Load balances connection establishment across a group of connector servers

By allocating connections between connector server groups and selecting groups with a small number of connections to receive connection requests, the problem of load imbalance of connector servers in the prior art is solved, and the load balancing of connections and efficient utilization of resources is achieved.

CN115486044BActive Publication Date: 2025-06-06MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180032106.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-05-01
Filing Date
2021-03-16
Publication Date
2025-06-06
Estimated Expiration
2041-03-16

AI Technical Summary

Technical Problem

The prior art is difficult to payload balance the connection between a public computer network and a private computer network between multiple sets of connector servers, resulting in unbalanced load on the connector server and degraded performance.

Method used

By allocating connections between connector server groups, the registration logic is used to determine the number of connections between the private computer network and each group, and selecting groups with fewer connections to receive connection requests to achieve load balancing between connector servers.

Benefits of technology

It realizes load balancing of connections between multiple sets of connector servers, improves the average efficiency of connector servers, ensures redundancy of connections and the security of private computer networks, and reduces resource access time and asset consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115486044B_ABST
    Figure CN115486044B_ABST
Patent Text Reader

Abstract

The present invention describes a technique that can load balance the establishment of connections between a group of connector servers in a public computer network by performing operations, the operations including receiving a connection request from a connector client in a private computer network, the connection request requesting to establish a connection between the connector client and one of the connector servers in the public computer network. The number of connections between the private computer network and each group is determined. Based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group, an identified group is selected from a plurality of groups. The connection request is provided to the identified group, which implements the establishment of a connection between the connector client and the connector servers in the identified group.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] A variety of services can be used to enable access to private networks over the Internet. Each private network can be an enterprise internal network or a private cloud. These services typically enable access to private networks by installing a "connector client" within the private network. Each connector client installed within the private network is typically configured to route traffic from the Internet to the private network. Connector clients are traditionally general purpose operations that listen for incoming resource requests from the Internet.

[0002] For example, a connector client can expose a public Internet IP address to receive resource requests from the Internet, which may require firewall exceptions and network address translation (NAT) rules to route traffic to the connector client within the private network. In another example, a connector client can establish a site-to-site connection with a connector server that has access to the connector client and the Internet. In this example, the connector server exposes a public Internet IP address to receive resource requests on behalf of the connector client. Site-to-site connections can connect local area networks (LANs) to federated LANs and may not scale the solution to more than a few connector clients per connector server because the LANs may overlap.

[0003] The connector clients in both of the above examples expose the private network in which the connector client is installed to risk by enabling (either directly or via a connector server) the creation of a connection from the Internet to a network that is intended to be private and is typically behind a NAT and firewall. Traditionally, connector clients are able to establish site-to-site connections with a single connector server, which can result in a load on the connector server that is too large for the connector server to adequately handle. For example, the burden of the load can cause the performance of the connector server to degrade. While multiple connector servers can be employed, the use of load balancers on the connector server side typically results in traffic being routed through the same connector server. Summary of the invention

[0004] Various methods are described herein, particularly for load balancing the connection establishment between a public computer network and a private computer network between multiple groups of connector servers. The public computer network is outside the private computer network. The public computer network includes multiple connector servers. The private computer network includes (e.g., hosting) multiple connector clients. Load balancing can distribute connections between connector servers. Load balancing can also distribute connections between connector clients. The load balancing between connector servers (e.g., connector server groups) will be described herein as server-level load balancing. The load balancing between connector clients is described herein as client-level load balancing. Each connection between a private computer network and a public computer network exists between a single connector client in the private computer network and a single connector server in the public computer network. Each connector client can be connected to a single connector server. Each connector server can be connected to one or more connector clients, thereby forming one or more corresponding connections. Each connection established between a connector client and a connector server enables the connector server to provide a request (also known as a resource request) for accessing resources in the private computer network to the connector client.

[0005] In order to make resources in the private computer network accessible to computing devices (e.g., user devices and / or proxy servers) in the public computer network, a connection is established between a connector client in the private computer network and a connector server in the public computer network. The establishment of the connection is load balanced between the connector server group.

[0006] In an example method, connector servers included in a public computer network are distributed between groups. Each group includes one or more connector servers from a plurality of connector servers. For example, the (multiple) connector servers in each group may not be included in any other group. A connection request is received from a connector client included in a private computer network. The connection request requests to establish a connection between the connector client and one of the plurality of connector servers in the public computer network. The public computer network is outside the private computer network. The number of connections between the private computer network and each group is determined. Based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group, an identified group is selected from a plurality of groups to receive the connection request. A connection request is provided to the identified group, which implements the establishment of a connection between the connector client and the connector server in the identified group based at least in part on selecting the identified group from the plurality of groups. For example, if the identified group includes a single connector server, a connection is established between the connector client and the only connector server in the identified group. In another example, if the identified group includes multiple connector servers, a connection can be established between the connector client and any connector server in the identified group based on any of the factors to achieve load balancing of connection establishment between the connector servers in the identified group.

[0007] Once a connection is established between a connector client and a connector server, resource requests received from a computing device (e.g., a user device or a proxy server) in a public computer network can be routed from the connector server to the connector client through the established connection. For example, when a computing device provides a request to access a resource in a private computer network, the computing device can be informed of multiple connector servers that are connected to the connector client in the private computer network. The computing device can determine which connector server to use to obtain access to the resource based on any of a number of factors to achieve load balancing of resource requests between connector servers. If the connector server used by the computing device is connected to multiple connector clients in the private computer network, the connector server can determine which connector client to use to obtain access to the resource based on any of a number of factors to achieve load balancing of resource requests between connector clients. Otherwise, the connector server can use the only available connector client. The information identifying the resource in the request enables the connector client used by the connector server to provide access to the resource to the computing device.

[0008] For example, a first request to access a resource included in a private computer network may be provided from a computing device included in a public computer network to a database included in the public computer network. The first request includes a network identifier that identifies the private computer network. A response to the first request may be received from the database at the computing device. The response includes an Internet Protocol address that corresponds to a corresponding connector server included in the public computer network based at least in part on a cross-reference of the Internet Protocol address with the network identifier in the database. A designated Internet Protocol address corresponding to a designated connector server may be selected from the Internet Protocol addresses by the computing device based at least in part on a comparison of the attributes of the corresponding connector server. Access to the resource by the computing device may be triggered by providing a second request to access the resource from the computing device to the designated connector server using the designated Internet Protocol address. The second request includes a network identifier and a resource identifier that identifies the resource. Providing the second request may cause the designated connector server to provide the second request to access the resource to an identified connector client that is hosted by the private computer network and is configured to provide access to the resource as a result of receiving the second request through a connection between the identified connector client and the designated connector server using the resource identifier.

