web application wrapper

By introducing a web address encapsulator system in a cloud computing environment and utilizing proxy servers and inline frame technology, the problem of context loss when users access web applications in a multi-tenant architecture is solved, and the integrity of session context and the improvement of user trust are achieved.

CN113966604BActive Publication Date: 2025-09-05MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080043765.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-06-21
Filing Date
2020-05-06
Publication Date
2025-09-05
Estimated Expiration
2040-05-06

AI Technical Summary

Technical Problem

In cloud computing environments, existing technologies are difficult to effectively solve the context loss problem in multi-tenant architectures, especially when using security services, where users cannot maintain the integrity of session context when accessing web applications.

Method used

By introducing a web address encapsulator system, a proxy server is used to convert web addresses into proxy addresses and encapsulate them into the encapsulator domain, and an inline frame is used to load the web page, thereby ensuring that the user maintains the integrity of the session context in the session of the security service.

Benefits of technology

This enables session context preservation when users access web applications in a multi-tenant architecture, enhances user trust, and solves the problem of context loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113966604B_ABST
    Figure CN113966604B_ABST
Patent Text Reader

Abstract

A proxy server is disclosed for retrieving a web address of a web server received from a client. The proxy server may include a reverse proxy server. The web address is converted to a proxy address at the proxy server. The proxy address is encapsulated into an encapsulator field using an encapsulation framework.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released through nominal management effort or interaction with a service provider. Cloud computing allows cloud consumers to access computing resources such as networks, network bandwidth, servers, processing memory, storage devices, applications, virtual machines, and services as a service (SaaS) in an elastic and sometimes non-permanent manner. Cloud computing platforms and infrastructure allow developers to build, deploy, and manage the assets and resources for applications. Cloud computing can include security services that protect resources and assets from attacks. Summary of the Invention

[0002] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0003] A cloud computing environment may include security services such as a cloud access security broker that can enforce policies and record session data between users and web applications. The present disclosure relates to a proxy server that implements a web address encapsulator system to receive web addresses (such as web sites or web applications) from clients to web servers. The proxy server may include a reverse proxy server. The web address is converted to a proxy address at the proxy server. The proxy address is encapsulated into an encapsulator domain using an encapsulation framework. The proxy address may include a proxy domain or suffix domain corresponding to the proxy server or the security service implemented using the proxy server. The encapsulator domain may correspond to a tenant of the security service. In one example, the encapsulation framework includes an inline frame. The client can navigate web addresses relative to the encapsulator domain. For example, the client can navigate to web addresses of various web pages, website files, or web applications relative to the encapsulator domain. The web page can be loaded into or within an inline frame. BRIEF DESCRIPTION OF THE DRAWINGS

[0004] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this disclosure. The accompanying drawings illustrate the embodiments and, together with the description, serve to explain the principles of the embodiments. Other embodiments and many of the expected advantages of the embodiments will be readily understood as they become better understood by reference to the following description. The elements of the drawings are not necessarily to scale relative to each other. Like reference numerals represent corresponding similar parts.

[0005] Figure 1 is a block diagram illustrating examples of computing devices that can be configured in a computer network to provide, for example, a cloud computing environment.

[0006] Figure 2 is a diagram illustrating an example of a cloud computing environment.

[0007] Figure 3 is a diagram illustrating an example web application wrapper system that may be included in Figure 2 in a cloud computing environment.

[0008] Figure 4 It's a picture Figure 3 A block diagram of an example method of a web application wrapper system. DETAILED DESCRIPTION

[0009] In the following description, reference is made to the accompanying drawings which form a part thereof, and in which specific embodiments in which the present invention may be practiced are shown by way of illustration. It should be understood that other embodiments may be utilized and structural or logical changes may be made without departing from the scope of the present invention. Therefore, the following description should not be considered limiting. It should be understood that, unless otherwise specifically noted, the features of the various example embodiments described herein may be combined in part or in whole with each other.

[0010] Figure 1 An exemplary computer system is illustrated that can be employed in an operating environment and used to host or run computer applications included on one or more computer-readable storage media that store computer-executable instructions for controlling a computer system (such as a computing device) to perform processes. The exemplary computer system includes a computing device, such as computing device 100. Computing device 100 can take one or more of a variety of forms. Such forms include tablet computers, personal computers, workstations, servers, handheld devices, consumer electronic devices (such as video game consoles or digital video recorders), etc., and can be a standalone device or configured as part of a computer network.

[0011] In a basic hardware configuration, the computing device 100 typically includes a processor system having one or more processing units (i.e., processors 102) and memory 104. For example, the processing unit may include two or more processing cores on a chip or two or more processor chips. In some examples, the computing device may also have one or more additional processing or special-purpose processors (not shown), such as a graphics processor for general-purpose computing on a graphics processor unit, to perform processing functions offloaded from the processor 102. The memory 104 may be arranged in a hierarchical manner and may include one or more levels of cache. Depending on the configuration and type of the computing device, the memory 104 may be volatile (such as random access memory (RAM)), non-volatile (such as read-only memory (ROM), flash memory, etc.), or some combination of the two.

[0012] Computing device 100 may also have additional features or functionality. For example, computing device 100 may also include additional storage. Such storage may be removable or non-removable and may include magnetic or optical disks, solid-state memory, or flash memory devices, such as removable storage 108 and non-removable storage 110. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any suitable method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Memory 104, removable storage 108, and non-removable storage 110 are all examples of computer storage media. Computer storage media include RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROMs, digital versatile disks (DVDs) or other optical storage devices, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, universal serial bus (USB) flash drives, flash memory cards or other flash memory devices, or any other storage medium that can be used to store the desired information and can be accessed by computing device 100. Therefore, a propagating signal itself does not qualify as a storage medium. Any such computer storage media may be part of computing device 100.

[0013] The computing device 100 typically includes one or more input and / or output connections, such as USB connections, display ports, proprietary connections, and other connections that connect to various devices to provide input and output to the computing device. Input devices 112 may include devices such as a keyboard, a pointing device (e.g., a mouse, a trackpad), a stylus, a voice input device, a touch input device (e.g., a touch screen), etc. Output devices 111 may include devices such as a display, speakers, a printer, etc.

[0014] The computing device 100 typically includes one or more communication connections 114 that allow the computing device 100 to communicate with other computers / applications 115. Example communication connections may include Ethernet interfaces, wireless interfaces, bus interfaces, storage area network interfaces, and proprietary interfaces. The communication connections may be used to couple the computing device 100 to a computer network, which may be categorized based on various characteristics such as topology, connection method, and scale. A network is a collection of computing devices and possibly other devices interconnected by communication channels that facilitate communication and allow sharing of resources and information between the interconnected devices. Examples of computer networks include local area networks, wide area networks, the Internet, or other networks.

[0015] In one example, one or more of the computing devices 100 can be configured as a client device for a user on a network. The client device can be configured to establish a remote connection with a server on the network in a computing environment. The client device can be configured to run an application or software such as an operating system, a web browser, a cloud access agent, a terminal emulator, or a utility.

[0016] In one example, one or more of the computing devices 100 can be configured as servers in a data center to provide distributed computing services, such as cloud computing services. The data center can provide pooled resources, and consumers or tenants can dynamically configure and scale applications on the pooled resources on demand without adding servers or additional networking. The data center can be configured to communicate with local computing devices, such as those used by cloud consumers, including personal computers, mobile devices, embedded systems, or other computing devices. Within the data center, the computing devices 100 can be configured as servers, either as standalone devices or as separate blades in a rack of one or more other server devices. One or more host processors (such as processor 102) and other components including memory 104 and storage 110 on each server run a host operating system that can support multiple virtual machines. A tenant can initially use one virtual machine on a server to run an application. The data center can activate additional virtual machines on the server or other servers as demand increases, and the data center can deactivate virtual machines when demand decreases.

