IP Library Granted Patent US 8,613,071
Granted Patent B2
US 8,613,071 · App. 11/489,414 · Granted Dec 17, 2013

Split termination for secure communication protocols

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,613,071
App. No.
11/489,414
Granted
Dec 17, 2013
Kind
B2
Abstract

Transaction accelerators can be configured to terminate secure connections. A server-side accelerator intercepts a secure connection request that is from a client and that is directed to a server. The server-side accelerator responds to the secure connection request in place of the server, thereby establishing a secure connection between the client and the server-side accelerator. Alternatively, the server-side accelerator monitors the establishment of a secure connection between the client and the server. After the secure connection has been established, the server-side accelerator forwards security information to a client-side accelerator, enabling the client-side accelerator to assume control of the secure connection. As a result of this arrangement, the client-side accelerator is able to encrypt and decrypt data on the secure connection and accelerate it in cooperation with the server-side accelerator. In a further embodiment, the accelerated traffic between accelerators is carried across the network via another secure connection.

Claims (121)

1. A method of initiating a secure connection, the method comprising:

intercepting a secure connection request from a client requesting a connection to a server, the intercepting using an intercepting entity distinct from the server;

initiating a secure connection with the client at the intercepting entity, wherein the secure connection is associated with at least one attribute enabling a secure communication of data via the secure connection while having access to data sent via the secure connection, wherein initiating a secure connection with the client comprises:

a) observing with the intercepting entity the initiation of a secure connection between the client and the server;

b) determining the attribute of the secure connection from the initiation of the secure connection; and

c) receiving an indication that the initiation of the secure connection between the client and the server is complete; and

forwarding the attribute from the intercepting entity to a network device distinct from the intercepting entity and in a path of the secure connection between the client and the intercepting entity such that the network device can use at least the attribute to maintain the secure connection with the client, the secure connection having been initiated with the intercepting entity, while having access to data sent via the secure connection.

2. The method of claim 1 , wherein the secure connection request initiates a connection between the client and the server.

3. The method of claim 1 , wherein the secure connection request initiates security for a previously-established connection between the client and the server.

4. The method of claim 1 , wherein intercepting the secure connection request from the client comprises:

receiving a secure connection request previously intercepted by a second intercepting entity in-path with the client and redirected to the intercepting entity.

5. The method of claim 4 , wherein receiving the secure connection request comprises:

receiving the secure connection request via a caching protocol.

6. The method of claim 1 , wherein intercepting the secure connection request from the client comprises:

intercepting the secure connection request from the client via an in-path network connection with the client.

7. The method of claim 1 , wherein observing the initiation of the secure connection is facilitated by receiving, by the intercepting entity, security information associated with the server.

8. The method of claim 1 , wherein initiating the secure connection comprises:

initiating a first secure connection between the intercepting entity and the server; and

initiating a second secure connection between the intercepting entity and the client.

9. The method of claim 8 , wherein the initiation of the first secure connection is completed before initiating the second secure connection.

10. The method of claim 8 , wherein the second secure connection is initiated before the initiation of the first secure connection is completed.

11. The method of claim 1 , wherein the attribute includes a cipher to be used to encrypt data for the secure connection.

12. The method of claim 1 , wherein the network device receiving the forwarded attribute is closer on a network to the client than the intercepting entity.

13. The method of claim 12 , wherein proximity of the network device and the intercepting entity to the client on the network is determined by network characteristics.

14. The method of claim 13 , wherein the network characteristics include network latencies of the network from the network device and the intercepting entity to the client.

15. The method of claim 13 , wherein the network characteristics include network bandwidths of the network from the network device and the intercepting entity to the client.

16. The method of claim 13 , wherein the network device receiving the forwarded attribute is separated from the client by a first network including a local area network and wherein the intercepting entity is separated from the client by a second network including a wide area network.

17. The method of claim 13 , wherein the network device receiving the forwarded attribute is integrated with a computer system including the client.

18. The method of claim 1 , further comprising:

intercepting data from the server directed to the client;

communicating at least a portion of the data to the network device in association with an indicator, such that the network device will further communicate the portion of the data with the client via the secure connection.

19. The method of claim 1 , further comprising:

receiving first data from the network device, wherein the first data corresponds with second data previously received by the network device from the client via the secure connection; and

communicating third data to the server, wherein the third data corresponds with the first data.

