IP Library Granted Patent US 7,870,380
Granted Patent B2
US 7,870,380 · App. 11/927,362 · Granted Jan 11, 2011

Providing secure connections for data transmission

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,870,380
App. No.
11/927,362
Granted
Jan 11, 2011
Kind
B2
Abstract

The disclosed system and method allow secure packet transmission to be provided with a minimum amount of overhead and to employ a cache having copies distributed among a plurality of different locations. SSL/TLS session information for a session with each of the proxy servers is stored in the cache so that it is accessible to at least one other proxy server. Using this arrangement, when a client computer switches from a connection with a first proxy server to a connection with a second proxy server, the second proxy server can retrieve SSL/TLS session information from the cache corresponding to the SSL/TLS communication session between the client device and the first proxy server. The second proxy server can then use the retrieved SSL/TLS session information to accept a session with the client device.

Claims (37)

1. A method for establishing a secure connection for data transmission via a network, the method comprising:

receiving a request to establish a secure session with a computer using an unreliable protocol, the request received via the network;

transmitting a request for cached session information from a server storing the cached session information, the server coupled to the network;

receiving cached session information from the server storing the cached session information;

establishing a secure session with the computer using the unreliable protocol;

transmitting updated session information from the secure session to a plurality of recipient servers coupled to the network;

determining that the updated session information has been received at the plurality of recipient servers; and

adjusting a rate of transmission of updated session information to the plurality of recipient servers based on the determined receipt of the updated session information by the plurality of recipient servers.

2. The method of claim 1 , wherein the request to establish the secure connection includes a session identifier.

3. The method of claim 1 , further comprising performing a search of a local cache to locate the cached session information upon receiving the request to establish the secure connection.

4. The method of claim 3 , wherein performing the search includes generating a search key based on a session identifier.

5. The method of claim 2 , further comprising:

generating a search key upon receiving the request to establish the secure connection, the search key generated based on the session identifier; and

transmitting the search key to the server storing the cached session information.

6. The method of claim 2 , wherein receiving the cached session information further comprises:

transmitting the session identifier to the server storing the cached session information; and

receiving resumption information for a session associated with the session identifier.

7. The method of claim 3 , further comprising generating a record for storage in the local cache, the record including resumption information, an expiration date associated with the record, and the session identifier.

8. The method of claim 3 , wherein resumption information includes a message authentication check algorithm, a cipher specification, and flag information indicating that the session can be used to initiate a connection.

9. The method of claim 8 , further comprising:

initiating the session with the computer based on the flag information; and

generating a record for storage in a local cache, the record including the resumption information, an expiration date associated with the record, and the session identifier.

10. The method of claim 1 , wherein the cached session information includes a peer certificate.

11. The method of claim 1 , wherein the cached session information includes a data compression algorithm.

12. A non-transitory computer-readable storage medium having embodied thereon a program, the program executable by a computer to perform a method for establishing a secure connection for data transmission in a network, the method comprising:

receiving a request to establish a secure session using an unreliable protocol;

transmitting a request for cached session information;

receiving cached session information;

establishing a secure session using the unreliable protocol;

transmitting updated session information from the secure session to a plurality of recipient servers;

determining that the updated session information has been received at the plurality of recipient servers; and

adjusting a rate of transmission of updated session information to the plurality of recipient servers based on the determined receipt of the updated session information by the plurality of recipient servers.

13. The non-transitory computer-readable storage medium of claim 12 , the method further comprising transmitting a positive acknowledgement of receipt of the cached session information.

14. The non-transitory computer-readable storage medium of claim 12 , the method further comprising transmitting a negative acknowledgement of receipt of the cached session information.

15. The non-transitory computer readable storage medium of claim 12 , the method further comprising initiating a session upon establishing a secure connection.

16. The method of claim 1 , wherein adjusting the rate of transmission includes postponing the transmission of a data segment corresponding to the updated session information.

17. The method of claim 1 , wherein adjusting the rate of transmission includes determining an average number of data segments in an input queue.

Assignments (19)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041072 FRAME: 235. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT. Recorded Apr 5, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042245/0523 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041072/0235 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
MERGER Recorded Feb 4, 2009
From: AVENTAIL CORPORATION
To: AVENTAIL LLC
Reel/Frame 022200/0475 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: VANHEYNINGEN, MARC D.; ERICKSON, RODGER D.
To: AVENTAIL CORPORATION
Reel/Frame 022152/0318 →