IP Library › Granted Patent US 11,102,125
Granted Patent B2
US 11,102,125 · App. 16/454,396 · Granted Aug 24, 2021

Securing communications between services in a cluster using load balancing systems and methods

Inventors: Mehul Patidar (Bengaluru, IN); Swetha Garipally (Bengaluru, IN); Nilamadhava Chaudhury (Bengaluru, IN); Subrata Sarkar (Bengaluru, IN)
Assignee: Citrix Systems, Inc.
H04L47/125H04L63/0281H04L63/0428H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,102,125
App. No.
16/454,396
Granted
Aug 24, 2021
Kind
B2
Abstract

Described embodiments provide systems and methods for securing communications between services in a cluster using load balancing. A first proxy of a first node of a cluster of nodes can receive a request for a service from at least one pod of the first node. The service can include a plurality of pods. The plurality of pods can execute in the cluster of nodes including the first node. The first proxy can select, responsive to a load balancing determination, a pod of a second node of the cluster of nodes to receive the request. An encrypted connection can be established with a second proxy of the second node. The request can be forwarded to the selected pod via the encrypted connection to the second proxy. The request can be decrypted at the second proxy and forwarded at the pod of the second node.

Claims (53)

1. A method for securing communications between services in a cluster using load balancing, the method comprising:

(a) receiving, by a first proxy of a first node of a cluster of nodes, a request from at least one pod of the first node for a service, the service including a plurality of pods executing in the cluster of nodes;

(b) selecting, by the first proxy responsive to a load balancing determination, a pod of a second node of the cluster of nodes to receive the request;

(c) establishing, by the first proxy, an encrypted connection between the first proxy and a second proxy of the second node; and

(d) forwarding, by the first proxy, the request to the selected pod via the encrypted connection to the second proxy, wherein the request is decrypted at the second proxy and forwarded at the pod of the second node.

2. The method of claim 1 , comprising:

generating at least one proxy for each node of the cluster of nodes to perform; and

providing the at least one proxy to each node of the cluster of nodes.

3. The method of claim 1 , comprising:

generating a first load balancer for the first proxy of the first node to perform service level load balancing for outbound traffic from the first node and pod level load balancing for inbound traffic intended for pods executing on the first proxy; and

generating a second load balancer for the second proxy of the second node to perform service level load balancing for outbound traffic from the second node and pod level load balancing for inbound traffic intended for pods executing on the second proxy.

4. The method of claim 1 , comprising:

receiving, by the first proxy, a plurality of requests for one or more services from a plurality of pods executing on the first node, the requests received in a first format; and

modifying, by the first proxy, the plurality of requests from the first format to a second format to encrypt each request of the plurality of requests for transmission through the encrypted connection.

5. The method of claim 1 , wherein the request includes an IP address of the service.

6. The method of claim 1 , comprising:

identifying, by the first proxy using a load balancer, each pod associated with the service and a node hosting the identified pods; and

determining, by the first proxy using the load balancer, a host node for each pod associated with the service.

7. The method of claim 1 , comprising decrypting, by the second proxy, the request received from the first proxy to an original format, the original format corresponding to a format of the request when the request was received at the first proxy.

8. The method of claim 1 , comprising transmitting, by the second proxy, a decrypted request to the pod of the second node.

9. The method of claim 1 , comprising:

identifying, by the first proxy, a plurality of pods associated with the service and a node hosting the identified pods; and

grouping, by the first proxy, the plurality of pods into multiple groups based on the node hosting the identified pods of the plurality of pods.

10. The method of claim 1 , comprising:

grouping, by the first proxy using a load balancer, one or more pods associated with the service and executing on the first node into a local group, the local group provided as a first backend server with a first protocol for the load balancer; and

grouping, by the first proxy using the load balancer, one or more pods associated with the service and executing on the second node into a remote group, the remote group provided as a second backend server with a second protocol for the load balancer, the first protocol different from the second protocol.

11. A system for securing communications between services in a cluster using load balancing, the system comprising:

a first proxy of a first node comprising one or more processors, coupled to a memory, and the first proxy configured to:

receive a request from at least one pod of the first node for a service, the service including a plurality of pods executing in a cluster of nodes including the first node;

select, responsive to a load balancing determination, a pod of a second node of the cluster of nodes to receive the request;

establish an encrypted connection between the first proxy and a second proxy of the second node; and

forward the request to the selected pod via the encrypted connection to the second proxy, wherein the request is decrypted at the second proxy and forwarded at the pod of the second node.

12. The system of claim 11 , wherein the first proxy is further configured to:

generate at least one proxy for each node of the cluster of nodes to perform; and

provide the at least one proxy to each node of the cluster of nodes.

13. The system of claim 11 , wherein the first proxy is further configured to:

generate a first load balancer for the first proxy of the first node to perform service level load balancing for outbound traffic from the first node and pod level load balancing for inbound traffic intended for pods executing on the first proxy; and

generating a second load balancer for the second proxy of the second node to perform service level load balancing for outbound traffic from the second node and pod level load balancing for inbound traffic intended for pods executing on the second proxy.

14. The system of claim 11 , wherein the first proxy is further configured to:

receive a plurality of requests for one or more services from a plurality of pods executing on the first node, the requests received in a first format; and

modify the plurality of requests from the first format to a second format to encrypt each request of the plurality of requests for transmission through the encrypted connection.

15. The system of claim 11 , wherein the request includes an IP address of the service.

16. The system of claim 11 , wherein the first proxy is further configured to:

identify, using a load balancer, each pod associated with the service and a node hosting the identified pods; and

determine, using the load balancer, a host node for each pod associated with the service.

17. The system of claim 11 , wherein the second proxy is further configured to decrypt the request received from the first proxy to an original format, the original format corresponding to a format of the request when the request was received at the first proxy.

18. The system of claim 11 , wherein the second proxy is further configured to transmit a decrypted request to the pod of the second node.

19. The system of claim 11 , wherein the first proxy is further configured to:

identify a plurality of pods associated with the service and a node hosting the identified pods; and

group the plurality of pods into multiple groups based on the node hosting the identified pods of the plurality of pods.

20. The system of claim 11 , wherein the first proxy is further configured to:

group, using a load balancer, one or more pods associated with the service and executing on the first node into a local group, the local group provided as a first backend server with a first protocol for the load balancer; and

group, using the load balancer, one or more pods associated with the service and executing on the second node into a remote group, the remote group provided as a second backend server with a second protocol for the load balancer, the first protocol different from the second protocol.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2019
From: PATIDAR, MEHUL; GARIPALLY, SWETHA; CHAUDHURY, NILAMADHAVA; SARKAR, SUBRATA
To: CITRIX SYSTEMS, INC.
Reel/Frame 049614/0691 →
Continuity (1)
Related Publication 20200412651A1 · Dec 31, 2020