[0017] A data center can be a local, private system that provides services to a single enterprise user, or it can be a publicly (or semi-publicly) accessible distributed system that provides services to multiple, potentially unrelated consumers and tenants, or a combination of both. Furthermore, a data center can be contained within a single geographic location, or it can be distributed across multiple locations around the world and provide redundancy and disaster recovery capabilities. For example, a data center can designate one virtual machine on a server as the primary location for a tenant application, and can activate another virtual machine on the same or another server as a secondary or backup in case the first virtual machine or server fails.

[0018] A cloud computing environment is typically implemented in one or more recognized models to run in one or more network-connected data centers. A private cloud deployment model includes infrastructure operated specifically for an organization, whether it is managed internally or by a third party, and whether it is hosted within the organization or at some remote external location. An example of a private cloud includes a self-operated data center. A public cloud deployment model includes infrastructure that is provided to the public or a large portion of the public (such as an industry group) and operated by an organization that provides cloud services. A community cloud is shared by several organizations and supports a specific community of organizations with common concerns (such as jurisdiction, compliance, or security). Deployment models typically include similar cloud architectures, but can include specific features that address specific considerations (such as security in a shared cloud model).

[0019] Cloud computing providers typically offer services for cloud computing environments as a service model, offered as one or more of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and other services, including Software as a Service (SaaS). Cloud computing providers offer their services through subscriptions to tenants or consumers. For example, Software as a Service (SaaS) providers offer software applications as a subscription service, typically accessed through a web browser or other thin client interface, without the consumer loading the application on their local computing device. Infrastructure as a Service (IaaS) providers provide consumers with the ability to configure processing, storage, networking, and other basic computing resources, upon which they can deploy and run software, including operating systems and applications. Consumers typically do not manage the underlying cloud infrastructure, but typically retain control over the computing platform and the applications running on it. Platform as a Service (PaaS) providers provide consumers with the ability to deploy applications they create or acquire onto the cloud infrastructure. These applications are created using programming languages, libraries, services, and tools supported by the provider. In some examples, consumers do not manage or control the underlying cloud infrastructure (including networks, servers, operating systems, or storage), but may control the deployed applications and possible configuration settings of the application hosting environment. In other examples, a provider may offer a combination of infrastructure and platform services to allow consumers to manage or control deployed applications and the underlying cloud infrastructure. A platform-as-a-service provider may include infrastructure (such as servers, storage, and networking) as well as middleware, development tools, business intelligence services, database management services, and the like, and may be configured to support application lifecycle functions, including one or more of building, testing, deploying, managing, and updating.

[0020] Figure 2An example of a computer network 200 in such a cloud computing environment is illustrated, which is used to host dynamic web pages (which may include web applications 202) on a web server for access by users on client devices 206. In the illustrated example, network 200 includes a security service 208, which may include a security broker such as a cloud access security broker, and is configured to handle network traffic between client devices 206 and web applications 204. Web applications 204 are software applications running on remote servers. In many cases, a web browser on client device 206 is used to access and implement web applications 204 via network 200 (such as the Internet).

[0021] In one example, web application 204 can be configured as a Software as a Service application, or SaaS. SaaS is a software model in which software is licensed on a subscription basis and centrally hosted. SaaS is typically accessed by users using a thin client (e.g., via a web browser application on a computing device such as computing device 100). SaaS has become a common delivery model for many business applications. SaaS applications are also known as web-based software, on-demand software, and hosted software. Many SaaS applications are based on a multi-tenant architecture, in which a single version of the application (with a single configuration, such as hardware, network, and operating system) is used by all consumers, or tenants. To support scalability, applications are installed on multiple machines or scaled horizontally within an environment such as one or more data centers. This contrasts with more traditional application architectures, in which multiple physical copies of the software (possibly including different versions or configurations) are installed across various consumer sites (such as different computing devices within an enterprise). Some SaaS applications do not use multi-tenancy, or may use other mechanisms (such as virtualization) to cost-effectively manage a large number of consumers instead of multi-tenancy. With the standardization of web technologies (such as HTML, JavaScript, and CSS) and the introduction and popularization of web application frameworks, SaaS applications have become popular, gradually reducing the cost of developing SaaS solutions.

