IP Library Granted Patent US 8,429,301
Granted Patent B2
US 8,429,301 · App. 12/785,364 · Granted Apr 23, 2013

Method and apparatus for resource locator identifier rewrite

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,301
App. No.
12/785,364
Granted
Apr 23, 2013
Kind
B2
Abstract

A method and apparatus for resource locator identifier rewrite have been presented. A security device receives from a resource host over a non-secure hypertext transfer protocol (HTTP) session a response to a request received from a client over a secure HTTP session. The response includes a uniform resource locator (URL) that is supposed to be for a resource host, but the URL does not designate a secure resource access protocol and the resource host requires the secure resource access protocol. The URL is located in the response and modified to designate the secure resource access protocol. After modification, the response is transmitted via the secure resource access protocol session to the client.

Claims (53)

1. A method for rewriting resource locator identifiers, the method comprising:

decrypting a request received from a client over a secure hypertext transfer protocol (HTTP) session;

forwarding the decrypted request to a resource host over a non-secure HTTP session;

receiving a response from the resource host over the non-secure HTTP session; and

determining whether a content type of the response is text,

wherein the response is sent directly to the client when the content type is not text, the response sent via the secure resource access protocol, and

wherein the response is modified when the content type is text, the modification comprising:

identifying one or more URLs in the response that does not designate the secure resource protocol;

modifying the URLs to designate the secure resource access protocol,

wherein the response including the modified URLs is sent via the secure resource access protocol session to the client.

2. The method of claim 1 , wherein the URL is modified when the response includes a header indicating “Content-Encoding”.

3. The method of claim 1 , wherein the modification further comprises removing from the response an indication that persistent connection is supported.

4. The method of claim 3 , wherein removing the indication from the response further comprises:

downgrading a version of HTTP indicated in a header of the response; and

modifying a connection field in the header or inserting a new field in the header.

5. The method of claim 1 , further comprising determining that a type of transfer encoding is supported by the resource host.

6. The method of claim 1 , wherein the modification further comprises removing from the response an indication that chunked transfer encoding is supported.

7. The method of claim 6 , wherein removing the indication from the response further comprises downgrading a version of HTTP indicated in a header of the response.

8. The method of claim 1 , wherein the modification further comprises modifying the request to indicate that the requesting client does not support chunked transfer encoding while preserving persistent connection and chunked transfer encoding in the response when the client supports persistent connection and chunked transfer encoding.

9. The method of claim 1 , wherein the modification further comprises modifying the response to prevent the client from using a content length indicated in the response.

10. A non-transitory machine-readable medium that provides instructions, executable by a set of one or more processors in a network security device to perform a method for rewriting resource locator identifiers, the method comprising:

decrypting a request received from a client over a secure hypertext transfer protocol (HTTP) session;

forwarding the decrypted request to a resource host over a non-secure HTTP session;

receiving a response from the resource host over the non-secure HTTP session; and

determining whether a content type of the response is text,

wherein the response is sent directly to the client when the content type is not text, the response sent via the secure resource access protocol and

wherein the response is modified when the content type is text, the modification comprising:

identifying one or more URLs in the response that does not designate the secure resource protocol;

modifying the URLs to designate the secure resource access protocol,

wherein the response including the modified URLs is sent via the secure resource access protocol session to the client.

11. The non-transitory machine-readable medium of claim 10 , wherein the URL is modified when the response includes a header indicating “Content-Encoding”.

12. The non-transitory machine-readable medium of claim 10 , further comprising executable instructions for removing from the response an indication that persistent connection is supported.

13. The non-transitory machine-readable medium of claim 12 , wherein removing the indication from the response further comprises:

downgrading a version of HTTP indicated in a header of the response; and

modifying a connection field in the header or inserting a new field in the header.

14. The non-transitory machine-readable medium of claim 10 , further comprising executable instructions for determining that a type of transfer encoding is supported by the resource host.

15. The non-transitory machine-readable medium of claim 10 , further comprising executable instructions for removing from the response an indication that chunked transfer encoding is supported.

16. The non-transitory machine-readable medium of claim 15 , wherein removing the indication from the response further comprises downgrading the version of HTTP indicated in a header of the response.

17. The non-transitory machine-readable medium of claim 10 , wherein the modification further comprises modifying the request to indicate that the requesting client does not support chunked transfer encoding while preserving persistent connection and chunked transfer encoding in the response when the client supports persistent connection and chunked transfer encoding.

18. The non-transitory machine-readable medium of claim 10 , wherein the modification further comprises modifying the response to prevent the client from using a content length indicated in the response.

19. A network security device comprising:

a set of one or more machine processors for executing instructions stored in memory to decrypt a request received from a client device over a secure hypertext transfer protocol (HTTP) session;

a set of one or more interfaces for:

forwarding the decrypted request to a resource host over a non-secure HTTP session; and

receiving a response from the resource host over the non-secure HTTP session, and

memory storing a resource access protocol module executable by one of the machine processors to:

determine whether a content type of the response is text,

wherein the response is sent directly to the client when the content type is not text, the response sent via the secure resource access protocol, and

wherein the response is modified when the content type is text, the modification comprising:

identifying one or more URLs in the response that does not designate the secure resource protocol;

modifying the URLs to designate the secure resource access protocol,

wherein the response including the modified URLs is sent via the secure resource access protocol session to the client.

20. The network security device of claim 19 , wherein the URL is modified when the response includes a header indicating “Content-Encoding”.

Assignments (21)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 029387 FRAME: 0390. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jul 9, 2021
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 056816/0250 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045818/0566 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT PATENT NO. 7752386 PREVIOUSLY RECORDED AT REEL: 037281 FRAME: 0007. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jan 11, 2018
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 045814/0740 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
CONVERSION AND NAME CHANGE Recorded Dec 14, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037282/0382 →
MERGER Recorded Dec 14, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037281/0007 →
CHANGE OF NAME Recorded Nov 30, 2012
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 029387/0455 →
MERGER Recorded Nov 30, 2012
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 029387/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2012
From: GMUENDER, JOHN E.; NGUYEN, HUY MINH; LEVY, JOSEPH H.; MASSING, MICHAEL B.; CHEN, ZHONG; TELEHOWSKI, DAVID M.
To: SONICWALL, INC.
Reel/Frame 029387/0240 →