IP Library Granted Patent US 12,615,162
Granted Patent B2
US 12,615,162 · App. 18/146,134 · Granted Apr 28, 2026

Methods for establishing a connection to a server with a cached certificate and devices thereof

Inventors: Neha Kochar (Seattle, WA); Liang Cheng (Seattle, WA); Saxon C. Amdahl (Seattle, WA)
Assignee: F5, Inc.
H04L9/3268H04L9/0861H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,162
App. No.
18/146,134
Granted
Apr 28, 2026
Kind
B2
Abstract

Methods, non-transitory computer readable media, network traffic manager apparatuses, and systems that assist with establishing a connection to a server with a certificate includes receiving a request for establishing an encrypted connection and obtaining a certificate responsive to the received request. Next, the network traffic manager apparatus generates a content cache key for the obtained certificate. Next, the network traffic manager apparatus retrieves a data structure in the cache using the generated content cache key for the obtained certificate. The retrieved data structure is generated and stored in the cache during a previous established encrypted connection. The data structure comprises of extracted data from a previous certificate. Then, the network traffic manager apparatus initiates encryptographic operations using the retrieved data structure from the cache.

Claims (60)

1 . A method for establishing a connection to a server with a certificate, the method implemented by a network traffic management system comprising one or more network traffic apparatuses, client devices, or server devices, the method comprising:

receiving a request for establishing an encrypted connection and obtaining a certificate responsive to the received request;

generating a content cache key for the obtained certificate;

retrieving, from the cache, a data structure comprising extracted data from a previous certificate using the generated content cache key for the obtained certificate, wherein the retrieved data structure is generated by:

validating the previous certificate by contacting an associated server to confirm accuracy of the extracted data; and

storing the previous certificate and the data structure comprising the verified extracted data in the cache during a previous established encrypted connection; and

initiating encryptographic operations using the retrieved data structure from the cache.

2 . The method as set forth in claim 1 , further comprising:

receiving the previous certificate for establishing the encrypted connection;

generating a previous content cache key using the previous certificate;

caching the data structure in the cache using the previous content cache key, wherein the data structure is generated using extracted data from the previous certificate and a revocation status; and

initiating encryptographic operations using the data structure.

3 . The method as set forth in claim 2 , wherein the certificate or the previous certificate is received by a client and the certificate or the previous certificate is a client certificate.

4 . The method as set forth in claim 2 , wherein the certificate or the previous certificate is received by a server and the certificate or the previous certificate is a server certificate.

5 . The method as set forth in claim 2 , wherein the data structure includes an expiration date extracted from the previous certificate, and wherein the stored data structure is updated using data extracted from the certificate when the expiration date is after a current date.

6 . A non-transitory computer readable medium having stored thereon instructions for establishing a connection to a server with a certificate comprising executable code which when executed by one or more processors, causes the processors to:

receive a request for establishing an encrypted connection and obtaining a certificate responsive to the received request;

generate a content cache key for the obtained certificate;

retrieve, from the cache, a data structure comprising extracted data from a previous certificate wherein the retrieved data structure is generated by:

validating the previous certificate by contacting an associated server to confirm accuracy of the extracted data; and

storing the previous certificate and the data structure comprising the verified extracted data in the cache during a previous established encrypted connection; and

initiate encryptographic operations using the retrieved data structure from the cache.

7 . The medium as set forth in claim 6 , wherein the executable code which when executed by the processors, further causes the processors to:

receive the previous certificate for establishing the encrypted connection;

generate a previous content cache key using the previous certificate;

cache the data structure in the cache using the previous content cache key, wherein the data structure is generated using extracted data from the previous certificate and a revocation status; and

initiate encryptographic operations using the data structure.

8 . The medium as set forth in claim 6 , wherein the certificate or the previous certificate is received by a client and the certificate or the previous certificate is a client certificate.

9 . The medium as set forth in claim 6 , wherein the certificate or the previous certificate is received by a server and the certificate or the previous certificate is a server certificate.

10 . The medium as set forth in claim 9 , wherein the data structure includes an expiration date extracted from the previous certificate, and wherein the stored data structure is updated using data extracted from the certificate when the expiration date is after a current date.

11 . A network traffic manager apparatus, comprising memory comprising programmed instructions stored in the memory and one or more processors configured to be capable of executing the programmed instructions stored in the memory to:

receive a request for establishing an encrypted connection and obtaining a certificate responsive to the received request;

generate a content cache key for the obtained certificate;

retrieve, from the cache, a data structure comprising extracted data from a previous certificate using the generated content cache key for the obtained certificate, wherein the retrieved data structure is generated by:

validating the previous certificate by contacting an associated server to confirm accuracy of the extracted data; and

storing the previous certificate and the data structure comprising the verified extracted data in the cache during a previous established encrypted connection; and

initiate encryptographic operations using the retrieved data structure from the cache.

12 . The device as set forth in claim 11 , wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to:

receive the previous certificate for establishing the encrypted connection;

generate a previous content cache key using the previous certificate;

cache the data structure in the cache using the previous content cache key, wherein the data structure is generated using extracted data from the previous certificate and a revocation status; and

initiate encryptographic operations using the data structure.