[0022] In some examples, SaaS applications may involve accessing or integrating data currently held by the consumer, and where such data is large or sensitive, integrating the data with remotely hosted software may be costly or risky, or may conflict with data governance regulations.

[0023] A security service 208 (such as a cloud access security broker) provides services between a user of a client device 206 and a web application 204. In one example, the security service 208 can support multiple users of an enterprise (such as users of the client device 206) accessing multiple SaaS applications (such as the web application 204) that are subscribed to or otherwise accessed by the enterprise. In some examples, the security service 208 can be deployed locally or accessed via a cloud service. In one example, the security service 208 can support multiple enterprises accessing one or more collections of SaaS applications in a multi-tenant model. The security service 208 can monitor activity between users of the client device 206 and the web application 204 and enforce security policies. For example, the cloud access security broker can monitor user activity, alert administrators to potentially dangerous behavior, enforce security policy compliance, and automatically prevent or reduce the likelihood of malware in the enterprise.

[0024] In one example, security service 208 is a distributed, cloud-based proxy that acts as an inline intermediary between user and application activity. For active applications, the security service binds itself to web application 204 through configuration changes within the application, and requests made to the application by the user of client device 206 are directed to the proxy for control and management. Security service 208 can apply authentication information within the architecture to track the identity of the user of client device 206 and the web application 204 being accessed. For example, security service 208 can operate as a reverse proxy at the authentication or traffic level to create redirects from web application 204. The user of client device 206 is directed to web application 204 via security service 208, rather than directly between the user of client device 206 and web application 204. User requests and web application responses traverse security service 208 during a session. For example, after the user of client device 206 authenticates to an active web application 204 served by security service 208, the security service can replace the web link to web application 204 with the domain of security service 208 to keep the user in session. Security service 208 can attach the security domain link to the link of network application, to keep the relevant link, cookie and script in session.In one example, security service 208 can save session activity in the log and execute the policy of session.

[0025] Figure 3A web address encapsulator system 300 is illustrated. In one example, the web address encapsulator system 300 can be incorporated into the security service 208. In another example, the encapsulator system 300 can be a standalone system hosted independently of the security service 208. The encapsulator system 300 can include a computer-readable storage device to store computer-executable instructions to control a processor, such as a server in a data center. In one example, the encapsulator system 300 can be implemented as a computer program to run on a processor as part of a proxy server, such as a reverse proxy server, to direct traffic between a client 302 and a web application server 304, for example, in the security service 208. For example, the encapsulator system 300 can direct traffic related to a web application running on the client 302 and the web server 304.

[0026] In this example, a web application server 304 hosts a web address that references a web resource that specifies the location of a web page on a computer network, such as computer network 200. In one example, the web address https: / / www.myapp.com / page / from / myapp indicates a protocol (HTTPS or Hypertext Transfer Protocol Secure), a host name (www.myapp.com), and a file path (page / from / myapp). The web address can conform to the syntax of a general universal resource indicator. Client 302 can include a web browser that can receive the web address and communicate with web server 304 that hosts the web page corresponding to the web address. Web server 304 can load the web page corresponding to the web address into the browser at client 302. In one example, the web page can be part of a website that has a set of pages that are indexed by a file path and included as part of a web application, such as an asynchronous web application. In one example, the web application can send and retrieve data asynchronously between client 302 and web server 304, and generally does not interfere with the display and behavior of the page in the web browser of client 302.