[0009] The present invention is provided to introduce a selection of concepts in a simplified form, and these concepts will be further described in the specific embodiments below. The present invention is not intended to identify the key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. In addition, it should be noted that the present invention is not limited to the specific embodiments and / or the specific embodiments described in other parts of this article. These embodiments presented in this article are for illustrative purposes only. Based on the teachings contained herein, other embodiments will be apparent to those skilled in the relevant technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The accompanying drawings, which are incorporated herein and constitute a part of the specification, illustrate embodiments of the invention and, together with the description, further serve to explain the principles involved and to enable those skilled in the art to make and use the disclosed technology.

[0011] Figure 1 to Figure 2 and Figures 5 and 6 is a block diagram of a connection establishment load balancing system according to an embodiment.

[0012] Figure 3A and Figure 3B are corresponding portions of an example activity diagram for load balancing establishment of connections among a group of connector servers according to one embodiment.

[0013] Figure 4 is an example activity diagram for load balancing resource requests among established connections according to one embodiment.

[0014] Figure 7 Depicted is a flow diagram of an example method for load balancing connection establishments according to one embodiment.

[0015] Figure 8 According to an embodiment Figure 1 To Figure 3 and Figures 5 and 6 A block diagram of an example implementation of the registration logic shown in .

[0016] Fig. 9 An example computer is depicted in which the present invention may be implemented.

[0017] Features and advantages of the disclosed technology will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings, in which like reference characters identify corresponding elements throughout the drawings. In the drawings, like reference numbers generally indicate identical, functionally similar, and / or structurally similar elements. The drawing in which an element first appears is indicated by the leftmost (multiple) digits in the corresponding reference number. DETAILED DESCRIPTION

[0018] I. Introduction

[0019] The following detailed description refers to the accompanying drawings which illustrate exemplary embodiments of the present invention. However, the scope of the present invention is not limited to these embodiments, but is defined by the appended claims. Therefore, embodiments beyond those shown in the drawings, such as modified versions of the illustrated embodiments, may still be included in the present invention.

[0020] The phrases "one embodiment", "an embodiment", "an example embodiment" or similar expressions mentioned in the specification indicate that the described embodiment may include a particular feature, structure or characteristic, but not every embodiment must include the particular feature, structure or characteristic. In addition, such phrases do not necessarily refer to the same embodiment. In addition, when a particular feature, structure or characteristic is described as being associated with an embodiment, it means that it is within the knowledge of those skilled in the art to implement such feature, structure or characteristic in combination with other embodiments, whether or not explicitly described.

[0021] Descriptors such as "first," "second," "third," etc. are used to refer to some elements discussed herein. Such descriptors are used to facilitate discussion of example embodiments and do not imply a necessary order for the elements mentioned unless such an order is expressly stated herein.

[0022] II. Example Embodiments

[0023] The example embodiments described herein are capable of load balancing the establishment of connections between a public computer network and a private computer network between multiple groups of connector servers. The public computer network is outside the private computer network. The public computer network includes multiple connector servers. The private computer network includes (e.g., hosting) multiple connector clients. Load balancing can distribute connections between connector servers. Load balancing can also distribute connections between connector clients. Load balancing between connector servers (e.g., connector server groups) will be described herein as server-level load balancing. Load balancing between connector clients will be described herein as client-level load balancing. Each connection between a private computer network and a public computer network exists between a single connector client in the private computer network and a single connector server in the public computer network. Each connector client can be connected to a single connector server. Each connector server can be connected to one or more connector clients, thereby forming one or more corresponding connections. Each connection established between a connector client and a connector server enables the connector server to provide a request (also known as a resource request) to the connector client to access resources in the private computer network.

[0024] In order to make resources in the private computer network accessible to computing devices (e.g., user devices and / or proxy servers) in the public computer network, a connection is established between a connector client in the private computer network and a connector server in the public computer network. According to one or more techniques described herein, the establishment of the connection is load balanced between a group of connector servers.

[0025] Once a connection is established between a connector client and a connector server, resource requests received from a computing device (e.g., a user device or a proxy server) in a public computer network can be routed from the connector server to the connector client via the established connection. For example, when a computing device provides a request to access a resource in a private computer network, the computing device can be informed of multiple connector servers that are connected to the connector client in the private computer network. The computing device can determine which connector server to use to obtain access to the resource based on any of a number of factors to achieve load balancing of resource requests between connector servers. If the connector server used by the computing device is connected to multiple connector clients in the private computer network, the connector server can determine which connector client to use to obtain access to the resource based on any of a number of factors to achieve load balancing of resource requests between connector clients. Otherwise, the connector server can use the only available connector client. The information identifying the resource in the request enables the connector client used by the connector server to provide access to the resource to the computing device.

[0026] The example techniques described herein have many advantages over conventional techniques for establishing a connection between a private computer network and a public computer network. For example, the example techniques may be able to load balance the establishment of a connection between a private computer network and a public computer network across multiple connector servers and / or multiple connector clients. Load balancing the establishment of a connection may enable connector clients and connector servers to more efficiently process connection requests and subsequent resource requests. For example, based on a comparison of the attributes of the first group and the second group (e.g., multiple connections associated with each of the first group and the second group), by establishing a connection between a connector client and a first group of connector servers instead of a second group of connector servers, the average efficiency of the connector client and / or connector server is improved. The example techniques may be able to ensure that two consecutive connection requests from corresponding connector clients in the same private computer network (e.g., and sharing the same tenant identifier) ​​are provided to different groups of connection servers.

[0027] Load balancing the establishment of connections can enable connector clients and connector servers to more reliably process connection requests and subsequent resource requests. For example, load balancing can provide redundancy for connections established between a private computer network and a public computer network. For example, when a connection is established between a private computer network and a corresponding group of connector servers in a public network and the group of connector servers goes offline (e.g., due to a restart, update, upgrade, or performance issue), resources in the private computer network can still be accessed through the group of connector servers that remain online (e.g., through the connections between the private computer network and these groups).

[0028] The example technology can increase the security of a private computer network. For example, when a connector client in the private computer network establishes a connection with a connector server, only the connector server is allowed to communicate with the connector client through the connection. No other entity can communicate with the connector client through the connection.

[0029] Example techniques can reduce the amount of time and / or assets (e.g., processors, memory, network bandwidth) consumed to establish a connection between a private computer network and a public computer network. For example, by load balancing the establishment of connections between connector server groups, the amount of time and / or assets consumed to establish connections using a relatively overloaded connector server or connector server group can be reduced (e.g., avoided). In addition, remedial actions can be avoided to reduce excessive load on such a connector server or connector server group while the performance of the connector server or group is impaired (e.g., degraded) due to the excessive load.

