IP Library Granted Patent US 7,343,398
Granted Patent B1
US 7,343,398 · App. 10/234,661 · Granted Mar 11, 2008

Methods, apparatuses and systems for transparently intermediating network traffic over connection-based authentication protocols

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,343,398
App. No.
10/234,661
Granted
Mar 11, 2008
Kind
B1
Abstract

Methods, apparatuses and systems allowing for the transparent intermediation of network traffic over connection-based authentication protocols. In one embodiment, the present invention allows a proxy to be placed into an NTLM or HTLMv2 environment and have it transparently ensure that NTLM transactions are handled appropriately, such that the proxy can interact (optimize/accelerate) with the authenticated content without breaking the authentication scheme. Embodiments of the present invention provide a proxy solution that is easily deployed and transparently fits into an existing NTLM environment.

Claims (24)

1. A method allowing for transparent intermediation of data flows over connection-based authentication schemes, comprising

maintaining, at a proxy server, at least one non-exclusive persistent connection to at least one origin server;

establishing, at the proxy server, client connections with respective client devices responsive to receipt of corresponding client requests, wherein the client requests designate respective origin servers;

if the client request includes an element associated with a connection-based authentication handshake for a transaction between the client and the origin server;

for each received client request that includes an element associated with a connection-based authentication handshake for a transaction between the client and the origin server, establishing an exclusive server connection between the proxy server and the origin server, wherein the exclusive server connection is exclusively for the transaction, associated with the connection-based authentication handshake, between the client and the origin server, and is not used for any other transactions, and forwarding the client requests request to the origin server over the respective exclusive server connections;

else, multiplexing received client requests to the origin server over a selected one of the at least one non-exclusive persistent connection to the origin server, if the client requests do not include an authentication element.

2. The method of claim 1 wherein the at least one non-exclusive connection is a persistent HTTP connection.

3. The method of claim 1 wherein the exclusive server connection is a persistent connection.

4. The method of claim 1 wherein the exclusive server connection is a persistent HTTP connection.

5. The method of claim 1 further comprising closing the exclusive server connection when the client connection is closed.

6. The method of claim 1 wherein the connection-based authentication scheme is NTLM.

7. The method of claim 6 wherein the element comprises an element associated with an NTLM authentication handshake.

8. The method of claim 7 wherein the element comprises an NTLM header.

9. The method of claim 8 wherein the NTLM header comprises a NLTM authorization message.

10. The method of claim 1 further comprising

forwarding subsequent client requests received over the client connection to the origin server over the exclusive server connection.

11. The method of claim 5 further comprising

forwarding subsequent client requests received over the client connection to the origin server over the exclusive server connection.

12. The method of claim 1 further comprising

receiving a response to the client request from the origin server over the exclusive server connection; and

forwarding the response to the client over the client connection.

13. The method of claim 12 further comprising

detecting at least one attribute associated with the client device;

optimizing the response receive from the origin server based on the at least one attribute.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2011
From: PACKETEER, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027307/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2002
From: LOWNSBROUGH, DEREK LEIGH
To: PACKETEER, INC.
Reel/Frame 013267/0780 →