[0027] The security service 208 acts as a reverse proxy server, receiving a web address for a corresponding web server from a client, appended with some proxy suffix (such as "us.cas.ms"), and forwarding it to the originally specified address. For example, a security service provided by Microsoft Corporation of Redmond, Washington under the trade name Microsoft Cloud Access Security can convert a web address with a domain including www.myapp.com to a proxy address with the suffix domain www.myapp.com.us.cas.ms. In this example, the web address is appended with the domain of the security service 208, or a suffix domain, such as us.cas.ms, to form a proxy address or suffix domain address. The domain of the security service 208 keeps users of the security service within a session (such as a proxy server) that directs the user through the security service 208, rather than directly to the web server 304. The relevant web addresses, JavaScript, and cookies within the web application 204 are replaced by the proxy address.

[0028] The wrapper system 300 wraps the proxy address into a wrapper domain with a wrapper frame. In an example where a user may be included as part of a tenant of the security service 208, where the tenant has a brand name or domain name of "Contoso", a proxy address of www.myapp.com.us.cas.ms may be provided with a wrapper domain address of www.myapp.contoso.com, which may be visible in the user's browser when the user navigates the website or web application. In one example, the reverse-proxied web address is wrapped in another inline frame. For example, the system 300 wraps a suffixed web application within a wrapper frame (such as an inline frame or inner frame). A user of the web application will navigate to a page relative to the wrapper domain. The wrapper frame will translate the web address relative to the suffixed domain and load it into the inline frame.

[0029] The use of brand names or tenant domain names in the packaging framework can give users increased confidence that the security service 208 is operational. Additionally, the wrapper system can solve the context loss problem, and the context loss problem can be reflected in architectures where web applications are accessed via a proxy server. In one example of the context loss problem, a path such as www.myapp.com / targetdocument is typically stored as a cookie for the target web application. When the suffix proxy solution is applied to access the target web application in a session, the context of the target document cannot usually be recovered without the cooperation of the target web application, which makes the suffix proxy solution difficult to use with many web applications. The wrapper system 300 solves the context loss problem because users browse web applications with the help of collaborative endpoints, thereby changing the way web applications are accessed.

[0030] The wrapper system 300 determines the appropriate wrapper domain to apply to the proxy address, which can be based on the subscription to the security service 208. In one example, the security service 208 can provide services for many tenants, each tenant having a set of users, and each tenant can be served by the same domain of the proxy service (such as us.cas.ms) to form the proxy address. The security service can apply a single domain of the proxy service. However, each tenant can include a corresponding wrapper domain, and the security service can apply the wrapper domain corresponding to the tenant.

[0031] In one example, the encapsulation frame includes an inline frame or inner frame ( <iframe>) that allows an HTML (HyperText Markup Language) document to be embedded within another HTML document. In one example, the proxy address is encapsulated within an inline frame. The user will navigate to a web application page associated with the wrapper domain. In the example provided for illustration, the web address of www.myapp.com / page / from / myapp will be displayed in the browser as www.myapp.contoso.com / #page / from / myapp. The encapsulation framework will transform the web address relative to the domain with the suffix www.myapp.com.us.cas.ms / page / from / myapp and load it inside the iframe. Other examples are envisioned. When the user navigates to other pages within a website or web application, the wrapper domain address stays in sync with the encapsulated suffix address or proxy address, and the encapsulated proxy address stays in sync with the wrapper domain address.

[0032] Figure 4 illustrates an example method 400 that can be used by a proxy server implementing the web wrapper system 300. At 402, the proxy server receives the web address of the web server 304 from the client 302 and transforms the web address into a proxy address. At 404, the proxy server encapsulates the proxy address into a wrapper domain with an encapsulation framework. In one example, the proxy address can provide a proxy domain or suffix domain corresponding to the proxy server or the security service 208 implemented through the proxy server. In one example, the wrapper domain can correspond to a tenant of the security service, and the security service can implement multiple different wrapper domains. In one example, the encapsulation framework includes an inline frame. The client can navigate the web address relative to the wrapper domain. For example, the client can navigate to the web addresses of various web pages or files of a website or web application relative to the wrapper domain. The web page can be loaded into or within the inline frame.

