IP Library Granted Patent US 9,344,451
Granted Patent B2
US 9,344,451 · App. 14/347,050 · Granted May 17, 2016

Enhanced thread handling in security handshaking

Inventors: Artur Bergman (San Francisco, CA); Alan Kasindorf (Mountain View, CA); Rogier Mulhuijzen (Den Haag, NL)
Assignee: Fastly, Inc.
H04L63/168H04L63/166H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,344,451
App. No.
14/347,050
Granted
May 17, 2016
Kind
B2
Abstract

Disclosed herein are methods, systems, and software for handling threaded processes in security handshaking between end users and content delivery nodes are presented. In one example, a method of operating a content delivery node includes identifying a secure layer connection request within an application thread, and initiating a new thread for a security handshake process based on the secure layer connection request. The method further includes, in response to completing the security handshake process, returning to the application thread.

Claims (39)

1. A method of operating a content delivery node that caches content for delivery to end user devices, the method comprising:

during execution of an application thread responsive to content request activity of at least an end user device, identifying a secure layer connection request within the application thread;

responsive to the secure layer connection request, initiating a security handshake process as a handshake thread selected from among a pool of idle handshake threads to execute the security handshake process for the application thread; and

in response to the handshake thread completing the security handshake process, returning to the application thread and returning the handshake thread to the pool of idle handshake threads.

2. The method of claim 1 wherein the secure layer connection request comprises a secure sockets layer request.

3. The method of claim 1 wherein the secure layer connection request comprises a transport layer security request.

4. The method of claim 1 wherein the application thread comprises a data thread.

5. The method of claim 4 wherein the data thread comprises a thread that handles the content request activity associated with the end user device.

6. The method of claim 1 further comprising:

identifying a subsequent secure layer connection request within the application thread;

responsive to the pool of idle handshake threads having no presently available threads, initiating a new handshake thread for a second security handshake process to handle the subsequent secure layer connection request; and

in response to completing the second security handshake process, returning to the application thread and placing the new handshake thread to the pool of idle handshake threads.

7. The method of claim 1 wherein the security handshake process verifies the end user device to receive data content associated with the content request activity.

8. The method of claim 1 wherein the security handshake process establishes communication parameters for a secure connection between the content delivery node and the end user device.

9. The method of claim 1 , further comprising:

responsive to returning the handshake thread to the pool of idle threads, terminating the handshake thread.

10. A computer apparatus to operate a content delivery node that caches content for delivery to end user devices, the computer apparatus comprising:

processing instructions that direct the content delivery node, when executed by the content delivery node, to:

during execution of an application thread responsive to content request activity of at least an end user device, identify a secure layer connection request within the application thread;

responsive to the secure layer connection request, initiate a security handshake as a handshake thread selected from among a pool of idle handshake threads to execute the security handshake process for the application thread; and

in response to the handshake thread completing the security handshake process, return to the application thread and returning the handshake thread to the pool of idle handshake threads; and

one or more non-transitory computer readable media that store the processing instructions.

11. The computer apparatus of claim 10 wherein the secure layer connection request comprises a secure sockets layer request.

12. The computer apparatus of claim 10 wherein the secure layer connection request comprises a transport layer security request.

13. The computer apparatus of claim 10 wherein the application thread comprises a data thread.

14. The computer apparatus of claim 13 wherein the data thread comprises a thread that handles the content request activity associated with the end user device.

15. The computer apparatus of claim 10 wherein the processing instructions further direct the content delivery node to:

responsive to the pool of idle handshake threads having no presently available threads, identify a subsequent secure layer connection request within the application thread;

initiate a new handshake thread for a second security handshake process to handle the subsequent secure layer connection request; and

in response to completing the second security handshake process, return to the application thread and place the new handshaking thread to the pool of idle handshaking threads.

16. The computer apparatus of claim 10 wherein the security handshake process verifies the end user device to receive data content associated with the content request activity.

17. The computer apparatus of claim 10 wherein the security handshake process establishes communication parameters for a secure connection between the content delivery node and the end user device.

18. The computer apparatus of claim 10 wherein the processing instructions that direct the content delivery node to return to the application thread direct the content delivery node to terminate the handshake thread responsive to returning the handshake thread to the pool of idle threads.

19. A method for operating a content delivery node that caches content for delivery to end user devices, the method comprising:

receiving content requests from the end user devices;

initiating an application thread to service the content requests;

identifying a plurality of secure layer connection requests for the application thread that are associated with the content requests; and

performing a multi-threaded security handshaking process by at least selecting handshake threads for each of the security layer connection requests from among a plurality of idle handshake threads to service the security layer connection requests for the application thread.

20. The method of claim 19 wherein the application thread comprises a data thread for processing the content requests.

Assignments (2)
SECURITY INTEREST Recorded Feb 17, 2021
From: FASTLY, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 055316/0616 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2014
From: BERGMAN, ARTUR; KASINDORF, ALAN; MULHUIJZEN, ROGIER
To: FASTLY INC.
Reel/Frame 032518/0335 →
Continuity (2)
Provisional Application 61766807 · Feb 20, 2013
Related Publication 20150341386A1 · Nov 26, 2015