Proxy server
Claim Score by NHIP
Abstract
A proxy server shares a plurality of modems connected to a wide area network among multiple client computers connected to a local area network. Each of the client computers on the local area network is assigned a local address while each of the plurality of modems is assigned a modem port address valid on the wide area network. In one embodiment, a processor controls address substitution allowing multiple client computers to share modems when communicating to host computers in a wide area network. The processor creates a descriptor list to keep track of the connections between the client computer and host computers on the wide area network and uses the descriptor list to determine to which client computer an incoming data packet should be sent. The processor also creates a proxied application list to determine if an outgoing data packet, received from one of the client computers, is one to be proxied through the proxy server.
Term
Term ended
Projected expiry passed 28 December 2018, 7.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
21 claims: 4 independent, 17 dependent
- 1A proxy server for use in connecting a wide area network with a plurality of client computers each having a local address, the proxy server comprising:a local port connected to a local area network and operative for sending a plurality of incoming local packets and for receiving a plurality of outgoing local packets to and from the plurality of client computers;a plurality of modems each having a modem port address and each connected to the wide area network, and operative for transmitting a plurality of outgoing remote packets and receiving a plurality of incoming remote packets;and a processor connected to the local port and connected to the plurality of modems, and operative for receiving one of the plurality of outgoing local packets from one of the plurality of client computers, for executing a load balancing algorithm and selecting one of the plurality of modems, for modifying the one of the plurality of outgoing local packets by substituting the modem port address of the selected modem for the local address of the one of the plurality of client computers to produce one of the plurality of outgoing remote packets, and for transmitting the one of the plurality of outgoing remote packets to the selected modem for transmission to the wide area network.
- 16A method of sharing a plurality of modems connected to a wide-area network among client computers of a local area network comprising:creating a first entry in a descriptor list for each open connection between a client computer and a host computer on the wide area-network, the first entry including a first mapped port number;generating an outgoing packet from the client computer, the outgoing packet including a first portion of data, corresponding to the first entry, and a source address, the first portion of data having a source port number;comparing the first portion of data with each first entry in the descriptor list to find a first corresponding first entry;if the first corresponding first entry is found, substituting the first mapped port number of the first corresponding first entry for the source port number;selecting a modem from the plurality of modems using a load balancing algorithm;substituting an address of the selected modem for the source address ;and transmitting the outgoing packet using the selected modem.
- 19A communication system, comprising; a plurality of client computers on a local area network, each client computer having a unique local address to differentiate from other client computers ; and a proxy server comprising:a local port connected to the local area network and operative for sending a plurality of incoming local packets to the plurality of client computers and for receiving a plurality of outgoing local packets from the plurality of client computers;a plurality of modems connected to a wide area network, and operative for transmitting a plurality of outgoing remote packets and receiving a plurality of incoming remote packets, each modem having a unique modem port address to differentiate from other modems;and a processor connected to the local port and connected to the plurality of modems, and operative for receiving one of the plurality of outgoing local packets from one of the plurality of client computers, for executing a load balancing algorithm and selecting one of the plurality of modems, for modifying the one of the plurality of outgoing local packets by substituting the modem port address of the selected modem for the local address of the one of the plurality of client computers, to produce one of the plurality of outgoing remote packets, and for transmitting the one of the plurality of outgoing remote packets to the selected modem for transmission to the wide area network.
- 20Broadest claimClaim Score 72, broad(NHIP)A method of communication, comprising:receiving a request from a client computer to establish a connection to a remote server having a remote server address;selecting a modem from a plurality of modems in response to the request using a load balancing algorithm;receiving a local data packet from the client computer;combining the remote server address and the local data packet to create a remote data packet;and sending the remote data packet to the remote server through the selected modem.
Independent claims4
57 paragraphs in 6 sections, as filed
COPYRIGHT NOTICE/PERMISSION
A portion of the disclosure of this patent document contains material which is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure as it appears in the Patent and Trademark Office patent file or records, but otherwise reserves all copyright rights whatsoever. The following notice applies to the software and data as described below and in the drawing hereto: Copyright © 1997, Multi-Tech Systems, Inc., All Rights Reserved.
FIELD OF THE INVENTION
The present invention is related to network servers and in particular to a proxy server.
