IP Library Granted Patent US 11,399,009
Granted Patent B2
US 11,399,009 · App. 16/686,694 · Granted Jul 26, 2022

Endpoint context agent traversal of network address table

Inventor: Jaakko Moller (Helsinki, FI)
Assignee: Forcepoint LLC
H04L63/0227H04L63/02H04L29/12405H04L29/12518H04L41/0226H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,399,009
App. No.
16/686,694
Granted
Jul 26, 2022
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for: (i) communicating, from a client device to a security device via a metadata connection, metadata regarding a data connection to be established by the client device, the metadata comprising a connection identifier uniquely identifying the data connection; and (ii) communicating, from the client device to the security device via the data connection, network traffic comprising a packet that includes the connection identifier, such that the security device may use the connection identifier to index an entry associated with the metadata that the security device has stored in a metadata cache.

Claims (26)

1. A computer-implemented method for managing network communication, comprising:

communicating, from a client device to a security device via a metadata connection, metadata regarding a data connection to be established by the client device, the metadata comprising a connection identifier uniquely identifying the data connection; and

communicating, from the client device to the security device via the data connection, network traffic comprising a packet that includes the connection identifier, such that the security device is operable to use the connection identifier to index an entry associated with the metadata that the security device has stored in a metadata cache;

wherein the metadata connection is a side channel isolated from the data connection, and wherein prior to communicating the packet, the client device is configured to insert, into a header of the packet, the connection identifier and a metadata connection identifier that uniquely identifies the side channel.

2. The method of claim 1 , wherein the packet that includes the connection identifier is an initial packet communicated from the client device as part of the network traffic.

3. The method of claim 1 , wherein the connection identifier is part of a custom header of the packet that includes the connection identifier.

4. The method of claim 1 , wherein the network traffic is communicated in response to a message from the security device to the client device indicating the security device has received the metadata.

5. The method of claim 1 , wherein the metadata comprises Endpoint Context Agent metadata.

6. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium comprising instructions executable by the processor and configured for:

communicating, from a client device to a security device via a metadata connection, metadata regarding a data connection to be established by the client device, the metadata comprising a connection identifier uniquely identifying the data connection; and

communicating, from the client device to the security device via the data connection, network traffic comprising a packet that includes the connection identifier, such that the security device is operable to use the connection identifier to index an entry associated with the metadata that the security device has stored in a metadata cache;

wherein the metadata connection is a side channel isolated from the data connection, and wherein prior to communicating the packet, the client device is configured to insert, into a header of the packet, the connection identifier and a metadata connection identifier that uniquely identifies the side channel.

7. The system of claim 6 , wherein the packet that includes the connection identifier is an initial packet communicated from the client device as part of the network traffic.

8. The system of claim 6 , wherein the connection identifier is part of a custom header of the packet that includes the connection identifier.

9. The system of claim 6 , wherein the network traffic is communicated in response to a message from the security device to the client device indicating the security device has received the metadata.

10. The system of claim 6 , wherein the metadata comprises Endpoint Context Agent metadata.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

communicating, from a client device to a security device via a metadata connection, metadata regarding a data connection to be established by the client device, the metadata comprising a connection identifier uniquely identifying the data connection; and

communicating, from the client device to the security device via the data connection, network traffic comprising a packet that includes the connection identifier, such that the security device is operable to use the connection identifier to index an entry associated with the metadata that the security device has stored in a metadata cache;

wherein the metadata connection is a side channel isolated from the data connection, and wherein prior to communicating the packet, the client device is configured to insert, into a header of the packet, the connection identifier and a metadata connection identifier that uniquely identifies the side channel.

12. The storage medium of claim 11 , wherein the packet that includes the connection identifier is an initial packet communicated from the client device as part of the network traffic.

13. The storage medium of claim 11 , wherein the connection identifier is part of a custom header of the packet that includes the connection identifier.

14. The storage medium of claim 11 , wherein the network traffic is communicated in response to a message from the security device to the client device indicating the security device has received the metadata.

15. The storage medium of claim 11 , wherein the metadata comprises Endpoint Context Agent metadata.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2019
From: MOLLER, JAAKKO
To: FORCEPOINT LLC
Reel/Frame 051037/0240 →
Continuity (1)
Related Publication 20210152519A1 · May 20, 2021