IP Library Granted Patent US 8,688,856
Granted Patent B2
US 8,688,856 · App. 11/338,065 · Granted Apr 1, 2014

Techniques for managing a network delivery path of content via a key

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,688,856
App. No.
11/338,065
Granted
Apr 1, 2014
Kind
B2
Abstract

Techniques for distributing content over a network via keys are provided. A key is associated with a particular destination or with a particular piece of content. A path management service derives and selectively communicates portions of a network path for moving the content to a destination on the basis of a value for a key. Any intermediate processing resource receives a next location within the path for forwarding the content from the path management service in response to presenting the key.

Claims (38)

1. A machine-implemented method to execute on a processing device, comprising:

receiving, by the processing device, a key from a first node;

acquiring, by the processing device, a delivery path for a network in response to the key, the delivery path securely managed and selectively communicated to the first node participating in routing content to the destination node via the delivery path, the first node does not have an Internet Protocol (IP) address of a destination node for which the content is to sent over the network, and the key is used by the method processing to discover an identity of the destination node, the identity is discovered based on a value for the key, once the identity is known, the method generates the delivery path for moving a message with the content over the network from the first node to the destination node, the message does not include path processing information and does not include path information, the message includes the content and the key and a particular address to a next node in the delivery path; and

instructing, by the processing device, the first node to forward the content associated with the key and the key to a second node, the second node is only communicated to the first node as a next hop addresses that is selectively identified from the delivery path, the first node cannot discover the delivery path and only is provided the next hop address for purposes of routing the content to the next hop address along with the key, the first, second, next, and destination nodes do not perform path processing for the content and do not have the path processing information.

2. The method of claim 1 further comprising:

receiving, by the processing device, the key from the second node; and

instructing, by the processing device, the second node to forward the content and the key to a third node, wherein the third node is communicated to the second node as another next hop address that is selectively identified from the delivery path.

3. The method of claim 2 further comprising, continuing to instruct, by the processing device, one or more additional nodes to forward the content and the key along within the network to next nodes associated with other next hop addresses until a destination node defined in the delivery path is reached.

4. The method of claim 1 , wherein instructing further includes instructing the first node to forward the content and the key to one or more additional nodes, wherein each additional node is associated with a different delivery path and wherein the key is a keychain.

5. The method of claim 1 , wherein acquiring further includes querying a key management service or key store with the key to acquire one or more identities associated with one or more destination nodes and using the one or more identities along with an identity of the first node to derive the delivery path from a topology of the network, the delivery path at least includes the second node.

6. The method of claim 1 , wherein acquiring further includes associating one or more alternative sub-paths within the delivery path.

7. The method of claim 6 further comprising accessing the one or more alternative sub-paths when a load or connect problem is detected a particular next node, wherein the second node is associated with one of the alternative sub-paths of the delivery path.

8. A machine-implemented method to execute on a processing device, comprising:

receiving, by the processing device, a key from a requestor, the key is provided by the requestor to acquire content over a network but a location for the content over the network is unknown to the requestor;

associating, by the processing device, the key with content by using a data store that houses an association between the key and the content, the association is also used to acquire the location for the content over the network;

identifying, by the processing device, the location over a network for the content; and

delivering, by the processing device, the content to the requestor via a delivery path that moves the content from the location over the network to the requestor using participants, each participant assists in routing the content over a portion of the delivery path and each participant is only aware of and provided a next hop address that the content is to be delivered to within the delivery path but each participant cannot discover the delivery path and each participant is unaware of a final destination node for the content, the delivery path is derived by the method processing using an Internet Protocol (IP) address of the requestor and the location of the content on the network, the content moved via a message that includes the content, the key, and a next address for a next processing node, the message lacks any path processing and the message lacks any path information, and the participants do not perform path processing for the content and do not have the path information.

9. The method of claim 8 further comprising, authenticating, by the processing device, the requestor before processing the received key.

10. The method of claim 8 further comprising, encrypting, by the processing device, the content before delivering the content to the requestor from the location.

11. The method of claim 8 , wherein delivering further includes guiding the participants of the network from the location to assist one another in forwarding the content over the network to the requestor.

12. The method of claim 8 further comprising:

receiving, by the processing device, a different key from a different requestor;

associating, by the processing device, the different key with the same content at the same location; and

delivering, by the processing device, the content over the network to the different requestor.

13. The method of claim 8 , wherein delivering further includes:

determining if the content is available from a cache service before checking the location for the content; and

delivering the content from cache if available, otherwise delivering from the location.

14. A machine-implemented method to execute on a processing device, comprising:

receiving, by the processing device, content having a key from a node;

querying, by the processing device, one or more neighboring nodes with the key for advice on where to forward the content next within a network if the key is not recognized; and

forwarding, by the processing device, the content through the network with the key to a next node in response to an answer from at least one of the one or more neighboring nodes if the key is not recognized, a delivery path for the content is separately and securely managed and is derived by using the key to discover an identity of a destination node that is to receive the content and using the identity of the destination node along with an initial requestor IP address to generate the delivery path over the network, just the node sending the content and the next node are known by a network participant when the content is forwarded from the network participant to the next node, the network participant assist in routing the content to a final destination node that is not known to the network participant, the content routed via a message that includes the content, the key, and an address to a next processing node and the message lacks any path processing and the message lacks any path information, the node, the neighboring nodes, and the destination node do not perform path processing for the content and do not have the path processing information.

15. The method of claim 14 further comprising:

recognizing, by the processing device, the key; and

decrypting, by the processing device, the content in response to recognizing the key.

16. The method of claim 14 , wherein querying further includes requesting assistance from a path management service to initially identify the one or more neighboring nodes to query.

17. The method of claim 14 , wherein querying further includes requesting assistance from an identity store to acquire identities for the one or more neighboring nodes before querying the one or more neighboring nodes for advice.

18. The method of claim 14 , wherein forwarding further includes forwarding the content to one or more additional nodes in response to the answer, wherein the answer indicates the content having the key is associated with multiple different destination nodes, and wherein the key is a keychain having multiple different keys associated with it.

19. The method of claim 14 further comprising, sending, by the processing device, a confirmation to at least one of the node that provided the content with the key and a path management service, wherein the confirmation indicates that the content and the key were forwarded if the key was not recognized or indicates that the content was properly received if the key was recognized.

Assignments (15)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →