IP Library Granted Patent US 8,312,308
Granted Patent B2
US 8,312,308 · App. 12/489,320 · Granted Nov 13, 2012

Systems and methods for SSL session cloning—transfer and regeneration of SSL security parameters across cores, homogenous system or heterogeneous systems

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,312,308
App. No.
12/489,320
Granted
Nov 13, 2012
Kind
B2
Abstract

The present invention is directed towards systems and methods for managing SSL session persistence and reuse in a multi-core system. A first core may indicate that an SSL session established by the first core is non-resumable. Responsive to the indication, the core may set an indicator at a location in memory accessible by each core of the multi-core system, the indicator indicating that the SSL session is non-resumable. A second core of the multi-core system may receive a request to reuse the SSL session. The request may include a session identifier of the SSL session. In addition, the session identifier may identify the first core as an establisher of the SSL session. The second core can identify from encoding of the session identifier whether the second core is not the establisher of the SSL session. Responsive to the identification, the second core may determine whether to resume the SSL session.

Claims (33)

1. A method of maintaining persistence of a secure socket layer (SSL) session across cores in a multi-core system, the method comprising:

a) establishing, by a first packet engine of a first core of a multi-core system, an SSL session with a client;

b) receiving, by a second packet engine of a second core of the multi-core system, a request from the client identifying a session identifier of the SSL session;

c) identifying, by the second packet engine, from a core identifier identified by the session identifier, that a core different than the second core established the SSL session; and

d) transmitting, by the second packet engine, a message requesting information about the established SSL session to the core identified by the core identifier.

2. The method of claim 1 , wherein step (a) further comprises receiving, by the first packet engine of the first core of the multi-core system deployed as an intermediary between the client and a server, the client's request to establish the SSL session with the server.

3. The method of claim 1 , wherein step (a) further comprises assigning the first core the core identifier based on an identifier of a processing unit.

4. The method of claim 1 , wherein step (a) further comprises receiving, by the first packet engine, from the server the session identifier for the SSL session.

5. The method of claim 1 , wherein step (b) further comprises determining, by a flow distributor, to forward the request to the second core based on a source port of the request.

6. The method of claim 1 , wherein step (c) further comprises decoding, by the second packet engine, the core identifier from a byte of the session identifier.

7. The method of claim 1 , wherein step (c) further comprises determining, by the second packet engine, that the session identifier is not in a session cache of the second core.

8. The method of claim 1 , wherein step (d) further comprises requesting, by the second packet engine, a minimum set of information to reuse the SSL session on the second core.

9. The method of claim 8 , further comprising transmitting, by the first core to the second core, a master key, a client certificate, a name of a cipher, a result of client authentication, and an SSL version.

10. The method of claim 1 , further comprising reusing, by the second core, the SSL session from the first core responsive to the request of the client.

11. A system for maintaining persistence of a secure socket layer (SSL) session across cores in a multi-core system, the system comprising:

a first packet engine executing on a first core of a multi-core system establishing an SSL session with a client;

a flow distributor of the multi-core system forwarding to a core of the multi-core system a request from the client to reuse the SSL session, the request comprising a session identifier;

a second packet engine executing on a second core receiving the request and identifying from encoding in the session identifier that a core different than the second core established the SSL session;

wherein the second packet engine transmits to the core identified by the session identifier a message requesting information about the established SSL session.

12. The system of claim 11 , wherein the multi-core system is deployed as an intermediary between the client and a server and receives the client's request to establish the SSL session with the server.

13. The system of claim 11 , wherein the first core is assigned the core identifier based on an identifier of a processing unit of the core.

14. The system of claim 11 , wherein the first packet engine receives from the server the session identifier for the SSL session.

15. The system of claim 11 , wherein the flow distributor determines to forward the request to the second core based on a source port of the request.

16. The system of claim 11 , wherein the second packet engine decodes the core identifier from a byte of the session identifier.

17. The system of claim 11 , wherein the second packet engine determines that the session identifier is not in a session cache of the second core.

18. The system of claim 11 , wherein the second packet engine requests a minimum set of information from the first core to reuse the SSL session on the second core.

19. The system of claim 18 , wherein the first core transmits to the second core a master key, a client certificate, a name of a cipher, a result of client authentication, and an SSL version.

20. The system of claim 11 , wherein second core reuses the SSL session from the first core responsive to the request of the client.

21. A method of maintaining persistence of a secure socket layer (SSL) session across processors in a multiple processor system, the method comprising:

a) establishing, by a first processor of a multiple processor system, an SSL session with a client;

b) receiving, by a second processor of the multiple processor system, a request from the client identifying a session identifier of the SSL session;

c) identifying, by the second processor, that a processor identifier encoded in the session identifier identifies a processor different than the second processor; and

d) transmitting, by the second processor, to the processor identified by the processor identifier a message requesting information about the established SSL session.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2009
From: KANEKAR, TUSHAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 023324/0422 →
Continuity (1)
Related Publication 20100325418A1 · Dec 23, 2010