IP Library › Granted Patent US 12,231,410
Granted Patent B2
US 12,231,410 · App. 17/742,359 · Granted Feb 18, 2025

Methods, systems, and computer readable media for processing QUIC communications in a network

Inventors: Michael Paul Galime (Utica, NY); Gabriel Oprisan (Bucharest, RO); Lucian Stoian (Bucharest, RO); Cosmin Banu (Bucharest, RO); Stefan Constantin Puiu (Bucharest, RO)
Assignee: KEYSIGHT TECHNOLOGIES, INC.
H04L63/0428H04L63/166H04L67/141H04L69/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,410
App. No.
17/742,359
Granted
Feb 18, 2025
Kind
B2
Abstract

Methods, systems, and computer readable media for processing QUIC communications in a network. An example system includes a first network interface for receiving a QUIC connection request from a first node in the network and, in response, establishing a first QUIC connection between the first node and the system. The system includes a QUIC processing module configured for receiving, via the first QUIC connection, encrypted QUIC data including a number of streams and decrypting the encrypted QUIC data, resulting in decrypted QUIC data. The QUIC processing module is configured for extracting each of the streams from the decrypted QUIC data, resulting in a plurality of extracted streams, and packaging at least one of the extracted streams into a non-QUIC protocol format, resulting in at least one packaged stream. The system includes a second network interface for transmitting the packaged stream to a second node in the network.

Claims (47)

1. A system for processing QUIC communications in a network, the system comprising:

a QUIC gateway including at least one processor, a client stub, and a server stub for establishing proxied QUIC communications between a client and a server;

the server stub for receiving a QUIC connection request from the client;

the QUIC gateway for modifying the QUIC connection request and forwarding the modified QUIC connection request to the server via the client stub;

wherein the client stub implements a client side of a QUIC handshake with the server to establish a first QUIC connection between the client stub and the server;

wherein the server stub implements a server side of a QUIC handshake with the server to establish a second QUIC connection between the server stub and the client;

wherein the QUIC gateway is configured for:

receiving, via the first QUIC connection, encrypted QUIC data comprising a plurality of streams;

decrypting the encrypted QUIC data, resulting in decrypted QUIC data;

extracting each of the streams from the decrypted QUIC data, resulting in a plurality of extracted streams;

packaging at least one of the extracted streams into a non-QUIC protocol format, resulting in at least one packaged stream;

re-encrypting the decrypted QUIC data and transmitting the re-encrypted QUIC data to the server via the client stub; and

a second network interface implemented on the QUIC gateway for transmitting the packaged stream to a network security tool, wherein the network security tool is configured to process the packaged stream in the non-QUIC protocol format and the network security tool comprises one or more of: a firewall, a deep packet inspection tool, an intrusion detection system (IDS), an intrusion prevention system (IPS), and a data leakage protection tool.

2. The system of claim 1 , wherein packaging at least one of the extracted streams into a non-QUIC protocol format comprises encapsulating the at least one of the extracted streams for transport by hypertext transfer protocol (HTTP) or hypertext transfer protocol secure (HTTPS).

3. The system of claim 1 , wherein the QUIC gateway is configured for packaging each of the extracted streams into a respective transport control protocol (TCP) connection.

4. The system of claim 1 , wherein the QUIC gateway is configured for collectively packaging the extracted streams into a same transport control protocol (TCP) connection.

5. The system of claim 1 wherein the QUIC gateway is configured to perform certificate forging using information copied from a security certificate of the server allow the QUIC gateway to operate as a man-in-the-middle proxy between the client and the server.

6. A method for processing QUIC communications in a network, the method comprising:

providing a QUIC gateway including a client stub and a server stub for establishing proxied QUIC communications between a client and a server;

receiving, by the server stub, a QUIC connection request from the client;

modifying, by the QUIC gateway, the QUIC connection request and forwarding the modified QUIC connection request to the server via the client stub;

implementing, by the client stub, a client side of a QUIC handshake with the server to establish a first QUIC connection between the client stub and the server;

implementing, by the server stub, a server side of a QUIC handshake with the server to establish a second QUIC connection between the server stub and the client;

receiving, by the QUIC gateway and via the first QUIC connection, encrypted QUIC data comprising a plurality of streams;

decrypting, by the QUIC gateway, the encrypted QUIC data, resulting in decrypted QUIC data;

extracting, by the QUIC gateway, each of the streams from the decrypted QUIC data, resulting in a plurality of extracted streams;

packaging, by the QUIC gateway, at least one of the extracted streams into a non-QUIC protocol format, resulting in at least one packaged stream;

transmitting, by the QUIC gateway, the packaged stream to network security tool, wherein the network security tool is configured to process the packaged stream in the non-QUIC protocol format and the network security tool comprises one or more of: a firewall, a deep packet inspection tool, an intrusion detection system (IDS), an intrusion prevention system (IPS), and a data leakage protection tool; and

re-encrypting, by the QUIC gateway, the decrypted QUIC data and transmitting the re-encrypted QUIC data to the server via the client stub.

7. The method of claim 6 , wherein packaging at least one of the extracted streams into a non-QUIC protocol format comprises encapsulating the at least one of the extracted streams for transport by hypertext transfer protocol (HTTP) or hypertext transfer protocol secure (HTTPS).

8. The method of claim 6 , comprising packaging each of the extracted streams into a respective transport control protocol (TCP) connection.

9. The method of claim 6 , comprising collectively packaging the extracted streams into a same transport control protocol (TCP) connection.

