IP Library Granted Patent US 7,979,528
Granted Patent B2
US 7,979,528 · App. 10/402,752 · Granted Jul 12, 2011

System and method for traversing firewalls, NATs, and proxies with rich media communications and other application protocols

Assignee: Radvision Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,979,528
App. No.
10/402,752
Granted
Jul 12, 2011
Kind
B2
Abstract

A tunneling system and method is described for traversing firewalls, NATs, and proxies. Upon a request from a device on the secure private network or on a public network such as the Internet, a connection to a designated or permitted device of the secure private network by way of the public network can be established, allowing selected devices of the private network to access devices on the public network. A bi-directional channel can be established where information such as rich multimedia and real-time voice and video can be accessed or communicated.

Claims (45)

1. A computer program product for use in conjunction with a computer device, the computer program product comprising a non-transitory computer-readable storage medium and a computer program product mechanism embodied therein that causes the computer device to perform data transfers across a security device interposed between the computer device and a second computer device, the computer program product having:

computer program codes to cause a gatekeeper computer device to monitor requests for data transfer to one or more determinable ports of an endpoint computer device, wherein the monitoring includes detecting whether a network security device is interposed between the gatekeeper computer device and the endpoint computer device;

computer program codes to cause the gatekeeper computer device to create a first data channel to the endpoint computer device in response to the detection of the network security device, wherein data communicated over the first data channel is transmitted using a connection-based protocol;

computer program codes to cause the gatekeeper computer device to, in response to detecting a registration request from the endpoint computer device, substitute private address information associated with the endpoint computer device in the registration request with alternate address information and transmit the alternate address information to the endpoint computer device;

computer program codes to cause the gatekeeper computer device to, in response to detecting a request to participate in a conference, initiate the conference using the alternate address information and instructing the endpoint computer device to create a second data channel to a conference server and provide the conference server with the alternate address information, wherein the computer program codes are further configured, for the data transmitted in the conference, to:

intercept data destined for one or more determinable destination ports of the endpoint computer device, wherein the intercepted data comprises packets of a connectionless protocol;

encapsulate the intercepted packets of the connectionless protocol within payload packets of a connection-based protocol and to send the encapsulated data to the endpoint computer device via the first data channel; and

in response to receiving a retransmission request for at least a portion of the encapsulated data from the endpoint computer device, transmit identifier packets of dummy packets or packets of a known sequence to the endpoint computer device, wherein the identifier packets satisfy the retransmission request and direct the endpoint computer device to discard the identifier packets;

further comprising computer program codes to cause the gatekeeper computer device to perform a security device detection process to determine whether establishment of the data channel is necessary.

2. The computer program product of claim 1 , wherein the intercepted data comprises packets of a connection-based protocol.

3. The computer program product of claim 1 , wherein the identifier packets include an alternating bit pattern.

4. The computer program product of claim 1 , wherein the gatekeeper computer device is a server coupled to one or more client endpoints.

5. The computer program product of claim 4 , further comprising computer program codes to cause the gatekeeper computer device to receive connectionless-based data from the client endpoints.

6. The computer program product of claim 5 , further comprising computer program codes to cause the gatekeeper computer device to send connectionless-based data to the client endpoints.

7. The computer program product of claim 1 , further comprising computer program codes to cause the gatekeeper computer device to receive connectionless-based data from and transmit connectionless-based data to an application endpoint appliance.

8. A computer program product for use in conjunction with a computer device, the computer program product comprising a non-transitory computer-readable medium and a computer program product mechanism embodied therein that causes the computer device to perform data transfers across a proxy interposed between the computer device and a second computer device, the computer program product having:

computer program codes to cause a gatekeeper computer device to monitor requests for data transfer to one or more determinable ports of the an endpoint computer device, wherein the monitoring includes detecting whether a network security device is interposed between the gatekeeper computer device and the endpoint computer device;

computer program codes to cause the gatekeeper computer device to create a first data channel by transmitting a tunnel connect message to the endpoint computer device in response to the detection of the network security device, wherein the tunnel connect message includes sequencing information, wherein data communicated over the first data channel is transmitted using a connection-based protocol;

computer program codes to cause the gatekeeper computer device to determine whether the proxy is interposed between the gatekeeper computer device and an endpoint computer device based at least on the tunnel connection message and the sequencing information;

computer program codes to cause the gatekeeper computer device to, in response to detecting a registration request from the endpoint computer device, substitute private address information associated with the endpoint computer device in the registration request with alternate address information and transmit the alternate address information to the endpoint computer device;

computer program codes to cause the gatekeeper computer device to, in response to detecting a request to participate in a conference, initiate the conference using the alternate address information and instructing the endpoint computer device to create a second data channel to a conference server and provide the conference server with the alternate address information, wherein the computer program codes are further configured, for the data transmitted in the conference, to:

intercept data destined for one or more determinable destination ports of the endpoint computer device, wherein the intercepted data comprises packets of a connectionless protocol;

encapsulate the intercepted packets of the connectionless protocol within payload packets of a connection-based protocol and to send the encapsulated data to the endpoint computer device via the first data channel; and

in response to receiving a retransmission request for at least a portion of the encapsulated data from the endpoint computer device, transmit identifier packets of dummy packets or packets of a known sequence to the endpoint computer device, wherein the identifier packets satisfy the retransmission request and direct the endpoint computer device to discard the identifier packets;

further comprising computer program codes to cause the gatekeeper computer device to perform a security device detection process to determine whether establishment of the data channel is necessary.

