IP Library Granted Patent US 7,860,975
Granted Patent B2
US 7,860,975 · App. 10/209,036 · Granted Dec 28, 2010

System and method for secure sticky routing of requests within a server farm

Assignee: Oracle America, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,860,975
App. No.
10/209,036
Granted
Dec 28, 2010
Kind
B2
Abstract

Upstream devices, such as load balancers or routers, within a server farm, may be configured to route requests to the servers handling sessions for those requests using a secure (e.g. encrypted) unique ID or network address received with requests identifying how requests may be routed through the server farm. Upstream devices or a server receiving a request that is not associated with a session may generate a unique ID or select a network address identifying how the request is routed through the server farm. The server handling the request forms a session ID and returns that session ID and the unique ID to the client that originated the request. Encryption may be performed on network addresses or session IDs. Upon receiving a request corresponding to an established session, an upstream device may then decrypt routing information from the encrypted unique ID or network address and send the request downstream accordingly.

Claims (44)

1. A method, comprising:

an upstream device receiving a client request;

the upstream device determining whether the client request is associated with an established session;

the upstream device selecting one of a plurality of servers and sending the client request to the selected server if the client request is not associated with an established session;

the selected server generating a session ID and providing a unique ID in response to the client request, and sending the session ID and unique ID to the client if the client request is not associated with an established session, wherein the unique ID comprises encrypted data identifying the selected server; and

the upstream device identifying one of the plurality of servers from encrypted data of a unique ID provided with the client request, and sending the client request to the identified server if the client request is associated with an established session.

2. The method as recited in claim 1 , further comprising, the upstream device generating the unique ID and sending the unique ID with the client request to the selected server if the client request is not associated with an established session.

3. The method as recited in claim 2 , further comprising the upstream device encrypting the unique ID.

4. The method as recited in claim 2 , further comprising the selected server encrypting the unique ID.

5. The method as recited in claim 2 , further comprising the selected server encrypting the session ID, wherein the unique ID is encrypted as part of the session ID.

6. The method as recited in claim 1 , further comprising, the selected server generating the unique ID if the client request is not associated with an established session.

7. The method as recited in claim 6 , further comprising the selected server encrypting the session ID, wherein the unique ID is encrypted as part of the session ID.

8. The method as recited in claim 1 , wherein the unique ID comprises a network address of the selected server.

9. The method as recited in claim 1 , wherein said selecting comprises selecting to balance the load of each server in the plurality of servers.

10. The method as recited in claim 1 , wherein said selected server generating and sending comprises a web server responding to the client request, wherein the client request is from a web client over the Internet.

11. The method as recited in claim 10 , further comprising the selected server establishing a session with the web client and storing session state information for the session.

12. The method as recited in claim 1 , wherein the upstream device is comprised within a hierarchy of upstream devices configured to route client requests to the servers.

13. A computer-readable storage medium, comprising computer instructions configured to implement:

an upstream device receiving a client request from a client;

the upstream device determining whether or not the client request is associated with an established session;

the upstream device selecting one of a plurality of servers and sending the client request to the selected server if the client request is not associated with an established session, wherein the plurality of servers are coupled to the upstream device and configured to store session information; and

the upstream device identifying one of the plurality of servers from encrypted data of a unique ID provided with the client request, and sending the client request associated with an established session to the identified server if the client request is associated with an established session.

14. The computer-readable storage medium as recited in claim 13 , wherein the computer instructions are further configured to implement the upstream device generating a unique ID and sending the unique ID with the client request to the selected server if the client request is not associated with an established session.

15. The computer-readable storage medium as recited in claim 14 , wherein the computer instructions are further configured to implement the upstream device encrypting the unique ID.

16. The computer-readable storage medium as recited in claim 13 , wherein the unique ID comprises a network address of the identified server.

17. The computer-readable storage medium as recited in claim 13 , wherein said selecting comprises selecting to balance the load of each server in the plurality of servers.

18. The computer-readable storage medium as recited in claim 13 , wherein the upstream device is comprised within a hierarchy of upstream devices configured to route the client requests to the servers.

19. A system, comprising:

an upstream device configured to receive a client request; and

a plurality of servers coupled to the upstream device and configured to store session information;

the upstream device is configured to select one of the plurality of servers and to send the client request to the selected server if the client request is not associated with an established session;

the selected server is configured to generate a session ID and provide a unique ID in response to the client request and to send the session ID and unique ID to the client if the client request is not associated with an established session, wherein the unique ID comprises encrypted data identifying the selected server;

the upstream device is configured to identify one of the plurality of servers from encrypted data of a unique ID provided with the client request and to send the client request to the identified server if the client request is associated with an established session.

20. The system as recited in claim 19 , wherein the upstream device is configured to generate the unique ID and to send the unique ID with the client request to the selected server if the client request is not associated with an established session.

21. The system as recited in claim 20 , wherein the upstream device is configured to encrypt the unique ID.

22. The system as recited in claim 20 , wherein the selected server is configured to encrypt the unique ID.

23. The system as recited in claim 20 , further comprising the selected server configured to encrypt the session ID, wherein the unique ID is encrypted as part of the session ID.

24. The system as recited in claim 19 , wherein the selected server is configured to generate the unique ID for a client request not associated with an established session.

25. The system as recited in claim 24 , wherein the selected server is configured to encrypt the session ID, wherein the unique ID is encrypted as part of the session ID.

26. The system as recited in claim 19 , wherein the unique ID comprises a network address of the selected server.

27. The system as recited in claim 19 , wherein said selecting comprises selecting to balance the load of each server in the plurality of servers.

28. The system as recited in claim 19 , wherein said selected server configured to generate and to send comprises a web server configured to respond to the client request, wherein the client request is from a web client over the Internet

29. The system as recited in claim 28 , wherein the selected server is configured to establish a session with the web client and storing session state information for the session.

30. The system as recited in claim 19 , wherein the upstream device is comprised within a hierarchy of upstream devices configured to route the client requests to the servers.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037306/0556 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2002
From: ELVING, CHRISTOPHER H.; SRINIVASAN, ARVIND
To: SUN MICROSYSTEMS, INC.
Reel/Frame 013160/0014 →
Continuity (1)
Related Publication 20040024880A1 · Feb 5, 2004