IP Library Granted Patent US 8,667,575
Granted Patent B2
US 8,667,575 · App. 12/976,688 · Granted Mar 4, 2014

Systems and methods for AAA-traffic management information sharing across cores in a multi-core system

Inventors: Ravindranath Thakur (Karnataka, IN); Puneet Agarwal (Karnataka, IN); Arkesh Kumar (San Jose, CA); Rui Li (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,667,575
App. No.
12/976,688
Filed
Dec 22, 2010
Granted
Mar 4, 2014
Kind
B2
Art Unit
2439
USPC
726/12
Abstract

A method for propagating authentication session information to a plurality of cores of a multi-core device includes establishing, by an authentication virtual server executing on a first core of a device intermediary to at least one client and server, a session for a user, the authentication virtual server authenticating the session. A traffic management virtual server executes on a second core of device, and receives a request to access a server via the session. The traffic management virtual server may identify, responsive to a determination that the session is not stored by the second core, from an identifier of the session that the first core established the session. The second core may send to the first core a request for data for the session identified by the identifier. The second core may receive from the first core a response to the second request identifying whether the session is valid.

Claims (29)

1. A method of propagating authentication session information to a plurality of cores of a multi-core device, the method comprising:

a) establishing, by an authentication virtual server executing on a first core of a plurality of cores of a device intermediary to a plurality of clients and one or more servers, a session for a user, the authentication virtual server authenticating the user via a challenge request prior to establishing the session;

b) receiving, by a traffic management virtual server executing on a second core of the plurality of cores, a first request to access a server of the one or more servers via the session;

c) identifying, by the traffic management virtual server responsive to a determination that the session is not stored by the second core, from an identifier of the session that the first core established the session, the determination comprising decoding a core identifier encoded in the identifier of the session, the core identifier identifying the first core and not the second core;

d) sending, by the second core to the first core, a second request for data for the session identified by the identifier; and

e) receiving, by the second core from the first core, a response to the second request, the response identifying whether the session is valid based on a search of the identifier of the session among identifiers that are valid in the device.

2. The method of claim 1 , wherein step (a) further comprises setting, by the authentication virtual server, a cookie for the session, the cookie comprising a domain session cookie.

3. The method of claim 1 , wherein step (c) further comprises determining, by the traffic management virtual server, that the session is not stored in memory local to the second core.

4. The method of claim 1 , wherein step (c) further comprises decoding, by the second core, the core identifier of the first core encoded in the identifier of the session, and identifying the first core as an owner core of the session.

5. The method of claim 1 , wherein step (d) comprises generating, by the second core, a core-to-core message specifying the identifier of the session.

6. The method of claim 1 , wherein step (e) further comprises receiving, by the second core from the first core, the response comprising a failure message identifying that the first core determined the identifier of the session is invalid.

7. The method of claim 1 , wherein step (e) further comprises receiving, by the second core from the first core, the response comprising data to create the session on the requesting core.

8. The method of claim 7 , further comprising creating, by the second core, the session in memory local to the second core.

9. The method of claim 7 , further comprising determining, by the second core, that a cookie for the session received from the first core, is invalid and responsive to the determination, sending a redirect to the authentication virtual server.

10. The method of claim 1 , wherein step (e) further comprises receiving, by the second core from the first core, the response comprising a successful message and responsive to the successful message, performing a local session lookup using the identifier of the session.

11. A system for propagating authentication session information via a plurality of cores of a multi-core device, the system comprising:

a device intermediary to a plurality of clients and one or more servers, the device comprising a plurality of cores;

an authentication virtual server executing on a first core of the plurality of cores establishing a session for a user, the authentication virtual server authenticating the user via a challenge request prior to establishing the session;

a traffic management virtual server, executing on a second core of the plurality of cores, receiving a first request to access a server of the one or more servers via the session, and identifying, responsive to a determination that the session is not stored by the second core, from an identifier of the session that the first core established the session, the determination comprising decoding a core identifier encoded in the identifier of the session, the core identifier identifying the first core and not the second core;

wherein the second core sends to the first core, a second request for data for the session identified by the identifier; and receives from the first core, a response to the second request, the response identifying whether the session is valid based on a search of the identifier of the session among identifiers that are valid in the device.

12. The system of claim 11 , wherein the authentication virtual server sets a cookie for the session, the cookie comprising a domain session cookie.

13. The system of claim 11 , wherein the traffic management virtual server determines that the session is not stored in memory local to the second core.

14. The system of claim 11 , wherein the second core decodes the core identifier of the first core encoded in the identifier of the session and identifies the first core as an owner core of the session.

15. The system of claim 11 , wherein the second core generates a core-to-core message specifying the identifier of the session.

16. The system of claim 11 , wherein the second core receives from the first core the response comprising a failure message identifying that the first core determined the identifier of the session is invalid.

17. The system of claim 11 , wherein the second core receives from the first core the response comprising data to create the session on the requesting core.

18. The method of claim 17 , wherein the second core creates the session in memory local to the second core.

19. The system of claim 17 , wherein the second core determines that a cookie for the session received from the first core, is invalid and responsive to the determination, sending a redirect to the authentication virtual server.

20. The system of claim 11 , wherein the second core receives from the first core the response comprising a successful message and responsive to the successful message, performing a local session lookup using the identifier of the session.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2013
From: THAKUR, RAVINDRANATH; AGARWAL, PUNEET
To: CITRIX SYSTEMS, INC.
Reel/Frame 030195/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2011
From: KUMAR, ARKESH; LI, RUI
To: CITRIX SYSTEMS, INC.
Reel/Frame 025960/0077 →
Continuity (2)
Provisional Application 61289539 · Dec 23, 2009
Related Publication 20110154443A1 · Jun 23, 2011