IP Library › Granted Patent US 12,732,480
Granted Patent B2
US 12,732,480 · App. 18/887,567 · Granted Sep 8, 2026

Internet protocol security tunnel rebalancer

Inventors: Peter John Hill (Seattle, WA); Surajpal Singh Sandhu (Cary, NC); Venkata Koteswararao Anumolu (San Ramon, CA); Aditya Sandeep Sonavane (Bellevue, WA)
Assignee: Oracle International Corporation
H04L63/0236H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,480
App. No.
18/887,567
Filed
Sep 17, 2024
Granted
Sep 8, 2026
Kind
B2
Art Unit
2455
USPC
726/13
Abstract

Techniques are described for managing secure connections (e.g., tunnels) between different endpoints using a pod of servers. Instead of computing devices connecting to a single server at a service IP address, the connections are spread among the different servers in the pod that can be reached using a public IP address.

Claims (38)

1 . A method to manage secure connections, the method comprising:

monitoring, using one or more processors, available computing resources of computing devices within a pod; wherein the computing devices within the pod are associated with one or more public Internet Protocol (IP) addresses that are the same for individual ones of the computing devices within the pod;

receiving, using the one or more processors, a packet addressed to a tunnel endpoint associated with a tunnel;

determining, using the one or more processors, a computing device within the pod that is assigned to perform processing associated with the packet;

determining, based on the monitoring, to process the packet using the computing device; and

causing the computing device within the pod to process the packet.

2 . The method of claim 1 , wherein the packet is receivable by any one of the computing devices within the pod.

3 . The method of claim 1 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.

4 . The method of claim 1 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes determining that the computing device manages the tunnel associated with the packet.

5 . The method of claim 4 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes accessing data that identifies the tunnels managed by each of the computing devices within the pod.

6 . The method of claim 1 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.

7 . The method of claim 6 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.

8 . The method of claim 1 , further comprising causing the tunnel endpoint to be moved from the computing device to a second computing device within the pod based on the monitoring.

9 . A system to manage secure connections, the system comprising:

a pod that includes computing devices, wherein the computing devices of the pod are associated with one or more public Internet Protocol (IP) addresses and perform processing associated with a plurality of tunnels;

one or more processors; and

non-transitory computer-readable medium storing a set of instructions, the set of instructions when executed by the one or more processors cause processing to be performed comprising:

monitoring available computing resources of the computing devices within the pod;

receiving a packet addressed to a tunnel endpoint associated with a tunnel of the plurality of tunnels;

determining a computing device within the pod that is assigned to perform processing associated with the packet;

determining, based on the monitoring, to process the packet using the computing device; and

causing the computing device within the pod to process the packet.

10 . The system of claim 9 , wherein the packet is receivable by any one of the computing devices within the pod.

11 . The system of claim 9 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.

12 . The system of claim 9 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes determining that the computing device manages the tunnel associated with the packet.

13 . The system of claim 12 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet, includes accessing data that identifies the tunnels managed by each of the computing devices within the pod.

14 . The system of claim 9 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.

15 . The system of claim 14 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.

16 . The system of claim 9 , further comprising causing the tunnel endpoint to be moved from the computing device to a second computing device within the pod based on the moni.

17 . A non-transitory computer-readable medium comprising instructions that when executed, cause one or more processors to perform operations including:

monitoring available computing resources of computing devices within a pod; wherein each of the computing devices within the pod are reachable using one or more public Internet Protocol (IP) addresses;

receiving a packet addressed to a tunnel endpoint associated with a tunnel;

determining a computing device within a pod that is assigned to perform processing associated with the packet;

determining, based on the monitoring, to process the packet using the computing device; and

causing the computing device within the pod to process the packet.

18 . The non-transitory computer-readable medium of claim 17 , wherein determining the computing device within the pod that is assigned to perform processing associated with the packet is based, at least in part, on available resources of the computing device.

19 . The non-transitory computer-readable medium of claim 17 , wherein causing the computing device within the pod to process the packet comprises forwarding the packet to a service IP address that is unique to the computing device.

