IP Library Granted Patent US 8,180,902
Granted Patent B1
US 8,180,902 · App. 12/571,430 · Granted May 15, 2012

Establishing network connections between transparent network devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,180,902
App. No.
12/571,430
Granted
May 15, 2012
Kind
B1
Abstract

Transparent network devices intercept messages from non-transparent network devices that establish a connection. Transparent network devices modify these messages to establish an inner connection with each other. The transparent network devices mimic at least some of the outer connection messages to establish their inner connection. The mimicked messages and any optional reset messages are intercepted by the transparent network devices to prevent them from reaching the outer connections. Transparent network devices modify network traffic, using error detection data, fragmentation data, or timestamps, so that inner connection network traffic inadvertently received by outer connection devices is rejected or ignored by the outer connection network devices. Transparent network devices may use different sequence windows for inner and outer connection network traffic. To prevent overlapping sequence windows, transparent network devices monitor the locations of the inner and outer connection sequence windows and may rapidly advance the inner connection sequence window as needed.

Claims (66)

1. A method of initiating a connection between transparent network devices, the method comprising:

intercepting a first message from a client device and addressed to a server device, wherein the first message includes a first sequence number and is adapted to initiate a first connection between the client device and the server device;

creating a first modified version of the first message adapted to initiate a second connection with a transparent network device in addition to the first connection with the server;

sending the first modified version of the first message towards the server device;

intercepting a second message from the server device and addressed to the client device, wherein the second message is adapted to continue the initiation of the first connection between the client device and the server device;

determining if the second message was previously intercepted by the transparent network device; and

in response to the determination that the second message was previously intercepted by the transparent network device, sending a second modified version of the first message towards the server, wherein the second modified version of the first message is adapted to continue the initiation of the second connection with the transparent network device;

wherein the second modified version of the first message includes a source address, a destination address, and a sequence number equal to a source address, a destination address, and a sequence number included in the first modified version of the first message.

2. The method of claim 1 , comprising:

receiving a first modified version of the second message in response to sending the second modified version of the first message, wherein the first modified version of the second message is adapted to continue the initiation of the second connection with the transparent network device; and

sending an acknowledgement message towards the server, wherein the acknowledgement message is adapted to indicate the establishment of a portion of the first connection with the client and the establishment of the second connection with the transparent network device.

3. The method of claim 2 , wherein the first modified version of the second message includes a source address, a destination address, and a sequence number equal to a source address, a destination address, and a sequence number included in the second message.

4. The method of claim 3 , wherein determining if the second message was previously intercepted by the transparent network device comprises determining if the second message includes a transparent device parameter previously added to the second message by the transparent device.

5. The method of claim 1 , wherein the second modified version of the first message includes a source address, a destination address, and a sequence number equal to a source address, a destination address, and a sequence number included in the first message.

6. The method of claim 1 , wherein the first and second modified versions of the first message each include a client parameter equal to a client parameter included in the first message.

7. The method of claim 1 , wherein the first message includes a first source network port different than a second source network port included in the second modified version of the first message.

8. A method of initiating a connection between transparent network devices, the method comprising:

intercepting a first message from a client device and addressed to a server device, wherein the first message is adapted to initiate a first connection between the client device and the server device;

creating a first modified version of the first message adapted to initiate a second connection with a second transparent network device in addition to the first connection with the server;

sending the first modified version of the first message towards the server device;

intercepting a second message from the server device and addressed to the client device, wherein the second message is adapted to continue the initiation of the first connection between the client device and the server device;

determining if the second message was previously intercepted by the second transparent network device;

in response to the determination that the second message was previously intercepted by the second transparent network device, sending a third message adapted to reset at least a first portion of the first connection; and

sending a second modified version of the first message towards the server, wherein the second modified version of the first message is adapted to continue the initiation of the second connection with the transparent network device.

9. The method of claim 8 , comprising:

receiving a first modified version of the second message in response to sending the second modified version of the first message, wherein the first modified version of the second message is adapted to continue the initiation of the second connection with the transparent network device; and

sending an acknowledgement message towards the server, wherein the acknowledgement message is adapted to indicate the establishment of a portion of the first connection between the first transparent network device and the client and the establishment of the second connection with second transparent network device.

