IP Library Granted Patent US 9,692,640
Granted Patent B1
US 9,692,640 · App. 14/478,214 · Granted Jun 27, 2017

Dynamic updates to a network server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,692,640
App. No.
14/478,214
Granted
Jun 27, 2017
Kind
B1
Abstract

Techniques are disclosed for configuring a server to establish a secure network communication session. An application monitors one or more resource utilization metrics of the server. Upon determining that at least one of the monitored resource metrics satisfies a specified condition, an optimization algorithm is selected based on the resource metrics and a configuration of the server. The optimization algorithm determines an updated configuration of the server while maintaining the security at par or better. The selected optimization algorithm is performed to modify determine the updated configuration of the server. Once determined, the application applies the updated configuration to the server.

Claims (40)

1. A method for managing network communication sessions on a server, the method comprising:

monitoring one or more resource utilization metrics of the server;

upon determining that at least one of the monitored resource metrics satisfies a specified condition, selecting an optimization algorithm based on the resource metrics and a configuration of the server, wherein the optimization algorithm determines an updated configuration of the server used in establishing secure network communication sessions;

performing the selected optimization algorithm to determine the updated configuration of the server, wherein the updated configuration of the server includes an update to one or more of a preferred cipher suite, a preferred digital certificate type, a session resumption validity interval, and a length of cryptographic keys generated by the server used in establishing secure network communication sessions; and

applying the updated configuration to the server.

2. The method of claim 1 , wherein applying the updated configuration modifies the preferred cipher suite of the server from an RSA-based cipher suite to an elliptic curve cryptography (ECC)-based cipher suite and modifies the preferred digital certificate type from an RSA-based digital certificate to an ECC-based digital certificate.

3. The method of claim 1 , wherein applying the updated configuration modifies the length of the cryptographic keys or the session resumption validity interval.

4. The method of claim 1 , wherein the network communication is established by a Secure Sockets Layer (SSL) or Transport Layer Security (TLS) handshake protocol.

5. The method of claim 1 , wherein the resource utilization metrics include at least one of an average CPU utilization, network I/O statistics, memory usage statistics, and cache utilization.

6. The method of claim 1 , wherein selecting the optimization algorithm comprises:

estimating resource usage limitations that would result from performing each one of a plurality of optimization algorithms to the server;

identifying, from the plurality, one of the optimization algorithms based on the estimated resource usage limitations and the configuration of the server; and

persisting the estimated resource usage limitations.

7. A non-transitory computer-readable storage medium storing instructions, which, when executed on a processor, performs an operation for managing network communication sessions on a server, the operation comprising:

monitoring one or more resource utilization metrics of the server;

upon determining that at least one of the monitored resource metrics satisfies a specified condition, selecting an optimization algorithm based on the resource metrics and a configuration of the server, wherein the optimization algorithm determines an updated configuration of the server used in establishing secure network communication sessions;

performing the selected optimization algorithm to determine the updated configuration of the server, wherein the updated configuration of the server includes an update to one or more of a preferred cipher suite, a preferred digital certificate type, a session resumption validity interval, and a length of cryptographic keys generated by the server used in establishing secure network communication sessions; and

applying the updated configuration to the server.

8. The non-transitory computer-readable storage medium of claim 7 , wherein applying the updated configuration modifies the preferred cipher suite of the server from an RSA-based cipher suite to an elliptic curve cryptography (ECC)-based cipher suite and modifies the preferred digital certificate type from an RSA-based digital certificate to an ECC-based digital certificate.

9. The non-transitory computer-readable storage medium of claim 7 , wherein applying the updated configuration modifies the length of the cryptographic keys or the session resumption validity interval.

10. The non-transitory computer-readable storage medium of claim 7 , wherein the network communication is established by a Secure Sockets Layer (SSL) or Transport Layer Security (TLS) handshake protocol.

11. The non-transitory computer-readable storage medium of claim 7 , wherein the resource utilization metrics include at least one of an average CPU utilization, network I/O statistics, memory usage statistics, and cache utilization.

12. The non-transitory computer-readable storage medium of claim 7 , wherein selecting the optimization algorithm comprises:

estimating resource usage limitations that would result from performing each one of a plurality of optimization algorithms to the server;

identifying, from the plurality, one of the optimization algorithms based on the estimated resource usage limitations and the configuration of the server; and

persisting the estimated resource usage limitations.

13. A system, comprising:

a processor; and

a memory storing one or more application programs configured to perform an operation for managing network communication sessions on a server, the operation comprising:

monitoring one or more resource utilization metrics of the server,

upon determining that at least one of the monitored resource metrics satisfies a specified condition, selecting an optimization algorithm based on the resource metrics and a configuration of the server, wherein the optimization algorithm determines an updated configuration of the server used in establishing secure network communication sessions,

performing the selected optimization algorithm to determine the updated configuration of the server, wherein the updated configuration of the server includes an update to one or more of a preferred cipher suite, a preferred digital certificate type, a session resumption validity interval, and a length of cryptographic keys generated by the server used in establishing secure network communication sessions, and

applying the updated configuration to the server.

14. The system of claim 13 , wherein applying the updated configuration modifies the preferred cipher suite of the server from an RSA-based cipher suite to an elliptic curve cryptography (ECC)-based cipher suite and modifies the preferred digital certificate type from an RSA-based digital certificate to an ECC-based digital certificate.

15. The system of claim 13 , wherein applying the updated configuration modifies the length of the cryptographic keys or the session resumption validity interval.

16. The system of claim 13 , wherein the resource utilization metrics include at least one of an average CPU utilization, network I/O statistics, memory usage statistics, and cache utilization.

17. The system of claim 13 , wherein selecting the optimization algorithm comprises:

estimating resource usage limitations that would result from performing each one of a plurality of optimization algorithms to the server;

identifying, from the plurality, one of the optimization algorithms based on the estimated resource usage limitations and the configuration of the server; and

persisting the estimated resource usage limitations.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2014
From: VELADANDA, HARI; LY, HOA; KHANNA, GAURAV
To: SYMANTEC CORPORATION
Reel/Frame 033676/0384 →