IP Library Granted Patent US 9,197,606
Granted Patent B2
US 9,197,606 · App. 13/432,847 · Granted Nov 24, 2015

Monitoring network performance of encrypted communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,606
App. No.
13/432,847
Granted
Nov 24, 2015
Kind
B2
Abstract

According to one general aspect, a method of using a first probing device may include monitoring one or more encrypted communications sessions between a first computing device and a second computing device. In some implementations of the method, each encrypted communications session includes transmitting a plurality of encrypted data objects between the first and second computing devices. The method may include deriving, by the first probing device, timing information regarding an encrypted communications session. The method may also include transmitting, from the first probing device to a second probing device, the derived timing information.

Claims (63)

1. A method of using a first probing device, the method comprising:

monitoring one or more encrypted communications sessions between a first computing device and a second computing device, wherein each encrypted communications session includes transmitting a plurality of encrypted data objects between the first and second computing devices;

deriving, by the first probing device, timing information regarding an encrypted communications session including:

receiving an indication of a location within the encrypted communications session for which the timing information is to be derived, the location being indicated via a byte offset from a start of a portion of the encrypted communications session;

determining when the indicated location has been received including determining a byte range within the encrypted communications session associated with an encrypted data object;

comparing the byte range associated with the encrypted data object to the byte offset; and

transmitting, from the first probing device to a second probing device, the derived timing information.

2. The method of claim 1 , further including:

decrypting, by the second probing device, at least a portion of the encrypted communications session; and

creating a set of metrics related to the encrypted communications session based upon the decrypted portion of the encrypted communications session and the derived timing information.

3. The method of claim 2 , wherein a data message is included within a first encryption envelope included by the encrypted communications session; and

wherein creating a set of metrics includes:

correlating a start of the data message with the derived timing information, provided by the first probing device, indicating the timing of a start the encryption envelope, and

correlating an end of the data message with the derived timing information, provided by the first probing device, indicating the timing of an end the encryption envelope.

4. The method of claim 1 , wherein deriving the timing information includes:

determining a start of an encryption envelope included by the encrypted communications session; and

determining an end of the encryption envelope.

5. The method of claim 1 , wherein the encrypted communications session includes data objects that are both compressed and encrypted; and

further including:

receiving the indication, by the first probing device and from the second probing device, of the location within the encrypted communications session for which the timing information is to be derived.

6. The method of claim 1 , wherein the encrypted communications session includes one or more encryption envelopes; and

wherein deriving the timing information includes:

basing the timing information on a timestamp associated with the encrypted envelopes.

7. The method of claim 1 , wherein deriving the timing information includes:

ignoring, for purposes of deriving the timing information, one or more received encrypted data objects included by the encrypted communications session that are indicated, by the first computing device, as ignorable.

8. A system comprising:

a first network tap point configured to duplicate, in a non-intrusive manner, at least part of an encrypted network communication transmitted to and from an access point device that forms the boundary between a first network and a second network;

a second network tap point configured to duplicate, in a non-intrusive manner, at least part of an encrypted network communication transmitted to and from a server computing device placed within, in a network topology sense, the second network;

a client-side probing device configured to:

monitor encrypted communications sessions between the server computing device and the client computing device, wherein each encrypted communications session includes transmitting a plurality of encrypted data objects between the server and client computing devices;

derive timing information regarding an encrypted communications session based upon one or more received encrypted data objects included by the encrypted communications session, including,

receive an indication of a location within the encrypted communications session for which the timing information is to be derived, the location being indicated via a byte offset from a start of a portion of the encrypted communications session;

determine when the indicated location has been received including determine a byte range within the encrypted communications session associated with an encrypted data object;

compare the byte range associated with the encrypted data object to the byte offset; and

transmit, to a server-side probing device, the derived timing information.

9. The system of claim 8 , further including a server-side probing device configured to:

decrypt at least a portion of the encrypted communications session; and

create a set of metrics related to the encrypted communications session based upon the decrypted portion of the encrypted communications session and the derived timing information.

10. The system of claim 9 , wherein the encrypted communications session includes at least one encryption envelope, wherein the encryption envelope includes a data message; and

wherein the server-side probing device is configured to:

correlate a start of the data message with the derived timing information, provided by the first probing device, indicating the timing of a start the encryption envelope, and

correlate an end of the data message with the derived timing information, provided by the first probing device, indicating the timing of an end the encryption envelope.

11. The system of claim 8 , wherein the client-side probing device is configured to:

determine a start of an encryption envelope included by the encrypted communications session; and

determine an end of the encryption envelope.

12. The system of claim 8 , wherein the client-side probing device is configured to:

store a timestamp associated with the received indicated location within the encrypted communications session.

13. The system of claim 8 , wherein the encrypted communications session includes data objects that are both compressed and encrypted; and

wherein the client-side probing device is configured to:

receive the indication, from a server-side probing device, of the location within the encrypted communications session for which the timing information is to be derived.

14. The system of claim 8 , wherein the client-side probing device is configured to:

base the timing information on a timestamp associated with the encrypted communications session as a whole instead of a timestamp associated with one of the encrypted data objects.

15. The system of claim 8 , wherein the client-side probing device is configured to:

ignore, for purposes of deriving the timing information, one or more received encrypted data objects included by the encrypted communications session that are indicated, by the first computing device, as ignorable.

16. A computer program product for managing a network, the computer program product being tangibly embodied on a non-transitory computer-readable medium and including executable code that, when executed, is configured to cause an apparatus to:

monitor encrypted communications sessions between a first computing device and a second computing device, wherein each encrypted communications session includes transmitting a plurality of encrypted data objects between the first and second computing devices;

derive, by the apparatus, timing information regarding an encrypted communications session based upon one or more received encrypted data objects included by the encrypted communications session; and

transmit, from the apparatus to a second apparatus, the derived timing information,

wherein the executable code is configured to, when executed, cause the apparatus to:

receive an indication, from a second apparatus, of a location within the encrypted communications session for which the timing information is to be derived;

for each received encrypted data packet, determine if the received encrypted data object is included with the indicated encrypted communications session;

determine the byte range within the encrypted communications session associated with the received encrypted data object; and

compare the byte range associated with the received encrypted data object to the indicated byte offset.

Assignments (16)
CHANGE OF NAME Recorded Jan 10, 2025
From: BLADELOGIC, INC.
To: BMC HELIX, INC.
Reel/Frame 069870/0796 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Jul 27, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043351/0189 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2017
From: BMC SOFTWARE, INC.
To: BLADELOGIC, INC.
Reel/Frame 042749/0439 →
SECURITY AGREEMENT Recorded Sep 11, 2013
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 031204/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2012
From: DESCHENES, DANNY; HSY, JOE; LAROSE, PIERRE
To: BMC SOFTWARE, INC.
Reel/Frame 028463/0702 →