[0030] Example techniques may be able to increase the speed of access to resources in a private computer network; increase the availability, speed, and stability of connector clients in a private computer network and / or connector servers to which the connector clients are connected; reduce CPU usage of connector clients and / or connector servers, and the like.

[0031] Example techniques can improve user efficiency, for example, by reducing the number of steps and / or amount of time a user takes when attempting to access a resource. For example, load balancing the establishment of a connection to a private computer network can reduce the likelihood that a user will be unable to access a resource in the private computer network due to no connection being available between the public computer network and the private computer network. Load balancing the establishment of a connection can reduce the likelihood that a user will have to restart an attempt to access a resource due to delays caused by an overload (e.g., by requests from other resources) of a connector server and / or connector client associated with the connection.

[0032] Figure 1 1 is a block diagram of a connection establishment load balancing system 100 according to one embodiment. Generally speaking, the connection establishment load balancing system 100 operates to provide information to a user in response to a request (e.g., a hypertext transfer protocol (HTTP) request) received from the user. The information may include files (e.g., web pages, images, audio files, video files, etc.), output of executable files, and / or any other suitable type of information. According to the example embodiments described herein, the connection establishment load balancing system 100 load balances connections to the private computer network 122.

[0033] like Figure 1 As shown, the connection establishment load balancing system 100 includes a public computer network 120 and a private computer network 122. The private computer network 122 includes (e.g., hosts) a plurality of connector clients 114A-114R and a plurality of resources 116A-116T. The connector clients 114A-114R are deployed in the private computer network 122, for example, by a tenant (e.g., an owner) that owns the private computer network 122. Each of the connector clients 114A-114R can be a respective process running on one or more processors in the private computer network 122. Each of the connector clients 114A-114R can establish one or more connections with any one or more respective connector servers 112A-112P included in the public computer network 120 to facilitate providing access to the resources 116A-116T. Each of the resources 116A-116T can be a document (e.g., a web page, an image, an audio file, a video file, etc.), an output of an executable file, or any other suitable type of resource.

[0034] The public computer network 120 is external to the private computer network 122. The public computer network 120 includes a plurality of user devices 102A-102M, a network 104, a plurality of network servers 106A-106N, an authentication server 108, a database 126, a plurality of connector servers 112A-112P, and a registration logic 124. Communications between the user devices 102A-102M, the network servers 106A-106N, the authentication servers 108, the database 126, the connector servers 112A-112P, and the registration logic 124 are conducted over the network 104 using well-known network communication protocols. The network 104 may be a wide area network (e.g., the Internet), a local area network (LAN), another type of network, or a combination thereof.

[0035] The user devices 102A-102M are processing systems capable of communicating with the network servers 106A-106N. An example of a processing system is a system including at least one processor capable of operating data according to a set of instructions. For example, the processing system may be a computer, a personal digital assistant, etc. The user devices 102A-102M are configured to provide requests to the network servers 106A-106N to request information stored on the network servers 106A-106N (or otherwise accessible via the network servers 106A-106N). The user devices 102A-102M are further configured to provide requests to the connector servers 112A-112P to request access to the private network 122 (e.g., one or more resources in the resources 116A-116T in the private network 122). For example, a user may initiate a request to execute a computer program (e.g., an application) using a client (e.g., a web browser, a web crawler, or other type of client) deployed on the user device 102, which is owned by the user or otherwise accessible. According to some example embodiments, user devices 102A-102M are able to access a domain (e.g., a website) hosted by network servers 106A-106N or a domain in resources 116A-116T included in private computer network 122 so that user devices 102A-102M can access information available through the domain. Such a domain may include a web page, which may be provided, for example, as a hypertext markup language (HTML) document and objects (e.g., files) linked therein.

[0036] Each of the user devices 102A-102M may include any client-enabled system or device, including but not limited to a desktop computer, a laptop computer, a tablet computer, a wearable computer such as a smart watch or head-mounted computer, a personal digital assistant, a cellular telephone, an Internet of Things (IoT) device, or the like. It will be appreciated that any one or more of the user devices 102A-102M may communicate with any one or more of the network servers 106A-106N and / or any one or more of the connector servers 112A-112P.

[0037] The first user device 102A includes a browser 110. The browser 110 is a software application configured to enable a user of the user device 102A to access resources on the World Wide Web (WWW). For example, when a user provides a request for a resource stored in a network server 106A-106N, the browser retrieves the resource from one or more network servers in the network server 106A-106N and provides the resource to be displayed to the user on the user device 102A. In another example, when a user provides a request for a resource stored in a private computer network 122 (e.g., any one of the resources 116A-116T), the browser (e.g., the client-side connection load balancing logic 118A in the browser) retrieves the resource from the private computer network 122 according to one or more example techniques described herein, and provides the resource to be displayed to the user on the user device 102A. For each of these examples, the request for a resource may include a uniform resource identifier (URI), which corresponds to a location where the resource is hosted (e.g., a memory location on a network server or a memory location in a private computer network 122). The URI may be a uniform resource locator (URL) or a uniform resource name (URN). Upon receiving the request, the browser 110 may retrieve the resource from a web server or private computer network 122 hosting the resource based on the URI. It will be appreciated that the resource may be a web page (e.g., a hypertext markup language (HTML) document).

[0038] The browser 110 includes a client-side connection load balancing logic 118A. The client-side connection load balancing logic 118A is configured to provide requests for resources stored in the private computer network 122 (e.g., any of the resources 116A-116T). For example, the client-side connection load balancing logic 118A may generate such requests based on (e.g., at least in part based on) instructions received from a user of a user device (e.g., any of the user devices 102A-102B). For example, the instructions may be received through a user interface of the user device. The instructions may instruct the client-side connection load balancing logic 118A to request a resource. In another example, the client-side connection load balancing logic 118A may not generate such requests based on instructions received from a user of the user device (e.g., independently of such instructions).

