IP Library Granted Patent US 10,104,166
Granted Patent B2
US 10,104,166 · App. 14/282,411 · Granted Oct 16, 2018

Systems and methods for providing load balancing as a service

Inventor: Abhishek Chauhan (Saratoga, CA)
Assignee: Citrix Systems, Inc.
H04L67/1002H04L12/6418H04L63/0209H04L63/102H04L67/28H04L67/42H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,166
App. No.
14/282,411
Granted
Oct 16, 2018
Kind
B2
Abstract

The present disclosure is directed generally to systems and methods for providing load balancing as a service. A load balancer executing on a device intermediary to a server and a plurality of clients can receive a request from an agent executing on the server. The request can be to initiate establishment of a transport layer connection. The load balancer can accept the request to establish the transport layer connection with the server. The load balancer can receive a request to access the server from a client of the plurality of clients. The load balancer can forward the request to the server via the transport layer connection established between the load balancer and the server responsive to the request of the server.

Claims (57)

1. A method of providing load balancing as a service, the method comprising:

receiving, by a load balancer executing on a device intermediary to a server and a plurality of clients, a first request from an agent executing on the server initiating establishment of a transport layer connection with the load balancer, the agent configured with a server pool name used by the agent to discover the load balancer using information about the server pool name published in a domain name system, the first request comprising a unique identifier of the server to the load balancer discovered by the agent of the server via the domain name system and authentication credentials to the server for the load balancer to establish the transport layer connection with the server;

determining, by the load balancer prior to accepting the request, that the load balancer is configured to perform load balancing of the server based on the unique identifier of the server;

authenticating, by the load balancer, the server using the authentication credentials to the server received by the load balancer via the first request from the agent;

accepting the first request, by the load balancer responsive to at least one of the determination or authentication;

performing, by the load balancer after accepting the first request, a handshake with the server to establish the transport layer connection between the server and the load balancer on the device intermediary to the server and the plurality of clients;

receiving, by the load balancer, a second request to access the server from a client of the plurality of clients; and

forwarding, by the load balancer based on at least the unique identifier of the server received from the agent, the second request to the server via the transport layer connection established between the load balancer and the server responsive to the first request of the server.

2. The method of claim 1 , further comprising:

receiving, by the device, a plurality of requests initiating establishment of a predetermined number of transport layer connections, the plurality of requests transmitted by a second agent executing on a second server on a disparate network from the first server, the second server separated from the first server via a firewall; and

accepting, by the device, the plurality of requests to establish the second predetermined number of transport layer connections with the second server.

3. The method of claim 1 , further comprising:

receiving, by the device, a plurality of requests initiating establishment of a predetermined number of transport layer connections from a plurality of agents executing on a corresponding plurality of servers on a same network.

4. The method of claim 1 , further comprising:

receiving, by the device, a plurality of requests initiating establishment of a predetermined number of transport layer connections from a plurality of servers, the plurality of servers separated from the device via a firewall and a public network.

5. The method of claim 1 , further comprising:

receiving, by the device, a plurality of requests from the agent to initiate establishment of transport layer connections with the load balancer responsive to the server coming online.

6. The method of claim 1 , further comprising:

receiving, responsive to at least one transport layer connection of the predetermined number of transport layer connections closing, a new request from the agent to initiate a new transport layer connection to maintain a predetermined number of transport layer connections.

7. The method of claim 1 , further comprising:

increasing, based on a policy, the predetermined number of transport layer connections to a second predetermined number of transport layer connections.

8. The method of claim 1 , further comprising:

identifying, by the device, a set of servers to load balance, the set of servers comprising the plurality of servers, the set of servers having the unique identifier; and

receiving, by the device, a plurality of requests to initiate a predetermined number of transport layer connections, the plurality of requests comprising the unique identifier of the set of servers and associated authentication credentials.

9. The method of claim 1 , further comprising:

identifying, by the device, a set of servers having the unique identifier, the set of servers comprising the plurality of servers separated from the load balancer via a firewall and a public network; and

managing, by the device, the set of servers.

10. The method of claim 1 , further comprising:

accepting the request responsive to determining that the load balancer is configured to perform load balancing for up to a predetermined number of connections.

11. The method of claim 1 , further comprising:

using, by the load balancer, the unique identifier of the server received from the request to include the server in a plurality of servers managed by the load balancer.

12. A system to provide load balancing as a service, the system comprising:

a device intermediary to a server and a plurality of clients comprising:

an interface configured to receive a first request from an agent executing on the server initiating establishment of a transport layer connection with the device, wherein the agent is configured with a server pool name used by the agent to discover the load balancer using information about the server pool name published in a domain name system, the first request comprising a unique identifier, of the server to the load balancer discovered by the agent of the server via the domain name system, and authentication credentials to the server for the load balancer to establish the transport layer connection with the server;

a policy engine configured to:

determine, prior to accepting the request, that the load balancer is configured to perform load balancing of the server based on the unique identifier of the server;

authenticate the server using the authentication credentials to the server received by the load balancer via the first request from the agent;

accept the first request responsive to at least one of the determination or authentication,

wherein the device, after accepting the first request, is configured to perform a handshake with the server to establish the transport layer connection between the server and the load balancer on the device intermediary to the server and the plurality of clients;

a load balancer configured to receive a second request to access the server from a client of the plurality of clients, and forward, based on at least the unique identifier of the server received from the agent, the second request to the server via the transport layer connection established between the load balancer and the server responsive to the first request of the server.

13. The system of claim 12 , wherein the device is further configured to:

receive a plurality of requests initiating establishment of a predetermined number of transport layer connections, the plurality of requests transmitted by a second agent executing on a second server on a disparate network from the first server, the second server separated from the first server via a firewall; and

accept the plurality of requests to establish the second predetermined number of transport layer connections with the second server.

14. The system of claim 12 , wherein the device is further configured to:

receive a plurality of requests initiating establishment of a predetermined number of transport layer connections from a plurality of agents executing on a corresponding plurality of servers on a same network.

15. The system of claim 12 , wherein the device is further configured to:

receive a plurality of requests initiating establishment of a predetermined number of transport layer connections from a plurality of servers, the plurality of servers separated from the device via a firewall and a public network.

16. The system of claim 12 , wherein the device is further configured to:

accept the request responsive to determining that the load balancer is configured to perform load balancing for up to a predetermined number of connections.

17. The system of claim 12 , wherein the device is further configured to:

receive, responsive to at least one transport layer connection of the predetermined number of transport layer connections closing, a new request from the agent to initiate a new transport layer connection to maintain a predetermined number of transport layer connections.

18. The system of claim 12 , wherein the device is further configured to:

increase, based on a policy, the predetermined number of transport layer connections to a second predetermined number of transport layer connections.

19. The system of claim 12 , wherein the device is further configured to:

identify a set of servers to load balance, the set of servers comprising the plurality of servers, the set of servers having the unique identifier; and

receive a plurality of requests to initiate a predetermined number of transport layer connections, the plurality of requests comprising the unique identifier of the set of servers and associated authentication credentials.

20. The system of claim 12 , wherein the device is further configured to: use the unique identifier of the server received from the request to include the server in a plurality of servers managed by the load balancer.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2014
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 032946/0316 →
Continuity (1)
Related Publication 20150341428A1 · Nov 26, 2015
Cited By (1)
US 12,367,072