusted tunnel bridge, a second authenticated communication channel with the first device, wherein sending the first data packet comprises sending the first data packet directly to the first device via the second authenticated communication channel.

6. The computer-implemented method of claim 1 , wherein the first network and the second network comprise different networks.

7. The computer-implemented method of claim 1 , wherein the first network and the second network comprise different networks, and access to the second network by the first device is limited by a firewall protecting the first network.

8. The computer-implemented method of claim 1 , further comprising receiving, by the trusted tunnel bridge, data from the first application that is generated by executing a query of a field-searchable data store via the first application.

9. The computer-implemented method of claim 1 , wherein the first data packet includes at least a portion of a set of events that is generated based on raw machine data that reflects activity in an information technology environment.

10. The computer-implemented method of claim 1 , further comprising:

receiving, by the trusted tunnel bridge from the first device, a request to establish a direct WebSocket connection between the first device and the trusted tunnel bridge; and

establishing the direct WebSocket connection,

wherein sending the first data packet comprises sending the first data packet via the direct WebSocket connection.

11. The computer-implemented method of claim 1 , wherein the trusted tunnel bridge comprises a first instance included in a plurality of instances of a trusted tunnel bridge platform, wherein each instance of the trusted tunnel bridge platform receives a copy of the first data packet.

12. The computer-implemented method of claim 1 , wherein the first application implements at least a portion of a data intake and query system.

13. A non-transitory computer-readable storage medium including instructions that, when executed by a processor, cause the processor to perform the steps of:

establishing, by a trusted tunnel bridge, a first authenticated communication channel with a first application executing in a first network;

receiving, by the trusted tunnel bridge and from the first application via the first authenticated communication channel, a first data packet;

determining, by the trusted tunnel bridge and based on the first data packet, a first device in a second network to which the first data packet should be routed; and

sending, by the trusted tunnel bridge to the first device, the first data packet.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the first network is protected by a firewall.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the steps further comprise establishing, by the trusted tunnel bridge, a second authenticated communication channel with the first device, wherein sending the first data packet comprises sending the first data packet directly to the first device via the second authenticated communication channel.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the first network and the second network comprise different networks, and access to the second network by the first device is limited by a firewall protecting the first network.

17. A computing device, comprising:

a memory that includes an application; and

a processor that is coupled to the memory, and when executing the application, performs:

establishing a first authenticated communication channel with a first application executing in a first network;

receiving, from the first application, a first data packet;

determining a first device in a second network to which the first data packet should be routed; and

sending, to the first device, the first data packet.

18. The computing device of claim 17 , wherein the first network is protected by a firewall.

19. The computing device of claim 17 , wherein the processor further performs establishing, by a trusted tunnel bridge, a second authenticated communication channel with the first device, wherein sending the first data packet comprises sending the first data packet directly to the first device via the second authenticated communication channel.

20. The computing device of claim 17 , wherein the first network and the second network comprise different networks, and access to the second network by the first device is limited by a firewall protecting the first network.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2024
From: EMERY, MICHAEL; CHOR, JESSE
To: SPLUNK INC.
Reel/Frame 068000/0356 →
Continuity (2)
Continuation 17162941 · Jan 29, 2021
Continuation 16051326 · Jul 31, 2018
References Cited (17)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11882099B1 · Chor · 2024 [cited by examiner]
US 20140304505A1 · Dawson · 2014 [cited by applicant]
US 20150009995A1 · Gross, IV et al. · 2015 [cited by applicant]
US 20150096011A1 · Watt · 2015 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]