ES2609457T3 - Procedimiento de acceso inverso para proteger aplicaciones de entrada y otras - Google Patents

Procedimiento de acceso inverso para proteger aplicaciones de entrada y otras Download PDF

Info

Publication number
ES2609457T3
ES2609457T3 ES13749686.5T ES13749686T ES2609457T3 ES 2609457 T3 ES2609457 T3 ES 2609457T3 ES 13749686 T ES13749686 T ES 13749686T ES 2609457 T3 ES2609457 T3 ES 2609457T3
Authority
ES
Spain
Prior art keywords
dmz
server
lan
connection
service
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
ES13749686.5T
Other languages
English (en)
Inventor
Amir Mizhar
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=46467095&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=ES2609457(T3) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by Individual filed Critical Individual
Application granted granted Critical
Publication of ES2609457T3 publication Critical patent/ES2609457T3/es
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0209Architectural arrangements, e.g. perimeter networks or demilitarized zones
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/029Firewall traversal, e.g. tunnelling or, creating pinholes

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)

Abstract

Un sistema que proporciona una conexión segura entre servidores de la LAN y clientes de la WAN que comprende: LAN y DMZ; en el que la LAN incluye el servicio, el servidor LAN y el controlador LAN; en el que la DMZ incluye el servidor DMZ y el servicio del colectivo de pilas DMZ; en el que, cuando una solicitud de cliente llega al servidor DMZ, este almacena la solicitud del cliente en el servicio del colectivo de pilas DMZ; en el que el controlador LAN establece una conexión saliente basada en TCP con el servicio del colectivo de pilas DMZ; en el que el servicio del colectivo de pilas DMZ pasa a continuación la información de conexión del cliente al servidor LAN por medio del controlador LAN; en el que el servidor LAN genera entonces dos conexiones TCP/IP: una conexión es con el servicio y la segunda es con una conexión saliente al servidor DMZ y que crea un enlace de conexión en el servidor LAN entre el servicio y la conexión saliente; en el que el servidor DMZ crea a continuación un enlace de conexión en el servidor DMZ entre la solicitud entrante de cliente y la conexión saliente procedente del servidor LAN; completando con ello la ruta de la solicitud del cliente; y por lo que, una vez que el enlace de conexión en el servidor DMZ enlaza la solicitud del cliente y la conexión saliente procedente del servidor LAN, la solicitud del cliente es finalmente difundida a través del servidor DMZ y el servidor LAN por el sistema, y a continuación los datos de la solicitud del cliente son difundidos desde el servicio al cliente.

Description

imagen1
imagen2

Claims (1)

  1. imagen1
ES13749686.5T 2012-02-19 2013-02-13 Procedimiento de acceso inverso para proteger aplicaciones de entrada y otras Active ES2609457T3 (es)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
IL21818512 2012-02-19
IL218185A IL218185B (en) 2012-02-19 2012-02-19 Reverse access system for securing front-end applications
PCT/IL2013/000017 WO2013121410A1 (en) 2012-02-19 2013-02-13 Reveres access method for securing front-end applications and others

Publications (1)

Publication Number Publication Date
ES2609457T3 true ES2609457T3 (es) 2017-04-20

Family

ID=46467095

Family Applications (1)

Application Number Title Priority Date Filing Date
ES13749686.5T Active ES2609457T3 (es) 2012-02-19 2013-02-13 Procedimiento de acceso inverso para proteger aplicaciones de entrada y otras

Country Status (6)

