IP Library › Granted Patent US 12,744,735
Granted Patent B2
US 12,744,735 · App. 18/773,755 · Granted Sep 22, 2026

Load balancing client connections across servers of a trust network

Inventors: Natan Elul (Tel Aviv, IL); Roy Azachi (Tel Aviv, IL); Gil Azrielant (Tel Aviv, IL)
Assignee: Hewlett Packard Enterprise Development LP
H04L47/125H04L63/0272H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,735
App. No.
18/773,755
Granted
Sep 22, 2026
Kind
B2
Abstract

In some examples, a proxy system establishes a client-side secure network tunnel between the proxy system and a client device, and establishes a plurality of server-side secure connections between the proxy system and respective servers of a trust network. The proxy system load balances a plurality of connections of the client device in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections.

Claims (51)

1 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a proxy system to:

establish a client-side secure network tunnel according to a tunneling protocol between the proxy system and a network device, the client-side secure network tunnel comprising client connections of requesters connected to the network device;

establish a plurality of server-side secure connections between the proxy system and respective servers of a trust network, wherein one or more target endpoints are accessible to the requesters through the network device and the servers; and

load balance, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising transferring a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection of the plurality of server-side secure connections to a second server-side secure connection of the plurality of server-side secure connections.

2 . The non-transitory machine-readable storage medium of claim 1 , wherein the plurality of server-side secure connections between the proxy system and the respective servers of the trust network comprise a plurality of server-side secure network tunnels between the proxy system and the respective servers of the trust network.

3 . The non-transitory machine-readable storage medium of claim 1 , wherein the client connections in the client-side secure network tunnel comprise Transmission Control Protocol (TCP) connections.

4 . The non-transitory machine-readable storage medium of claim 1 , wherein the load balancing of the client connections of the requesters across the servers of the trust network is according to a dynamic load balancing process based on conditions of the servers of the trust network.

5 . The non-transitory machine-readable storage medium of claim 4 , wherein the conditions of the servers of the trust network comprise an issue impacting a performance of a server of the servers.

6 . The non-transitory machine-readable storage medium of claim 5 , wherein the conditions of the servers of the trust network comprise an update of a server of the servers.

7 . The non-transitory machine-readable storage medium of claim 4 , wherein the dynamic load balancing process creates a new server-side secure connection to another server of the trust network based on the conditions of the servers.

8 . The non-transitory machine-readable storage medium of claim 4 , wherein the dynamic load balancing process terminates a server-side secure connection of the plurality of server-side secure connections based on the conditions of the servers.

9 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:

detect an unavailability of a first server of the servers of the trust network; and

based on detecting the unavailability of the first server, transfer a subset of client connections of the requesters established through the first server-side secure connection to the second server-side secure connection.

10 . The non-transitory machine-readable storage medium of claim 9 , wherein the unavailability of the first server is based on a fault of the first server, a fault of a link to the first server, the first server being overburdened, or an update being performed at the first server.

11 . The non-transitory machine-readable storage medium of claim 9 , wherein the transfer of the subset of client connections of the requesters from the first server-side secure connection to the second server-side secure connection is performed without re-establishing the client-side secure network tunnel.

12 . The non-transitory machine-readable storage medium of claim 1 , wherein the requesters comprise an electronic device or a virtual computing entity.

13 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:

inspect a data packet received from the network device, the data packet including a client identifier; and

query a routing table for a destination based on the client identifier,

wherein the load balancing is based on updating the routing table.

14 . The non-transitory machine-readable storage medium of claim 1 , wherein the plurality of server-side secure connections comprise server-side secure network tunnels including a first server-side secure network tunnel and a second server-side secure network tunnel, and the instructions upon execution cause the proxy system to:

establish a third server-side secure network tunnel between the proxy system and a further server in the trust network; and

terminate the second server-side secure network tunnel in response to determining that the third server-side secure network tunnel is operational.

15 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the proxy system to:

maintain counters for the respective server-side secure connections;

increment a first counter for the first server-side secure connection in response to data packets being directed by the proxy system through the first server-side secure connection;

increment a second counter for the second server-side secure connection in response to data packets being directed by the proxy system through the second server-side secure connection; and

determine whether a difference between a first count of the first counter and a second count of the second counter exceeds a threshold,

wherein the transferring of the first client connection from the first server-side secure connection to the second server-side secure connection is based on the difference exceeding the threshold.

16 . The non-transitory machine-readable storage medium of claim 1 , wherein the client-side secure network tunnel is established according to an Internet Protocol Security (IPSec) protocol.