BACKGROUND OF THE INVENTION
Traditionally, connecting networked computers to the Internet required establishing a dial-up connection for each network computer, or a dedicated line or frame relay connection shared by all network computers. Individual dial-up connections optimize bandwidth and connection time while a dedicated connection provides the easy extension of Internet resources to newly added network computers. Each approach has major drawbacks, however.
Each networked computer using an individual dial-up connection requires an unique account with an Internet Service Provider (ISP), its own phone line, and a modem, in addition to the hardware necessary to connect the computer to the network. The cost of the modems, phone lines, and ISP accounts quickly becomes prohibitive in a small to medium sized network.
A dedicated connection eliminates the cost burdens of individual dial-up connections since the dedicated connection utilizes the hardware necessary to connect the computer to the network. The drawbacks to a dedicated connection are the cost of the dedicated connection, the cost of the equipment necessary to connect the network to the dedicated connection, and the additional overhead associated with managing the network and securing the network from unauthorized, external access.
Therefore, there is a need to connect network computers to the Internet without incurring the cost burdens associated with either individual dial-up accounts or a dedicated connection while incorporating the benefits of both approaches.
SUMMARY OF THE INVENTION
A proxy server shares a plurality of modems connected to a wide area network among multiple client computers connected to a local area network. The proxy server comprises the plurality of modems, a local port connected to the local area network, and a processor connected to the local port and to the modems. Each of the client computers on the local area network is assigned a local address while each of the modems is assigned a modem port address. The local port receives outgoing local packets destined for the wide area network from the client computers and sends incoming local packets from the wide area network to the client computers. The modems transmit outgoing remote packets and receive incoming remote packets to and from the wide area network. When the processor receives an outgoing local packet from one of the client computers through the local port, the processor selects one of the modems and substitutes the modem port address of the selected modem for the local address of the client computer in the outgoing local packet to create an outgoing remote packet. The processor transmits the outgoing remote packet to the selected modem for transmission to the wide area network. When the processor receives an incoming remote packet from a modem, the processor determines a destination client computer for the incoming remote packet, and substitutes the local address of the destination client computer for the modem port address of the modem in the incoming remote packet to create an incoming local packet. The processor transmits the incoming local packet to the destination client computer through the local port. The processor creates a descriptor list to keep track of the connections between the client computer and host computers on the wide area network and uses the descriptor list to determine to which client computer an incoming remote packet should be sent. The processor also creates a proxied application list to determine if an outgoing local packet is one to be proxied through the proxy server.
The structure of the descriptor list and the proxied application list are described in detail as are the processes performed by proxy server software which causes the processor to perform as summarized above. Additionally, various algorithms used to select a modem are also described.
Because the proxy server shares multiple modems among the computer of a local area network, the number of phone lines, modems, and ISP accounts are greatly reduced while maintaining the benefits of using only the amount of bandwidth needed at one time associated with dial-up Internet accounts. Furthermore, the proxy server allows easy connections of new client computers to the Internet but without the overhead associated with a dedicated connection. Additionally, because the proxy server translates between non-registered local area network addresses and valid Internet addresses, the local area network is secured against unauthorized, external access.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1A is a block diagram of one embodiment of a proxy server of the present invention.
FIG. 1B is a block diagram of communications flow in the proxy server shown in FIG. <b>1</b>A.
FIG. 2 is diagram of one embodiment of a packet header used by the proxy server of FIG. <b>1</b>A.
FIG. 3 is a diagram of one embodiment of a proxied application list used by the proxy server of FIG. <b>1</b>A.
FIG. 4 is a diagram of one embodiment of a descriptor list used by the proxy server of FIG. <b>1</b>A.
FIG. 5A is a flow chart of processes performed by the proxy server of FIG. 1A in response to receiving an outgoing packet.
FIG. 5B is a flow chart of processes performed by the proxy server of FIG. 1A in response to receiving an incoming packet.
FIG. 5C is a flow chart of process performed by the proxy server of FIG. 1A to select a port for outgoing packets.
FIG. 6 is a diagram of one embodiment of a status list used by the proxy server of FIG. <b>1</b>A.