10. The method of claim 9 , wherein the second modified version of the first message includes a first sequence number different than a second sequence number included in the first modified version of the first message.

11. The method of claim 8 , wherein the second modified version of the first message includes a source address and a destination address equal to a source address and a destination address included in the first modified version of the first message.

12. The method of claim 8 , wherein the first portion of the first connection reset by the third message does not include a second portion of the first connection between the transparent network device and the server.

13. The method of claim 8 , wherein the first portion of the first connection reset by the second message does not include a second portion of the first connection between the transparent network device and the server.

14. A method of initiating a connection between transparent network devices, the method comprising:

intercepting a first message from a client device and addressed to a server device, wherein the first message is adapted to initiate a first connection between the client device and the server device;

creating a first modified version of the first message adapted to initiate a second connection with a second transparent network device in addition to the first connection with the server;

sending the first modified version of the first message towards the server device;

intercepting a second message from the server device and addressed to the client device, wherein the second message is adapted to reset at least a first portion of the first connection between the client device and the server device;

determining if the second message was created by the second transparent network device; and

in response to the determination that the second message was created by the second transparent network device, sending a second modified version of the first message towards the server, wherein the second modified version of the first message is adapted to continue the initiation of the second connection with the transparent network device.

15. The method of claim 14 , comprising:

receiving a third message in response to sending the second modified version of the first message, wherein the third message is adapted to continue the initiation of the second connection with the transparent network device; and

sending an acknowledgement message towards the server, wherein the acknowledgement message is adapted to indicate the establishment of a portion of the first connection between the first transparent network device and the client and the establishment of the second connection with second transparent network device.

16. The method of claim 15 , wherein the second modified version of the first message includes a source address and a destination address equal to a source address and a destination address included in the first modified version of the first message.

17. The method of claim 16 , wherein a first sequence number included in the first modified version of the first message is different than a second sequence number included in the second modified version of the first message.

18. A method of initiating a connection between transparent network devices, the method comprising:

intercepting a first message from a client device and addressed to a server device, wherein the first message includes a first connection parameter adapted to initiate a first network connection between the client device and the server device;

creating a first modified version of the first message including the first connection parameter and a second connection parameter adapted to initiate a second network connection with a transparent network device, wherein the second connection parameter is included in a transparency-unrelated portion of the first modified version of the first message;

sending the first modified version of the first message towards the server device;

intercepting a second message from the server device and addressed to the client device, wherein the second message is adapted to continue the initiation of the first network connection between the client device and the server device;

determining if the second message was previously intercepted by the transparent network device; and

in response to the determination that the second message was previously intercepted by the transparent network device, continuing the initiation of the second network connection.

19. The method of claim 18 , wherein determining if the second message was previously intercepted by the transparent network device comprises:

searching a transparency-unrelated portion of the second message for an indicator added to the second message by the transparent network device.

20. The method of claim 18 , comprising:

sending the second message towards the client device.

21. The method of claim 18 , comprising:

in response to the determination that the second message was previously intercepted by the transparent network device, sending a modified second message towards the client device.

22. The method of claim 18 , wherein the transparency-unrelated portion of the first modified message includes a protocol extension field.

23. The method of claim 22 , wherein the protocol extension field includes a TCP options field.

24. The method of claim 18 , wherein the transparency-unrelated portion of the first modified message includes a sequence number.

25. The method of claim 18 , wherein continuing the initiation of the second network connection comprises:

creating a third message adapted to continue the initiation of the second network connection with the transparent network device, wherein the third message includes a third connection parameter, wherein the third connection parameter is included in a transparency-unrelated portion of the third message; and

sending the third message towards the server device.

26. The method of claim 25 , wherein the third message is a second modified version of the first message including the first connection parameter.

27. The method of claim 26 , comprising:

sending a fourth message adapted to reset at least a first portion of the first network connection.

28. The method of claim 25 , wherein the third message is an acknowledgement message.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2010
From: DAY, MARK; MILLER, BRIAN; GUPTA, NITIN; LANDRUM, ALFRED; LAM, BLANCO ZEE LEUNG
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 024482/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2009
From: DAY, MARK; MILLER, BRIAN; GUPTA, NITIN; LANDRUM, ALFRED; LAM, BLANCO ZEE LEUNG
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 023678/0873 →