20. The method of claim 1 , wherein forwarding the attribute to the network device includes:

initiating an additional secure connection with the network device; and

communicating the attribute via the additional secure connection.

21. A method of communicating securely with a client, the method comprising:

intercepting a secure connection request from a client to a server at a first network device;

initiating a first secure connection between the first network device and the client in response to the secure connection request; and

in response to the initiation of the first secure connection being successfully completed:

communicating an indicator from the first network device to a second network device that is in a network path between the client and the first network device, wherein the indicator is both an indicator that the first secure connection has been established between the client and the first network device and the indicator is also useable by the second network device to access and process secure communications that occur between the client and the first network device; and

assuming control of the first secure connection with the client at the second network device, such that communications between the client and the server pass through the first secure connection between the client and the second network device;

wherein the indication that the initiation of the secure connection marks the end of interactions that require a private key and the start of interactions that require only a symmetric key.

22. The method of claim 21 , wherein intercepting the secure connection request from the client comprises:

receiving a secure connection request previously intercepted by an intercepting entity in-path with the client and redirected to the first network device.

23. The method of claim 21 , wherein intercepting the secure connection request from the client comprises:

intercepting the secure connection request from the client via an in-path network connection with the client.

24. The method of claim 21 , further comprising:

receiving first data from the server directed to the client at the first network device;

communicating second data corresponding to the first data from the first network device to the second network device; and

communicating third data corresponding to the second data from the second network device to the client via the first secure connection.

25. The method of claim 24 , wherein the second data comprises an optimized version of the first data and the third data comprises a de-optimized version of the second data equivalent to the first data.

26. The method of claim 21 , further comprising:

receiving first data from the client directed to the server at the second network device via the first secure connection;

communicating second data corresponding to the first data from the second network device to the first network device; and

communicating third data corresponding to the second data from the first network device to the server.

27. The method of claim 26 , wherein the second data comprises an optimized version of the first data and the third data comprises a de-optimized version of the second data equivalent to the first data.

28. The method of claim 21 , wherein initiating the first secure connection with the client in response to the secure connection request comprises determining if the server is capable of establishing a secure connection with the client in response to the secure connection request.

29. The method of claim 28 , wherein determining if the server is capable of establishing a secure connection with the client in response to the secure connection request comprises establishing a second secure connection between the first network device and the server.

30. The method of claim 21 , wherein the second network device initiates communications with the client via the first secure connection using a symmetric encryption key in response to the indication.

31. The method of claim 30 , wherein the indication includes the symmetric encryption key.

32. The method of claim 30 , further comprising:

selecting a symmetric encryption key by the second network device;

communicating the selected symmetric encryption key to the first network device; and

communicating the selected symmetric encryption key from the first network device to the client during or after the initiation of the first secure connection.

33. The method of claim 21 , wherein the first and second network devices communicate via a second secure connection.

34. The method of claim 33 , wherein the first and second network devices initiate the second secure connection using public-key cryptography and certificates signed by a mutually-trusted certifying authority.

35. The method of claim 33 , wherein the first and second network devices initiate the second secure connection using self-signed certificates and procedures for deliberate acceptance of such certificates.

36. The method of claim 33 , wherein the second secure connection uses a security different from a security of the first secure connection.

37. The method of claim 33 , wherein the second secure connection uses a security similar to a security of the first secure connection.

38. The method of claim 33 , wherein the second secure connection communicates data associated with the first secure connection and an additional secure connection between the first and second network devices communicates data associated with an additional client.

39. The method of claim 38 , wherein the length of use of a single inner channel connection is determined by a number of outer channel connections that have used the single inner channel connection.

40. The method of claim 38 , wherein the length of use of a single inner channel connection is determined by time elapsed since the first use of the single inner channel connection.

41. The method of claim 38 , wherein a pool of inner-channel connections is available for reuse.

42. The method of claim 21 , where a server-side outer channel connection is reused for multiple client-side outer channel connections.

43. The method of claim 42 , wherein the length of use of a single server-side outer channel connection is determined by the number of client-side outer channel connections that have used it.

44. The method of claim 42 , wherein the length of use of a single server-side outer channel connection is determined by time elapsed since the first use of the single server-side outer channel connection.

