IP Library Granted Patent US 8,458,782
Granted Patent B2
US 8,458,782 · App. 11/975,107 · Granted Jun 4, 2013

Authenticated session replication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,782
App. No.
11/975,107
Granted
Jun 4, 2013
Kind
B2
Abstract

Apparatus, systems, and methods may operate to receive, at an authentication agent in a first local area network (LAN), a virtual proxy authentication identification from a virtual proxy serving as a single point of trust for a second LAN across a wide area network. The virtual proxy authentication identification may be included in a modified session message originated within the second LAN. As a result, the apparatus, systems, and methods can operate to transmit content associated with the modified session message to a first plurality of individual proxy modules in the first LAN. Additional apparatus, systems, and methods are disclosed.

Claims (53)

1. An apparatus, comprising:

a first virtual proxy implemented in a non-transitory machine accessible medium to process on at least one machine within a first local area network (LAN) accessible via a plurality of virtual proxies including the first virtual proxy; and

an authentication agent to process within the first LAN and to communicate with a plurality of individual proxy modules within the first LAN, wherein the first virtual proxy is selected from the plurality of virtual proxies to represent each of the plurality of individual proxy modules as a single point of trust across a wide area network (WAN) to authentication agents outside the first LAN, wherein the first virtual proxy is to replace a local proxy authentication identification used for a local session message received from any one of the plurality of individual proxy modules with a unique identification assigned to the first virtual proxy, the unique identification to be transmitted to a second LAN outside the first LAN across the WAN and the unique identification to allow the first virtual proxy to be identified across the WAN, and wherein the authentication agent is to receive a modified session message originated within the second LAN across the WAN and to transmit content associated with the modified session message to the plurality of individual proxy modules.

2. The apparatus of claim 1 , wherein the first virtual proxy is to modify the local session message according to a virtual proxy authentication identification associated with the first virtual proxy to provide a modified session message.

3. The apparatus of claim 1 , wherein the apparatus comprises a server including the first virtual proxy and the authentication agent.

4. The apparatus of claim 1 , further comprising:

a memory to store a configuration including protocols and ports associated with the plurality of individual proxy modules and their respective local proxy authentication identifications.

5. The apparatus of claim 1 , wherein the authentication agent is to communicate with a selected one of the other virtual proxies in any selected location across the WAN.

6. The apparatus of claim 1 , wherein the authentication agent is configured to receive the modified session message from a second virtual proxy serving as the single point of trust for the second LAN across the WAN, wherein the second virtual proxy is different from the first virtual proxy.

7. A system, comprising:

a first virtual proxy within a first local area network (LAN) accessible via a plurality of virtual proxies including the first virtual proxy, to receive a local session message from any one of a first plurality of individual proxy modules within the first LAN, the first virtual proxy selected from the plurality of virtual proxies to serve as a single point of trust for the first LAN across a wide area network (WAN); and

a first authentication agent implemented in a non-transitory machine accessible medium to process on at least one machine within the first LAN and to receive a first modified session message having a virtual proxy authentication identification from a second virtual proxy located in a second LAN outside the first LAN across the WAN, wherein the first virtual proxy is to replace a local proxy authentication identification used for the local session message with a unique identification assigned to the first virtual proxy, the unique identification to be transmitted to the second LAN across the WAN and the unique identification to allow the first virtual proxy to be identified across the WAN, and wherein the first authentication agent is to transmit content associated with the first modified session message to the first plurality of individual proxy modules.

8. The system of claim 7 , wherein each of the first plurality of individual proxy modules are included in a corresponding different server.

9. The system of claim 7 , wherein the first virtual proxy is configured to transmit a second modified session message to a second authentication agent in the second LAN across the WAN after modifying the local session message to provide the second modified session message identifying the first virtual proxy.

10. The system of claim 9 , wherein the local proxy authentication identification in the local session message comprises a specified protocol.

11. The system of claim 9 , further comprising:

the second authentication agent to transmit content associated with the second modified session message just to a second plurality of individual proxy modules in the second LAN.

12. The system of claim 7 , wherein the first authentication agent is configured to transmit the content directly to the first plurality of individual proxy modules.

13. The system of claim 7 , wherein the content is created at one of a second plurality of individual proxy modules located within the second LAN.

14. The system of claim 7 , wherein the virtual proxy authentication identification is transmitted across the WAN separate from the session messages.

15. The system of claim 7 , wherein the virtual proxy authentication identification is transmitted across the WAN based on a specified trust relationship between the first virtual proxy and the authentication agents.

