Transmission control of protocol state exchange for dynamic stateful service insertion
First Claim
1. A system for a Transmission Control Protocol (TCP) state handoff of a data traffic flow, the system comprising:
- a hardware state machine unit configured to;
determine a plurality of TCP states at predetermined times, each TCP state of the plurality of TCP states being separately determined at a particular predetermined time,wherein each of the plurality of TCP states includes data concerning a session between a client and a server at the particular predetermined time;
a hardware transaction processing unit configured to;
store the TCP state for each of the predetermined times to a database;
receive a request to apply a predetermined policy to the session, wherein the session is processed by the hardware transaction processing unit and wherein the applying the predetermined policy to the session includes transferring the processing of the session to a hardware access control unit;
based on the request, transfer the processing of the session from the hardware transaction processing unit to the hardware access control unit by sending a session request associated with the session between the client and the server to the hardware access control unit, the session request including a current TCP state of the plurality of TCP states, the current TCP state being the TCP state stored for a current time and including the data concerning the session for the current time, the session request further including an instruction to process the session according to the predetermined policy; and
the hardware access control unit configured to;
switch from a stand-by mode to an active mode based on receipt of the session request, the hardware access control unit operating in the stand-by mode in absence of session requests from the hardware transaction processing unit;
upon switching to the active mode, in response to the instruction to process the session, act as a TCP proxy in the session between the client and the server by establishing the session between the hardware access control unit and the client and establishing the session between the hardware access control unit and the server based on the current TCP state; and
based on the instruction included in the session request, process the session request and further data packets associated with the session based on the current TCP state and according to the predetermined policy.
1 Assignment
0 Petitions
Accused Products
Abstract
Provided are methods and systems for a Transmission Control Protocol (TCP) state handoff of a data traffic flow. A method for a TCP state handoff of a data traffic flow comprises determining a TCP state at predetermined times by a state machine unit. The TCP state includes data concerning a session between a client and a server. The TCP state for the predetermined times is stored to a database. A request to apply a predetermined policy to the session is received by a transaction processing unit and, based on the request, a session request associated with the session between the client and the server is sent to an access control unit. The session request is processed by the access control unit based on the TCP state and according to the predetermined policy.
446 Citations
20 Claims
-
1. A system for a Transmission Control Protocol (TCP) state handoff of a data traffic flow, the system comprising:
-
a hardware state machine unit configured to; determine a plurality of TCP states at predetermined times, each TCP state of the plurality of TCP states being separately determined at a particular predetermined time, wherein each of the plurality of TCP states includes data concerning a session between a client and a server at the particular predetermined time; a hardware transaction processing unit configured to; store the TCP state for each of the predetermined times to a database; receive a request to apply a predetermined policy to the session, wherein the session is processed by the hardware transaction processing unit and wherein the applying the predetermined policy to the session includes transferring the processing of the session to a hardware access control unit; based on the request, transfer the processing of the session from the hardware transaction processing unit to the hardware access control unit by sending a session request associated with the session between the client and the server to the hardware access control unit, the session request including a current TCP state of the plurality of TCP states, the current TCP state being the TCP state stored for a current time and including the data concerning the session for the current time, the session request further including an instruction to process the session according to the predetermined policy; and the hardware access control unit configured to; switch from a stand-by mode to an active mode based on receipt of the session request, the hardware access control unit operating in the stand-by mode in absence of session requests from the hardware transaction processing unit; upon switching to the active mode, in response to the instruction to process the session, act as a TCP proxy in the session between the client and the server by establishing the session between the hardware access control unit and the client and establishing the session between the hardware access control unit and the server based on the current TCP state; and based on the instruction included in the session request, process the session request and further data packets associated with the session based on the current TCP state and according to the predetermined policy. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A method for a TCP state handoff of a data traffic flow, the method comprising:
-
determining, by a hardware state machine unit, a plurality of TCP states at predetermined times, each TCP state of the plurality of TCP states being separately determined at a particular predetermined time, wherein each of the plurality of TCP states includes data concerning a session between a client and a server at the particular predetermined time; storing, to a database, the TCP state for the predetermined times; receiving, by a hardware transaction processing unit, a request to apply a predetermined policy to the session, wherein the session is processed by the hardware transaction processing unit and wherein the applying the predetermined policy to the session includes transferring the processing of the session to a hardware access control unit; based on the request, transferring the processing of the session from the hardware transaction processing unit to the hardware access control unit by sending, by the hardware transaction processing unit, a session request associated with the session between the client and the server to the hardware access control unit, the session request including a current TCP state of the plurality of TCP states, the current TCP state being the TCP state stored for a current time and including the data concerning the session for the current time, the session request further including an instruction to process the session according to the predetermined policy; and switching, by the hardware access control unit, from a stand-by mode to an active mode based on receipt of the session request, the hardware access control unit operating in the stand-by mode in absence of session requests from the hardware transaction processing unit; upon switching to the active mode, in response to the instruction to process the session, acting, by the hardware access control unit, as a TCP proxy in the session between the client and the server by establishing the session between the hardware access control unit and the client and establishing the session between the hardware access control unit and the server based on the current TCP state; and based on the instruction included in the session request, processing, by the hardware access control unit, the session request and further data packets associated with the session based on the current TCP state and according to the predetermined policy. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18, 19)
-
-
20. A system for a TCP state handoff of a data traffic flow, the system comprising:
-
a hardware state machine unit configured to; determine a plurality of TCP states at predetermined times, each TCP state of the plurality of TCP states being separately determined at a particular predetermined time, wherein each of the plurality of TCP states includes data concerning a session between a client and a server at the particular predetermined time; a hardware transaction processing unit configured to; store the TCP state for each of the predetermined times to a database; receive a request to apply a predetermined policy to the session, wherein the session is processed by the hardware transaction processing unit and wherein the applying the predetermined policy to the session includes transferring the processing of the session to a hardware access control unit; based on the request, transferring the processing of the session from the hardware transaction processing unit to the hardware access control unit by sending a session request associated with the session between the client and the server to the hardware access control unit, the session request including a current TCP state of the plurality of TCP states, the current TCP state being the TCP state stored for a current time and including the data concerning the session for the current time, wherein the session request is sent to the hardware access control unit using a magic packet, the magic packet including the current TCP state and an instruction to process the session according to the predetermined policy; and the hardware access control unit configured to; switch from a stand-by mode to an active mode based on receipt of the session request, the hardware access control unit operating in the stand-by mode in absence of session requests from the hardware transaction processing unit; upon switching to the active mode, in response to the instruction to process the session, act as a TCP proxy in the session between the client and the server by establishing the session between the hardware access control unit and the client and establishing the session between the hardware access control unit and the server based on the current TCP state; and based on the instruction included in the session request, process the session request and further data packets associated with the session based on the current TCP state and according to the predetermined policy, wherein the processing of the session request includes establishing a further session between the client and the server, the further session being established based on the current TCP state retrieved by the hardware access control unit.
-
Specification