US2019207979A1PendingUtilityA1

System and method of pre-establishing ssl session connections for faster ssl connection establishment

Assignee: CITRIX SYSTEMS INCPriority: Jan 29, 2016Filed: Mar 11, 2019Published: Jul 4, 2019
Est. expiryJan 29, 2036(~9.5 yrs left)· nominal 20-yr term from priority
H04L 67/2842H04L 63/166H04L 67/04H04L 63/0823H04L 67/125H04L 67/12H04L 67/42H04L 67/14H04L 67/146H04L 63/1408H04L 67/10H04L 67/2823H04L 67/01H04L 67/568H04L 67/565
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure session pre-handshake establishment module facilitates a secure session connection request between an appliance and a server associated with a website. The facilitation causes the appliance to receive session information. At least one session to one or more servers listed in a server group is reused if the session information corresponding to the secure session connection request has been cached. Secure session connections between the appliance and servers listed in the server group are formed if the session information corresponding to the secure session connection request has not been cached to pre-establish one or more SSL connections so that when one or more SSL connection requests are received, the one or more pre-established SSL connections can be used without performing full SSL handshake procedures.

Claims

exact text as granted — not AI-modified
That which is claimed: 
     
         1 . An appliance of pre-establishing Secure Socket Layer (SSL) session connections for SSL connection establishment, the appliance comprising:
 a secure session pre-handshake establishment module configured to:
 facilitate a secure session connection request between an appliance and a server associated with a website, with the secure session connection request including a name of the server associated with the website, wherein the facilitation causes the appliance to receive session information; 
 reuse at least one session to one or more servers listed in a server group if the session information corresponding to the secure session connection request has been cached; and 
 form secure session connections between the appliance and servers listed in the server group if the session information corresponding to the secure session connection request has not been cached to pre-establish one or more SSL connections so that when one or more SSL connection requests are received, the one or more pre-established SSL connections can be used without performing full SSL handshake procedures. 
   
     
     
         2 . The appliance of  claim 1 , wherein the secure session pre-handshake establishment module is further configured to identify the server group based on information of the server associated with the website in the secure session connection request. 
     
     
         3 . The appliance of  claim 1 , wherein the names of the servers listed in the server group comprise a head server name and a plurality of sub-servers names, a head server representing at least one webpage and comprising a plurality of objects provided by the plurality of sub-servers to load completely the at least one webpage. 
     
     
         4 . The appliance of  claim 3 , wherein the secure session pre-handshake establishment module is further configured to determine whether there is a matching server among the head server name and the plurality of sub-servers names in the server group, the matching server matching to the server associated with the website. 
     
     
         5 . The appliance of  claim 4 , wherein the secure session pre-handshake establishment module is further configured to increase a frequency count of the matching server based on the determination that there is a matching server. 
     
     
         6 . The appliance of  claim 1 , wherein the session information comprises at least one of session identifier and session ticket information. 
     
     
         7 . The appliance of  claim 6 , wherein the session information is acquired based on a SSL/Transport Layer Security (TLS) full handshake protocol. 
     
     
         8 . The appliance of  claim 1 , wherein the secure session pre-handshake establishment module is further configured to:
 accumulate the session connection request and subsequent session connection requests for a predetermined time period, based on the determination that session information corresponding to the session connection request and the subsequent session connection requests has not been cached;   determine whether there are one or more matching servers in the server group matching to the session connection request and the subsequent session connection requests; and   update a frequency count of each of the one or more matching servers based on the determination that there are the one or more matching servers.   
     
     
         9 . The appliance of  claim 8 , wherein the secure session pre-handshake establishment module is further configured to add or delete at least one server from the server group based on a number of the frequency count. 
     
     
         10 . The appliance of  claim 1 , wherein the secure session pre-handshake establishment module is further configured to:
 accumulate SSL connections made by a client device for a predetermined time period; and   determine a list of one or more server names belonging to the server group based on the accumulated SSL connections.   
     
     
         11 . A method of pre-establishing Secure Socket Layer (SSL) session connections for SSL connection establishment, the method comprising:
 facilitating a secure session connection request between an appliance and a server associated with a website, with the secure session connection request including a name of the server associated with the website, wherein the facilitation causes the appliance to receive session information;   reusing at least one session to one or more servers listed in a server group if the session information corresponding to the secure session connection request has been cached; and   forming secure session connections between the appliance and servers listed in the server group if the session information corresponding to the secure session connection request has not been cached to pre-establish one or more SSL connections so that when one or more SSL connection requests are received, the one or more pre-established SSL connections can be used without performing full SSL handshake procedures.   
     
     
         12 . The method of  claim 11 , further comprising identifying the server group based on information of the server associated with the website in the secure session connection request. 
     
     
         13 . The method of  claim 11 , wherein the names of the servers listed in the server group comprise a head server name and a plurality of sub-servers names, a head server representing at least one webpage and comprising a plurality of objects provided by the plurality of sub-servers to load completely the at least one webpage. 
     
     
         14 . The method of  claim 13 , further comprising determining whether there is a matching server among the head server name and the plurality of sub-servers names in the server group, the matching server matching to the server associated with the website. 
     
     
         15 . The method of  claim 14 , further comprising increasing a frequency count of the matching server based on the determination that there is a matching server. 
     
     
         16 . The method of  claim 11 , wherein the session information comprises at least one of session identifier and session ticket information, and is acquired based on a SSL/Transport Layer Security (TLS) full handshake protocol. 
     
     
         17 . The method of  claim 11 , further comprising:
 accumulating the session connection request and subsequent session connection requests for a predetermined time period, based on the determination that session information corresponding to the session connection request and the subsequent session connection requests has not been cached;   determining whether there are one or more matching servers in the server group matching to the session connection request and the subsequent session connection requests; and   updating a frequency count of each of the one or more matching servers based on the determination that there are the one or more matching servers.   
     
     
         18 . The method of  claim 17 , wherein the secure session pre-handshake establishment module is further configured to add or delete at least one server from the server group based on a number of the frequency count. 
     
     
         19 . The method of  claim 11 , wherein the secure session pre-handshake establishment module is further configured to:
 accumulate SSL connections made by a client device for a predetermined time period; and   determine a list of one or more server names belonging to the server group based on the accumulated SSL connections.   
     
     
         20 . A non-transitory computer readable storage medium that stores a set of instructions that are executable by at least one processor of an appliance to cause the appliance to perform a method of pre-establishing Secure Socket Layer (SSL) session connections for SSL connection establishment, the method comprising:
 facilitating a secure session connection request between an appliance and a server associated with a website, with the secure session connection request including a name of the server associated with the website, wherein the facilitation causes the appliance to receive session information;   reusing at least one session to one or more servers listed in a server group if the session information corresponding to the secure session connection request has been cached; and   forming secure session connections between the appliance and servers listed in the server group if the session information corresponding to the secure session connection request has not been cached to pre-establish one or more SSL connections so that when one or more SSL connection requests are received, the one or more pre-established SSL connections can be used without performing full SSL handshake procedures.

Join the waitlist — get patent alerts

Track US2019207979A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.