IP Library Patent Application 12718565
Patent Application
App. No. 12/718,565

SECURE CONNECTION INITIATION WITH HOSTS BEHIND FIREWALLS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/718,565
Abstract

The invention is directed to an inter-host signaling protocol, referred to herein as Knock-On Protocol (KOP), for establishing in a secure manner a connection with a host behind firewall. Some embodiments of the invention are directed to a Knock-On Feature (KOF) used in intermediate firewalls or network address translators to enable connection establishment through the FW or NAT to hosts behind the FW or NAT. Advantageously the KOF may include a prefix-based protection feature to protect against address spoofing used in a message flood attack.

Claims (60)

1 . A method of establishing a connection between a first host system and a second host system through a firewall protecting the second host system, comprising:

performing by a knock-on-feature (KOF) apparatus the steps of:

receiving a first message sent by the first host system;

determining the first message is of a first type for establishing the connection between the first host system and a second host system;

determining respective addresses of the first and second hosts systems from the first message;

determining if any state information exists on the KOF apparatus for a 2-tuple corresponding to the addresses of the first and second host systems; and

sending the first message to the first host system if no said state information for the 2-tuple exists on the KOF apparatus.

2 . The method of claim 1 wherein the step of sending comprises initializing and starting a first timer for the 2-tuple.

3 . The method of claim 2 wherein the step of sending further comprises initializing and incrementing a message counter for the 2-tuple.

4 . The method of claim 3 further comprising:

checking the first timer if said state information for the 2-tuple exists on the KOF apparatus; and

removing said state information on the KOF apparatus if the first timer has expired.

5 . The method of claim 4 further comprising performing the following steps if said state information for the 2-tuple exists on the KOF apparatus:

checking a count of the message counter;

starting a second timer for the 2-tuple and dropping the first message if the count has reached a predetermined value; and

sending the first message to the second host system if the count has not reached the predetermined value.

6 . The method of claim 5 further comprising performing the following steps if said state information for the 2-tuple exists on the KOF apparatus:

checking the second timer;

dropping the first message if the second timer has not expired; and

removing all said state information for the 2-tuple on the KOF apparatus if the second timer has expired.

7 . The method of claim 6 further comprising:

receiving a second message sent by the second host system;

determining that the second message is of a second type for requesting information from the first host system in response to the first message; and

sending the second message to the first host system.

8 . The method of claim 1 further comprising:

determining an amount of state information existing on the KOF apparatus with respect to the second host system; and

combining, responsive to the amount exceeding a predetermined maximum, state information of two host system pairs, each pair comprising the second host system and another host system that is different in each pair, into state information for one host system pair comprising the address of the second host system and an address prefix common to respective addresses of the other host systems of the two host system pairs.

9 . The method of claim 8 further comprising:

setting a combined timer for said one host system pair to a minimum of respective first timers of the two host system pairs; and

setting a combined message counter for said one host system pair to a maximum of respective message counters for the two host system pairs.

10 . The method of claim 1 further comprising:

receiving a third message sent by the second host system;

determining the third message is of a third type for terminating the connection between the first and second host systems; and

removing from the KOF, responsive to receiving the third type of message, 5-tuple state information for the 2-tuple, the 5-tuple state information including in addition to the 2-tuple and with respect to the connection: an indication of protocol type, an indication of a first port of the first host system, and an indication of a second port of the second host system.

11 . The method of claim 10 , where the KOF apparatus is part of the firewall, the method further comprises:

receiving a fourth message sent by the second host system;

determining the fourth message is of a fourth type for initiating the connection responsive to the first message; and

starting a third timer with respect to the 5-tuple.

12 . The method of claim 11 further comprising:

receiving communication traffic sent by the first host system and destined to the second host system;

checking the third timer;

determining if state information for the 5-tuple exists on the firewall; and

passing the communication traffic responsive to the third timer having not expired and responsive to the state information for the 5-tuple existing on the firewall.

13 . The method of claim 5 , where the KOF apparatus is external to and in series with the firewall, the method further comprises:

checking the second timer;

dropping the first message if the second timer has not expired;

removing, if the second timer has expired, all said state information for the 2-tuple on the KOF apparatus including 5-tuple state information for the 2-tuple, the 5-tuple state information including in addition to the 2-tuple and with respect to the connection: an indication of protocol type, an indication of a first port of the first host system, and an indication of a second port of the second host system.

14 . The method of claim 1 , where the KOF apparatus is part of a relay server that is external to the firewall, the step of receiving comprises receiving the first message over a prior established first signaling connection between the first host system and the relay server; and the step of sending comprises sending the first message to the second host system over a prior established signaling connection between the second host system and the relay server.

15 . The method of claim 1 , wherein the step of sending further comprises:

creating on the KOF a 2-tuple entry corresponding to the addresses of the first and second host systems; and

setting that 2-tuple entry to a pass state.

16 . The method of claim 10 , wherein removing further comprises:

creating on the KOF a 2-tuple entry corresponding to the addresses of the first and second host systems; and

setting that 2-tuple entry to a block state.

17 . The method of claim 1 further comprising:

determining an amount of state information existing on the KOF apparatus with respect to the first host system; and

combining, responsive to the amount exceeding a predetermined maximum, state information of two host system pairs, each pair comprising the first host system and another host system that is different in each pair, into state information for one host system pair comprising the address of the second host system and an address prefix common to respective addresses of the other host systems of the two host system pairs.

18 . A firewall comprising a knock-on-feature (KOF) apparatus for performing the method of claim 1 .

19 . A relay server comprising a knock-on-feature (KOF) apparatus for performing the method of claim 1 .

20 . A knock-on-feature (KOF) system for performing the method of claim 1 .

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2011
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 026712/0415 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2011
From: ALCATEL-LUCENT IRELAND LTD.
To: ALCATEL LUCENT
Reel/Frame 026117/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2010
From: HAMPEL, KARL GEORG
To: ALCATEL-LUCENT USA, INC.
Reel/Frame 024037/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2010
From: CHERUBINI, DAVIDE; RAZAVI, ROUZBEH
To: ALCATEL-LUCENT IRELAND LTD.
Reel/Frame 024037/0369 →