IP Library Granted Patent US 8,386,637
Granted Patent B2
US 8,386,637 · App. 13/410,032 · Granted Feb 26, 2013

Connection forwarding

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,386,637
App. No.
13/410,032
Granted
Feb 26, 2013
Kind
B2
Abstract

Two or more network traffic processors connected with the same LAN and WAN are identified as neighbors. Neighboring network traffic processors cooperate to overcome asymmetric routing, thereby ensuring that related sequences of network traffic are processed by the same network proxy. A network proxy can be included in a network traffic processor or as a standalone unit. A network traffic processor that intercepts a new connection initiation by a client assigns a network proxy to handle all messages associated with that connection. The network traffic processor conveys connection information to neighboring network traffic processors. The neighboring network traffic processors use the connection information to redirect network traffic associated with the connection to the assigned network proxy, thereby overcoming the effects of asymmetric routing. The assigned network proxy handles redirected network traffic in much the same way that it would handle network traffic received directly.

Claims (92)

1. A system, comprising:

a first initiation-side proxy and a second initiation-side proxy;

the first initiation-side proxy comprising:

a) one or more processors;

b) a first network interface, for receiving information at the first initiation-side proxy;

c) logic configured to receive, directly or indirectly via the first network interface, first connection setup information for a first connection being set up between a client and a server; and

d) logic configured to send, to the second initiation-side proxy, second connection setup information, wherein the second connection setup information comprises at least a portion of the first connection setup information; and

the second initiation-side proxy comprising:

a) one or more processors;

b) a second network interface, for receiving information at the second initiation-side proxy;

c) logic configured to store the second connection setup information; and

d) logic configured to receive, directly or indirectly via the second network interface: (1) connection setup response information, and (2) response-side proxy-identifying information that indicates the presence of a response-side proxy; and

e) logic configured to forward, based at least in part on the stored second connection setup information, both the connection setup response information and the response-side proxy-identifying information from the second initiation-side proxy to the first initiation-side proxy;

wherein the first initiation-side proxy further comprises logic configured to establish a second connection between the first initiation-side proxy and the response-side proxy based at least in part on the response-side proxy-identifying information and in response to receiving the connection setup response information.

2. The system of claim 1 , wherein the first initiation-side proxy further comprises logic configured to proxy the one or more messages over the second connection in response to receiving one or more messages from the client to the server at the first initiation-side proxy, wherein proxying the one or more messages comprises sending representations of the one or messages over the second connection to the response-side proxy.

3. The system of claim 1 , wherein the forwarded connection setup response information comprises at least one of:

1) at least a portion of a message received by the second initiation-side proxy encapsulated using a tunneling protocol;

2) a message having a modified destination address relative to an initial destination address as received by the second initiation-side proxy; and

3) a payload extracted from a message received by the second initiation-side proxy.

4. The system of claim 1 , further comprising:

logic, of the second initiation-side proxy, configured to receive third connection setup information for a third connection being set up between a second client and a second server;

logic, of the second initiation-side proxy, configured to send, to the first initiation-side proxy, fourth connection setup information, wherein the fourth connection setup information comprises at least a portion of the third connection setup information;

logic, of the first initiation-side proxy, configured to store the fourth connection setup information;

logic, of the first initiation-side proxy, configured to receive: (1) second connection setup response information, and (2) second response-side proxy-identifying information that indicates the presence of a second response-side proxy;

logic, of the first initiation-side proxy, configured to forward both the second connection setup response information and the second response-side proxy-identifying information from the first initiation-side proxy to the second initiation-side proxy based at least in part on the stored fourth connection setup information; and

logic, of the second initiation-side proxy, configured to establish a fourth connection between the second initiation-side proxy and the second response-side proxy based at least in part on the second response-side proxy-identifying information and in response to receiving the second connection setup response information.

5. The system of claim 1 , wherein the first response-side proxy is a different response-side proxy than the second response-side proxy.

6. The system of claim 1 , wherein the first initiation-side proxy includes logic configured to maintain a connection state internally based on the connection setup response information, the connection state corresponding to a connection between the first initiation-side proxy and the first response-side proxy as if the connection setup response information sent from the second initiation-side proxy to the first initiation-side proxy had been received at the first initiation-side proxy from the first response-side proxy.

7. A method, comprising:

receiving, directly or indirectly via a first network interface, at a first initiation-side proxy comprising one or more processors, first connection setup information for a first connection being set up between a client and a server; and

sending, to a second initiation-side proxy comprising one or more processors, second connection setup information, wherein the second connection setup information comprises at least a portion of the first connection setup information;

storing, at the second initiation-side proxy, the second connection setup information;

receiving, directly or indirectly via a second network interface, at the second initiation-side proxy: (1) connection setup response information, and (2) response-side proxy-identifying information that indicates the presence of a response-side proxy;

forwarding, based at least in part on the stored second connection setup information, both the connection setup response information and the response-side proxy-identifying information from the second initiation-side proxy to the first initiation-side proxy; and

establishing a second connection between the first initiation-side proxy and the response-side proxy based at least in part on the response-side proxy-identifying information and in response to receiving the connection setup response information.

8. The method of claim 7 , further comprising:

proxying the one or more messages over the second connection in response to receiving one or more messages from the client to the server at the first initiation-side proxy, wherein proxying the one or more messages comprises sending representations of the one or messages over the second connection to the response-side proxy.

