IP Library Granted Patent US 9,584,516
Granted Patent B2
US 9,584,516 · App. 14/605,731 · Granted Feb 28, 2017

Proxy authentication for a multiple core network device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,584,516
App. No.
14/605,731
Granted
Feb 28, 2017
Kind
B2
Abstract

The present invention is generally related to a network computing device including a first processor communicating with a second processor as a proxy for a client device when authenticating access privileges of the client device. The present invention may include more than two processors where at least one of the multiple processors may be optimized for performing one or more control functions and one or more other processors may be optimized for transferring data or administrating the transfer of data through a gateway or firewall.

Claims (42)

1. A method for authorizing the access privileges of a client device, the method comprising:

a computing device receiving an authorization request to access a computing resource on a computing network, wherein the computing device includes a plurality of processors, and the authorization request is received over a first network communication interface from the client device at a first processor of the plurality of processors;

creating a communication pathway between the first processor and a second processor of the plurality of processors, wherein the communication pathway between the first processor and the second processor is a socket communication that associates a first set of program code with a second set of program code;

the first processor executing the first set of program code that admintistrates forwarding of information from the authorization request to the second processor in a communication, the communication identifying an internet protocol (IP) address and a port number associated with the client device;

the second processor executing the second set of program code that administrates the transmission of a request that corresponds to the authorization request to an authorization server;

receiving a response to the corresponding request from the authentication server by the second processor;

transmitting information from the received response over the communication pathway to the first processor in a second communication, wherein the second communication is from the second processor to the first processor, and the IP address and the port of the client device are identified by the second communication;

the first processor forwarding at least a portion of the information from the response to the client device over the first network computing interface; and

allowing the client device to access the computing resource when information in the forwarded response indicates that the client device is authorized to access the computing resource.

2. The method of claim 1 , wherein the first set of program code is optimized for managing the transfer of data, and the second set of program code is optimized for administrating control functions.

3. The method of claim 2 , wherein the second set of program code includes operating system software.

4. The method of claim 1 , wherein the corresponding request is transmitted over a second network communication interface to the authentication server, and the response received from the authentication server is received over the second network communication interface.

5. The method of claim 2 , wherein the authentication server authenticates credentials of the client device by comparing information stored at the authentication server with the information from the corresponding request, and the response received from the authentication server indicates that the client device has been granted access to the requested computing resource.

6. A non-transitory computer readable storage medium having embodied thereon a program executable by one or more processors for authorizing the access privileges of a client device, the method comprising:

a computing device receiving an authorization request to access a computing resource on a computing network, wherein the computing device includes a plurality of processors, and the authorization request is received over a first network communication interface from a client device at a first processor of the plurality of processors;

creating a communication pathway between the first processor and a second processor of the plurality of processors, wherein the communication pathway between the first processor and the second processor is a socket communication that associates a first set of program code with a second set of program code;

the first processor executing the first set of program code that administrates forwarding of information from the authorization request to the second processor in a communication, the communication identifying an internet protocol (IP) address and a port number associated with the client device;

the second processor executing the second set of program code that administrates the transmission of a request that corresponds to the authorization request to an authorization server;

receiving a response to the corresponding request from the authentication server by the second processor;

transmitting information from the received response over the communication pathway to the first processor in a second communication, wherein the second communication is from the second processor to the first processor, and the IP address and the port of the client device are identified by the second communication;

the first processor forwarding at least a portion of the information from the response to the client device over the first network computing interface; and

allowing the client device to access the computing resource when information in the forwarded response indicates that the client device is authorized to access the computing resource.

7. The non-transitory computer readable storage medium of claim 6 , wherein the first set of program code is optimized for managing the transfer of data, and the second set of program code is optimized for administrating control functions.

8. The non-transitory computer readable storage medium of claim 7 , wherein the second set of program code includes operating system software.

9. The non-transitory computer readable storage medium of claim 6 , wherein the corresponding request is transmitted over a second network communication interface to the authentication server, and the response received from the authentication server is received over the second network communication interface.

10. The non-transitory computer readable storage medium of claim 7 , wherein the authentication server authenticates credentials of the client device by comparing information stored at the authentication server with the information from the corresponding request, and the response received from the authentication server indicates that the client device has been granted access to the requested computing resource.

11. A system for authorizing the access privileges of a client device, the system comprising:

a memory;

a first processor;

a second processor; and

a first network computing interface, wherein:

an authorization request to access a computing resource is received over the first network communication interface from a client device, and information in the authorization request includes information is received by a first processor,

the first processor executing a first set of program code creates a communication pathway between the first processor and the second processor executing a second set of program code,

the communication pathway between the first processor and the second processor is a socket communication that associates the first set of program code with the second set of program code,

the first processor executing the first set of program code forwards the information from the authentication request in a communication over the communication pathway to the second processor, the forwarded communication identifies the internet protocol address and a port number associated with the client device,

the second processor executing the second set of program code that administrates the transmission of a request that corresponds to the authorization request to an authorization server, the second processor receives a response to the corresponding request from the authentication server,

the second processor administrates the transmission of information from the received response over the communication pathway to the first processor in a second communication, wherein the second communication is from the second processor to the first processor, and the IP address and the port of the client device are identified by the second communication, the first processor forwards at least a portion of the information from the response to the client device over the first network computing interface, and

the client device is allowed to access the computing resource when information in the forwarded response indicates that the client device is authorized to access the computing resource.

12. The system of claim 11 , wherein the first set of program code is optimized for managing the transfer of data, and the second set of program code is optimized for administrating control functions.

13. The system of claim 12 , wherein the second set of program code includes operating system software.

14. The system of claim 12 , further comprising a second network communication interface, wherein the corresponding request is transmitted over the second network communication interface to the authentication server, and the response received from the authentication server is received over the second network communication interface.

15. The system of claim 12 , wherein the authentication server authenticates credentials of the client device by comparing information stored at the authentication server with the information from the corresponding request, and the response received from the authentication server indicates that the client device has been granted access to the requested computing resource.

Assignments (21)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
CHANGE OF NAME Recorded May 29, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 047058/0082 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
MERGER Recorded Dec 17, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037315/0818 →
CONVERSION AND NAME CHANGE Recorded Dec 17, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037317/0128 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2015
From: CAI, RIJI; CHEN, ZHONG
To: SONICWALL, INC.
Reel/Frame 034819/0879 →