IP Library Granted Patent US 12,500,865
Granted Patent B2
US 12,500,865 · App. 17/134,777 · Granted Dec 16, 2025

Secure network communication system and method

Inventor: Thomas Maher (Dublin, IE)
Assignee: Akamai Technologies Ireland Limited
H04L63/0281H04L63/0272H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,865
App. No.
17/134,777
Granted
Dec 16, 2025
Kind
B2
Abstract

A secure network communication system and method for secure data exchange using TCP are disclosed. The system provides data exchange between a client and server, through an agent and broker interconnected to exchange data over an unsecured network. Upon receipt of a control packet from the client, the broker forwards a modified control packet to the agent using a secure protocol. The agent inspects the modified control packet and forwards it to the server. Upon receipt of a response packet from the server, the agent forwards the response packet to the broker using a secure protocol. Upon receipt of the response packet, the agent modifies the response packet and forwards it to the client. If the exchange of control packets indicates establishment of a TCP session, the agent and the broker establish a data channel between themselves to create a transparent TCP channel between the client and the server.

Claims (15)

1 . A data transmission system for secure data exchange using transmission control protocol between a client and a server, comprising:

an agent computing device connected to the server, and a broker computing device connected to the client, wherein at least one of the agent computing device and the broker computing device comprise computer program code executed by a hardware processor, wherein:

the agent computing device is configured to initiate a secure control session with the broker computing device;

the broker computing device is configured to receive a control packet from the client and, in response, to generate and send a modified version of the control packet to the agent computing device using the secure control session;

the agent computing device is configured to receive the modified version of the control packet and, in response, to initiate a control connection with the server;

the agent computing device is configured to respond to establishment of the control connection with the server to initiate a secure data session with the broker computing device; and

the broker computing device is configured to respond to initiation of the secure data session to send a response to the control packet from the client such that a data connection is established between the client and the broker computing device;

wherein the secure control session is established from a direction of the server towards the client, and the control packet to establish the data connection is sent from the direction of the client towards the server.

2 . The data transmission system as described in claim 1 wherein the agent computing device and the broker computing device are coupled to one another over an unsecured network link.

3 . The data transmission system as described in claim 1 wherein the agent computing device and the client are coupled to one another over a secure link.

4 . The data transmission system as described in claim 1 wherein the broker computing device and the server are coupled to one another over a secure link.

5 . The data transmission system of claim 1 wherein initiating the control connection with the server comprises generating a new control packet and sending the new control packet to the server.

6 . The data transmission system of claim 5 wherein the new control packet is a Transport Control Protocol Synchronize (TCP SYN) packet.

7 . The data transmission system of claim 5 wherein the control packet, the modified version of the control packet, and the new control packet are Transport Control Protocol Synchronize (TCP SYN) packets.

8 . The data transmission system of claim 1 wherein the secure data session between the agent computing device and the broker computing device occurs via at least one of: a firewall, a proxy, and a Network Address Translation (NAT) device.

Assignments (2)
CHANGE OF NAME Recorded Mar 20, 2024
From: ASAVIE TECHNOLOGIES LIMITED
To: AKAMAI TECHNOLOGIES IRELAND LIMITED
Reel/Frame 066833/0878 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2020
From: MAHER, THOMAS
To: ASAVIE TECHNOLOGIES LIMITED
Reel/Frame 054753/0044 →
Priority Claims (1)
IE 2005/0376 · Jun 3, 2005 · national
Continuity (3)
Continuation 15244074 · Aug 23, 2016
Continuation 11920903
Related Publication 20210119975A1 · Apr 22, 2021
References Cited (6)
US 20020042875A1 · Shukla · 2002 [cited by examiner]
US 20030140140A1 · Lahtinen · 2003 [cited by examiner]
US 20040153669A1 · Yang · 2004 [cited by examiner]
US 20050021999A1 · Touitou · 2005 [cited by examiner]
Clemens Kerer et al., “ShareMe: Running a Distributed Systems Lab for 600 Students With Three Faculty Members”, 2005, pp. 1-8. (Year: 2005). [cited by examiner]
Larry Korba, “Towards Securing Network Management Agent Distribution and Communication,” 1999, pp. 1-14. (Year: 1999). [cited by examiner]