9. The method of claim 7 , wherein forwarding the connection setup response information to the first initiation-side proxy comprises at least one of:

1) encapsulating at least a portion of a message received by the second initiation-side proxy using a tunneling protocol;

2) modifying a destination address of a message received by the second initiation-side proxy; and

3) extracting the payload from a message received by the second initiation-side proxy and sending the payload to the first initiation-side proxy.

10. The method of claim 7 , further comprising:

receiving, at the second initiation-side proxy, third connection setup information for a third connection being set up between a second client and a second server;

sending, from the second initiation-side proxy to the first initiation-side proxy, fourth connection setup information, wherein the fourth connection setup information comprises at least a portion of the third connection setup information;

storing, at the first initiation-side proxy, the fourth connection setup information;

receiving, at the first initiation-side proxy: (1) second connection setup response information, and (2) second response-side proxy-identifying information that indicates the presence of a second response-side proxy;

forwarding both the second connection setup response information and the second response-side proxy-identifying information from the first initiation-side proxy to the second initiation-side proxy based at least in part on the stored fourth connection setup information; and

establishing a fourth connection between the second initiation-side proxy and the second response-side proxy based at least in part on the second response-side proxy-identifying information and in response to receiving the second connection setup response information.

11. The method of claim 7 , wherein the first response-side proxy is a different response-side proxy than the second response-side proxy.

12. The method of claim 7 , further comprising:

maintaining, at the first initiation-side proxy, a connection state internally based on the connection setup response information, the connection state corresponding to a connection between the first initiation-side proxy and the first response-side proxy as if the connection setup response information sent from the second initiation-side proxy to the first initiation-side proxy had been received at the first initiation-side proxy from the first response-side proxy.

13. A system, comprising:

a first device and a second device,

the first device comprising:

a) one or more processors;

b) a first network interface, for receiving information at the first device;

c) logic configured to receive, directly or indirectly via the first network interface, first connection setup information for a first connection being set up between a first host and a second host; and

d) logic configured to send, to the second device, second connection setup information, wherein the second connection setup information comprises at least a portion of the first connection setup information; and

the second device, comprising:

a) one or more processors;

b) a second network interface, for receiving information at the second device;

c) logic configured to store, in a memory, the second connection setup information;

d) logic configured to receive, directly or indirectly via the second network interface, connection setup response information;

e) logic configured to forward the connection setup response information to the first device based at least in part on the stored second connection setup information;

f) logic configured to receive, directly or indirectly via the second network interface or another network interface, device identifying information that indicates the presence of a third device; and

g) logic configured to forward the device identifying information from the second device to the first device based at least in part on the stored second connection setup information.

14. The system of claim 13 , wherein the first device further comprises:

e) logic configured to establish a second connection between the first device and the third device based at least in part on the device identifying information and in response to receiving the connection setup response information.

15. The system of claim 13 , wherein the first host is a client that issues requests and the second host is a server that responds to client requests.

16. The system of claim 13 , wherein the second host is a client that issues requests and the first host is a server that responds to client requests.

17. The system of claim 13 , wherein the first device and the second device are proxies.

18. The system of claim 13 , wherein the first device and the second device are routers.

19. The system of claim 13 , wherein the first device and the second device are interceptors.

20. The system of claim 13 , wherein the first host is an initiator of a transaction and the second host is a responder to the transaction.

21. The system of claim 13 , wherein forwarding the connection setup response information is performed in response to a match between a connection identifier obtained at the first device as part of setup of the first connection and a connection identifier obtained at the second device as part of the connection setup response information.

22. A method, performed by one or more computing devices having network connectivity, comprising:

receiving, directly or indirectly via a first network interface, at a first device, first connection setup information for a first connection being set up between a first host and a second host;

sending, from the first device to the second device, second connection setup information, wherein the second connection setup information comprises at least a portion of the first connection setup information;

storing, at the second device, the second connection setup information;

receiving, directly or indirectly via a second network interface, at the second device, connection setup response information;

based at least in part on the stored second connection setup information, forwarding, from the second device to the first device, the connection setup response information;

receiving, directly or indirectly via the second network interface or another network interface, at the second device, device identifying information that indicates the presence of a third device; and

based at least in part on the stored second connection setup information, forwarding the device identifying information from the second device to the first device.

23. The method of claim 22 , the method further comprising:

in response to receiving the connection setup response information and the device identifying information at the first device, establishing a second connection between the first device and the third device based at least in part on the device identifying information.

24. The method of claim 22 , wherein the first host is a client that issues requests and the second host is a server that responds to client requests.

25. The method of claim 22 , wherein the second host is a client that issues requests and the first host is a server that responds to client requests.

26. The method of claim 22 , wherein the first device and the second device are proxies.

27. The method of claim 22 , wherein the first device and the second device are routers.

28. The method of claim 22 , wherein the first device and the second device are interceptors.

29. The method of claim 22 , wherein the first host is an initiator of a transaction and the second host is a responder to the transaction.

30. The method of claim 22 , wherein forwarding the connection setup response information is performed in response to a match between a connection identifier obtained at the first device as part of setup of the first connection and a connection identifier obtained at the second device as part of the connection setup response information.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →