IP Library Granted Patent US 9,661,083
Granted Patent B1
US 9,661,083 · App. 14/308,052 · Granted May 23, 2017

Efficient notification protocol through firewalls

Inventors: Joseph R. Eykholt (Los Altos, CA); Adrian Caceres (Los Gatos, CA)
Assignee: Ayla Networks, Inc.
H04L67/147
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,661,083
App. No.
14/308,052
Granted
May 23, 2017
Kind
B1
Abstract

A first computing device sends a plurality of request messages to a second computing device that is outside a firewall associated with the first computing device, each request message of the plurality of request messages comprising a request for the second computing device to send a response message to the first computing device after a time period specified in the request message. The first computing device determines a timeout period of the firewall based on one or more response messages that are received responsive to the plurality of request messages. The first computing device sends or receives an additional message to or from the second computing device within the timeout period to prevent the firewall from blocking future messages from the second computing device.

Claims (65)

1. A method comprising:

sending, by a first computing device that is behind a firewall, a first request message to a first port of a second computing device that is outside the firewall, wherein the first port is associated with a first flow of a plurality of concurrent flows between the first computing device and the second computing device, and wherein the first request message comprises a request for the second computing device to send a first response message to the first computing device after a specified first time period;

sending, by the first computing device, a second request message to a second port of the second computing device that is associated with a second flow of the plurality of concurrent flows, the second request message comprising a request for the second computing device to send a second response message to the first computing device after a specified second time period that is greater than the specified first time period; and

responsive to receiving the first response message and failing to receive the second response message, performing the following comprising:

determining that a timeout period of the firewall is greater than the specified first time period and less than the specified second time period, wherein the failure to receive the second response message indicates that the second flow is terminated;

keeping the first flow active by performing at least one of sending an additional message to the first port of the second computing device or receiving the additional message from the first port of the second computing device within the specified first time period to prevent the firewall from blocking future messages from the second computing device;

determining a third time period that is greater than the specified first time period and less than the specified second time period; and

sending a third request message to the second port, the third request message comprising a request for the second computing device to send a third response message to the first computing device after the third time period.

2. The method of claim 1 , wherein the first request message, the first response message, the second request message, the second response message, the third request message and the additional message are user datagram protocol (UDP) messages, and wherein the timeout period of the firewall is a timeout period for a UDP flow.

3. The method of claim 2 , further comprising performing the following responsive to a failure to receive the first response message and a failure to receive the second response message:

sending a fourth request message to the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the specified first time period, the specified second time period or a specified fourth time period, wherein the fourth request message and the fourth response message are transmission control protocol (TCP) messages; and

responsive to receiving the fourth response message, determining that an alternative timeout period of the firewall is less than or equal to the specified first time period, the specified second time period or the specified fourth time period.

4. The method of claim 1 , further comprising performing the following responsive to receiving the first response message and receiving the second response message:

determining that the timeout period of the firewall is greater than the specified second time period;

keeping the first flow active by performing at least one of sending the additional message to the first port of the second computing device or receiving the additional message from the first port of the second computing device within the specified second time period to prevent the firewall from blocking future messages from the second computing device;

determining a fourth time period that is greater than the specified second time period; and

sending a fourth request message to the second port or a third port of the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the fourth time period.

5. The method of claim 1 , further comprising:

responsive to receiving the first response message and failing to receive the second response message, setting a first messaging frequency based at least in part on the specified first time period, wherein the first computing device sends keep-alive messages to the second computing device in accordance with the messaging frequency, and wherein the keep-alive messages do not call for responses.

6. The method of claim 5 , further comprising:

setting a second messaging frequency that is less frequent than the first messaging frequency, wherein the first computing device sends probe messages to the second computing device in accordance with the second messaging frequency, and wherein the probe messages call for responses.

7. The method of claim 1 , wherein the first computing device comprises an embedded system and the second computing device comprises a server computing device that provides a service to the embedded system.

8. A non-transitory computer readable storage medium having instructions that, when executed by a processing device of a first computing device, cause the processing device to perform operations comprising:

sending, by the processing device, a first request message to a first port of a second computing device that is outside a firewall associated with the first computing device, wherein the first port is associated with a first flow of a plurality of concurrent flows between the first computing device and the second computing device, and wherein the first request message comprises a request for the second computing device to send a first response message to the first computing device after a specified first time period;

sending, by the processing device, a second request message to a second port of the second computing device that is associated with a second flow of the plurality of concurrent flows, the second request message comprising a request for the second computing device to send a second response message to the first computing device after a specified second time period that is greater than the specified first time period; and

responsive to receiving the first response message and failing to receive the second response message, performing the following comprising:

determining that a timeout period of the firewall is greater than the specified first time period and less than the specified second time period, wherein the failure to receive the second response message indicates that the second flow is terminated;

keeping the first flow active by performing at least one of sending an additional message to the first port of the second computing device or receiving the additional message from the first port of the second computing device within the specified first time period to prevent the firewall from blocking future messages from the second computing device;

determining a third time period that is greater than the specified first time period and less than the specified second time period; and

sending a third request message to the second port, the third request message comprising a request for the second computing device to send a third response message to the first computing device after the third time period.

9. The non-transitory computer readable storage medium of claim 8 , wherein the first request message, the first response message, the second request message, the second response message, the third request message and the additional message are user datagram protocol (UDP) messages, and wherein the timeout period of the firewall is a timeout period for a UDP flow.

10. The non-transitory computer readable storage medium of claim 9 , the operations further comprising performing the following responsive to a failure to receive the first response message and a failure to receive the second response message:

sending a fourth request message to the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the specified first time period, the specified second time period or a specified fourth time period, wherein the fourth request message and the fourth response message are transmission control protocol (TCP) messages; and

responsive to receiving the fourth response message, determining that an alternative timeout period of the firewall is less than or equal to the specified first time period, the specified second time period or the specified fourth time period.

