IP Library Granted Patent US 11,212,205
Granted Patent B2
US 11,212,205 · App. 16/802,986 · Granted Dec 28, 2021

System and method for soft failovers for proxy servers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,212,205
App. No.
16/802,986
Granted
Dec 28, 2021
Kind
B2
Abstract

A packet broker that performs a health-status check of a proxy server while the proxy server processes one or more proxy connections. The packet broker may attempt to exchange a heartbeat signal with the proxy server, and if unsuccessful, the proxy server is assumed to be failing. In such cases, a failover is desirable. Rather than implementing a “hard” failover, in which no further communication packets are directed to the proxy server, a “soft” failover is performed where the packet broker prevents new proxy connections from being processed by the proxy server, but maintains at least one (e.g., all) of the current proxy connections that are being processed by the proxy server.

Claims (47)

1. Apparatus for use with at least one proxy server processing at least one current proxy connection, the apparatus comprising:

a digital memory, configured to store one or more packet identifiers; and

proxy-managing circuitry, configured to:

receive a plurality of communication packets,

using the packet identifiers, identify those of the communication packets that belong to the current proxy connection,

perform a health-status check of the proxy server, and

in response to a failure in the health-status check of the proxy server:

maintain the current proxy connection, by directing to the proxy server those of the communication packets that belong to the current proxy connection, and

prevent any new proxy connections from being processed by the proxy server, by not directing at least some of the communication packets to the proxy server, wherein the proxy server is configured to fail the health-status check in response to receiving a shutdown command.

2. The apparatus according to claim 1 , comprising a packet broker that comprises the proxy-managing circuitry.

3. The apparatus according to claim 1 , further comprising a bypass switch, comprising:

a network interface, configured to receive the communication packets via a network; and

bypass-switch circuitry, configured to direct the communication packets to the proxy-managing circuitry.

4. The apparatus according to claim 3 , wherein the bypass-switch circuitry is further configured to:

perform a health-status check of the proxy-managing circuitry, and,

in response to a failure in the health-status check of the proxy-managing circuitry, bypass the proxy-managing circuitry, by not directing communication packets received by the network interface to the proxy-managing circuitry.

5. The apparatus according to claim 1 ,

wherein the packet identifiers include respective packet-identifier 5-tuples,

wherein respective headers of the communication packets include respective communication-packet 5-tuples, and

wherein the proxy-managing circuitry is configured to identify those of the communication packets that belong to the current proxy connection by attempting to match the communication-packet 5-tuples with the packet-identifier 5-tuples.

6. A method for use with at least one proxy server processing at least one current proxy connection, the method comprising, using proxy-managing circuitry:

receiving a plurality of communication packets;

identifying those of the communication packets that belong to the current proxy connection;

performing a health-status check of the proxy server; and

in response to a failure in the health-status check of the proxy server:

maintaining the current proxy connection, by directing to the proxy server those of the communication packets that belong to the current proxy connection,

preventing any new proxy connections from being processed by the proxy server, by not directing at least some of the communication packets to the proxy server, and

using the proxy server, failing the health-status check in response to receiving a shutdown command.

7. The method according to claim 6 , further comprising:

performing a health-status check of the proxy-managing circuitry, and,

in response to a failure in the health-status check of the proxy-managing circuitry, bypassing the proxy-managing circuitry, by not directing received communication packets to the proxy-managing circuitry.

8. The method according to claim 6 , wherein identifying those of the communication packets that belong to the current proxy connection comprises identifying those of the communication packets that belong to the current proxy connection using one or more packet identifiers that are stored in a digital memory.

9. The method according to claim 8 ,

wherein the packet identifiers include respective packet-identifier 5-tuples,

wherein respective headers of the communication packets include respective communication-packet 5-tuples, and

wherein identifying those of the communication packets that belong to the current proxy connection comprises identifying those of the communication packets that belong to the current proxy connection by attempting to match the communication-packet 5-tuples with the packet-identifier 5-tuples.

10. A computer software product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor, cause the processor to:

receive a plurality of communication packets,

using a plurality of packet identifiers stored in a digital memory, identify those of the communication packets that belong to a current proxy connection of proxy server,

perform a health-status check of the proxy server, and

in response to a failure in the health-status check of the proxy server:

maintain the current proxy connection, by directing to the proxy server those of the communication packets that belong to the current proxy connection, and

prevent any new proxy connections from being processed by the proxy server, by not directing at least some of the communication packets to the proxy server, wherein the proxy server is configured to fail the health-status check in response to receiving a shutdown command.

11. The computer software product according to claim 10 ,

wherein the packet identifiers include respective packet-identifier 5-tuples,

wherein respective headers of the communication packets include respective communication-packet 5-tuples, and

wherein the instructions cause the processor to identify those of the communication packets that belong to the current proxy connection by attempting to match the communication-packet 5-tuples with the packet-identifier 5-tuples.

Assignments (3)
CHANGE OF NAME Recorded Apr 20, 2022
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 059710/0742 →
CHANGE OF NAME Recorded Dec 23, 2021
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 060751/0532 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2020
From: FRID, NAOMI
To: VERINT SYSTEMS LTD.
Reel/Frame 052403/0617 →