IP Library Granted Patent US 8,245,287
Granted Patent B2
US 8,245,287 · App. 12/240,141 · Granted Aug 14, 2012

Server message block (SMB) security signatures seamless session switch

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,245,287
App. No.
12/240,141
Granted
Aug 14, 2012
Kind
B2
Abstract

The present invention relates to systems, apparatus, and methods of securely transmitting data between a client and a server. The method includes receiving an initial security message from the client. The security message is to establish security between the server and the client. Further, the client's security parameters are set to enabled and not required. The method further includes forwarding the initial security message to the server and intercepting a security response from the server. The response includes security data and security parameters set to enabled and required. The method includes extracting the security data from the security response, and using the security data to establish a secure socket connection between the proxy server and the server. Furthermore, the method alters the request by changing the security parameters to not enabled and not required, and transmits the altered request and establishes a non-secure socket connection.

Claims (44)

1. A method of securely transmitting data between a client and a server, the method comprising:

receiving, at a client proxy, an initial security message from the client, wherein the security message is to establish security between the server and the client, and wherein the client's security parameters are set to enabled and not required;

forwarding the initial security message to the server;

intercepting, at a proxy server, a security response from the server, wherein the response includes security data and security parameters set to enabled and required;

extracting the security data from the security response, and using the security data to establish a secure socket connection between the proxy server and the server;

altering the request by changing the security parameters to not enabled and not required; and

transmitting the altered request to the client and establishing a non-secure socket connection between the proxy client and the client.

2. The method of securely transmitting data between a client and a server of claim 1 , further comprising:

receiving, at the proxy client via the non-secure socket connection, a file request directed to the server; and

compressing the file request and transmitting it to the proxy server.

3. The method of securely transmitting data between a client and a server of claim 2 , further comprising:

decompressing, at the proxy server, the compressed file request; and transmitting the decompressed file request via the secure socket connection.

4. The method of securely transmitting data between a client and a server of claim 2 or 3 , wherein the socket connections are server message block (SMB) socket connections.

5. The method of securely transmitting data between a client and a server of claim 2 , wherein the file request is one or more of a file delete, file copy, file move, folder delete, folder copy, and folder move request.

6. The method of securely transmitting data between a client and a server of claim 1 , wherein the security data comprises at least one of a message authentication code (MAC), a checksum, and a session key.

7. The method of securely transmitting data between a client and a server of claim 1 , wherein the altered request is transmitted using the ITP transport protocol.

8. The method of securely transmitting data between a client and a server of claim 1 , wherein the server is a content server.

9. The method of securely transmitting data between a client and a server of claim 8 , wherein the content server comprises one or more of the following: an email server, an FTP server, a web server, a file server, and a database server.

10. The method of securely transmitting data between a client and a server of claim 1 , further comprising establishing a secure socket between the proxy server and the server.

11. The method of securely transmitting data between a client and a server of claim 10 , further comprising:

transmitting a compressed version of the file request to the proxy server;

decompressing, at the proxy server, the compressed version of the file request; and

transmitting the decompressed file request to the server through the secure socket.

12. The method of securely transmitting data between a client and a server of claim 1 , wherein the proxy client and the proxy server are connected over a high latency link.

13. The method of securely transmitting data between a client and a server of claim 12 , wherein the high latency link comprises one or more of the following: a satellite link, a cellular link, a wireless link, a Bluetooth link, and an RF link.

14. The method of securely transmitting data between a client and a server of claim 1 , wherein the proxy server and the server are connection over a low latency link.

15. The method of securely transmitting data between a client and a server of claim 14 , wherein the low latency link comprises one or more of the following: a broadband link, a T1 link, a cable link, a digital subscriber line (DSL) link, and an analog DSL (ADSL) link.

16. A system for securely transmitting data between a client and a server, the system comprising:

a client system including a proxy client configured to receive an initial security message from the client, wherein the client's security parameters are set to enabled and not required, and to forward the initial security message;

a content server configured to transmit a security response, wherein the response includes security data and security parameters set to enabled and required; and

a proxy server coupled with the content server over a low latency communications link and the client system via the proxy client over a high latency communications link, the proxy server configured to intercept the security response, extract the security data from the security response, use the security data to establish a secure socket connection between the proxy server and the content server, alter the request by changing the security parameters to not enabled and not required, and transmit the altered request to the client;

wherein the proxy client is further configured to establish a non-secure socket connection between the proxy client and the client.

17. The system for securely transmitting data between a client and a server of claim 16 , wherein the proxy client is further configured to receive via the non-secure socket connection a file request directed to the content server, compress the file request, and transmit the file request to the proxy server.

18. The system for securely transmitting data between a client and a server of claim 17 , wherein the proxy server is further configured to decompress the compressed file request and transmit the decompressed file request to the proxy client via the secure socket connection.

19. A non-transitory machine-readable medium for securely transmitting data between a client and a server having sets of instructions which, when executed by a machine, cause the machine to:

receive, at a client proxy, an initial security message from the client, wherein the security message is to establish security between the server and the client, and wherein the client's security parameters are set to enabled and not required;

forward the initial security message to the server;

intercept, at a proxy server, a security response from the server, wherein the response includes security data and security parameters set to enabled and required;

extract the security data from the security response, and using the security data to establish a secure socket connection between the proxy server and the server;

alter the request by changing the security parameters to not enabled and not required; and

transmit the altered request to the client and establishing a non-secure socket connection between the proxy client and the client.

20. The non-transitory machine-readable medium for securely transmitting data between a client and a server, wherein the sets of instructions which when further executed by the machine, cause the machine to;

receive, at the proxy client via the non-secure socket connection, a file request directed to the server; and

compress the file request and transmitting it to the proxy server.

Assignments (11)
PARTIAL RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 48715/0589 Recorded Jun 6, 2025
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
To: VIASAT, INC.
Reel/Frame 071638/0083 →
PARTIAL RELEASE OF SECURITY INTEREST AT REEL/FRAME 063822/0446 Recorded Jun 4, 2025
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VIASAT, INC.
Reel/Frame 071495/0223 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2025
From: MUFG BANK, LTD. (AS SUCCESSOR-IN-INTEREST TO MUFG UNION BANK, N.A. (F/K/A UNION BANK, N.A.)), AS AGENT
To: VIASAT, INC.
Reel/Frame 071321/0026 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2025
From: MUFG BANK, LTD. (AS SUCCESSOR-IN-INTEREST TO MUFG UNION BANK, N.A. (F/K/A UNION BANK, N.A.)), AS AGENT
To: VIASAT, INC.
Reel/Frame 071321/0036 →
PARTIAL RELEASE OF SECURITY INTEREST AT REEL/FRAME 059332/0558 Recorded Jun 4, 2025
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VIASAT, INC.
Reel/Frame 071495/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2025
From: VIASAT, INC.
To: SNAPPI HOLDCO, INC.
Reel/Frame 070293/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2025
From: SNAPPI HOLDCO, INC.
To: SNAPPI, INC.
Reel/Frame 070293/0879 →
SECURITY AGREEMENT Recorded Jun 1, 2023
From: VIASAT, INC.
To: BANK OF AMERICA, N.A., AS AGENT
Reel/Frame 063822/0446 →
SECURITY AGREEMENT Recorded Mar 7, 2022
From: VIASAT, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 059332/0558 →
SECURITY INTEREST Recorded Mar 27, 2019
From: VIASAT, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 048715/0589 →
SECURITY AGREEMENT Recorded May 9, 2012
From: VIASAT, INC.
To: UNION BANK, N.A.
Reel/Frame 028184/0152 →