Method, system, and logic for in-band exchange of meta-information

US9426176B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9426176-B2
Application numberUS-201414520118-A
CountryUS
Kind codeB2
Filing dateOct 21, 2014
Priority dateMar 21, 2014
Publication dateAug 23, 2016
Grant dateAug 23, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In an embodiment, a method is provided for enabling in-band data exchange between networks. The method can comprise receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server; receiving the data from a network element located in the first network; encoding the data into at least one custom SSL record; and transmitting the at least one regular SSL record and the at least one custom SSL record to an enveloping proxy. In another embodiment, a method can comprise receiving at least one regular secure sockets layer (SSL) record and at least one custom SSL record for a SSL session established between a client and a server; extracting the data from the at least one custom SSL; transmitting the at least one regular SSL record.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for enabling in-band data exchange between a first network and a second network, the method comprising: receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server, wherein the first enveloping proxy does not have access to a first key needed to decrypt the at least one regular SSL record; receiving, by the first enveloping proxy, data from a network element located in the first network; converting, by the first enveloping proxy, the data to a format for transmission in-band by encoding the data into at least one custom SSL record; and transmitting, by a processor in the first enveloping proxy, the data in-band from the first network to the second network over the SSL session by: interleaving ones of the at least one custom SSL record and ones of the least one regular SSL record to generate an interleaved data, the interleaved data being generating without decrypting the at least one regular SSL record, and transmitting the interleaved data to a second enveloping proxy located in the second network, wherein the interleaved data is transmitted via a network component that is to translate a tuple identifying the interleaved data to an alternate tuple identifying the interleaved data, and wherein the second enveloping proxy has access to a second key needed to decrypt the at least one custom SSL record and does not have access to the first key needed to decrypt the at least one regular SSL record. 2. The method of claim 1 , wherein encrypted data within the at least one regular SSL record is to be decrypted only by the server and the server has access to the first key needed to decrypt the at least one regular SSL record. 3. The method of claim 1 , wherein the transmitting the interleaved data to the second enveloping proxy located in the second network comprises transmitting the interleaved data over a data connection between the first enveloping proxy and the second enveloping proxy. 4. The method of claim 1 , wherein the receiving the data from the network element located in the first network comprises receiving the data over an out-of-band channel between the network element and the first enveloping proxy. 5. The method of claim 1 , wherein the first network is a service provider network, the first enveloping proxy is a service provider enveloping proxy, the second network is a content provider network, the second enveloping proxy is a content provider enveloping proxy, and the server is a content server. 6. The method of claim 1 , wherein the first network is a content provider network, the first enveloping proxy is a content provider enveloping proxy, the second network is a service provider network, the second enveloping proxy is a service provider enveloping proxy, and the server is a content server. 7. The method of claim 1 , wherein the interleaved data is transmitted within a single data flow, and further comprising the tuple identifying the single data flow and the alternate tuple identifying the single data flow. 8. A system for enabling in-band data exchange between a first network and a second network, the system comprising: at least one memory element; at least one processor coupled to the at least one memory element; and a data encoding module, on a first enveloping proxy, to interface with the at least one processor and further to: receive at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server, wherein the first enveloping proxy does not have access to a first key needed to decrypt the at least one regular SSL record; receive data from a network element located in the first network; convert the data to a format for transmission in-band by encoding the data into at least one custom SSL record; and transmit the data in-band from the first network to the second network over the SSL session by: interleaving ones of the at least one custom SSL record and ones of the least one regular SSL record to generate an interleaved data, the interleaved data being generating without decrypting the at least one regular SSL record, and transmitting the interleaved data to a second enveloping proxy located in the second network, wherein the interleaved data is transmitted via a network component that is to translate a tuple identifying the interleaved data to an alternate tuple identifying the interleaved data, and wherein the second enveloping proxy has access to a second key needed to decrypt the at least one custom SSL record and does not have access to the first key needed to decrypt the at least one regular SSL record. 9. The system of claim 8 , wherein encrypted data within the at least one regular SSL record is to be decrypted only by the server and the server has access to the first key needed to decrypt the at least one regular SSL record. 10. The system of claim 8 , wherein the transmitting the interleaved data to the second enveloping proxy located in the second network comprises transmitting the interleaved data over a data connection between the first enveloping proxy and the second enveloping proxy. 11. The system of claim 8 , wherein the receiving the data from the network element located in the first network comprises receiving the data over an out-of-band channel between the network element and the first enveloping proxy. 12. The system of claim 8 , wherein the first network is a service provider network, the first enveloping proxy is a service provider enveloping proxy, the second network is a content provider network, the second enveloping proxy is a content provider enveloping proxy, and the server is a content server. 13. The system of claim 8 , wherein the first network is a content provider network, the first enveloping proxy is a content provider enveloping proxy, the second network is a service provider network, the second enveloping proxy is a service provider enveloping proxy, and the server is a content server. 14. The system of claim 8 , wherein the interleaved data is transmitted within a single data flow, and further comprising the tuple identifying the single data flow and the alternate tuple identifying the single data flow. 15. One or more non-transitory tangible media for enabling in-band data exchange between a first network and a second network, the one or more non-transitory tangible media including code for execution and when executed by a processor operable to perform operations comprising: receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server, wherein the first enveloping proxy does not have access to a first key needed to decrypt the at least one regular SSL record; receiving, by the first enveloping proxy, data from a network element located in the first network; converting, by the first enveloping proxy, the data to a format for transmission in-band by encoding the data into at least one custom SSL record; and transmitting, by a processor in the first enveloping proxy, the data in-band from the first network to the second network over the SSL session by: interleaving ones of the at least one custom SSL record and ones of the least one regular SSL record to generate an interleaved data, the interleaved data being generating without decrypting the at least one regular SSL record, and transmitting the interleaved data to a second enveloping proxy located in the second network, wherein the interleaved data is transmitted via a ne

Assignees

Inventors

Classifications

  • Electricity · mapped topic

  • wherein the sending and receiving network entities apply symmetric encryption, i.e. same key used for encryption and decryption (cryptographic mechanisms or cryptographic arrangements for symmetric key encryption H04L9/06) · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • Proxies · CPC title

  • H04L63/166Primary

    at the transport layer · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9426176B2 cover?
In an embodiment, a method is provided for enabling in-band data exchange between networks. The method can comprise receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server; receiving the data from a network element located in the first network; encoding the data into a…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/166. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).