IP Library Granted Patent US 11,799,827
Granted Patent B2
US 11,799,827 · App. 17/956,493 · Granted Oct 24, 2023

Intelligently routing a response packet along a same connection as a request packet

Inventors: Marek Przemyslaw Majkowski (Warsaw, PL); Alexander Forster (Austin, TX); Maciej Biłas (Warsaw, PL)
Assignee: CLOUDFLARE, INC.
H04L61/5069H04L45/34H04L45/38H04L45/72H04L45/741H04L45/745H04L61/5007H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,827
App. No.
17/956,493
Granted
Oct 24, 2023
Kind
B2
Abstract

A first edge server of multiple edge servers of a distributed edge computing network receives a request from a client device regarding a resource hosted at an origin server according to an anycast implementation. The first edge server modifies the request to include identifying information for the first edge server prior to sending the request to the origin server. The origin server responds with a response packet that includes the identifying information of the first edge server. Instead of routing the response packet to the client device directly, one of the multiple edge servers receives the response packet due to the edge servers each having the same anycast address. If the edge server that receives the response packet is not the first edge server, that edge server transmits the response packet to the first edge server, who processes the response packet and transmits the response packet to the client device.

Claims (36)

1. A method, comprising:

receiving, by an origin server from a first edge server of an edge network that includes a plurality of edge servers, a request packet from a client device for an action to be performed on a resource hosted at the origin server, wherein the request packet indicates an IP address of the client device as a source of the request packet, wherein the request packet has been modified by the first edge server to include information that identifies the first edge server from other edge servers in the plurality of edge servers, and wherein each of the plurality of edge servers has a same first anycast IP address;

processing, by the origin server, the request packet;

generating, by the origin server, a response packet, the response packet having an IP address of the client device as a destination of the response packet and the information that identifies the first edge server;

encapsulating, by the origin server, the response packet, wherein a header of the encapsulated response packet includes the same first anycast IP address of each of the plurality of edge servers as a destination of the encapsulated response packet; and

sending, by the origin server, the encapsulated response packet to the edge network, wherein the encapsulated response packet is received by a second edge server of the plurality of edge servers, and wherein the response packet is sent to the first edge server after the encapsulated response packet is decapsulated to indicate the information that identifies the first edge server.

2. The method of claim 1 , wherein the response packet is encapsulated into a GRE packet, the GRE packet preserving the IP address of the client device as a destination of the response packet.

3. The method of claim 1 , wherein the request packet is an IPv4 request packet, and wherein a source-routing option is used to tag the request packet with the information that identifies the first edge server.

4. The method of claim 1 , wherein the request packet is an IPv6 request packet, and wherein a flow-label option is used to tag the request packet with the information that identifies the first edge server.

5. The method of claim 1 , wherein the information that identifies the first edge server from the other edge servers in the plurality of edge servers is included in a tag in the response packet.

6. The method of claim 1 , wherein encapsulating the response packet includes: identifying that the request packet includes the information that identifies the first edge server from the other edge servers in the plurality of edge servers.

7. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause said processor to perform operations comprising:

receiving, by an origin server from a first edge server of an edge network that includes a plurality of edge servers, a request packet from a client device for an action to be performed on a resource hosted at the origin server, wherein the request packet indicates an IP address of the client device as a source of the request packet, wherein the request packet has been modified by the first edge server to include information that identifies the first edge server from other edge servers in the plurality of edge servers, and wherein each of the plurality of edge servers has a same first anycast IP address;

processing, by the origin server, the request packet;

generating, by the origin server, a response packet, the response packet having an IP address of the client device as a destination of the response packet and the information that identifies the first edge server;

encapsulating, by the origin server, the response packet, wherein a header of the encapsulated response packet includes the same first anycast IP address of each of the plurality of edge servers as a destination of the encapsulated response packet; and

sending, by the origin server, the encapsulated response packet to the edge network, wherein the encapsulated response packet is received by a second edge server of the plurality of edge servers, and wherein the response packet is sent to the first edge server after the encapsulated response packet is decapsulated to indicate the information that identifies the first edge server.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the response packet is encapsulated into a GRE packet, the GRE packet preserving the IP address of the client device as a destination of the response packet.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the request packet is an IPv4 request packet, and wherein a source-routing option is used to tag the request packet with the information that identifies the first edge server.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the request packet is an IPv6request packet, and wherein a flow-label option is used to tag the request packet with the information that identifies the first edge server.

11. The non-transitory machine-readable storage medium of claim 7 , wherein the information that identifies the first edge server from the other edge servers in the plurality of edge servers is included in a tag in the response packet.

12. The non-transitory machine-readable storage medium of claim 7 , wherein encapsulating the response packet includes:

identifying that the request packet includes the information that identifies the first edge server from the other edge servers in the plurality of edge servers.

13. An apparatus, comprising:

a processor; and

a non-transitory machine-readable storage medium coupled with the processor that stores instructions that, when executed by the processor, cause said processor to perform the following:

receive, by an origin server from a first edge server of an edge network that includes a plurality of edge servers, a request packet from a client device for an action to be performed on a resource hosted at the origin server, wherein the request packet indicates an IP address of the client device as a source of the request packet, wherein the request packet has been modified by the first edge server to include information that identifies the first edge server from other edge servers in the plurality of edge servers, and wherein each of the plurality of edge servers has a same first anycast IP address;

process, by the origin server, the request packet;

generate, by the origin server, a response packet, the response packet having an IP address of the client device as a destination of the response packet and the information that identifies the first edge server;

encapsulate, by the origin server, the response packet, wherein a header of the encapsulated response packet includes the same first anycast IP address of each of the plurality of edge servers as a destination of the encapsulated response packet; and

send, by the origin server, the encapsulated response packet to the edge network, wherein the encapsulated response packet is received by a second edge server of the plurality of edge servers, and wherein the response packet is sent to the first edge server after the encapsulated response packet is decapsulated to indicate the information that identifies the first edge server.

14. The apparatus of claim 13 , wherein the response packet is encapsulated into a GRE packet, the GRE packet preserving the IP address of the client device as a destination of the response packet.

15. The apparatus of claim 13 , wherein the request packet is an IPv4 request packet, and wherein a source-routing option is used to tag the request packet with the information that identifies the first edge server.

16. The apparatus of claim 13 , wherein the request packet is an IPv6 request packet, and wherein a flow-label option is used to tag the request packet with the information that identifies the first edge server.

17. The apparatus of claim 13 , wherein the information that identifies the first edge server from the other edge servers in the plurality of edge servers is included in a tag in the response packet.

18. The apparatus of claim 13 , wherein encapsulating the response packet includes: identifying that the request packet includes the information that identifies the first edge server from the other edge servers in the plurality of edge servers.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: MAJKOWSKI, MAREK PRZEMYSLAW; FORSTER, ALEXANDER; BILAS, MACIEJ
To: CLOUDFLARE, INC.
Reel/Frame 061259/0840 →
Continuity (3)
Continuation 17131439 · Dec 22, 2020
Continuation 16397567 · Apr 29, 2019
Related Publication 20230019293A1 · Jan 19, 2023