10. The method of claim 6 comprising performing, by the QUIC gateway, certificate forging using information copied from a security certificate of the server allow the QUIC gateway to operate as a man-in-the-middle proxy between the client and the server.

11. A non-transitory computer readable medium comprising computer executable instructions embodied in the non-transitory computer readable medium that when executed by at least one processor of at least one computer cause the at least one computer to perform steps comprising:

providing a QUIC gateway including a client stub and a server stub for establishing proxied QUIC communications between a client and a server;

receiving, by the server stub, a QUIC connection request from the client;

modifying, by the QUIC gateway, the QUIC connection request and forwarding the modified QUIC connection request to the server via the client stub;

implementing, by the client stub, a client side of a QUIC handshake with the server to establish a first QUIC connection between the client stub and the server;

implementing, by the server stub, a server side of a QUIC handshake with the server to establish a second QUIC connection between the server stub and the client;

receiving, by the QUIC gateway and via the first QUIC connection, encrypted QUIC data comprising a plurality of streams;

decrypting, by the QUIC gateway, the encrypted QUIC data, resulting in decrypted QUIC data;

extracting, by the QUIC gateway, each of the streams from the decrypted QUIC data, resulting in a plurality of extracted streams;

packaging, by the QUIC gateway, at least one of the extracted streams into a non-QUIC protocol format, resulting in at least one packaged stream;

transmitting the packaged stream to a network security tool, wherein the network security tool is configured to process the packaged stream in the non-QUIC protocol format and the network security tool comprises one or more of: a firewall, a deep packet inspection tool, an intrusion detection system (IDS), an intrusion prevention system (IPS), and a data leakage protection tool; and

re-encrypting, by the QUIC gateway, the decrypted QUIC data and transmitting the re-encrypted QUIC data to the server via the client stub.

12. The non-transitory computer readable medium of claim 11 , wherein packaging at least one of the extracted streams into a non-QUIC protocol format comprises encapsulating the at least one of the extracted streams for transport by hypertext transfer protocol (HTTP) or hypertext transfer protocol secure (HTTPS).

13. The non-transitory computer readable medium of claim 11 comprising performing, by the QUIC gateway, certificate forging using information copied from a security certificate of the server allow the QUIC gateway to operate as a man-in-the-middle proxy between the client and the server.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SPELLING OF THE CONVEYING PARTY NAME PREVIOUSLY RECORDED AT REEL: 064056 FRAME: 0326. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 5, 2023
From: KEYSIGHT TECHNOLOGIES RO SRL
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 065774/0905 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: KEYSIGHT TECHNOLOGIES RO SLA
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 064056/0326 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA. IT SHOULD READ "KEYSIGHT TECHNOLOGIES RO SRL" INSTEAD OF "KEYSIGHT TECHNOLGIES RO SRL" PREVIOUSLY RECORDED AT REEL: 063600 FRAME: 0635. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 6, 2023
From: OPRISAN, GABRIEL; STOIAN, LUCIAN; BANU, COSMIN; PUIU, STEFAN CONSTANTIN
To: KEYSIGHT TECHNOLOGIES RO SRL
Reel/Frame 064253/0120 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: OPRISAN, GABRIEL; STOIAN, LUCIAN; BANU, COSMIN; PUIU, STEFAN CONSTANTIN
To: KEYSIGHT TECHNOLGIES RO SRL
Reel/Frame 063600/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: GALIME, MICHAEL PAUL
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 063600/0632 →
Priority Claims (1)
RO a 2022 00251 · May 10, 2022 · national
Continuity (1)
Related Publication 20230370435A1 · Nov 16, 2023
References Cited (16)
US 7076650B1 · Sonnenberg · 2006 [cited by examiner]
US 10015208B2 · Patil et al. · 2018 [cited by applicant]
US 10778812B1 · Kou · 2020 [cited by examiner]
US 10904219B2 · Eriksson et al. · 2021 [cited by applicant]
US 20140298041A1 · Consalus · 2014 [cited by examiner]
US 20170070531A1 · Huston, III · 2017 [cited by examiner]
US 20180041613A1 · Lapidous · 2018 [cited by examiner]
US 20190116123A1 · Shiell · 2019 [cited by examiner]
US 20230074838A1 · De Foy · 2023 [cited by examiner]
US 20230085513A1 · Mestery · 2023 [cited by examiner]
“Usage statistics of QUIC for websites,” W3Techs, Web Technology Surveys, https://w3techs.com/technologies/details/ce-quic, pp. 1-2 (Nov. 2021). [cited by applicant]
Duke, “QUIC Will Eat the Internet,” Blog, Office of the CTO, https://www.f5.com/company/blog/quic-will-eat-the-Internet, pp. 1-4 (Feb. 22, 2021). [cited by applicant]
“Savoury implementation of the QUIC transport protocol and HTTP/3,” cloudflare/quiche, https://github.com/cloudflare/quiche/releases, pp. 1-18 (Feb. 4, 2022). [cited by applicant]
Reen et al., “DPIFuzz: A Differential Fuzzing Framework to Detect DPI Elusion Strategies for QUIC,” ACSAC 2020, pp. 1-13 (Dec. 7-11, 2020). [cited by applicant]
Grigorik et al., “Introduction to HTTP/2,” web.dev, pp. 1-21 (Sep. 1, 2019). [cited by applicant]
Parikh, “Designing a Network Validation Pipeline,” NET, https://www.intentionet.com/blog/designing-a-network-validation-pipeline/, pp. 1-8 (Mar. 15, 2019). [cited by applicant]