DESCRIPTION OF THE EMBODIMENTS
In the following detailed description of the embodiments, reference is made to the accompanying drawings which form a part hereof, and in which is shown by way of illustration specific embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention, and it is to be understood that other embodiments may be utilized and that structural, logical and electrical changes may be made without departing from the spirit and scope of the present inventions. The following detailed description is, therefore, not to be taken in a limiting sense, and the scope of the present inventions is defined only by the appended claims.
The leading digit(s) of reference numbers appearing in the Figures corresponds to the Figure number, with the exception that the same reference number is used throughout to refer to an identical component which appears in multiple Figures. Signals and connections may be referred to by the same reference number or label, and the actual meaning will be clear from its use in the context of the description.
An overview of one embodiment of the proxy server hardware and software is first described in reference to FIGS. 1A and 1B. The particular methods performed by an exemplary embodiment of the proxy server software are next described in detail by reference to data structure diagrams in FIGS. 2, <b>3</b> and <b>4</b>, and a series of flowcharts shown in FIGS. <b>5</b>x. The methods to be performed by the proxy server software constitute computer programs made up of computer-executable instructions. Describing the methods by reference to a flowchart enables one skilled in the art to develop such programs including such instructions to carry out the methods on suitable computerized servers (the processor of the server executing the instructions from computer-readable media).
Proxy Sever Overview
The embodiment of the proxy server <b>100</b> shown in FIG. 1A has a local area network (LAN) port <b>101</b>, three modems <b>103</b>, <b>104</b>, <b>105</b> serving as wide area network (WAN) ports, a command port <b>107</b>, a microprocessor <b>109</b>, and memory <b>111</b>. The LAN (local) port <b>101</b> connects the proxy server <b>100</b> to a local area network <b>121</b> of client computers <b>121</b>, <b>122</b>, <b>123</b>. The modems <b>103</b>-<b>105</b> connect the proxy server <b>100</b> to the Internet <b>131</b> through an Internet Service Provider (ISP). The ISP assigns a valid Internet address (modem port address) to each WAN port <b>103</b>-<b>105</b>. Proxy server software <b>113</b> (shown in FIG. 1B) executing in the microprocessor <b>109</b> manages the transfer of data packets between the client computers on the LAN <b>121</b> and host computers <b>133</b>, <b>134</b>, <b>135</b> on the Internet <b>131</b>. The command port <b>107</b> is used to configure the proxy server through a non-network computer <b>141</b>.
In an alternate embodiment, one of the WAN ports <b>103</b>-<b>105</b> serves as a dial-in connection so that a remote computer can connect to the proxy server <b>100</b> without being connected to the Internet. In yet another embodiment, one of the WAN ports <b>103</b>-<b>105</b> alternates between a dial-in connection and an ISP connection depending on predetermined parameters such as time of day and/or communication traffic.
Further alternate embodiments having more or fewer than three modems are contemplated as within the scope of the invention and the applicability of the following descriptions to such alternate embodiments will be readily apparent to one of skill in the art.
FIG. 1B illustrates a single client computer <b>123</b> on the LAN <b>121</b> connected to a host computer <b>133</b> on the Internet <b>121</b> through the WAN port <b>103</b> on the proxy server <b>493</b><b>100</b>. The following descriptions are also applicable to the alternate embodiments in which the WAN port <b>103</b> serves as a dial-in connection.
When a user invokes an Internet application <b>125</b> on the client computer <b>123</b>, the application <b>125</b> sends a data stream <b>126</b> to a corresponding communications protocol stack <b>127</b> on the client computer <b>123</b>. For example, data streams from a World Wide Web browser or a FTP/TFTP (File Transport Protocol/Trivial File Transport Protocol) session are directed to a TCP/IP stack. The protocol stack <b>127</b> creates outgoing LAN (local) packets <b>128</b> from the data and places the LAN packets <b>128</b> on the LAN <b>121</b> for routing to their destination.
The proxy server <b>100</b> receives the LAN packets <b>128</b> on the LAN port <b>101</b> and the proxy server software <b>113</b> determines if the data in each LAN packet <b>128</b> is to be transferred to the Internet (“proxied”). Packets which are not to be proxied are discarded. Because the client computer <b>123</b> is assigned a unique LAN address which is not a valid Internet address, the proxy server <b>100</b> must translate between the LAN address of the client computer <b>123</b> and the valid Internet address of the WAN port <b>103</b> for outgoing local packets which will be proxied. After converting the outgoing LAN packet <b>128</b> to an outgoing Internet (WAN) packet <b>137</b>, the proxy server software transfers the outgoing Internet (remote) packet <b>137</b> to the Internet using modem (WAN port) <b>103</b> for delivery to the host computer <b>133</b>. The proxy server software <b>113</b> performs the reverse process when it receives an incoming Internet packet through WAN port <b>103</b> to create an incoming LAN packet for transmission to the appropriate client computer.