[0039] In one example implementation, the client-side connection load balancing logic 118A provides a request for a resource to the database 126. The request includes a network identifier that identifies the private computer network 122. According to the implementation, the client-side connection load balancing logic 118A receives a response to the request from the database 126. The response includes a plurality of Internet Protocol addresses corresponding to corresponding connector servers (e.g., any connector server in the connector servers 112A-112P) based at least in part on Internet Protocol addresses cross-referenced with network identifiers in the database 126. Further according to the implementation, the client-side connection load balancing logic 118A selects a specified Internet Protocol address from the Internet Protocol addresses received from the database 126, the specified Internet Protocol address corresponding to the specified connector server, based at least in part on a comparison of the attributes of the connector servers corresponding to the received Internet Protocol addresses. Examples of the attributes of the connector servers include, but are not limited to, the geographic location of the connector server, the proportion of time that the connector server is available, the degree to which the processor and / or memory of the connector server is utilized, and the number of resource requests processed (e.g., processed) by the connector server. Further in accordance with the implementation, the client-side connection load balancing logic 118A triggers access of the resource by the first user device 102A to the resource by providing a second request to the designated connector server to access the resource using the designated Internet Protocol address. The second request includes a network identifier and a resource identifier that identifies the resource. By providing the second request, the client-side connection load balancing logic 118A causes the designated connector server to provide the second request to access the resource to the identified connector client (e.g., any connector client of connector clients 114A-114R) through a connection between the identified connector client and the designated connector server, which results in the identified connector client providing access to the resource using the resource identifier.

[0040] For illustrative purposes and not limitation, the browser 110 is shown as being incorporated in the first user device 102A. It will be appreciated that the browser 110 may be incorporated in any of the user devices 102A-102M. For example, each of the user devices 102A-102M may include a corresponding browser.

[0041] The network servers 106A-106N are processing systems capable of communicating with the user systems 102A-102M. The network servers 106A-106N are configured to execute a computer program that provides resources to the user in response to receiving a request from the user. For example, the resources may include files (e.g., web pages, images, audio files, video files, etc.), output of executable files, or any other suitable type of resources. According to some example embodiments, the network servers 106A-106N are configured to host corresponding websites so that the websites can be accessed by users connected to establish the load balancing system 100.

[0042] Connector servers 112A-112P are processing systems capable of communicating with user systems 102A-102M. Connector servers 112A-112P are configured to act as intermediaries between user devices 102A-102M and connector clients 114A-114R in response to connector clients 114A-114R establishing connections with connector servers 112A-112P.

[0043] The first connector server 112A includes server-side connection load balancing logic 118B. The server-side connection load balancing logic 118B is configured to facilitate providing access to resources 116A-116T in the private computer network 122 in response to receiving a request for resources 116A-116T from a user device (e.g., any of the user devices 102A-102M). For example, when the server-side connection load balancing logic 118B receives a request for a resource from a client device (e.g., the client-side connection load balancing logic 118A in the client device), the server-side connection load balancing logic 118B provides (e.g., forwards) a resource identifier that identifies the resource to the identified connector client so that the identified connector client provides access to the resource to the user device. The server-side connection load balancing logic 118B can select the identified connector client from any of the connector clients 114A-114R that have a connection to the connector server based at least in part on a comparison of attributes of those connector clients 114A-114R. Examples of properties of a connector client include, but are not limited to, the amount of processing and / or memory assets consumed by the connector client and the number of requests for resource(s) processed by the connector client.

[0044] For illustrative purposes and not limitation, the server-side connection load balancing logic 118B is shown as being incorporated in the first connector server 112A. It will be appreciated that the server-side connection load balancing logic 118B may be incorporated in any of the connector servers 112A-112P. For example, each of the connector servers 112A-112P may include corresponding server-side connection load balancing logic.

[0045] The registration logic 124 is configured to load balance the establishment of connections between the groups of connection servers 112A-112P. For example, the registration logic 124 allocates the connector servers 112A-112P in the groups so that each group includes at least one of the connector servers 112A to 112P. The connector servers 112A-112P can be allocated between the groups so that none of the connector servers 112A-112P is included in more than one group. The registration logic 124 is configured to process connection requests from the connector clients 114A-114R. Each connection request received from the connector client requests to establish a connection between the connector client and one of the connector servers 112A-112P. Upon receiving each connection request, the registration logic 124 determines the number of connections between the private computer network 122 (e.g., any connector client of the connector clients 114A-114R in the private computer network 122) and each group. Upon receiving each connection request, registration logic 124 further selects one of the plurality of groups to receive the connection request based at least in part on the number of connections between private computer network 122 and the selected group being less than or equal to the number of connections between private computer network 112 and each other group. Upon receiving each connection request, registration logic 124 further provides the connection request to the selected group corresponding to the connection request, which enables a corresponding connection to be established between the connector client from which the connection request was received and a connector server in the selected group.

[0046] In one example implementation, the registration logic 124 includes a registration server that performs the operations described above with respect to the registration logic 124. In another example, the registration logic 124 includes a plurality of registration servers, a registration server load balancer for load balancing the registration servers, and a database for storing a shared state shared by the registration servers. Figures 5 to 8 Further details regarding some example implementations of registration logic 124 are provided in the discussion of .

[0047] The authentication server 108 is configured to issue tokens in response to requests received from the connector clients 114A-114R. The authentication server 108 is also configured to verify tokens received from the connector servers 112A-112P. In the connection establishment example, when the connector client attempts to establish a connection with the connector server, the connector server may request a token from the connector client, which prompts the connector client to request a token from the authentication server 108. After the authentication server 108 issues the token to the connector client, the connector client may provide the token to the connector server, and the connector server may forward the token received from the connector client to the authentication server 108 for verification.

[0048] According to the connection establishment example, the authentication server 108 can compare the token issued by the authentication server 108 and the token received from the connector server to determine whether to validate the token received from the connector server. If the token issued by the authentication server 108 and the token received from the connector server match (e.g., are identical or semantically identical), the authentication server 108 validates the token received from the connector server. If the token issued by the authentication server 108 and the token received from the connector server do not match, the authentication server 108 does not validate the token received from the connector server. The authentication server 108 validates the token received from the connector server so that the connector client can register a new connection between the connector client and the connector server in the database 126, thereby establishing a connection. The authentication server 108 does not validate (e.g., invalidates) the token received from the connector server so that the connector client cannot register a new connection, and the connection is therefore not established.

[0049] When a connection is registered to the database 126 (e.g., when a connection is established), the database 126 stores the network identifiers and IP addresses received from the connector servers 112A-112P. Each IP address identifies (e.g., uniquely identifies) a connector server. Each network identifier identifies a private computer network (e.g., private computer network 122). For example, when a connection is to be established between a connector client and a connector server, the database 126 receives the following items from the connector server: (A) a network identifier that identifies the private computer network hosting the connector client, and (B) an IP address that identifies the connector server. According to this example, the database 126 cross-references the network identifier and the IP address to describe the connection. In one aspect, the database 126 can cross-reference the network identifier and the IP address by storing the network identifier and the IP address in a common (i.e., the same) row of the database 126. In another aspect, the database 126 can cross-reference the network identifier and the IP address by generating cross-reference information indicating (e.g., describing) the relationship between the network identifier and the IP address. The database 126 can cross-reference the network identifier and the IP address for each connection to be established.