Country Link
US (4) US9935958B2 (es)
EP (1) EP2815554B1 (es)
CN (1) CN104412558B (es)
ES (1) ES2609457T3 (es)
IL (1) IL218185B (es)
WO (1) WO2013121410A1 (es)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8560604B2 (en) 2009-10-08 2013-10-15 Hola Networks Ltd. System and method for providing faster and more efficient data communication
US9241044B2 (en) 2013-08-28 2016-01-19 Hola Networks, Ltd. System and method for improving internet communication by using intermediate nodes
US11023846B2 (en) 2015-04-24 2021-06-01 United Parcel Service Of America, Inc. Location-based pick up and delivery services
US11057446B2 (en) 2015-05-14 2021-07-06 Bright Data Ltd. System and method for streaming content from multiple servers
LT3767494T (lt) 2017-08-28 2023-03-10 Bright Data Ltd. Būdas pagerinti turinio parsisiuntimą, pasirenkant tunelinius įrenginius
EP3780557B1 (en) 2019-02-25 2023-02-15 Bright Data Ltd. System and method for url fetching retry mechanism
EP4383686A1 (en) 2019-04-02 2024-06-12 Bright Data Ltd. System and method for managing non-direct url fetching service
US11190489B2 (en) 2019-06-04 2021-11-30 OPSWAT, Inc. Methods and systems for establishing a connection between a first device and a second device across a software-defined perimeter
CN113141402B (zh) * 2021-04-20 2022-11-29 中国建设银行股份有限公司 一种食堂自动化用户同步方法和装置
EP4377817A4 (en) 2021-07-26 2025-05-28 Bright Data Ltd. Emulating web browser in a dedicated intermediary box
EP4418625B1 (en) 2023-02-20 2025-03-26 Barclays Execution Services Limited Message routing system

Family Cites Families (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4639275A (en) 1982-04-22 1987-01-27 The Board Of Trustees Of The University Of Illinois Forming disordered layer by controlled diffusion in heterojunction III-V semiconductor
US4843033A (en) 1985-09-27 1989-06-27 Texas Instruments Incorporated Method for outdiffusion of zinc into III-V substrates using zinc tungsten silicide as dopant source
US4824798A (en) 1987-11-05 1989-04-25 Xerox Corporation Method of introducing impurity species into a semiconductor structure from a deposited source
US4927773A (en) 1989-06-05 1990-05-22 Santa Barbara Research Center Method of minimizing implant-related damage to a group II-VI semiconductor material
US9197599B1 (en) 1997-09-26 2015-11-24 Verizon Patent And Licensing Inc. Integrated business system for web based telecommunications management
US20170118214A1 (en) * 2001-12-12 2017-04-27 Pervasive Security Systems, Inc. Method and architecture for providing access to secured data from non-secured clients
US7506058B2 (en) * 2001-12-28 2009-03-17 International Business Machines Corporation Method for transmitting information across firewalls
US20030204602A1 (en) * 2002-04-26 2003-10-30 Hudson Michael D. Mediated multi-source peer content delivery network architecture
US7181493B2 (en) 2003-12-23 2007-02-20 Unisys Corporation Platform independent model-based framework for exchanging information in the justice system
US7444505B2 (en) * 2004-04-22 2008-10-28 At&T Intellectual Property I, L.P. Method, system and software for maintaining network access and security
US20050251855A1 (en) * 2004-05-04 2005-11-10 Hob Gmbh & Co. Kg Client-server-communication system
JP4492248B2 (ja) * 2004-08-04 2010-06-30 富士ゼロックス株式会社 ネットワークシステム、内部サーバ、端末装置、プログラム、およびパケット中継方法
US8701175B2 (en) * 2005-03-01 2014-04-15 Tavve Software Company Methods, devices, systems and computer program products for providing secure communications between managed devices in firewall protected areas and networks segregated therefrom
US8296837B2 (en) * 2005-03-18 2012-10-23 Barclays Capital Inc. VoIP proxy server
GB0508624D0 (en) * 2005-04-28 2005-06-08 Ibm Reverse proxy system and method
CN1921377B (zh) * 2005-08-26 2010-09-15 鸿富锦精密工业(深圳)有限公司 数据同步系统及方法
US20070180512A1 (en) * 2005-10-21 2007-08-02 Hewlett-Packard Development Company, L.P. Methods of setting up and operating a reverse channel across a firewall
US8272045B2 (en) * 2005-12-15 2012-09-18 Barclays Capital Inc. System and method for secure remote desktop access
US8479275B1 (en) * 2006-02-01 2013-07-02 Cisco Technology, Inc. Secure high-throughput data-center network employing routed firewalls
CN101110693A (zh) * 2006-07-17 2008-01-23 上海华虹Nec电子有限公司 一种互联网网站安全架构系统
US8181238B2 (en) * 2007-08-30 2012-05-15 Software Ag Systems and/or methods for streaming reverse HTTP gateway, and network including the same
US20090094691A1 (en) * 2007-10-03 2009-04-09 At&T Services Inc. Intranet client protection service
US8825854B2 (en) * 2008-11-24 2014-09-02 Sap Ag DMZ framework
US8413241B2 (en) * 2009-09-17 2013-04-02 Oracle America, Inc. Integrated intrusion deflection, detection and introspection
US9059962B2 (en) * 2013-03-13 2015-06-16 Route1 Inc. Secure access to applications behind firewall