The proxy server software supports multilink operation if the ISP supports a suitable protocol such as ML-PPP (Multi Link Point to Point Protocol). The goal of multilink operation (“channel bonding”) is to coordinate multiple independent communications links between a pair of systems, thus providing a virtual link with greater bandwidth than any of the constituent members. ML-PPP protocol is used to split, recombine and sequence datagrams across the multiple logical data links to bond the multiple links into a single data transmission channel.
The processes performed by the proxy server software <b>113</b> and supporting data structures are described next.
Proxy Server Software
The proxy server software <b>311</b> of FIG. 1B is next described in the general context of computer-executable instructions, such as program modules, being executed by the microprocessor <b>109</b> of proxy server <b>100</b> as shown in FIG. <b>1</b>A. Although no particular structure or arrangement of program modules is required by the invention, generally the program modules include routines, programs, objects, components, data structures, etc., that perform particular tasks or implement particular abstract data types.
Each packet <b>200</b> received by the proxy server software from either the LAN <b>121</b> or the Internet <b>131</b> contains a header <b>201</b> that specifies addresses for the source <b>203</b> and destination <b>205</b> computers, and an application port, or service, number <b>207</b>, <b>209</b> for the source and destination applications that will service the data in the packet. The header <b>201</b> also contains the transport protocol <b>211</b> used to transfer the packet, such as TCP (Transmission Control Protocol) for a browser or UDP (User Datagram Protocol) for FTP/TFTP. Headers for packets containing systems messages delivered between the client and source computers using the Internet Control Messaging Protocol (ICMP) do not contain source and destination port numbers as the messages are independent of any particular application.
For an outgoing TCP/IP LAN packet, the source of a packet is uniquely identified by the LAN address <b>203</b> for the originating, source, client computer, such as computer <b>123</b> in FIG. 1B, and the application source port number <b>207</b> for the application that created the packet. The destination for an outgoing TCP/UDP LAN packet is uniquely identified by an Internet destination address <b>205</b> for a host computer on the Internet, such as host computer <b>133</b> in FIG. 1B, and a application destination port number <b>209</b> on the host computer. The destination address <b>205</b>, destination port number <b>209</b>, LAN address <b>203</b>, and source port number <b>207</b> together identify a particular application connection between the client and host computers. Similarly, the source of an ICMP LAN packet is the LAN address of the client computer, the destination is the Internet address of the host computer, and the ICMP connection is identified by the destination address and the LAN address.
The proxy server software maintains three data structures: a proxied application list <b>300</b>, a descriptor list <b>400</b> of open connections, and a status list <b>600</b>. Although the data structures are described as lists, one of skill in the art will readily recognize that the data structures can be embodied as relational data base tables, file records, operating system registry entries, or other well-known arrangements of data, and stored on computer-readable media of various types including random access memory, fixed disk, or CDROM.
One embodiment of the proxied application list <b>300</b> is illustrated in FIG. <b>3</b>. The application list <b>300</b> created when the proxy server software is initialized. Each entry <b>301</b> in the application list <b>300</b> contains the transport protocol <b>303</b> and the application port number <b>304</b> for an application which will be proxied through the proxy server.
One embodiment of the descriptor list <b>400</b> is illustrated in FIG. <b>4</b>. The descriptor list <b>400</b> contains an entry <b>401</b> for each open TCP/UDP connection. Each entry <b>401</b> is keyed on the destination port <b>406</b>, transport protocol <b>407</b>, destination address <b>408</b>, and LAN address <b>409</b>. The destination port <b>406</b>, transport protocol <b>407</b>, destination address <b>408</b>, LAN address <b>409</b>, and the source port <b>410</b>, are collectively referred to as a connection descriptor <b>405</b>. The descriptor list <b>400</b> also contains an entry <b>411</b> keyed on the transport protocol <b>416</b>, destination address <b>417</b>, and LAN address <b>418</b> for each ICMP connection, collectively shown as connection descriptor <b>415</b>. The mapped port number <b>403</b> and identifier <b>413</b> shown in FIG. 4 are explained below.