[0050] According to the above example, when the database 126 subsequently receives a request for the IP address of a connector server having a connection with a connector client hosted by a private computer network from the client-side connection load balancing logic 118A, the database 126 can provide all IP addresses of the corresponding connector servers having a connection with the connector client hosted by the private computer network, so that the client-side connection load balancing logic 118A can perform server-level load balancing for these connector servers. For example, the database 126 can determine all IP addresses of the corresponding connector servers having connections with the connector client hosted by the private computer network based at least in part on these Internet Protocol addresses and the network identifier identifying the private computer network. In one aspect, the database 126 can traverse the rows of the database 126 to identify those rows in which the network identifier is cross-referenced with the IP address, and then forward the cross-referenced IP address to the client-side connection load balancing logic 118A. In another aspect, the database 126 can review the generated cross-reference information to identify which IP addresses are indicated by the cross-reference information as having a relationship with the network identifier, and then forward these IP addresses to the client-side connection load balancing logic 118A.

[0051] The client-side connection load balancing logic 118A and / or the server-side connection load balancing logic 118B can be implemented in various ways to load balance connections to the private computer network 122, including in hardware, software, firmware, or any combination thereof. The registration logic 124 can be implemented in various ways to load balance the establishment of connections between the group of connector servers 112A-112P, including in hardware, software, firmware, or any combination thereof. For example, the client-side connection load balancing logic 118A, the server-side connection load balancing logic 118B, and / or the registration logic 124 can be implemented as a computer program code configured to execute in one or more processors. In another example, the client-side connection load balancing logic 118A, the server-side connection load balancing logic 118B, and / or the registration logic 124 can be at least partially implemented as a hardware logic / electrical circuit device. For example, the client-side connection load balancing logic 118A, the server-side connection load balancing logic 118B, and / or the registration logic 124 may be implemented at least in part in a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), an application specific standard product (ASSP), a system on a chip (SoC), a complex programmable logic device (CPLD), etc. Each SoC may include an integrated circuit chip that includes one or more processors (e.g., a microcontroller, a microprocessor, a digital signal processor (DSP), etc.), a memory, one or more communication interfaces, and / or additional circuits, and / or embedded firmware to perform its functions.

[0052] Figure 2 is a block diagram of another exemplary connection establishment load balancing system 200 according to one embodiment. Figure 2 The connection in the load balancing system 200 is established with Figure 1 The connection establishment load balancing system 100 shown in FIG. 2 is substantially the same, except that the connection establishment load balancing system 200 includes a proxy server 228. In addition, Figure 2 The first user device 202A does not include Figure 1 In contrast, the proxy server 200 includes a proxy-side connection load balancing logic 218C, which includes a client-side connection load balancing logic 118A. Figure 1 The functionality of the client-side connection load balancing logic 118A shown in FIG.

[0053] like Figure 2 As shown, the connection establishment load balancing system 200 includes a public computer network 220 and a private computer network 222. The private computer network 222 includes a plurality of connector clients 214A-214R and a plurality of resources 216A-216T, which can be connected in a manner similar to Figure 1114A-114R and resources 116A-116T shown in FIG.

[0054] The public computer network 220 includes a plurality of user devices 202A-202M, a network 204, a plurality of network servers 206A-206N, an authentication server 208, a database 226, a plurality of connector servers 212A-212P, and a registration logic 224, which can be respectively similar to Figure 1 The plurality of user devices 102A-102M, network 104, plurality of network servers 106A-106N, authentication server 108, database 126, plurality of connector servers 112A-112P, and registration logic 124 shown in FIG. 1 operate in the manner of FIG. 1 , except that the first user device 202A does not include Figure 1 The client-side connection load balancing logic 118A is shown. Although the first user device 202A is not shown as including a browser, it will be appreciated that any of the user devices 202A-202M can include a browser. The public computer network 220 also includes a proxy server 228. Communications between the user devices 202A-202M, the network servers 206A-206N, the authentication server 208, the database 226, the connector servers 212A-212P, the registration logic 224, and the proxy server 228 are conducted over the network 204 using well-known network communication protocols.

[0055] The proxy server 228 is a processing system that acts as an intermediary between the user devices 202A-202M and the network servers 206A-206N to intercept requests initiated by the user devices 202A-202M to request resources from the network servers 206A-206N. The proxy server also acts as an intermediary between the user devices 202A-202M and the connector servers 212A-212P to intercept requests initiated by the user devices 202A-202M to access the private network 222 (e.g., any one of the resources 216A-216T in the private network 222). The proxy server 228 is configured to analyze and / or modify resources requested by the client device before delivering the requested or modified resources to the client device. For example, the proxy server 228 can define and enforce policies to control user behavior with respect to resources; detect risky behavior, violations, and suspicious data points and activities about resources; and integrate remediation workflows to mitigate risks. According to this example, the proxy server 228 can modify the resources processed at the network server and / or the resources 216A-216T in the private computer network 222 based on the policy. It will be appreciated that the request to access the resource can be initiated by the proxy server 228. For example, the request is not necessarily intercepted by the proxy server 228 from the user device 202A-202M.

[0056] The proxy server 228 includes a proxy-side connection load balancing logic 218C. The proxy-side connection load balancing logic 218C is configured to provide requests for resources (e.g., any of the resources 116A-116T) stored in the private computer network 122 in response to receiving a request from any of the user devices 102A-102M. For example, the proxy-side connection load balancing logic 218C may analyze the request to identify the resources indicated therein, analyze and / or modify those resources, and then forward the requested or modified resources to the client device(s) from which the request was received.

[0057] In one example implementation, the proxy-side connection load balancing logic 218C provides a request for a resource to the database 126. The request includes a network identifier that identifies the private computer network 122. According to the implementation, the proxy-side connection load balancing logic 218C receives a response to the request from the database 126. The response includes a plurality of Internet Protocol addresses corresponding to corresponding connector servers (e.g., any of the connector servers 112A-112P) based at least in part on the Internet Protocol addresses cross-referenced with the network identifier in the database 226. Further according to the implementation, the proxy-side connection load balancing logic 218C selects a specified Internet Protocol address from the Internet Protocol addresses received from the database 126, the specified Internet Protocol address corresponding to the specified connector server, based at least in part on a comparison of the attributes of the connector servers to which the received Internet Protocol addresses correspond. Further according to the implementation, the proxy-side connection load balancing logic 218C triggers access of the resource by the proxy server 202 to the resource by providing a second request to access the resource to the specified connector server using the specified Internet Protocol address. The second request includes the network identifier and a resource identifier that identifies the resource. By providing the second request, the proxy-side connection load balancing logic 218C causes the designated connector server to provide a second request for access to the resource to an identified connector client (e.g., any of connector clients 114A-114R) through a connection between the identified connector client and the designated connector server, which results in the identified connector client providing access to the resource using the resource identifier.