11. The non-transitory computer readable storage medium of claim 8 , the operations further comprising:

responsive to receiving the first response message and failing to receive the second response message, setting a first messaging frequency based at least in part on the specified first time period, wherein the processing device sends keep-alive messages to the second computing device in accordance with the messaging frequency, and wherein the keep-alive messages do not call for responses; and

setting a second messaging frequency that is less frequent than the first messaging frequency, wherein the processing device sends probe messages to the second computing device in accordance with the second messaging frequency, and wherein the probe messages call for responses.

12. The non-transitory computer readable storage medium of claim 8 , wherein the first computing device comprises an embedded system and the second computing device comprises a server computing device that provides a service to the embedded system.

13. A client computing device comprising:

a memory; and

a processing device coupled to the memory, wherein the processing device is to:

send a first request message to a first port of a second computing device, wherein the first port is associated with a first flow of a plurality of concurrent flows between the client computing device and the second computing device, and wherein the first request message comprises a request for the second computing device to send a first response message to the client computing device after a specified first time period;

send a second request message to a second port of the second computing device that is associated with a second flow of the plurality of concurrent flows, the second request message comprising a request for the second computing device to send a second response message to the client computing device after a specified second time period that is greater than the specified first time period; and

responsive to receiving the first response message and failing to receive the second response message, perform the following comprising:

determine that a timeout period of a firewall interposed between the client computing device and the second computing device is greater than the specified first time period and less than the specified second time period, wherein the failure to receive the second response message indicates that the second flow is terminated;

keep the first flow active by periodically sending an additional message to the first port of the second computing device within the specified first time period to prevent the firewall from blocking future messages from the second computing device;

determine a third time period that is greater than the specified first time period and less than the specified second time period; and

send a third request message to the second port, the third request message comprising a request for the second computing device to send a third response message to the first computing device after the third time period.

14. The client computing device of claim 13 , wherein the client computing device comprises an embedded system and the second computing device comprises a server computing device that provides a service to the embedded system.

15. The method of claim 1 , wherein the specified first time period is known to be lower than the timeout period of the firewall.

16. The non-transitory computer readable storage medium of claim 8 , the operations further comprising performing the following responsive to receiving the first response message and receiving the second response message:

determining that the timeout period of the firewall is greater than the specified second time period;

keeping the first flow active by performing at least one of sending the additional message to the first port of the second computing device or receiving the additional message from the first port of the second computing device within the specified second time period to prevent the firewall from blocking future messages from the second computing device;

determining a fourth time period that is greater than the specified second time period; and

sending a fourth request message to the second port or a third port of the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the fourth time period.

17. The non-transitory computer readable storage medium of claim 8 , wherein the specified first time period is known to be lower than the timeout period of the firewall.

18. The client computing device of claim 13 , wherein the first request message, the first response message, the second request message, the second response message, the third request message and the additional message are user datagram protocol (UDP) messages, and wherein the timeout period of the firewall is a timeout period for a UDP flow.

19. The client computing device of claim 18 , wherein the processing device is further to perform the following responsive to a failure to receive the first response message and a failure to receive the second response message:

send a fourth request message to the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the specified first time period, the specified second time period or a specified fourth time period, wherein the fourth request message and the fourth response message are transmission control protocol (TCP) messages; and

responsive to receiving the fourth response message, determine that an alternative timeout period of the firewall is less than or equal to the specified first time period, the specified second time period or the specified fourth time period.

20. The client computing device of claim 13 , wherein the processing device is further to perform the following responsive to receiving the first response message and receiving the second response message:

determine that the timeout period of the firewall is greater than the specified second time period;

keep the first flow active by performing at least one of sending the additional message to the first port of the second computing device or receiving the additional message from the first port of the second computing device within the specified second time period to prevent the firewall from blocking future messages from the second computing device;

determine a fourth time period that is greater than the specified second time period; and

send a fourth request message to the second port or a third port of the second computing device, the fourth request message comprising a request for the second computing device to send a fourth response message to the first computing device after the fourth time period.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: RUN LIANG TAI (HONG KONG) INVESTMENT COMPANY LIMITED
To: AYLA NETWORKS, INC.
Reel/Frame 052282/0957 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE NAME OF THE ASSIGNOR AND THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 052213 FRAME: 0718. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 25, 2020
From: AYLA NETWORKS, INC.; AYLA NETWORKS HOLDING CORPORATION
To: PINNACLE VENTURES, L.L.C., AS AGENT
Reel/Frame 052230/0408 →
SECURITY INTEREST Recorded Mar 24, 2020
From: PINNACLE VENTURES, L.L.C., AS AGENT
To: AYLA NETWORKS HOLDING CORPORATION; AYLA NETWORKS, INC.
Reel/Frame 052213/0718 →
RELEASE OF SECURITY INTEREST Recorded Apr 10, 2019
From: EAST WEST BANK
To: AYLA NETWORKS, INC.
Reel/Frame 048849/0527 →
SECURITY INTEREST Recorded Apr 8, 2019
From: AYLA NETWORKS, INC.
To: RUN LIANG TAI (HONG KONG) INVESTMENT COMPANY LIMITED
Reel/Frame 048820/0035 →
SECURITY INTEREST Recorded Jul 26, 2017
From: AYLA NETWORKS, INC.
To: EAST WEST BANK
Reel/Frame 043106/0617 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2014
From: EYKHOLT, JOSEPH R.; CACERES, ADRIAN
To: AYLA NETWORKS, INC.
Reel/Frame 033130/0300 →
Continuity (1)
Provisional Application 61836549 · Jun 18, 2013