One embodiment of the status list <b>600</b> is illustrated in FIG. <b>6</b> and explained in conjunction with FIGS. 5A, <b>5</b>B and <b>5</b>C which describe the methods or processes performed by the proxy server software. Beginning with FIG. 5A, when an outgoing LAN packet, such as packet <b>128</b> in FIG. 1B, is received by the proxy server <b>100</b>, the proxy server software determines if the packet is to be proxied (step <b>501</b>). For TCP/UDP LAN packets, the determination is based on comparing the entries <b>301</b> in the application list <b>300</b> against the corresponding information in the packet header <b>200</b>. A match indicates that the TCP/UDP LAN packet is to be proxied. In the case of ICMP LAN packets, only packets having a message type of “echo request” will be proxied. LAN packets which are not to be proxied are ignored by the proxy server.
Once the determination is made that a LAN packet is to be proxied at step <b>501</b>, the proxy server software determines whether the connection requested by a packet is an existing open connection (step <b>503</b>) using the descriptor list <b>400</b> and the information contained in the packet header <b>200</b>. If the corresponding information in the packet header <b>200</b> does not match a entry <b>401</b> in the descriptor list <b>400</b>, the connection has not yet been opened and, therefore, must be created. However, because the combination of application port number and the LAN address in a LAN packet is valid only within the local area network, those values cannot be used to open a new connection.
Therefore, the proxy server software selects an application port number which is not reserved or in use by the proxy server (step <b>505</b>). For a new TCP/UDP connection (which is not a FTP/TFTP connection), the software creates an new entry <b>401</b> in the descriptor list <b>400</b>, stores the appropriate information the LAN packet header <b>200</b> as the connection descriptor <b>405</b>, and inserts the selected application port number into the mapped port <b>403</b> (step <b>507</b>).
If the application is FTP/TFTP, the proxy server software creates one entry <b>401</b> in the descriptor list <b>400</b> that corresponds to the connection between the client computer and the FTP/TFTP application port on the host computer, and a second entry <b>401</b> in the descriptor list <b>400</b> for the connection between the client computer and the data transfer port on the host computer.
The proxy server software also creates an entry <b>601</b> in the status list <b>600</b> for a newly opened connection. The entry <b>601</b> contains an open connection identifier <b>603</b> for the open connection, a physical port identifier <b>605</b> which identifies the physical port on which the open connection communications, and an idle timer <b>607</b>.
When the appropriate entry <b>401</b> is created or matched, the LAN packet converted to an Internet packet by the proxy server software (step <b>509</b>). The mapped port <b>403</b> in the entry <b>401</b> is used as the source port <b>207</b> in the packet header <b>200</b>. Similarly, the proxy server software replaces the LAN address of the client computer with the Internet address of one of the WAN port <b>103</b>-<b>105</b> on the proxy server <b>100</b>. The WAN port used for the communication is specified by the physical port identifier <b>605</b>. The selection process for a WAN port is described in more detail below.
If the FTP/TFTP LAN packet contains a “PORT” command, the proxy server software also replaces the port number specified in the data portion of the packet. As will be readily apparent to one of skill in the art, such a modification can result in a change of the packet size, so the software modifies appropriate sections of the header of each packet transferred through the FTP/TFTP connection accordingly.
In the case of an ICMP packet, the proxy server software creates a new entry <b>411</b> in the descriptor list <b>400</b>, stores a unique identifier <b>413</b> for the ICMP connection and the connection descriptor <b>415</b> information from the packet header <b>200</b>. The identifier <b>413</b> is included in the ICMP packet at step <b>509</b>. An exemplary ICMP packet is shown in Table 1 below. The identifier field shown in Table 1 is mapped before forwarding the ICMP packet to the Internet.