[0058] Proxy server 228 may be coupled to user devices 202A-202M, network 204, and / or network servers 206A-206N in any suitable arrangement. For example, proxy server 228 may be configured as a forward proxy server or a reverse proxy server.

[0059] The proxy side connection load balancing logic 218C can be implemented in various ways to load balance the connection to the private computer network 122, including in hardware, software, firmware, or any combination thereof. For example, the proxy side connection load balancing logic 218C can be implemented as a computer program code configured to be executed in one or more processors. In another example, the proxy side connection load balancing logic 218C can be at least partially implemented as a hardware logic / electrical circuit device. For example, the proxy side connection load balancing logic 218C can be at least partially implemented in a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), an application specific standard product (ASSP), a system on a chip (SoC), a complex programmable logic device (CPLD), etc. Each SoC may include an integrated circuit chip that includes one or more processors (e.g., a microcontroller, a microprocessor, a digital signal processor (DSP), etc.), a memory, one or more communication interfaces, and / or additional circuits, and / or embedded firmware to perform its functions.

[0060] Figure 3A and Figure 3B is a corresponding portion of an example activity diagram 300 for load balancing establishment of connections among a group of connector servers according to one embodiment. Figure 3A and Figure 3B Each of the diagrams depicts a connector client 314, a registration logic 324, a connector server 312, an authentication server 308, and a database 310, which are Figure 1 and Figure 2 310. The example implementations of the connector client 114 or 214, registration logic 124 or 224, connector server 112 or 212, authentication server 108 or 208, and database 126 or 210 shown in . Activities 332, 334, 336, 338, 340, 342, 344, 346, 348, 350, 352, 354, 356, 358, 360, 362, 364, 366, 368, 370, 372, 374, 376, 378, and 380 will now be described with reference to connector client 314, registration logic 324, connector server 312, authentication server 308, and database 310.

[0061] In activity 332, registration logic 324 assigns connector server 312 to the identified group. For example, registration logic 324 can assign multiple connector servers between multiple groups so that each group includes at least one connector server. However, for ease of discussion, the assignment of a single connector server 312 is described herein.

[0062] In activity 334, connector client 314 provides a connection request requesting to establish a connection with a public computer network (e.g., public computer network 120 or 220). For example, multiple connector clients in a private computer network (e.g., private computer network 122 or 222) may request corresponding connections with one or more public networks. However, each single connector client 314 is described herein for discussion.

[0063] In activity 336, registration logic 324 determines a number of connections for each of the plurality of groups of connection servers. The number of connections for a group is the cumulative number of connections between the private computer network including connector clients 314 and the connector server(s) in the group.

[0064] In activity 338 , registration logic 324 selects the identified group from the plurality of groups based on (eg, based at least in part on) the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group.

[0065] In activity 340, registration logic 324 provides the connection request to the identified group. It will be appreciated that the connection request provided by registration logic 324 is not necessarily the same as the connection request provided by connector client 314. It will also be appreciated that any connector server in the identified group may be able to service the connection request, subject to any criteria that may be established for determining which connector server in the identified group to service the connection request. Figure 3A In the embodiment of FIG. 3 , connector server 312 is shown as having been selected to service the connection request. It can be assumed that connection server 312 meets any criteria established for servicing the connection request. For example, connection server 312 can be selected to service the request based on the fact that connection server 312 has no more connections to the private computer network than every other connection server in the identified group.

[0066] In activity 342 , connector server 312 requests a token from connector client 314 .

[0067] In activity 344 , connector client 314 requests a token from authentication server 308 .

[0068] In activity 346, authentication server 308 provides a token to connector client 314. For example, authentication server 308 can generate a token to include a secret associated with connector client 314. For non-limiting illustrative purposes, FIG. 3A to FIG. 3BIn an embodiment of the invention, the secret includes a tenant identifier that identifies (eg, uniquely identifies) the owner of the private computer network. It will be appreciated that the secret does not necessarily include a tenant identifier.

[0069] In activity 348 , connector client 314 provides connector server 312 with the token received from authentication server 308 .

[0070] In activity 350, connector server 312 provides a verification request to authentication server 308, requesting verification of a token provided by connector client 314 to connector server 312. For example, the verification request may include the token provided by connector client 314 to connector server 312.

[0071] In activity 352, authentication server 308 verifies the token provided by connector client 314 to connector server 312. For example, authentication server 308 may compare the token provided by connector client 314 to connector server 312 and the token provided by authentication server 308 to connector client 314 to determine whether the tokens are the same. If the tokens are the same, authentication server 308 validates the token provided by connector client 314 to connector server 312. If the tokens are not the same, authentication server 308 does not validate (e.g., invalidates) the token provided by connector client 314 to connector server 312. It will be assumed that authentication server 308 validates the token provided by connector client 314 to connector server 312. Otherwise, authentication server will not proceed with activity 354.

[0072] In activity 354, authentication server 308 provides connector server 312 with verification of the token that connector client 314 provided to connector server 312. Receipt of the verification by connector server 312 indicates to connector server 312 that connector client 314 is, in fact, connector client 314.

[0073] The process of activity diagram 300 is Figure 3B 356. In activity 356, the connector server 312 resolves the tenant identifier from the token provided by the connector client 314 to the connector server 312 or the token provided by the authentication server 308 to the connector client 314 (recall that the tokens are the same). It will be appreciated that the connector server 312 can resolve any suitable secret from the token. The secret does not have to be the tenant identifier. The activities will be described below with reference to the tenant identifier. It will be appreciated that those activities can be performed for any suitable secret that does not necessarily include the tenant identifier.

[0074] In activity 358 , connector client 314 provides connector server 312 with a network name, which is the name of the private computer network.

[0075] In activity 360 , connector server 312 provides the network name, tenant identifier, and Internet Protocol (IP) address of connector server 312 to database 310 .

[0076] In activity 362, database 310 adds the network name, tenant identifier, and IP address of connector server 312 to a common (i.e., identical) row of database 310. By adding the network name, tenant identifier, and IP address of connector server 312 to the common row of database 310, database 310 cross-references the network name and tenant identifier with the IP address. It will be appreciated that database 310 need not necessarily add the network name, tenant identifier, and IP address of connector server 312 to the common row. For example, database 310 may cross-reference the network name and tenant identifier with the IP address in any suitable manner. For example, database 310 may generate cross-reference information to indicate a relationship between the network name, tenant identifier, and IP address. By indicating the relationship, the cross-reference information may cross-reference the network name and tenant identifier with the IP address.

[0077] In activity 364 , the connector server 312 stores the network name and the tenant identifier in memory (eg, memory of the connector server 312 ).

[0078] In activity 366 , connector client 314 requests a new token from authentication server 308 .

[0079] In activity 368, authentication server 308 provides the new token to connector client 314. For example, authentication server 308 can generate the new token to include a secret associated with connector client 314 (eg, a tenant identifier).

[0080] In activity 370 , connector client 314 provides the new token received from authentication server 308 to connector server 312 .

[0081] In activity 372, connector server 312 provides a verification request to authentication server 308, requesting verification of a new token provided by connector client 314 to connector server 312. For example, the verification request may include the new token provided by connector client 314 to connector server 312.

[0082] In activity 374, authentication server 308 verifies the new token provided by connector client 314 to connector server 312. For example, authentication server 308 may compare the new token provided by connector client 314 to connector server 312 and the new token provided by authentication server 308 to connector client 314 to determine that the tokens are the same.

[0083] In activity 376, authentication server 308 provides connector server 312 with verification of the new token that connector client 314 provided to connector server 312. Receipt of the verification by connector server 312 indicates to connector server 312 that connector client 314 is, in fact, connector client 314.

[0084] In activity 378 , connector server 312 resolves the tenant identifier from either the new token provided by connector client 314 to connector server 312 or the new token provided by authentication server 308 to connector client 314 (recall that the tokens are the same).

[0085] At activity 380, connector server 312 compares the tenant identifier parsed from the new token at activity 378 with the tenant identifier parsed from the token at activity 356 to determine if the tenant identifiers are the same. The tenant identifiers being the same indicates that the connection between connector client 314 and connection server 312 continues to exist (e.g., neither connector client 314 nor connector server 312 has abandoned the connection).

[0086] Activities 366, 368, 370, 372, 374, 376, 378, and 380 represent re-registration processes (also known as refresh processes) that can be iteratively performed on a periodic schedule. For example, connector client 314 can be required to periodically refresh each of its connections (e.g., each connection between connector client 314 and connector server 312) on a periodic schedule to prevent database 310 from deleting the record of the corresponding connection from database 310. Database 310 can establish a lifetime for each connection, that is, unless the connection is refreshed before the end of the specified time period, the connection will be terminated after the specified time period. The specified time period starts at the moment the connection is established, and as long as the connection is refreshed during the previous cycle, the specified time period restarts at the beginning of each subsequent cycle of the periodic schedule. If connector client 314 does not refresh the connection before the end of the specified time period of a cycle, database 310 will delete the record of the connection from database 310, and the connection can no longer be used by connector client 314 and connector server 312. The specified time period associated with each time to live can be any suitable period, such as 5 minutes, 10 minutes, or 23 minutes. Connector client 314 can be configured to refresh the connection on another periodic schedule, the period of which is less than the time period associated with each time to live. For example, connector client 314 can be configured to refresh the connection every 2 minutes, every 3 minutes, every 5 minutes, or every 8 minutes.

[0087] In some example embodiments, one or more of the activities 332, 334, 336, 338, 340, 342, 344, 346, 348, 350, 352, 354, 356, 358, 360, 362, 364, 366, 368, 370, 372, 374, 376, 378, and / or 380 of the activity diagram 300 may not be performed. Furthermore, activities in addition to or in place of the activities 332, 334, 336, 338, 340, 342, 344, 346, 348, 350, 352, 354, 356, 358, 360, 362, 364, 366, 368, 370, 372, 374, 376, 378, and / or 380 may be performed. It will be appreciated that some activities may be combined and / or performed in parallel.

[0088] Figure 4 is an example activity diagram 400 for load balancing resource requests among established connections according to one embodiment. Figure 4 Depicted are computing device 402, connector client 414, connector server 412, authentication server 408, and database 410, which are Figure 1 and Figure 2402; the example implementation of the user device 102 or 202 or the proxy server 228; the connector client 114 or 214; the connector server 112 or 212; the authentication server 108 or 208; and the database 126 or 210 shown in . Activities 432, 434, 436, 438, 440, and 442 will now be described with reference to the computing device 402, the connector client 414, the connector server 412, the authentication server 408, and the database 410.

[0089] In activity 432, computing device 402 requests access to a resource by providing a network name and a tenant identifier. For example, computing device 402 may provide a resource request including a network name and a tenant identifier. The network name is the name of a private computer network, and the tenant identifier identifies the owner of the private computer network.

[0090] In activity 434, database 410 provides the IP address of each corresponding connector server (i.e., each connector server has an IP address corresponding to the network name and the tenant identifier). For example, database 410 can traverse the rows of database 410 to identify each row including the network name and the tenant identifier. According to this example, database 410 can identify the IP address in each row including the network name and the tenant identifier. It can be said that database 410 cross-references the network name and the tenant identifier with the IP address in each row. The IP addresses in these rows correspond to (e.g., identify) the corresponding connector servers that have a connection to the private computer network. Database 410 can provide each of these IP addresses to computing device 402. In another example, database 410 can review cross-reference information that cross-references the network name and the tenant identifier with the IP address of each connector server that has a connection to the private computer network. According to this example, database 410 can review the cross-reference information to identify the IP address of the connector server that has a connection to the private computer network. Database 410 can provide these IP addresses to computing device 402.

[0091] In activity 436, computing device 402 load balances the connection between the private computer network and the public computer network by selecting an IP address from the IP addresses received by computing device 402 from database 410. Computing device 402 may select the IP address based at least in part on a comparison of attributes of a corresponding connector server corresponding to a corresponding IP address received by computing device 402 from database 410. In activity 436, computing device 402 also requests access to a resource by providing a resource request including a network name and a tenant identifier to connector server 412, the resource request corresponding to the selected IP address.

[0092] In activity 438, connector server 412 verifies whether the network name and tenant identifier in the resource request received from computing device 402 matches the network name and tenant identifier in the resource request received from computing device 402. Figure 3B At activity 364 in , the network name and tenant identifier stored in memory are matched.

[0093] In activity 440, connector server 412 load balances resource requests among connector clients in the private computer network by selecting a connector client from among the connector clients based on any of a plurality of factors associated with the connector clients. It will be appreciated that if connector client 414 is the only connector client, then resource requests need not necessarily be load balanced among multiple connector clients. In activity 440, connector server 412 also requests access to a resource by providing a resource request including a network name, a resource identifier identifying the resource, and possibly a tenant identifier to connector client 414.

[0094] In activity 442 , connector client 414 provides computing device 402 with access to a resource based on the network name, resource identifier, and possibly tenant identifier included in the resource request received by connector client 414 from connector server 412 .

