发明名称 Load balancing approach for scaling secure sockets layer performance
摘要 A load-balancing approach for scaling Secure Sockets Layer (SSL) performance is disclosed. During a handshake phase of establishing a SSL connection among a client and server, a processor card identifier value, processor identifier value, and session index value are encoded in a session identifier value that is sent to a client. When the client subsequently resumes the SSL session, it provides the session identifier value, and the encoded values are used for routing the session to an SSL processor that has the negotiated security parameters for the session. In one embodiment, a load balancer distributes the SSL sessions across multiple SSL termination engines that actually carry out SSL processing, based on the card identifier value and the processor identifier. If one of the SSL termination engine cards fails, the load balancer card routes all sessions destined for the failed card to other cards that are operating. The SSL processor that receives such session data determines that it does not have a session table entry matching the session identifier, creates a new session identifier and gives the new session identifier to the client.
申请公布号 US7111162(B1) 申请公布日期 2006.09.19
申请号 US20010954330 申请日期 2001.09.10
申请人 CISCO TECHNOLOGY, INC. 发明人 BAGEPALLI NAGARAJ;PATRA ABHIJIT
分类号 H04L9/00;G06F15/16 主分类号 H04L9/00
代理机构 代理人
主权项
地址