20 . The non-transitory computer-readable medium of claim 19 , wherein forwarding the packet to the computing device includes generating an encapsulated packet at a first computing device that received the packet and forwarding the encapsulated packet to the service IP address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2024
From: HILL, PETER JOHN; SANDHU, SURAJPAL SINGH; ANUMOLU, VENKATA KOTESWARARAO; SONAVANE, ADITYA SANDEEP
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 069044/0872 →
Continuity (1)
Related Publication 20260122034A1 · Apr 30, 2026
References Cited (31)
US 6704282B1 · Sun et al. · 2004 [cited by applicant]
US 6735631B1 · Oehrke et al. · 2004 [cited by applicant]
US 10601779B1 · Matthews et al. · 2020 [cited by applicant]
US 10680965B1 · Pingale et al. · 2020 [cited by applicant]
US 10721097B2 · Nandoori et al. · 2020 [cited by applicant]
US 20130114465A1 · McGovern · 2013 [cited by examiner]
US 20150295890A1 · Qin · 2015 [cited by examiner]
US 20170085486A1 · Chung · 2017 [cited by examiner]
US 20180159929A1 · Heckle · 2018 [cited by examiner]
US 20190379590A1 · Rimar · 2019 [cited by examiner]
US 20200280592A1 · Ithal · 2020 [cited by examiner]
US 20200403922A1 · Yu et al. · 2020 [cited by applicant]
US 20210314300A1 · Shen · 2021 [cited by examiner]
US 20220159030A1 · Kang · 2022 [cited by examiner]
US 20220337549A1 · Spencer · 2022 [cited by examiner]
US 20220345402A1 · Chen · 2022 [cited by examiner]
US 20250047605A1 · Elul · 2025 [cited by examiner]
US 20250300969A1 · Bailey · 2025 [cited by examiner]
CN 101719815A · 2010 [cited by applicant]
EP 3241312B1 · 2019 [cited by applicant]
“About Always on VPN”, Available Online at: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/overview-always-on-vpn, May 23, 2023, pp. 1-8. [cited by applicant]
“AnyConnect Implementation and Performance/Scaling Reference for COVID-19 Preparation”, Cisco, Available Online at https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331-anyconnect-… [cited by applicant]
“Getting Started with Inbound Traffic Management”, Available Online at: https://help.stonesoft.com/onlinehelp/StoneGate/SMC/6.5.0/GUID-8322A022-6CE7-4DE5-B7A5-EF7E5082D28D.html, Accessed from Internet on Aug. 12, 2023, … [cited by applicant]
“High Availability Options—Cisco ASA Series VPN CLI Configuration Guide”, CLI Book 3, vol. 9.9, Available Online at: https://www.cisco.com/c/en/us/td/docs/security/asa/asa99/configuration/vpn/asa-99-vpn-config/vpn-ha.ht… [cited by applicant]
“IPsec Tunnels with Dynamic Endpoints”, Available Online at: https://www.juniper.net/documentation/US/en/software/junos/interfaces-adaptive-services/topics/topic-map/ipsectunnels-dynamic-endpoints.html, Jun. 16, 2023, p… [cited by applicant]
“Load Balancing VMware Tunnel (Per-App VPN)”, Available Online at: https://docs.vmware.com/en/VMware-NSX-Advanced-Load-Balancer/22.1/Solutions_Guide/GUID-53C08E69-E5EA-4921-AB74-0AAF048FACF7.html, Accessed from Internet… [cited by applicant]
“Reliable and Scalable VPN Secure Tunneling”, Zevenet, Available Online at: https://www.zevenet.com/knowledge-base/howtos/reliable-and-scalable-vpn-secure-tunneling/, Accessed from Internet on Aug. 12, 2023, pp. 1-8. [cited by applicant]
“VMware Workspace ONE Tunnel: Key Concepts”, Available Online at: https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/VMware_Tunnel/GUID-CF70E72C-1C92-4CD2-A627-97B5BB46288C.html, Accessed from Internet on Aug.… [cited by applicant]
“VPN Load Balancing on the CSM in Directed Mode Configuration Example”, Cisco, Available Online at: https://www.cisco.com/c/en/us/support/docs/interfaces-modules/content-switching-module/63390-vpnlb-csm-directed.html, A… [cited by applicant]
Mcdonnell , et al., “Intel® Dynamic Load Balancer (Intel® DLB)—Scaling of IPsec Workloads”, Intel Corporation, Available Online at https://networkbuilders.intel.com/solutionslibrary/intel-dynamic-load-balancer-intel-dlb… [cited by applicant]
Tsai , et al., “A Clustering and Traffic-Redistribution Scheme for High-Performance IPsec VPNs”, International Conference on High-Performance Computing, Dec. 2005, pp. 432-443. [cited by applicant]