16. A method, comprising:

receiving, at a first virtual proxy within a first local area network (LAN) accessible via a plurality of virtual proxies including the first virtual proxy, a local proxy authentication identification associated with one of a first plurality of individual proxy modules within the first LAN;

replacing, at the first virtual proxy, the local proxy authentication identification with a unique identification assigned to the first virtual proxy, the unique identification to be transmitted to a second LAN outside the first LAN across a wide area network (WAN) and the unique identification to allow the first virtual proxy to be identified across the WAN, the first virtual proxy selected from the plurality of virtual proxies to serve as single point of trust for the first LAN across the WAN for session messages from the first plurality of individual proxy modules; and

responsive to receiving a modified session message originated within the second LAN across the WAN, transmitting content associated with the modified session message to the first plurality of individual proxy modules.

17. The method of claim 16 , further comprising:

transmitting the virtual proxy authentication identification across the WAN to an authentication agent in the second LAN, and to other authentication agents representing other LANs.

18. The method of claim 16 , further comprising:

receiving, at an authentication agent in the second LAN, the virtual proxy authentication identification in a modified one of the session messages from the first virtual proxy across the WAN; and

transmitting content associated with the modified one of the session messages just to a second plurality of individual proxy modules in the second LAN.

19. The method of claim 16 , comprising:

reading the local proxy authentication identification from a configuration database; and

associating the local proxy authentication identification with one of the session messages.

20. The method of claim 19 , comprising:

populating the configuration database with information regarding a trust relationship among the first virtual proxy, the first plurality of individual proxy modules, and an authentication agent in the second LAN.

21. A method, comprising:

receiving, at an authentication agent in a first local area network (LAN) accessible via a plurality of virtual proxies including a first virtual proxy selected from the plurality of virtual proxies to serve as a single point of trust for the first LAN across a wide area network (WAN), a virtual proxy authentication identification from a second virtual proxy serving as the single point of trust for a second LAN across the WAN, the virtual proxy authentication identification comprising a unique identification assigned to the second virtual proxy, the unique identification to allow the second virtual proxy to be identified across the WAN; and

transmitting content associated with a modified session message originated within the second LAN and the virtual proxy authentication identification just to a first plurality of individual proxy modules in the first LAN.

22. The method of claim 21 , wherein the transmitting comprises transmitting the content directly from the authentication agent to the first plurality of individual proxy modules.

23. The method of claim 21 , further comprising:

modifying, at the second virtual proxy, a local session message received from one of a second plurality of individual proxy modules in the second LAN using the virtual proxy authentication identification to provide the modified session message.

24. The method of claim 21 , further comprising:

repeating the receiving to replicate sessions created in the second LAN and authenticated by the second virtual proxy.

25. The method of claim 21 , further comprising:

assigning unique virtual proxies, including at least one of the first virtual proxy or the second virtual proxy, to connection endpoints of the WAN.

26. The method of claim 25 , wherein the connection endpoints comprise transmission control protocol (TCP) endpoints, and combinations of Internet Protocol (IP) addresses and TCP ports for the connection endpoints are used to establish trust between peers.

27. The method of claim 25 , wherein the connection endpoints comprise secure socket layer (SSL) endpoints, and at least one of server certificates and client certificates are used to establish trust between peers.

28. The method of claim 21 , further comprising:

communicating information regarding a session associated with the modified session message from the second virtual proxy to the authentication agent; and

replicating the information within the first LAN using the first plurality of individual proxy modules trusted by the authentication agent.

29. An apparatus, comprising:

a first virtual proxy implemented in a non-transitory machine accessible medium to process on at least one machine within a first local area network (LAN); and

an authentication agent to process within the first LAN and to communicate with a plurality of individual proxy modules within the first LAN, wherein the first virtual proxy is to represent each of the plurality of individual proxy modules as a single point of trust across a wide area network (WAN) to authentication agents outside the first LAN, wherein the first virtual proxy is to replace a local proxy authentication identification used for a local session message received from any one of the plurality of individual proxy modules with a unique identification assigned to the first virtual proxy, the unique identification to be transmitted to a second LAN outside the first LAN across the WAN and the unique identification to allow the first virtual proxy to be identified across the WAN, and wherein the authentication agent is to receive a modified session message originated within the second LAN across the WAN, to transmit content associated with the modified session message to the plurality of individual proxy modules, and to refrain from transmitting the content associated with the modified session message to the first virtual proxy.

Assignments (14)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2008
From: SRIRAM, TV; KONDAPALLI, ASWINIKUMAR
To: NOVELL, INC.
Reel/Frame 020445/0523 →