[0033] The example system 300 and method 400 can be implemented as a combination of one or more hardware devices and a computer program for controlling the system (such as a computing system having a processor and a memory) to execute the method 400. For example, the system 300 and method 400 can be implemented as a computer-readable medium or computer-readable storage device having an executable instruction set for controlling the processor to execute the method 400.System 300 and method 400 can be included as a service in a cloud environment, such as a security service that implements a cloud access security broker to enforce security policies, and implemented as a proxy server, such as a reverse proxy server, on a computing device 100 in a data center to direct web traffic between a client 302 and a web server 304. Although specific embodiment is illustrated and described herein , it will be understood by those skilled in the art that various alternative and / or equivalent implementations may be used to replace the specific embodiment shown and described without departing from the scope of the invention. The application is intended to encompass any modification or variation of the specific embodiment discussed herein.< / iframe>

Claims

1. A method for encapsulating a web address, wherein a proxy server receives the web address from a client, the web address corresponding to a web page hosted by a web server, the method comprising: At the proxy server, converting the web address into a proxy address, wherein the proxy address is used to access the web page via the proxy server; as well as The proxy address is encapsulated into a wrapper domain corresponding to a tenant of the proxy server using an encapsulation framework, and the encapsulated proxy address is used to navigate to the web address relative to the wrapper domain. The method according to claim 1 , wherein the proxy server is a reverse proxy server.

3. The method of claim 1, wherein the proxy server directs traffic between the client and the web server. The method of claim 1 , wherein the proxy address is an address of a secure service. The method of claim 4 , wherein the wrapper domain corresponds to a tenant of the security service. The method of claim 1 , wherein the web address corresponds to a web application.

7. The method of claim 1, wherein the client navigates the web address relative to the wrapper domain.

8. The method of claim 7, wherein the encapsulation framework translates the proxy address relative to the encapsulator domain of a suffix domain.

9. The method of claim 8, wherein the encapsulator field is synchronized with the suffix field.

10. The method of claim 1, wherein the wrapper domain is loaded as a web page in an iframe.

11. A computer-readable storage device storing computer-executable instructions for controlling a processor to: converting, at the proxy server, a web address received from the client into a proxy address, the web address corresponding to a web page hosted by the web server, the proxy address being used to access the web page via the proxy server; and The proxy address is encapsulated into a wrapper domain corresponding to a tenant of the proxy server using an encapsulation framework, and the encapsulated proxy address is used to navigate to the web address relative to the wrapper domain.

12. The computer-readable storage device of claim 11, wherein the instructions to encapsulate the proxy address with an encapsulation frame comprise an inline frame.

13. The computer-readable storage device of claim 12, wherein the instructions for encapsulating the proxy address include loading the web address into an iframe.

14. The computer-readable storage device of claim 11, comprising instructions for navigating the web address relative to the wrapper domain.

15. A web address encapsulator system, comprising: a memory device for storing a set of instructions; as well as A processor configured to execute the set of instructions to: converting, at the proxy server, a web address received from the client into a proxy address, the web address corresponding to a web page hosted by the web server, the proxy address being used to access the web page via the proxy server; as well as The proxy address is encapsulated into a wrapper domain corresponding to a tenant of the proxy server using an encapsulation framework, and the encapsulated proxy address is used to navigate to the web address relative to the wrapper domain.

16. The system of claim 15, wherein the instructions are implemented using a security service. The system of claim 16 , wherein the security service is a cloud access security broker.

18. The system of claim 17, wherein the cloud access security brokers security policies.

19. The system of claim 16, wherein the security service logs accesses of the web server.

20. The system of claim 15, wherein the proxy server is a reverse proxy server for directing web traffic between the client and the web server.

Citation Information

Patent Citations

  • A cloud suffix proxy and methods thereof

    CN105793826A