<tables><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="1"><colspec colname="1" colwidth="217pt" align="center" /><thead><row><entry namest="1" nameend="1" rowsep="1">TABLE 1</entry></row><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry><chemistry><img id="EMI-C00001" file="USH0002065-20030506-C00001.TIF" wi="147.39165" he="43.4322" img-content="chem" img-format="tif" alt="embedded image" /><attachments><attachment idref="CHEMCDX-00001" attachment-type="cdx" file="USH0002065-20030506-C00001.CDX" /><attachment idref="CHEMMOL-00001" attachment-type="mol" file="USH0002065-20030506-C00001.MOL" /></attachments></chemistry></entry></row><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
Once the LAN packet has been converted to a valid Internet packet as described above, the proxy server software recomputes the appropriate checksums to complete step <b>509</b>. The proxy software then transfers the converted packet to the Internet through the selected WAN port (step <b>511</b>).
Because an outgoing TCP/UDP Internet packet specifies the mapped port <b>403</b> as the source port <b>207</b> in its header <b>200</b>, an incoming Internet packet on the same connection will specify the mapped port <b>403</b> as the destination port <b>209</b> in its header <b>200</b>. As shown in FIG. 5B, the proxy server software matches the mapped port <b>403</b> and the protocol <b>211</b> specified in the header <b>200</b> of the incoming Internet to the corresponding entry <b>401</b> in the descriptor list <b>400</b> (step <b>521</b>). The proxy server software then replaces the destination address <b>205</b> and destination port <b>209</b> in the header <b>200</b> of the incoming packet with the LAN address <b>409</b> and application port <b>410</b> from the entry <b>401</b> (step <b>523</b>). Similarly, the identifier in an incoming ICMP packet is used to find the corresponding entry <b>411</b> in the descriptor list <b>400</b> at step <b>521</b>, and the destination address <b>205</b> in the incoming packet is replaced by the LAN address <b>418</b> from the entry <b>401</b> at step <b>523</b>. The software recomputes the checksums for the packet to complete the conversion between Internet and LAN packets at step <b>523</b> and transfers the converted packet to the LAN for routing to the specified client computer (step <b>525</b>).
The WAN port selection process is illustrated in FIG. <b>5</b>C. In order to balance the load on the proxy's server's physical WAN ports, i.e., the modems, the proxy server software only permanently assigns a physical port to a new connection if the application, such as ICMP, requires the same source address for the life of the connection (step <b>533</b>). For an ICMP connection (step <b>535</b>), the proxy server software selects the first active port (step <b>537</b>). For other applications that require the use of the same physical port, the proxy server selects the port with the least amount of load when the connection is initially established (step <b>539</b>).
For applications that do not require the same physical port (steps <b>553</b> and <b>545</b>), the proxy server software dynamically selects a port each time a packet is to be sent to the Internet (step <b>543</b>). The software will select the active port with the least amount of load. A physical port which is currently not active is selected when all active ports are equally loaded. A WAN port can be inactive because, for example, it is both a dial-in and Internet connection. If all ports are active and equally loaded, the software selects the first active port.
The idle timer <b>607</b> is set to an initial value when the connection is opened (step <b>557</b>). Each timer <b>607</b> is decremented by foreground process (not illustrated) each minute there is no activity on the corresponding connection. Activity on the connection resets the appropriate timer <b>607</b> to the initial value (step <b>555</b>) while a TCP “close” command (step <b>551</b>) sets the timer to an amount pre-determined to be adequate for the closing operations (step <b>553</b>). In the case of an ICMP echo request message, the timer <b>607</b> is set to zero (step <b>550</b>) when the response (step <b>549</b>) is received. When a timer <b>607</b> reaches zero, the corresponding connection is closed and the descriptor entry <b>411</b> and status entry <b>601</b> are freed (not illustrated).
A physical port can be closed by either the proxy server, the ISP, or due to a failed communications link between the proxy server and the ISP. When a physical port is closed, all connections using that physical port are closed and the corresponding descriptors and status entries freed.
As described above, each client computer is assigned a unique LAN address. In one embodiment, such addresses are permanently assigned external to the proxy server. In an alternate embodiment, the proxy server software acts as a DHCP (Dynamic Host Configuration Protocol) to dynamically assign an address to a client computer when the client computer requests a connection. As the operations of a DHCP server are well known to one skilled in the art, no detailed functional description is provided.
