IP Library Granted Patent US 7,543,070
Granted Patent B1
US 7,543,070 · App. 11/234,486 · Granted Jun 2, 2009

System and method for negotiating multi-path connections through boundary controllers in a networked computing environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,543,070
App. No.
11/234,486
Granted
Jun 2, 2009
Kind
B1
Abstract

A system and method for negotiating multi-path connections between a plurality of intermediary devices, such as boundary controllers, in a networked computing environment is described. A client-side communications session is established between a requesting client and an intermediary device available from a plurality of intermediary devices on a primary communications channel in accordance with a connection-oriented network protocol. A server-side communications session is established between the intermediary device and the requested server on a primary communications channel in accordance with the connection-oriented network protocol. Differences in routing parameters defined for the client-side communications session and the server-side communications session are determined. The routing parameter differences are communicated to at least one other such intermediary device over an out-of-band communications channel.

Claims (39)

1. A system for communicating routing information between a plurality of link layer intermediary devices in a networked computing environment, comprising:

a link layer intermediary device available from a plurality of link layer intermediary devices receiving a session packet including a connection request from a requesting client;

an encapsulation module generating an echo request packet identified as originating from the requesting client and addressed to a requested server and encapsulating the session packet including the connection request within the echo request packet;

the link layer intermediary device forwarding the echo request packet to the requested server;

at least one other such link layer intermediary device receiving an echo response packet from the requested server;

an unencapsulation module unencapsulating the session packet including the connection request from within the echo response packet and retrieving routing information from the session packet; and

the at least one other such link layer intermediary device forwarding a response packet to the requesting client.

2. A system according to claim 1 , wherein the echo request packet is an Internet Control Message Protocol (ICMP) echo request packet and the echo response packet is an ICMP echo response packet.

3. A system according to claim 1 , further comprising a connection established between the requesting client and the link layer intermediary device in accordance with a connection-oriented network protocol.

4. A system according to claim 1 , wherein the intermediary device comprises at least one of a firewall and a boundary controller.

5. A system according to claim 1 , wherein the intermediary device includes a boundary controller.

6. A system according to claim 5 , wherein the boundary controller implements link layer protocols.

7. A system according to claim 5 , further comprising obtaining connection information from the unencapsulated session packet.

8. A system according to claim 7 , wherein the connection information is shared between peer boundary controllers.

9. A system according to claim 7 , wherein the connection information is shared between peer boundary controllers prior to transacting a handshake with the requested server.

10. A system according to claim 7 , wherein the connection information passes through a single boundary controller.

11. A system according to claim 5 , wherein the boundary controller is incorporated directly into a network protocol stack.

12. A system according to claim 11 , wherein the network protocol stack runs on one of a firewall, a server, and a client.

13. A system according to claim 1 , wherein the connection request includes a SYN packet.

14. A method for communicating routing information between a plurality of link layer intermediary devices in a networked computing environment, comprising:

receiving a session packet including a connection request from a requesting client on a link layer intermediary device available from a plurality of link layer intermediary devices;

generating an echo request packet identified as originating from the requesting client and addressed to a requested server and encapsulating the session packet including the connection request within the echo request packet;

forwarding the echo request packet to the requested server;

receiving an echo response packet from the requested server on at least one other such link layer intermediary device;

unencapsulating the session packet including the connection request from within the echo response packet and retrieving routing information from the session packet; and

forwarding a response packet to the requesting client.

15. A method according to claim 14 , wherein the echo request packet is an Internet Control Message Protocol (ICMP) echo request packet and the echo response packet is an ICMP echo response packet.

16. A method according to claim 14 , further comprising establishing a connection between the requesting client and the link layer intermediary device in accordance with a connection-oriented network protocol.

17. A computer-readable storage medium holding code for performing the method of claim 14 .

18. A computer program product embodied on a computer readable storage medium for communicating routing information between a plurality of link layer intermediary devices in a networked computing environment, comprising:

computer code for receiving a session packet including a connection request from a requesting client on a link layer intermediary device available from a plurality of link layer intermediary devices;

computer code for generating an echo request packet identified as originating from the requesting client and addressed to a requested server and encapsulating the session packet including the connection request within the echo request packet on an encapsulation module;

computer code for forwarding the echo request packet to the requested server on the link layer intermediary device;

computer code for receiving an echo response packet from the requested server on at least one other such link layer intermediary device;

computer code for unencapsulating the session packet including the connection request from within the echo response packet and retrieving routing information from the session packet on an unencapsulation module; and

computer code for forwarding a response packet to the requesting client on the at least one other such link layer intermediary device.

19. The computer product of claim 18 , wherein the echo request packet is an Internet Control Message Protocol (ICMP) echo request packet and the echo response packet is an ICMP echo response packet.

20. The computer product of claim 18 , further comprising computer code for establishing a connection between the requesting client and the link layer intermediary device in accordance with a connection-oriented network protocol.

21. The computer product of claim 18 , wherein the intermediary device comprises at least one of a firewall and a boundary controller.

Assignments (8)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Sep 22, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 017030/0401 →