IP Library Granted Patent US 8,732,796
Granted Patent B1
US 8,732,796 · App. 13/688,690 · Granted May 20, 2014

Addressing security in asymmetrical networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,796
App. No.
13/688,690
Granted
May 20, 2014
Kind
B1
Abstract

Security in an asymmetrical network is addressed. At a security element, a handshake message is received on a path within the asymmetrical network. The handshake message is associated with an attempt to establish a session. A determination is made as to whether there is an entry for the handshake message in a local state table. When there is no entry in the local state table, then an entry is generated in the local state table, a notification of the handshake message is sent to a centralized computing platform that tracks handshake messages received by a plurality of security elements in the asymmetrical network, and the handshake message is allowed to pass along the path. A notification is received from the centralized computing platform that the session associated with the handshake message is allowed, based on associated handshake messages received at the centralized computing platform.

Claims (35)

1. One or more nontransitory computer-readable media having embodied thereon computer-useable instructions that, when executed by a computing device, facilitate a method for addressing security in a TCP-based asymmetrical network having a plurality of paths, the method comprising:

at a security element, receiving a first handshake message on a path within the asymmetrical network, wherein the first handshake message is associated with an attempt to establish a first session;

determining whether there is an entry for the first handshake message in a local state table associated with the security element;

when there is no entry in the local state table for the first handshake message, then

A) generating an entry in the local state table for the first handshake message,

B) sending a notification of the first handshake message to a centralized computing platform that tracks handshake messages received by a plurality of security elements in the asymmetrical network, and

C) allowing the first handshake message to pass along the path.

2. The media of claim 1 , the method further comprising when there is an entry in the local state table for the SYN handshake message, then dropping the handshake message.

3. The media of claim 1 , the method further comprising receiving a notification from the centralized computing platform that a session associated with the handshake message is allowed, based on associated handshake messages received at the centralized computing platform.

4. The media of claim 3 , the method further comprising in response to receiving the notification from the centralized computing platform that a session associated with the handshake message is allowed, storing an indication that the session associated with the handshake message is allowed, wherein messages associated with the allowed session are permitted to pass along the path.

5. The media of claim 1 the method further comprising:

at the security element, receiving a second handshake message on the path within the asymmetrical network, wherein the second handshake message is associated with an attempt to establish a second session;

sending a notification of the second handshake message to the centralized computing platform;

when there is already an entry for the second handshake message in a session table associated with the central computing device, then dropping the second handshake message.

6. A security element for addressing security in a TCP-based asymmetrical network having a plurality of paths, the security element comprising:

the security element configured to

A) receive a handshake message along a path in the asymmetrical network, wherein the handshake message is associated with an attempt to establish a session,

B) store an entry for the handshake message in a local session table,

C) send a notification of the handshake message to a centralized computing device that tracks handshake messages received by a plurality of security elements in the asymmetrical network,

D) receive a notification from the central computing device that the session is allowed, and

E) permit packets associated with the session to pass along the path based on the notification from the central computing device that the session is allowed.

7. The security element of claim 6 , further comprising the security element configured to drop a given handshake message when an entry for the given handshake message is already stored in the local state table.

8. The security element of claim 6 , further comprising the security element configured to drop a given handshake message when an entry for the given handshake message is already stored in a state table associated with the centralized computing device.

9. The security element of claim 6 , wherein the notification from the central computing device that the session is allowed is based on handshake messages tracked by the central computing device.

10. One or more nontransitory computer-readable media having embodied thereon computer-useable instructions that, when executed by a computing device, facilitate a method for addressing security in a TCP-based asymmetrical network having a plurality of paths, the method comprising:

at a security element, receiving a SYN handshake message on a path within the asymmetrical network;

determining whether there is an entry for the SYN handshake message in a local state table associated with the security element;

when there is no entry in the local state table for the SYN handshake message, then

A) generating an entry in the local state table for the SYN,

B) sending a notification of the SYN handshake message to a centralized computing platform that tracks handshake messages received by a plurality of security elements in the asymmetrical network, and

C) allowing the handshake message to pass along the path.

11. The media of claim 10 , the method further comprising when there is an entry in the local state table for the SYN handshake message, then dropping the SYN handshake message.

12. The media of claim 10 , the method further comprising receiving a notification from the centralized computing platform that a session associated with the SYN handshake message is allowed.

13. The media of claim 12 , wherein the notification from the centralized computing platform that the session associated with the SYN handshake message is allowed is based on associated handshake messages received at the centralized computing platform.

14. The media of claim 12 , the method further comprising in response to receiving the notification from the centralized computing platform that a session associated with the SYN handshake message is allowed, storing an indication that the session associated with the SYN handshake message is allowed, wherein messages associated with the allowed session are permitted to pass along the path.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2012
From: ATIEH, EZZAT; MOHIUDDIN, MOHAMMED; JAFARI, REZA
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 029375/0646 →