45. The method of claim 42 , wherein a pool of inner-channel connections is available for reuse.

46. The method of claim 28 , wherein determining if the server is capable of establishing a secure connection with the client in response to the secure connection request comprises:

accessing a secure connection cache for information characterizing previous secure connection requests denied by the server;

comparing characteristics of the secure connection request with the information;

forwarding the secure connection request to the server in response to a determination that the characteristics of the secure connection request are similar to the information, thereby enabling the server to establish a secure connection with the client.

47. The method of claim 46 , further comprising:

invalidating at least a portion of the secure connection cache in response to a change in private key information stored at the first network device.

48. The method of claim 46 , further comprising:

sharing at least a portion of the secure connection cache with an additional network device connected with the server.

49. The method of claim 21 , wherein assuming control of the secure connection with the client at the second network device includes:

detecting a secure connection renegotiation request by the client at the second network device;

communicating an indicator of the secure connection renegotiation request from the second network device to the first network device;

in response to the indicator of the secure connection renegotiation request, assuming control of the first secure connection with the client at the first network device;

determining at the first network device whether the first secure connection is renegotiable by the first network device;

in response to determining that the first secure connection is renegotiable by the first network device:

renegotiating the first secure connection with the client; and

forwarding the secure connection renegotiation request to the server in response to a determination that the first network device cannot renegotiate the first secure connection, thereby enabling the server to renegotiate a secure connection with the client.

50. A method of communicating securely with a client, the method comprising:

observing an initiation of a secure connection between a client and a server at a first network device, wherein the first network device receives security information from the server;

receiving an indication that the initiation of the secure connection between the client and the server is complete;

communicating an indicator from the first network device to a second network device that both indicates that the secure connection has been established between the client and the first network device and that is also useable by the second network device to process secure communications that occur between the client and the first network device;

assuming control at the second network device of the secure connection with the client on behalf of the server, the secure connection having been established between the client and the first network device;

receiving data directed to the client from the server via the second network device; and communicating the data to the client via the secure connection;

wherein the indication that the initiation of the secure connection marks the end of interactions that require a private key and the start of interactions that require only a symmetric key.

51. The method of claim 50 , wherein the indication that the initiation of the secure connection is complete includes at least one attribute enabling the secure communication of data via the secure connection.

52. The method of claim 51 , wherein the attribute includes a symmetric key.

53. The method of claim 50 , wherein the server is a VPN device.

54. The method of claim 50 , wherein assuming control of the secure connection comprises:

determining an attribute of the secure connection from observing the initiation of the secure connection.

55. A method of initiating a secure connection between a client and a server, wherein traffic over the secure connection is to pass from the client through a first proxy and a second proxy to the server, the method comprising:

intercepting, at the first proxy, a connection request that is from the client, the connection request directed to the server;

intercepting, at the second proxy, a secure connection request that is from the client, the secure connection request directed to the server requesting establishment of the secure connection with the server, wherein establishment of the secure connection with the server requires a first datum that is provided by the server;

obtaining the first datum at the second proxy;

establishing authenticated communication between the first proxy and the second proxy; and

after establishing authenticated communication between the first proxy and the second proxy, providing data from the second proxy to the first proxy, wherein such data is data specific to the secure connection and is data required to establish the first proxy as a termination of the secure connection with the client and wherein such data is provided to the first proxy using the authenticated communication between the first proxy and the second proxy;

wherein the first datum is a private key of the server, wherein a session key is required for the authenticated communication between the first proxy and the second proxy, and wherein the data required to establish the first proxy as the termination of the secure connection with the client is the session key.

56. The method of claim 55 , further comprising:

establishing a first unsecured connection between the client and the first proxy prior to providing the data from the second proxy to the first proxy;

establishing a second unsecured connection between the first proxy and the second proxy prior to intercepting the secure connection request; and

establishing authenticated communication between the client and the second proxy using the first datum; and

obtaining the first datum from the server for use by the second proxy.

57. The method of claim 55 , wherein the first datum includes at least one of private key information for the server, certificate information for the server, exchanged self-signed certificates, and exchanged externally-signed certificates.

58. The method of claim 55 , wherein the first proxy and the second proxy are identically configured.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2006
From: DAY, MARK STUART; LARSEN, CASE; MERUGU, SHASHIDHAR
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 018117/0424 →