IP Library Granted Patent US 8,316,118
Granted Patent B1
US 8,316,118 · App. 13/082,186 · Granted Nov 20, 2012

Cooperative proxy auto-discovery and connection interception

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,316,118
App. No.
13/082,186
Granted
Nov 20, 2012
Kind
B1
Abstract

In a network supporting transactions between clients and servers and proxies that are interposable in a network path between at least one client and at least one server, wherein a pair of proxies can modify a packet stream between a client and a server such that packet data from the client to the server is transformed at a client-side proxy of the proxy pair and untransformed at a server-side proxy of proxy pair and such that packet data from the server to the client is transformed at the server-side proxy and untransformed at the client-side proxy, a method and apparatus for a discovering proxy to transparently discover its position in a proxy pair by using proxy signals to indicate to other proxies that could pair with the discovering proxy. A discovering proxy might determine that it is a client-side proxy by receipt of a packet from client without a proxy signal. A discovering proxy might determine that it is a server-side proxy by receipt of a packet from server without a return proxy signal. Once a proxy pair is discovered, that proxy pair might transform traffic from the server to the client or vice versa, transforming the traffic at one proxy of the proxy pair and untransforming the traffic at the other proxy of the pair.

Claims (31)

1. In a network supporting transactions between clients and servers, wherein clients have network nodes from which transactions are requested and servers have network nodes from which to issue responses responsive to client requests, wherein packets between a first client and a first server travel over a first network path that may include one or more additional nodes between a first client network node and a first server network node, a method of probing for node devices on a network path comprising:

receiving, at a first probe node in the network path, a first packet from a target client wherein the first packet is a packet directed at a target server;

modifying the first packet to signal presence of the first probe node in the network path, thus forming a modified first packet having therein a presence signal;

forwarding the modified first packet onto the network path, directed toward the target server;

monitoring, at the first probe node, a plurality of packets directed at the target client and associated with the target server to detect whether any packets of the plurality of packets contain return signals, wherein a return signal is a signal from a first device at a second probe node that detects the presence signal in the modified first packet and wherein a first return signal is an indication that the first device at the second probe node detected the presence signal as being a probing signal;

acting on a first successful probe if a responsive return signal is received corresponding to a presence signal sent from the first probe node;

updating a mapping table with results of the first successful probe; and

following a current connection, using a mapping from the mapping table in a later connection.

2. The method of claim 1 , wherein the acting on comprises recording the successful probe or otherwise altering a state of the first probe node.

3. The method of claim 1 , wherein modifying the first packet comprises adding an optional field to the first packet.

4. The method of claim 1 , wherein the first return signal is an added optional field in a return packet of the plurality of packets.

5. The method of claim 1 , further comprising:

following the first successful probe, intercepting client-server communications;

instantiating a connection between the first device at the second probe node that sent the return signal and a second device at the first probe node;

terminating client connections at the first probe node;

terminating server connections at the second probe node; and

transforming client-server traffic according to a protocol conversion.

6. The method of claim 5 , wherein the second device at the first probe node is a client-side proxy and the first device at the second probe node is a server-side proxy.

7. The method of claim 5 , wherein the protocol conversion is a segment cloning conversion.

8. The method of claim 1 , further comprising using the mapping table to transform and untransform data using segment cloning.

9. A networking device, having an interface to a network and a processor for processing packet data, the network supporting clients coupled to the network and servers coupled to the network, whereby clients request transactions and servers issue responses responsive to client requests, wherein packets between a first client and a first server travel over a first network path that may include the networking device between a first client network node and a first server network node, the networking device comprising:

logic to receive packets and identify, for a packet, a packet source and a packet destination,

logic for receiving a first packet from a target client wherein the first packet is a packet directed at a target server;

logic for modifying the first packet to signal presence of the first probe node in the network path, thus forming a modified first packet having therein a presence signal;

an interface for forwarding the modified first packet onto the network path, directed toward the target server;

storage for information about previously sent presence signals;

logic for determining when a received packet is a packet directed at the target client and associated with the target server and also contains a return signal, wherein a return signal is a signal from another device that indicates that the other device detected the presence signal;

logic for storing an indication of a successful probe, wherein a responsive return signal is received corresponding to the presence signal;

a mapping table for storing results of successful probes; and

logic to route packets in a later connection using a mapping from the mapping table.

10. The networking device of claim 9 , where the networking device is a network proxy device.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2011
From: DEMMER, MICHAEL J.; MCCANNE, STEVEN; LANDRUM, ALFRED
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 026093/0859 →