IP Library Granted Patent US 9,596,286
Granted Patent B2
US 9,596,286 · App. 13/480,494 · Granted Mar 14, 2017

Method to process HTTP header with hardware assistance

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,596,286
App. No.
13/480,494
Granted
Mar 14, 2017
Kind
B2
Abstract

In processing Hypertext Transfer Protocol (HTTP) headers, a packet pre-processor is configured with at least one predetermined header field identifier. The packet pre-processor detects at least one header field identifier in a header field of an HTTP packet received over an HTTP session between a host and a server, matches the predetermined header field identifier to the header field identifier in the HTTP packet, generates a header report block comprising information corresponding to the header field identifier in the HTTP packet, and sends the HTTP packet and the header report block to a processor module for processing the HTTP packet based on the header report block. The processor module receives the HTTP packet and the header report block from the packet pre-processor, retrieves a service policy using the header report block, applies the service policy to the HTTP packet, and sends the HTTP packet to the host or the server.

Claims (78)

1. A method of packet processing for load balancing by a processor module in conjunction with a packet pre-processor of a service gateway comprising:

receiving a first packet from a host device, the first packet associated with a predetermined protocol, the first packet comprising a request for a network service;

locating a header field block of the first packet, the header field block including a header field value associated with a network service operable on a plurality of servers, the header field block being produced by the packet pre-processor of the service gateway performing a method comprising:

receiving a second packet, the second packet directed to the network service,

detecting a header field of the second packet,

matching the header field with a predetermined header field identifier, the predetermined header field identifier associated with the network service, and

generating the header field block having the header field value associated with the predetermined header field identifier;

ascertaining the network service and identifying the server for processing the network service based at least in part on a header field value of the second packet; and

directing the second packet to the identified server.

2. The method of claim 1 wherein the predetermined protocol is Hypertext Transfer Protocol (HTTP) and the communications session is an HTTP session.

3. The method of claim 2 further comprising:

validating the first packet for the predetermined protocol.

4. The method of claim 1 wherein the header field block further comprises:

a header field location indicating a starting location of the header field identifier; and

a header field size indicating a size of the header field identifier.

5. The method of claim 1 further comprising:

applying at least one of traffic management and security control associated with the network service to the first packet.

6. The method of claim 1 further comprising:

locating a sub-header field block of the first packet, the sub-header field block having a sub-header field identifier; and

ascertaining the network service further using the sub-header field identifier.

7. The method of claim 6 wherein the sub-header field block further comprises:

a sub-header field location indicating a starting location of the sub-header field identifier; and

a sub-header field size indicating a size of the sub-header field identifier.

8. The method of claim 7 further comprising:

removing the sub-header field identifier from the first packet.

9. A system for packet processing for load balancing comprising:

a packet pre-processor of a service gateway, the packet pre-processor being hardware based and performing a first method comprising:

receiving a first packet from a host device, the first packet being routed to a server of a plurality of servers, the server associated with a network service,

detecting a header field of the first packet,

matching the header field with a predetermined header field identifier, the predetermined header field identifier associated with the network service, and

generating a header field block having a header field value associated with the predetermined header field identifier; and

a processor module of the service gateway, the processor module executing instructions stored in a computer-readable medium to perform a second method comprising:

receiving a second packet associated with a predetermined protocol,

locating a header field block in the second packet, the header field block including a header field value, the header field value being associated with the service over a network,

ascertaining the network service using the header field value of the second packet,

identifying the server for processing the second packet using an association between the network service and the server, and

directing the second packet to the identified server.

10. The system of claim 9 wherein the predetermined protocol is Hypertext Transfer Protocol (HTTP) and the communications session is an HTTP session.

11. The system of claim 10 wherein the second method further comprises:

validating the second packet for the predetermined protocol.

12. The system of claim 9 wherein the header field block further comprises:

a header field location indicating a starting location of the header field identifier; and

a header field size indicating a size of the header field identifier.

13. The system of claim 9 wherein the second method further comprises:

applying at least one of traffic management and security control associated with the network service to the second packet.

14. The system of claim 13 wherein the second method further comprises:

locating a sub-header field block of the second packet, the sub-header field block having a sub-header field identifier; and

ascertaining the network service further using the sub-header field identifier.

15. The system of claim 14 wherein the sub-header field block further comprises:

a sub-header field location indicating a starting location of the sub-header field identifier; and

a sub-header field size indicating a size of the sub-header field identifier.

16. The system of claim 15 wherein the second method further comprises:

removing the sub-header field identifier from the second packet.

17. A non-transitory computer-readable storage medium having embodied thereon instructions, the instructions being executable by a processor to perform a method for load balancing, the method comprising:

receiving a first packet from a host device, the first packet associated with a predetermined protocol;

locating a header field block of the first packet, the header field block including a header field value associated with a network service operable on a plurality of servers, the header field block being produced by a packet pre-processor of a service gateway performing a method comprising:

receiving a second packet, the second packet directed to the network service,

detecting a header field of the second packet,

matching the header field with a predetermined header field identifier, the predetermined header field identifier associated with the network service, and

generating the header field block having the header field value associated with the predetermined header field identifier;

ascertaining the network service and identifying the server from the plurality of servers, based at least in part on a header field value of the second packet; and

directing the first packet to the identified server.

18. The non-transitory computer-readable storage medium of claim 17 wherein the predetermined protocol is Hypertext Transfer Protocol (HTTP) and the communications session is an HTTP session.

19. The non-transitory computer-readable storage medium of claim 18 wherein the method further comprises:

validating the first packet for the predetermined protocol.

20. The non-transitory computer-readable storage medium of claim 17 wherein the header field block further comprises:

a header field location indicating a starting location of the header field identifier; and

a header field size indicating a size of the header field identifier.

21. The non-transitory computer-readable storage medium of claim 17 wherein the method further comprises:

applying at least one of traffic management and security control associated with the network service to the first packet.

22. The non-transitory computer-readable storage medium of claim 17 wherein the method further comprises:

locating a sub-header field block of the first packet, the sub-header field block having a sub-header field identifier; and

ascertaining the network service further using the sub-header field identifier.

23. The non-transitory computer-readable storage medium of claim 22 wherein the sub-header field block further comprises:

a sub-header field location indicating a starting location of the sub-header field identifier; and

a sub-header field size indicating a size of the sub-header field identifier.

24. The non-transitory computer-readable storage medium of claim 23 wherein the method further comprises:

removing the sub-header field identifier from the first packet.

Assignments (2)
SECURITY INTEREST Recorded Sep 30, 2013
From: A10 NETWORKS, INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 031485/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2012
From: KAMAT, GURUDEEP; DAVIS, IAN E.; JALAN, RAJKUMAR
To: A10 NETWORKS, INC.
Reel/Frame 028284/0520 →