IP Library Granted Patent US 9,332,091
Granted Patent B2
US 9,332,091 · App. 13/867,499 · Granted May 3, 2016

Address manipulation to provide for the use of network tools even when transaction acceleration is in use over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,332,091
App. No.
13/867,499
Granted
May 3, 2016
Kind
B2
Abstract

In address-manipulation enabled transaction accelerators, the transaction accelerators include outer-connection addressing information in packets emitted over an inner connection between transaction accelerators and inner-connection addressing information is added in packets sent over the inner connection. The inner-connection addressing information can be carried in TCP option fields, directly in other fields, or indirectly through data structures maintained by the endpoints processing the connection. Address information can be encoded into header fields originally intended for other purposes but that are unused or encoded into used fields, overlaid in combination with other data that is being carried in those used fields. The existence of inner-connection addressing information in a packet can be signaled by a flag in the packet, by a bit or other designated encoding. The flag can be in an unused header field or overlaid. Where replacement and option addition is needed, swappers and unswappers might be used.

Claims (54)

1. A method of indicating addressing information in network traffic transmitted over a proxied connection between a client and a server, the method comprising:

associating a first transport connection with a second transport connection, wherein the second transport connection comprises a proxy connection;

determining source and destination network addresses of the first transport connection; and

recording, in at least one packet transported over the second transport connection, the source and destination network addresses of the first transport connection, wherein:

(a) the first transport connection carries unaccelerated network traffic between the client and a client-side proxy; and

(b) the second transport connection carries accelerated network traffic between the client-side proxy and a server-side proxy, wherein at least some of the accelerated network traffic contains payload data or whole messages that appear different from corresponding unaccelerated network traffic that was transformed to obtain the accelerated network traffic.

2. The method of claim 1 , further comprising:

detecting, at a network element, a packet transported over the second transport connection; and

determining whether the detected packet includes recorded source and destination addresses of the first transport connection.

3. The method of claim 2 , further comprising using the recorded source and destination addresses by network tools to differentiate packets.

4. The method of claim 2 , wherein the network tools comprise at least one process from the group consisting of a traffic classification process, a filtering policy process, a quality of service (“QoS”) enforcement policy, and an access control list policy process.

5. The method of claim 2 , further comprising using the recorded source and destination addresses to update state of a network monitoring process upon determining that the detected packet includes recorded addresses.

6. The method of claim 5 , wherein the network monitoring process comprises a traffic measurement process.

7. The method of claim 1 , further comprising:

determining source and destination ports of the first transport connection; and

recording, in at least one packet transported over the second transport connection, the source and destination ports of the first transport connection.

8. The method of claim 7 , further comprising:

detecting, at a network element, a packet transported over the second transport connection;

determining whether the detected packet includes at least one or more of a set of recorded source and destination addresses of the first transport connection or a set of recorded source and destination ports of the first transport connection.

9. The method of claim 8 , wherein a network tool comprises a quality of service enforcement process that uses at the least one of the set of recorded source and destination addresses or the set of recorded source and destination ports, to enforce a QoS policy.

10. The method of claim 8 , wherein a network tool comprises a process that uses the at least one of the set of recorded source and destination addresses or the set of recorded source and destination ports, to perform one process from the group consisting of a traffic classification process, a filtering policy process and an access control list policy process.

11. The method of claim 8 , further comprising using the set of recorded source and destination addresses or the set of recorded source and destination ports, to update the state of a network monitoring process.

12. The method of claim 11 , wherein the network monitoring process comprises a traffic measurement process.

13. A method of indicating addressing information in network traffic transported over a proxied connection between a client and a server, the method comprising:

associating a first transport connection with a second transport connection, wherein the second transport connection comprises a proxy connection;

determining source and destination ports of the first transport connection; and

recording, in at least one packet transmitted over the second transport connection, the source and destination ports of the first transport connection, wherein:

the first transport connection carries unaccelerated network traffic between the client and a client-side proxy; and

the second transport connection carries accelerated network traffic between the client-side proxy and a server-side proxy, wherein at least some of the accelerated network traffic contains payload data or whole messages that appear different from corresponding unaccelerated network traffic that was transformed to obtain the accelerated network traffic.

14. The method of claim 1 , wherein a third transport connection carries unaccelerated network traffic between the server-side proxy and the server.

15. A non-transitory computer-readable medium tangibly embodying a program of machine-readable instructions executable by a digital processing apparatus having stored thereon instructions, comprising:

program code for reading packet headers, wherein at least a plurality of packet headers include network addressing information for use in network traffic transmitted over a proxied connection between a client and a server;

program code for associating a first transport connection with a second transport connection, wherein:

the second transport connection comprises a proxy connection;

the first transport connection is configured to carry unaccelerated network traffic between the client and a client-side proxy; and

the second transport connection is configured to carry accelerated network traffic between the client-side proxy and a server-side proxy, wherein at least some of the accelerated network traffic contains payload data or whole messages that appear different from corresponding unaccelerated network traffic that was transformed to obtain the accelerated network traffic;

program code for determining source and destination network addresses of the first transport connection; and

program code for recording, in at least one packet transported over the second transport connection, both the source and destination network addresses of the first transport connection.

16. The non-transitory computer-readable medium 15 , further comprising:

program code for detecting, at a network element, a packet transported over the second transport connection; and

program code for determining whether the detected packet includes recorded source and destination addresses of the first transport connection.

17. The non-transitory computer-readable medium of claim 16 , further comprising program code for using the recorded source and destination addresses by network tools to differentiate packets.

18. The non-transitory computer-readable medium of claim 17 , wherein the network tools comprise at least one process from the group consisting of a traffic classification process, a filtering policy process, a quality of service (“QoS”) enforcement policy, and an access control list policy process.

19. The non-transitory computer-readable medium of claim 16 , further comprising program code for using the recorded source and destination addresses to update state of a network monitoring process upon determining the detected packet includes recorded addresses.

20. The non-transitory computer-readable medium of claim 19 , wherein the network monitoring process comprises a traffic measurement process.

21. The non-transitory computer-readable medium of claim 15 , further comprising:

program code for determining source and destination ports of the first transport connection; and

program code for recording, in at least one packet transported over the second transport connection, the source and destination ports of the first transport connection.

22. The non-transitory computer-readable medium of claim 21 , further comprising:

program code for detecting, at a network element, a packet transported over the second transport connection;

program code for determining whether the detected packet includes at least one or more of a set of recorded source and destination addresses of the first transport connection or a set of recorded source and destination ports of the first transport connection.

23. The non-transitory computer-readable medium of claim 22 , further comprising program code for a quality of service (“QoS”) enforcement process that uses at the least one of the set of recorded source and destination addresses or the set of recorded source and destination ports, to enforce a QoS policy.

24. The non-transitory computer-readable medium of claim 22 , further comprising program code for using the at least one of the set of recorded source and destination addresses or the set of recorded source and destination ports to perform one process from the group consisting of a traffic classification process, a filtering policy process and an access control list policy process.

25. The non-transitory computer-readable medium of claim 22 , further comprising program code for using the set of recorded source and destination addresses or the set of recorded source and destination ports to update the state of a network monitoring process.

Assignments (17)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2013
From: LANDRUM, ALFRED; LY, KAND; MCCANNE, STEVEN
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 030877/0223 →