Also Published As

Publication number Publication date
CN104412558B (zh) 2019-01-29
EP2815554A4 (en) 2015-12-23
US9935958B2 (en) 2018-04-03
EP2815554A1 (en) 2014-12-24
USRE50745E1 (en) 2026-01-06
IL218185A0 (en) 2012-06-28
IL218185B (en) 2018-12-31
USRE50113E1 (en) 2024-09-03
CN104412558A (zh) 2015-03-11
US20180176225A1 (en) 2018-06-21
HK1207766A1 (en) 2016-02-05
US10110606B2 (en) 2018-10-23
WO2013121410A1 (en) 2013-08-22
US20150020161A1 (en) 2015-01-15
EP2815554B1 (en) 2016-10-05

Similar Documents

Publication Publication Date Title
ES2609457T3 (es) Procedimiento de acceso inverso para proteger aplicaciones de entrada y otras
IN2013MU02744A (es)
CL2016001381A1 (es) Redes de entrega de contenidos peer-to-peer, método y administrador
EP3429246A3 (en) Network architecture and security with encrypted client device contexts
US20160057211A1 (en) System and method for secure integration of web and mobile applications on the public internet with enterprise application servers in the public, private or hybrid cloud
CL2018001771A1 (es) Tecnologías de red
AR076351A1 (es) Metodo de funcionamiento de un dispositivo cliente cuando se conecta a una red y su correspondiente sistema y dispositivo
WO2013019708A3 (en) Managing notification messages
AR081944A1 (es) Metodo y aparato para unir la autenticacion del abonado y la autenticacion del dispositivo en sistemas de comunicacion
BR112015030544A2 (pt) sistemas de autenticação eletrônica
TW201642169A (en) Systems and methods for high availability of hardware security modules for cloud-based web services
EP2575297A3 (en) Apparatus and method for providing virtual private network service based on mutual authentication
ES2635556T3 (es) Método seguro para la concesión remota de derechos de funcionamiento
MX2018009569A (es) Proteccion de los dispositivos de red por un cortafuegos.
JP2013513160A5 (es)
BR112014014776A2 (pt) aparelho, sistemas e métodos de descoberta de endereço ip para configuração de link direto canalizado
PE20190832A1 (es) Sistemas y metodos para proporcionar una arquitectura de sistema de notificacion
BR112017014984A2 (pt) técnicas para gerenciar um cliente da rede remoto a partir de um aplicativo em um dispositivo móvel
BR102018014023A8 (pt) Sistema e método de comunicação segura
CL2012000868A1 (es) Un metodo para proporcionar acceso a una cuenta mantenida por una institucion financiera.
WO2014028512A3 (en) Messaging in a hosted private branch exchange
ES2606697T3 (es) Transmisión de un mensaje multimedia duplicado mediante la emisión de un mensaje de texto
AR096079A1 (es) Aparato, sistemas, y métodos para interacciones de red
ES2599072T3 (es) Método y dispositivo de balanceo de carga de un agrupamiento de servidores (granja) para el establecimiento de una comunicación bidireccional de servidor a servidor y programa de ordenador para los mismos
ES2571377T3 (es) Sistema y método para intermediar entre dispositivos de abonado y proveedores de servicio de comunicación