17 . A method comprising:

establishing, by a proxy system comprising a hardware processor, a client-side secure network tunnel according to a tunneling protocol between the proxy system and a network device, the client-side secure network tunnel comprising client connections of requesters connected to the network device;

establishing, by the proxy system, a plurality of server-side secure connections between the proxy system and respective servers of a trust network, wherein one or more target endpoints are accessible to the requesters through the network device and the servers; and

load balancing, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising updating a routing table at the network device that transfers traffic of a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection of the plurality of server-side secure connections to a second server-side secure connection of the plurality of server-side secure connections.

18 . The method of claim 17 , comprising:

maintaining, by the proxy system, counters for the respective server-side secure connections;

incrementing, by the proxy system, a first counter for the first server-side secure connection in response to data packets being directed by the proxy system through the first server-side secure connection;

incrementing, by the proxy system, a second counter for the second server-side secure connection in response to data packets being directed by the proxy system through the second server-side secure connection; and

determining, by the proxy system, whether a difference between a first count of the first counter and a second count of the second counter exceeds a threshold,

wherein the transferring of the traffic of the first client connection from the first server-side secure connection to the second server-side secure connection is based on the difference exceeding the threshold.

19 . A proxy system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

establish a client-side secure network tunnel according to a tunneling protocol between the proxy system and a client device, the client-side secure network tunnel comprising client connections of requesters connected to the client device;

establish a plurality of server-side secure connections between the proxy system and destination servers in a trust network, wherein one or more target endpoints are accessible to the requesters through the client device and the destination servers;

receive information of conditions of the destination servers in the trust network; and

based on the conditions of the destination servers, load balance, by the proxy system, the client connections of the requesters in the client-side secure network tunnel across the destination servers of the trust network through respective server-side secure connections of the plurality of server-side secure connections, the load balancing comprising transferring a first client connection of the client connections in the client-side secure network tunnel from a first server-side secure connection to a second server-side secure connection.

20 . The proxy system of claim 19 , wherein the load balancing comprises:

adding a further server-side secure connection to another destination server of the trust network based on the conditions of the destination servers, or

terminating a server-side secure connection to a destination server based on a condition of the destination server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2024
From: ELUL, NATAN; AZACHI, ROY; AZRIELANT, GIL
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 067995/0631 →
Continuity (2)
Provisional Application 63516663 · Jul 31, 2023
Related Publication 20250047605A1 · Feb 6, 2025
References Cited (29)
US 9106482B1 · Bapat · 2015 [cited by examiner]
US 11528320B1 · Paralikar · 2022 [cited by examiner]
US 20020174034A1 · Au · 2002 [cited by examiner]
US 20170163724A1 · Puri · 2017 [cited by examiner]
US 20190372936A1 · Sullenberger et al. · 2019 [cited by applicant]
US 20200412825A1 · Siefker · 2020 [cited by examiner]
US 20210392079A1 · Slovetskiy · 2021 [cited by examiner]
US 20220166647A1 · Norbutas et al. · 2022 [cited by applicant]
US 20220345491A1 · Luo · 2022 [cited by examiner]
US 20220385637A1 · Thangapandi et al. · 2022 [cited by applicant]
US 20220394016A1 · Solanki et al. · 2022 [cited by applicant]
US 20230076070A1 · Gupta et al. · 2023 [cited by applicant]
US 20230118718A1 · Solanki et al. · 2023 [cited by applicant]
US 20230208923A1 · Woodworth · 2023 [cited by examiner]
US 20230344921A1 · Duraisamy et al. · 2023 [cited by applicant]
US 20230421471A1 · Beredimas · 2023 [cited by examiner]
US 20240129310A1 · Andrews · 2024 [cited by examiner]
US 20250047606A1 · Elul et al. · 2025 [cited by applicant]
WO WO2024081014A1 · 2024 [cited by examiner]
Donenfeld, NDSS, WireGuard: Next Generation Kernel Network Tunnel, 2017 (12 pages). [cited by applicant]
Elul et al., U.S. Appl. No. 18/773,763 entitled Load Balancing VPN Traffic filed Jul. 16, 2024 (32 pages). [cited by applicant]
Kubernetes, Nodes dated on or before Jul. 9, 2023 (10 pages). [cited by applicant]
Michael Kerrisk, namespaces(7)—Linux manual page, Dec. 2023 (7 pages). [cited by applicant]
Russell et al., iptables(8)—Linux man page downloaded Jun. 6, 2024 (34 pages). [cited by applicant]
Scholz et al., Performance Implications of Packet Filtering with Linux eBPF, 2018 (9 pages). [cited by applicant]
StrongSwan Documentation, Route-based VPN available—May 21, 2023 (13 pages). [cited by applicant]
Wikipedia, WireGuard, Jul. 16, 2023 (8 pages). [cited by applicant]
Wireguard Fast, Modern, Secure VPN Tunnel available Jul. 30, 2023 (7 pages). [cited by applicant]
Wu, Master's Thesis, Analysis of the WireGuard protocol, Jun. 17, 2019 (88 pages). [cited by applicant]