Transparent middlebox graceful entry and exit

US2016119190A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016119190-A1
Application numberUS-201614987481-A
CountryUS
Kind codeA1
Filing dateJan 4, 2016
Priority dateJul 31, 2012
Publication dateApr 28, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Middleboxes include a processor configured to determine that a network connection between a client device and a server device is idle. A connection table is configured to create a first connection entry at the middlebox for the client device and a second connection entry at the middlebox for the server device. The first and second connection entries are initialized after determining that the network connection between the client device and the server device is idle. A network control module is configured to activate redirection of the network connection between the client device and the server device to the middlebox after determining that the network connection between the client device and the server device is idle.

First claim

Opening claim text (preview).

What is claimed is: 1 . A middlebox, comprising: a processor configured to determine that a network connection between a client device and a server device is idle; a connection table configured to create a first connection entry at the middlebox for the client device and a second connection entry at the middlebox for the server device, where the first and second connection entries are initialized after determining that the network connection between the client device and the server device is idle; and a network control module configured to activate redirection of the network connection between the client device and the server device to the middlebox after determining that the network connection between the client device and the server device is idle. 2 . The middlebox of claim 1 , wherein the network monitoring module is further configured to receive network information at the middlebox from a hardware tap to monitor network state information. 3 . The middlebox of claim 1 , wherein the network monitoring module is configured to receive network information at the middlebox from a separate network monitoring device to monitor network state information. 4 . The middlebox of claim 1 , wherein the middlebox is in-band with the network connection between the client device and the server device. 5 . The middlebox of claim 4 , wherein the network control module is further configured to change rules at the middlebox from routing to redirection to activate redirection. 6 . The middlebox of claim 1 , wherein the middlebox is out-of-band with the network connection between the client device and the server device. 7 . The middlebox of claim 6 , wherein the network control module is further configured to direct a router device to redirect the network connection between the client device and the server device through the middlebox to activate redirection. 8 . The middlebox of claim 1 , wherein the processor is further configured to determine that no information has been sent between the client device and the server device for at least a predetermined period of time to determining that the connection is idle. 9 . The middlebox of claim 1 , wherein the processor is further configured to determine whether the network connection between the client device and the server device would benefit from the middlebox's intercession based on monitored packet loss and round-trip times and to trigger the idle determination, the connection entry creation, and the redirection activation based on said determination. 10 . The middlebox of claim 1 , wherein the state information includes one or more of an IP address, port numbers, transport control protocol (TCP) sequence numbers, TCP options, and a congestion window. 11 . A middlebox, comprising: a processor configured to determine a degree of mismatch between a sequence number in a first connection between the middlebox and a client device and a sequence number in a second connection between the middlebox and a server device; and a network control module configured to delay acknowledgment signals from the middlebox on a connection to decrease the degree of mismatch between sequence numbers and to establish a direct connection between the client device and the server device without mediation by the middlebox upon a determination that the degree of mismatch between sequence numbers is zero. 12 . The middlebox of claim 11 , wherein the respective sequence numbers for the connection between the middlebox and the client device and for the connection between the middlebox and the server device are initialized to a same initial sequence number. 13 . The middlebox of claim 11 , wherein the network control module is configured to delay acknowledgment signals in the first connection between the middlebox and the client device. 14 . The middlebox of claim 11 , wherein the network control module is configured to delaying acknowledgment signals in the second connection between the middlebox and the server device. 15 . The middlebox of claim 11 , wherein the middlebox is in-band with the network connection between the client device and the server device. 16 . The middlebox of claim 15 , wherein the network control module is configured to switch rules at the middlebox from redirection to routing to establish a direct connection between the client device and the server device. 17 . The middlebox of claim 11 , wherein the middlebox is out-of-band with the network connection between the client device and the server device. 18 . The middlebox of claim 17 , wherein the network control module is configured to direct an external router to redirect the network connections between the client device and the middlebox and between the server device and the middlebox to exclude the middlebox to establish a direct connection between the client device and the server device. 19 . The middlebox of claim 11 , wherein the processor is further configured to determine whether the network connection between the client device and the server device does not benefit from the middlebox's intercession based on monitored packet loss and round-trip times and to trigger the determination of a degree of mismatch, the delay of signals, and the establishment of a connection based on said determination. 20 . A computer readable storage medium comprising a computer readable program for removing a middlebox from an existing network connection, wherein the computer readable program when executed on a computer causes the computer to perform the steps of: determining that a network connection between the client device and the server device is idle with a processor; creating a first connection entry at a middlebox for the client device and a second connection entry at the middlebox for the server device, where the first and second connection entries are initialized after determining that the network connection between the client device and the server device is idle; and activating redirection of the network connection between the client device and the server device after determining that the network connection between the client device and the server device is idle.

Assignees

Inventors

Classifications

  • Signalling channels for network management communication · CPC title

  • Out-of-band transfers · CPC title

  • H04L41/12Primary

    Discovery or management of network topologies · CPC title

  • H04L69/16Primary

    Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP] · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016119190A1 cover?
Middleboxes include a processor configured to determine that a network connection between a client device and a server device is idle. A connection table is configured to create a first connection entry at the middlebox for the client device and a second connection entry at the middlebox for the server device. The first and second connection entries are initialized after determining that the ne…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L41/12. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Apr 28 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).