13 . The device as set forth in claim 11 , wherein the certificate or the previous certificate is received by a client and the certificate or the previous certificate is a client certificate.

14 . The device as set forth in claim 11 , wherein the certificate or the previous certificate is received by a server and the certificate or the previous certificate is a server certificate.

15 . The device as set forth in claim 14 , wherein the data structure includes an expiration date extracted from the previous certificate, and wherein the stored data structure is updated using data extracted from the certificate when the expiration date is after a current date.

16 . A network traffic management system, comprising one or more traffic management apparatuses, client devices, or server devices, the network traffic management system comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to:

receive a request for establishing an encrypted connection and obtaining a certificate responsive to the received request;

generate a content cache key for the obtained certificate;

retrieve, from the cache, a data structure comprising extracted data from a previous certificate using the generated content cache key for the obtained certificate, wherein the retrieved data structure is generated by:

validating the previous certificate by contacting an associated server to confirm accuracy of the extracted data; and

storing the previous certificate and the data structure comprising the verified extracted data in the cache during a previous established encrypted connection; and

initiate encryptographic operations using the retrieved data structure from the cache.

17 . The network traffic management system of claim 16 , wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to:

receive the previous certificate for establishing the encrypted connection;

generate a previous content cache key using the previous certificate;

cache the data structure in the cache using the previous content cache key, wherein the data structure is generated using extracted data from the previous certificate and a revocation status; and

initiate encryptographic operations using the data structure.

18 . The network traffic management system of claim 16 , wherein the certificate or the previous certificate is received by a client and the certificate or the previous certificate is a client certificate.

19 . The network traffic management system of claim 16 , wherein the certificate or the previous certificate is received by a server and the certificate or the previous certificate is a server certificate.

20 . The network traffic management system of claim 19 , wherein the data structure includes an expiration date extracted from the previous certificate, and wherein the stored data structure is updated using data extracted from the certificate when the expiration date is after a current date.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2023
From: KOCHAR, NEHA; CHENG, LIANG; AMDAHL, SAXON
To: F5, INC.
Reel/Frame 063238/0786 →
Continuity (1)
Related Publication 20250300844A1 · Sep 25, 2025
References Cited (35)
US 7778194B1 · Yung · 2010 [cited by examiner]
US 8707028B2 · Wicker · 2014 [cited by examiner]
US 8966267B1 · Pahl · 2015 [cited by examiner]
US 9154488B2 · Innes · 2015 [cited by examiner]
US 9306839B2 · Shanmugavadivel · 2016 [cited by examiner]
US 9328455B2 · Yamamoto · 2016 [cited by examiner]
US 9742806B1 · Rothstein · 2017 [cited by examiner]
US 9887982B2 · Andrews · 2018 [cited by examiner]
US 9893883B1 · Chaubey · 2018 [cited by examiner]
US 10110592B2 · Veladanda · 2018 [cited by examiner]
US 10116621B2 · Bandini · 2018 [cited by examiner]
US 10230695B2 · Cline · 2019 [cited by examiner]
US 10951652B1 · Sharifi Mehr · 2021 [cited by examiner]
US 10958666B1 · Witten · 2021 [cited by examiner]
US 11528150B1 · Stapleton · 2022 [cited by examiner]
US 11968302B1 · Kumar · 2024 [cited by examiner]
US 20020069361A1 · Watanabe · 2002 [cited by examiner]
US 20020196935A1 · Wenocur · 2002 [cited by examiner]
US 20030041110A1 · Wenocur · 2003 [cited by examiner]
US 20060005026A1 · Song · 2006 [cited by examiner]
US 20060005237A1 · Kobata · 2006 [cited by examiner]
US 20090327708A1 · Hazlewood · 2009 [cited by examiner]
US 20110154018A1 · Edstrom · 2011 [cited by examiner]
US 20110231923A1 · Bollay · 2011 [cited by examiner]
US 20150100780A1 · Rubin · 2015 [cited by examiner]
US 20160269369A1 · Thomson · 2016 [cited by examiner]
US 20170142100A1 · Bollay · 2017 [cited by examiner]
US 20170230355A1 · Su · 2017 [cited by examiner]
US 20190044929A1 · Kashyap · 2019 [cited by examiner]
US 20190245700A1 · Dobre · 2019 [cited by examiner]
US 20220210147A1 · Galvin · 2022 [cited by examiner]
Van den Abeele et al.; “Secure Service Proxy: A CoAP(s) Intermediary for a Securer and Smarter Web of Things”, 2017, MDPI, pp. 1-30. (Year: 2017). [cited by examiner]
Van den Abeele et al.; “Secure Service Proxy: A CoAP(s) Intermediary for a Securer and SmarterWeb of Things”, 2017, mdpi.com/journal/sensors, pp. 1-30. (Year: 2017). [cited by examiner]
International Search Report and Written Opinion Dated Mar. 18, 2024. PCT Application No. PCT/US2023/080010. [cited by applicant]
International Preliminary Report on Patentability for PCT/US2023/080010, dated Jun. 24, 2025. [cited by applicant]