IP Library › Granted Patent US 7,995,594
Granted Patent B2
US 7,995,594 · App. 12/643,707 · Granted Aug 9, 2011

Protocol and system for firewall and NAT traversal for TCP connections

Assignee: NETGEAR, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,995,594
App. No.
12/643,707
Granted
Aug 9, 2011
Kind
B2
Abstract

Embodiments of this invention provides a system and a protocol to enable two transmission control protocol TCP peers that exist behind one or more firewalls and network address translators NATs to automatically setup a true peer-to-peer TCP connection and exchange data without making changes to the firewall or NAT devices or existing TCP-based applications. In embodiments of this invention, the synchronization between the blind TCP peers is achieved using a system that consists of a registration server, an agent application, and a virtual network interface that together relay and replicate the control signals between the two TCP peers. In addition, embodiments of this invention are also used to traverse the NAT and establish a bi-directional peer-to-peer TCP connection in the firewall.

Claims (22)

1. A method of establishing an end-to-end TCP connection between two peers separated by at least one firewall, comprising the steps of:

setting up a control channel between the two TCP peers by operation of a Registration Server;

probing each of the two TCP peers for an IP address and a port identifier;

instructing a TCP layer in each of the two TCP peers to open a TCP connection using the IP address and the port identifier;

using an Agent Application to relay a TCP three-way handshaking control message sequence between the two TCP peers using the control channel;

using a Virtual Network Interface to reconstruct the TCP three-way handshaking control message sequence;

using the Virtual Network Interface to pass the TCP three-way handshaking control message sequence into a TCP/IP protocol stack on each of the two TCP peers; and

establishing a TCP connection in the firewall.

2. A method of establishing an end-to-end TCP connection between two peers, comprising the steps of:

setting up a control channel between the two TCP peers;

instructing a TCP layer in each of the two TCP peers to open a TCP connection;

relaying a TCP three-way handshaking control message sequence between the two TCP peers using the control channel;

reconstructing the TCP three-way handshaking control message sequence;

passing the TCP three-way handshaking control message sequence into a TCP/IP protocol stack on each of the two TCP peers; and

establishing a TCP connection between the peers.

3. A system for establishing an end-to-end TCP connection between two peers separated by at least one firewall, comprising:

means for setting up a control channel between the two TCP peers;

means for instructing a TCP layer in each of the two TCP peers to open a TCP connection;

means for relaying a TCP three-way handshaking control message sequence between the two TCP peers using the control channel;

means for reconstructing the TCP three-way handshaking control message sequence;

means for passing the TCP three-way handshaking control message sequence into a TCP/IP protocol stack on each of the two TCP peers; and

means for establishing a TCP connection in the firewall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2010
From: LEAF NETWORKS, LLC
To: NETGEAR, INC.
Reel/Frame 023839/0639 →
Continuity (3)
Continuation 11260921 · Oct 27, 2005
Provisional Application 60659556 · Mar 8, 2005
Related Publication 20100153560A1 · Jun 17, 2010