US2021126965A1PendingUtilityA1

Systems and methods for scaling down cloud-based servers handling secure connections

Assignee: CISCO TECH INCPriority: Jun 15, 2018Filed: Jan 7, 2021Published: Apr 29, 2021
Est. expiryJun 15, 2038(~11.9 yrs left)· nominal 20-yr term from priority
H04L 67/1029H04L 67/1027H04L 41/0897H04L 67/1001H04L 67/1031H04L 43/16H04L 43/0817H04L 12/66G06F 9/45558H04L 63/164H04L 43/08G06F 2009/4557H04L 63/166H04L 63/0272H04L 41/5096H04L 63/068H04L 67/1002
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosed technology relates to systems and methods for automatically scaling down network resources, such as servers or gateway instances, based on predetermined thresholds. A system is configured to detect a reduction in one or more network metrics related to a first server, and instruct the first server to issue a rekey request to a plurality of devices connected to the first server. The system is further configured to instruct a load balancer to route to at least one other server responses from the plurality of devices to the rekey request, and determine a number of connections remaining between the first server and the plurality of devices. The system may be further configured to instruct the load balancer to terminate the first server based on the detected number of connections remaining between the first server and the plurality of devices.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, at a load balancer, instructions to route responses from a plurality of devices connected to a first server to a second server, wherein the responses are to a rekey request that is sent to the plurality of devices based on one or more measures of one or more network metrics related to the first server;   routing, by the load balancer, the responses from the plurality of devices to the second server based on the instructions; and   terminating, by the load balancer, the first server based on a number of connections remaining between the first server and the plurality of devices.   
     
     
         2 . The method of  claim 1 , wherein the one or more network metrics include at least one of a number of connections to the first server, CPU usage of the first server, and memory utilization of the first server. 
     
     
         3 . The method of  claim 1 , wherein the number of connections remaining between the first server and the plurality of devices is determined from a query that is transmitted to the first server to solicit a response indicating a number of active connections between the first server and the plurality of devices. 
     
     
         4 . The method of  claim 1 , wherein the rekey request is sent from the first server to the plurality of devices. 
     
     
         5 . The method of  claim 1 , wherein the number of connections remaining between the first server and the plurality of devices is determined based on a number of tunnel sessions existing at the first server. 
     
     
         6 . The method of  claim 1 , further comprising receiving, at the load balancer, instructions to refrain from sending any subsequent rekey requests to the rekey request to the first server. 
     
     
         7 . The method of  claim 1 , further comprising receiving at the load balancer, instructions to refrain from sending any new connection requests to the first server. 
     
     
         8 . The method of  claim 1 , wherein the rekey request is sent to the plurality of devices in response to a detected reduction in the one or more network metrics related to the first server. 
     
     
         9 . The method of  claim 1 , wherein the rekey request is sent to the plurality of devices based on the one or more measures of the one or more network metrics with respect to one or more thresholds. 
     
     
         10 . A system comprising:
 one or more processors; and   a computer-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to:
 receive instructions to route responses from a plurality of devices connected to a first server to a second server, wherein the responses are to a rekey request that is sent to the plurality of devices based on one or more measures of one or more network metrics related to the first server; 
 route the responses from the plurality of devices to the second server based on the instructions; and 
 terminate the first server based on a number of connections remaining between the first server and the plurality of devices. 
   
     
     
         11 . The system of  claim 10 , wherein the one or more network metrics include at least one of a number of connections to the first server, CPU usage of the first server, and memory utilization of the first server. 
     
     
         12 . The system of  claim 10 , wherein the number of connections remaining between the first server and the plurality of devices is determined from a query that is transmitted to the first server to solicit a response indicating a number of active connections between the first server and the plurality of devices. 
     
     
         13 . The system of  claim 10 , wherein the rekey request is sent from the first server to the plurality of devices. 
     
     
         14 . The system of  claim 10 , wherein the number of connections remaining between the first server and the plurality of devices is determined based on a number of tunnel sessions existing at the first server. 
     
     
         15 . The system of  claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to receive instructions to refrain from sending any subsequent rekey requests to the rekey request to the first server. 
     
     
         16 . The system of  claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to receive instructions to refrain from sending any new connection requests to the first server. 
     
     
         17 . The system of  claim 10 , wherein the rekey request is sent to the plurality of devices in response to a detected reduction in the one or more network metrics related to the first server. 
     
     
         18 . The system of  claim 10 , wherein the rekey request is sent to the plurality of devices based on the one or more measures of the one or more network metrics with respect to one or more thresholds. 
     
     
         19 . A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the one or more processors to:
 receive instructions to route responses from a plurality of devices connected to a first server to a second server, wherein the responses are to a rekey request that is sent to the plurality of devices based on one or more measures of one or more network metrics related to the first server;   route the responses from the plurality of devices to the second server based on the instructions; and   terminate the first server based on a number of connections remaining between the first server and the plurality of devices.   
     
     
         20 . The non-transitory computer-readable storage medium of  claim 19 , wherein the instructions further cause the one or more processors to receive instructions to refrain from sending any subsequent rekey requests to the rekey request to the first server.

Join the waitlist — get patent alerts

Track US2021126965A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.