IP Library Granted Patent US 10,142,356
Granted Patent B2
US 10,142,356 · App. 15/224,339 · Granted Nov 27, 2018

Channel data encapsulation system and method for use with client-server data channels

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); Manuel Nedbal (Santa Clara, CA)
Assignee: ShieldX Networks, Inc.
H04L63/1416H04L45/30H04L63/1408H04L67/1002G06F2221/2151H04L45/123H04L45/124H04L45/125H04L63/0428H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,142,356
App. No.
15/224,339
Granted
Nov 27, 2018
Kind
B2
Abstract

Systems and methods are disclosed that relate to network security to monitor and report threats in network traffic of a datacenter. For example, one embodiment discloses a method of receiving, by a first security microservice, a first channel data encapsulation packet encapsulating a first encapsulation context and a first encapsulated data, performing a security service on the first encapsulated data using the first encapsulation context, transmitting by the first security microservice a second channel data encapsulation packet to a second security microservice, wherein the second channel encapsulation packet comprises a request for security services, receiving by the first security microservice a response from the second security microservice comprising a second security microservice context, a second security microservice timestamp, and a second security microservice load. The first security microservice further generates a timestamp and a load included in a response to the first channel data encapsulation packet.

Claims (44)

1. A method comprising:

receiving, by a first security microservice, a first channel data encapsulation packet encapsulating a first encapsulation context and a first encapsulated data;

performing a security service on the first encapsulated data using the first encapsulation context, wherein the security service is one of a plurality of microservices used to secure traffic passing between applications and servers through a routing network;

receiving, by the first security microservice, a response from the second security microservice comprising a second security microservice context, a second timestamp, and a second load;

generating, by the first security microservice, a first timestamp and a first load, wherein the timestamps represent the duration of processing performed by the first and second microservices and the first and second loads represent the loading of the first and second microservices processing the encapsulated channel data, the loading being represented in either relative or absolute terms; and

transmitting, by the first security microservice, a response to the first channel data encapsulation packet, wherein the response includes the first timestamp and first load generated by the first security microservice, wherein the timestamp and load values are recorded to be used in load balancing decisions for future security service requests among microservices; and

wherein the first and second security microservices are implemented with computer-readable instructions stored in memory on a network security server, the memory coupled to one or more hardware processors executing the first and second security microservices.

2. The method of claim 1 , wherein the first channel data encapsulation packet to contain an encapsulation identifier to distinguish a data channel associated with the first data channel encapsulation packet within a network environment.

3. The method of claim 2 , wherein the first channel data encapsulation packet to contain an encapsulation header.

4. The method of claim 3 , wherein the encapsulation header to define a location within the first channel data encapsulation packet of the first encapsulation context and a first encapsulation service load.

5. The method of claim 4 , wherein the encapsulation header further to define a timestamp, and wherein the first security microservice to record the second security microservice timestamp and the second security microservice load.

6. The method of claim 3 , wherein the first channel data encapsulation packet further to include an encapsulation checksum.

7. The method of claim 6 , wherein calculating the encapsulation checksum to use the encapsulation identifier and the encapsulation header.

8. A system comprising:

a memory; and

a processor to execute instructions to implement a first security microservice, the first security microservice to:

receive a first channel data encapsulation packet encapsulating a first encapsulation context and a first encapsulated data;

perform a security service on the first encapsulated data using the first encapsulation context, wherein the security service is one of a plurality of microservices used to secure traffic passing between applications and servers through a routing network;

transmit a second channel data encapsulation packet to a second security microservice, wherein the second channel data encapsulation packet comprises a request for security services;

receive a response from the second security microservice comprising a second security microservice context, a second timestamp, and a second load;

generate a first timestamp and a first load, wherein the timestamps represent the duration of processing performed by the first and second microservices and the loads represent the loading of the first and second microservices processing the encapsulated channel data, the loading being represented in either relative or absolute terms; and

transmit a response to the first channel data encapsulation packet, the response including the first timestamp and first load, wherein the timestamp and load values are recorded to be used in load balancing decisions for future security service requests among microservices, and

wherein the first and second security microservices are implemented with computer-readable instructions stored in memory on a network security server, the memory coupled to one or more hardware processors executing the first and second security microservices.

9. The system of claim 8 ,

wherein the first channel data encapsulation packet to contain an encapsulation identifier to distinguish a data channel associated with the first data channel encapsulation packet within a network environment.

10. The system of claim 9 ,

wherein the first channel data encapsulation packet to contain an encapsulation header.

11. The system of claim 10 , wherein the encapsulation header to define a location within the first channel data encapsulation packet of the first encapsulation context and a first encapsulation service load.

12. The system of claim 11 , wherein the encapsulation header further to define a timestamp.

13. The system of claim 10 , wherein the first channel data encapsulation packet further to include an encapsulation checksum.

14. The system of claim 13 , wherein the first security microservice to use the encapsulation identifier and the encapsulation header when calculating the encapsulation checksum.

15. The system of claim 8 , wherein the first security microservice to record the second security microservice timestamp and the second security microservice load.

16. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method comprising:

receiving, by a first security microservice, a first channel data encapsulation packet encapsulating a first encapsulation context and a first encapsulated data;

performing a security service on the first encapsulated data using the first encapsulation context, wherein the security service is one of a plurality of microservices used to secure traffic passing between applications and servers through a routing network;

transmitting, by the first security microservice, a second channel data encapsulation packet to a second security microservice, wherein the second channel data encapsulation packet comprises a request for security services;

receiving by the first security microservice a response from the second security microservice comprising a second security microservice context, a second timestamp, and a second load;

generating, by the first security microservice, a first timestamp and a first load, wherein the timestamps represent the duration of processing performed by the first and second microservices and the first and second loads represent the loading of the first and second microservices processing the encapsulated channel data, the loading being represented in either relative or absolute terms; and

transmitting, by the first security microservice, a response to the first channel data encapsulation packet, wherein the response includes the first timestamp and first load generated by the first security microservice, wherein the timestamp and load values are recorded to be used in load balancing decisions for future security service requests among microservices; and

wherein the first and second security microservices are implemented with computer-readable instructions stored in memory on a network security server, the memory coupled to one or more hardware processors executing the first and second security microservices.

17. The non-transitory computer-readable medium of claim 16 , wherein the first channel data encapsulation packet to contain an encapsulation identifier to distinguish a data channel associated with the first data channel encapsulation packet within a network environment.

18. The non-transitory computer-readable medium of claim 16 , wherein the first channel data encapsulation packet to contain an encapsulation header.

19. The non-transitory computer-readable medium of claim 18 , wherein the encapsulation header to define a location within the first channel data encapsulation packet of the first encapsulation context and the first encapsulation data.

20. The non-transitory computer-readable medium of claim 18 , wherein the encapsulation header further to define a timestamp.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: SHIELDX NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 056227/0125 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2021
From: COMERICA BANK
To: SHIELDX NETWORKS, INC.
Reel/Frame 055585/0847 →
SECURITY INTEREST Recorded Jul 27, 2020
From: SHIELDX NETWORKS, INC.
To: COMERICA BANK
Reel/Frame 053313/0544 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2016
From: AHUJA, RATINDER PAUL SINGH; NEDBAL, MANUEL
To: SHIELDX NETWORKS, INC.
Reel/Frame 039297/0893 →
Continuity (1)
Related Publication 20180034833A1 · Feb 1, 2018
Cited By (2)
US 12,367,320 US 12,549,571