The proxy server software also provides monitoring and management of the proxy server using a browser or Telnet program on a computer connected through the LAN port, the command port, or a WAN port. User input is received in the form of Telnet, HTTP, or FTP commands. When the microprocessor <b>109</b> recognizes that a command is addressed to the proxy server <b>100</b>, not to a client or host computer, a security check is performed to ensure that the user is permitted access to the monitoring and management facilities of the proxy server software. Any results from the command are returned through the port on which the command arrived. Telnet, HTTP, and FTP commands, and the software required to support their operations, are well-known to one of skill and are, therefore, not discussed in further detail.
Proxy Server Summary
The proxy server has been described in terms of its hardware and software components, from an overview of the operation of the hardware and software, through detailed descriptions of the processes performed by the software and the data structures employed by the processes. It is to be understood that the above description is intended to be illustrative, and not restrictive. Many other embodiments will be apparent to those of skill in the art upon reviewing the above description. The scope of the invention should, therefore, be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.
Because the proxy server shares multiple modems among the computer of a local area network, the number of phone lines, modems, and ISP accounts are greatly reduced while maintaining the benefits of using only the amount of bandwidth needed at one time associated with dial-up Internet accounts. Furthermore, the proxy server allows easy connections of new LAN computers to the Internet but without the overhead associated with a dedicated connection. Additionally, because the proxy server translates between non-registered LAN addresses and valid Internet addresses, the LAN is secured against unauthorized, external access.
Contents6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7752333B1 | Cited by | United States of America | Search report |
| CN103731680A | Cited by | China | Search report |
| US2003229809A1 | Cited by | United States of America | Pre-grant |
| US9241177B2 | Cited by | United States of America | Applicant |
| US10778659B2 | Cited by | United States of America | Applicant |
| US9992180B2 | Cited by | United States of America | Applicant |
| US7328284B2 | Cited by | United States of America | Applicant |
| US9325676B2 | Cited by | United States of America | Applicant |
| US2005198302A1 | Cited by | United States of America | Pre-grant |
| US2003208531A1 | Cited by | United States of America | Pre-grant |
| US2004001469A1 | Cited by | United States of America | Pre-grant |
| US9088807B2 | Cited by | United States of America | Applicant |
| US2003112823A1 | Cited by | United States of America | Pre-grant |
| US7447778B2 | Cited by | United States of America | Search report |
| US2002099827A1 | Cited by | United States of America | Pre-grant |
| US2003208631A1 | Cited by | United States of America | Pre-grant |
| US10382595B2 | Cited by | United States of America | Applicant |
| US7404012B2 | Cited by | United States of America | Applicant |
| US7024479B2 | Cited by | United States of America | Applicant |
| US8194625B2 | Cited by | United States of America | Search report |
| US10637839B2 | Cited by | United States of America | Applicant |
| US9348927B2 | Cited by | United States of America | Applicant |
| US8477753B2 | Cited by | United States of America | Applicant |
| KR101469824B1 | Cited by | Republic of Korea | Examiner |
| US7227864B2 | Cited by | United States of America | Search report |
| US2003208633A1 | Cited by | United States of America | Pre-grant |
| US7356608B2 | Cited by | United States of America | Applicant |
| US8819755B2 | Cited by | United States of America | Applicant |
| US5371852A | Cites | United States of America | Search report |
| US6035020A | Cites | United States of America | Search report |
| US6038594A | Cites | United States of America | Search report |
| US6091737A | Cites | United States of America | Search report |
| US6115755A | Cites | United States of America | Applicant |
| US6157950A | Cites | United States of America | Search report |
| US6182141B1 | Cites | United States of America | Search report |
| US6185625B1 | Cites | United States of America | Search report |
| US6243379B1 | Cites | United States of America | Applicant |
| US6253247B1 | Cites | United States of America | Applicant |
| US6282193B1 | Cites | United States of America | Applicant |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 22174298 | United States of America | A | |
| US19980221742 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| USH2065HThis record | United States of America | H |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- H2065
- Publication, EPODOC
- USH2065H
- Application
- 9221742
- Application, DOCDB
- 22174298
- Application, EPODOC
- US19980221742
Titles
- English
- Proxy server
Classification
- CPC, 8
- H04L67/1008
- H04L69/16
- H04L69/22
- H04L69/161
- H04L67/1001
- H04L67/563
- H04L67/63
- G06F15/173
- IPC, 2
- H04L29 06
- H04L29 08