9. The computer program product of claim 8 , wherein the intercepted data comprises packets of a connection-based protocol and packets of a connectionless protocol.

10. The computer program product of claim 8 , wherein the gatekeeper computer device is a server coupled to one or more client endpoints.

11. The computer program product of claim 10 , further comprising computer program codes to cause the gatekeeper computer device to receive connectionless-based data from the client endpoints.

12. The computer program product of claim 11 , further comprising computer program codes to cause the gatekeeper computer device to send connectionless-based data to the client endpoints.

13. The computer program product of claim 8 , further comprising computer program codes to cause the gatekeeper computer device to receive connectionless-based data from and transmit connectionless-based data to an application endpoint appliance.

14. A method of transferring data from a first computer device to a second computer device, the method comprising:

monitoring requests for data transfer to one or more determinable ports of an endpoint computer device, wherein the monitoring includes detecting whether a network security device is interposed between a gatekeeper computer device and the endpoint computer device;

creating a first data channel to the endpoint computer device in response to the detection of the network security device, wherein data communicated over the first data channel is transmitted using a connection-based protocol;

in response to detecting a registration request from the endpoint computer device, substituting private address information associated with the endpoint computer device in the registration request with alternate address information and transmitting the alternate address information to the endpoint computer device;

in response to detecting a request to participate in a conference, initiating the conference using the alternate address information and instructing the endpoint computer device to create a second data channel to a conference server and provide the conference server with the alternate address information; wherein data for the conference is transmitted by:

intercepting data destined for one or more determinable destination ports of the endpoint computer device, wherein the intercepted data comprises packets of a connectionless protocol;

encapsulating the intercepted packets of the connectionless protocol within payload packets of a connection-based protocol and to send the encapsulated data to the endpoint computer device via the first data channel; and

in response to receiving, a retransmission request for at least a portion of the encapsulated data from the endpoint computer device, transmitting identifier packets of dummy packets or packets of a known sequence to the endpoint computer device, wherein the identifier packets satisfy the retransmission request and direct the endpoint computer device to discard the identifier packets;

further comprising performing a security device detection process to determine whether establishment of the data channel is necessary.

15. The method of claim 14 , wherein the intercepted data comprises packets of a connection-based protocol.

16. The method of claim 14 , wherein the identifier packets include an alternating bit pattern.

17. The method of claim 14 , wherein the gatekeeper computer device is a server coupled to one or more client endpoints.

18. The method of claim 17 , further comprising receiving connectionless-based data from the client endpoints.

19. The method of claim 18 , further comprising sending connectionless-based data to the client endpoints.

20. The method of claim 14 , further comprising receiving connectionless-based data from and transmit connectionless-based data to an application endpoint appliance.

Assignments (20)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 015220/0443 Recorded Dec 15, 2017
From: MORRISON & FOERSTER LLP; HURON CONSULTING GROUP; APPLIED DISCOVERY, INC.
To: AVAYA INC. (SUCCESSOR-IN-INTEREST TO FIRST VIRTUAL COMMUNICATIONS, INC.)
Reel/Frame 044892/0242 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2014
From: RADVISION LTD
To: AVAYA, INC.
Reel/Frame 032153/0189 →
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2008
From: MORRISON & FOERSTER LLP
To: FIRST VIRTUAL COMMUNICATIONS, INC.
Reel/Frame 021985/0586 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2005
From: FIRST VIRTUAL COMMUNICATIONS, INC.
To: RADVISION LTD.
Reel/Frame 016047/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2005
From: EISENBERG, ALFRED J.; THOMPSON, JOHN A.; BUNDY, DAVID O.
To: FIRST VIRTUAL COMMUNICATIONS, INC.
Reel/Frame 015609/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2004
From: FIRST VIRTUAL COMMUNICATIONS, INC.
To: MORRISON & FOERSTER LLP; HURON CONSULTING GROPU
Reel/Frame 015220/0443 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2004
From: BUNDY, DAVID O.; EISENBERG, ALFRED J.; THOMPSON, JOHN A.
To: FIRST VIRTUAL COMMUNICATIONS, INC.
Reel/Frame 014995/0031 →
Continuity (2)
Provisional Application 60367826 · Mar 27, 2002
Related Publication 20030188001A1 · Oct 2, 2003