[0095] In some example embodiments, one or more activities 432, 434, 436, 438, 440, and / or 442 of activity diagram 400 may not be performed. Furthermore, activities in addition to or in place of activities 432, 434, 436, 438, 440, and / or 442 may be performed. It will be appreciated that some activities may be combined and / or performed in parallel.

[0096] Figure 5 FIG. 5 is a block diagram of another exemplary connection establishment load balancing system 500 according to one embodiment. Figure 5 As shown, the connection establishment load balancing system 500 includes a public computer network 520 and a private computer network 522. The private computer network 522 includes a first connector client 514A and a second connector client 514B, each of which can be connected in a manner similar to Figure 1 The connector clients 114A-114R shown operate in the same manner as any of the connector clients except that Figure 5Each of the connector clients 514A-514B in the public computer network 520 is configured to provide connection requests generated by the corresponding connector client to the registration server load balancer 532, asking which connector server among the connector servers 512A-512B in the public computer network 520 each connection request is to be sent to. The connection requests generated by the first connector client 514A and the second connector client 514B and provided to the registration server load balancer 532 are collectively referred to herein as "combined connector requests."

[0097] The first connector client 514A is assigned to the first connector server 512A. The second connector client 514B is assigned to the second connector server 512B. For example, the first connector client 514A and the second connector client 514B can be assigned to the corresponding first group of connection servers and the second group of connection servers. According to this example, for non-limiting illustrative purposes, the first group includes only the first connector server 512A, and the second group includes only the second connector server 512B. It will be appreciated that each group of connector servers can include any appropriate number of connector servers (e.g., 1, 2, 3, 4, 5 or 6 connector servers). The number of connector servers in each group can be the same or different from the number of connector servers in other groups. The first connector client 514A being assigned to the first connector server 512A can mean that the only connection server to which the first connector client 514A can provide a connection request is the first connector server 512A. The second connector client 514B being assigned to the second connector server 512B can mean that the only connection server to which the second connector client 514B can provide a connection request is the second connector server 512B. Therefore, the first connector client 514A is configured to send a connection request to the first connector server 512A instead of to the second connector server 512B in response to a notification received by the first connector client 514A from the registration server load balancer 532. The second connector client 514B is configured to send a connection request to the second connector server 512B instead of to the first connector server 512A in response to a notification received by the second connector client 514B from the registration server load balancer 532.

[0098] The first connector client 514A receives a first notification from the registration server load balancer 532, instructing the first connector client 514A to provide a first subset of combined connection requests to the first connector server 512A. The second connector client 514B receives a second notification from the registration server load balancer 532, instructing the second connector client 514B to provide a second subset of combined connection requests to the second connector server 512B. It will be appreciated that each connection request in the first subset and each connection request in the second subset may have been generated by any one of the first connector client 514A and the second connector client 514B. Therefore, the first notification may instruct the first connector client 514A to provide one or more of the connection requests generated by the second connector client 514B to the first connector server 512A to facilitate the establishment of one or more corresponding connections between the first connector client 514A and the first connector server 512A. The second notification may instruct the second connector client 514B to provide one or more of the connection requests generated by the first connector client 514A to the second connector server 512B to facilitate the establishment of one or more corresponding connections between the second connector client 514B and the second connector server 512B.

[0099] The public computer network 520 includes a computing device 502, a first connector server 512A and a second connector server 512B, and a registration logic 524. The computing device 502 can be connected in a manner similar to Figure 4 Each of the first connector server 512A and the second connector server 512B can be similar to Figure 1 The registration logic 524 is shown to include a database 510, a plurality of registration servers 530A-530V, and a registration server load balancer 532.

[0100] The database 510 stores the state of each connector server in the connector servers 512A-512B. The state of each connector server indicates the number of connections between the private computer network 522 (e.g., the first connector client 514A or the second connector client 514B in the private computer network 522) and the connector server. By storing the state of each connector server in the connector servers 512A-512B, the database 510 is able to perform stateful load balancing on the connection between the connector clients 514A-514B and the connector servers 512A-512B. For example, the database 510 can be configured to synchronize the registration servers 530A-530V to share a common state, which includes knowledge of the number of connections between the private computer network 522 and each connector server in the connector servers 512A-512B. The database 510 can determine the number of connections between the private computer network 522 and each connector server based on an indication of the number of connections received from the connector server, any registration server in the registration servers 530A-530V, or the registration server load balancer 532.

[0101] exist Figure 5In the embodiment of the present invention, for non-limiting illustrative purposes, the database 510 is shown as receiving connection information 528 from the first connector server 512A. The connection information 528 indicates the number of connections established between the private computer network 522 and the first connector server 512A. The database 510 can receive such connection information from each connection server, which indicates the number of connections between the private computer network 522 and the corresponding connector server. It will be appreciated that such connection information does not necessarily have to be received from each connection server. For example, the database 510 can receive connection information about each connection server from any one or more registration servers or registration server load balancers 532 of registration servers 530A-530V. If the connection information about the connection server is received from the connection server, the connection information can confirm the establishment of the connection; and if the connection information about the connection server is received from one or more registration servers or registration server load balancers 532 in the registration servers 530A-530V, the connection information indicates that the connection is to be established, rather than actually establishing the connection. Thus, if a connection server (or a corresponding connector client) is down after connection information is provided by one or more of registration servers 530A-530V or registration server load balancer 532 but before a connection is established (e.g., by database 510 receiving registration information about a connection from a connection server), database 510 may store an inaccurate calculation of the number of connections between private computer network 522 and the connection server. The registration information used to register the connection may include the name of private computer network 522, a tenant identifier associated with private computer network 522, and / or an IP address of a connector server.

[0102] The registration server load balancer 532 receives the combined connection request from the first connector client 514A and the second connector client 514B, and load balances the combined connection request across the registration servers 530A-530V. For example, the registration server load balancer 532 may attempt to balance the number of connection requests forwarded to each of the registration servers 530A-530V. Therefore, upon receiving a connection request from the first connector client 514A or the second connector client 514B, the registration server load balancer 532 may provide the connection request to the following registration server, the number of connection requests that the registration server load balancer 532 has provided to the registration server is less than or equal to the number of connection requests that the registration server load balancer 532 has provided to each other registration server. Upon receiving a notification from any of the registration servers 530A-530V indicating that the selected connector server has been selected to receive the connection request, the registration server load balancer 532 instructs the connector client assigned to the selected connector server to provide the connection request to the selected connector server, which causes the connector client to provide the connection request to the selected connector server. For example, the registrar load balancer 532 can provide a uniform resource identifier (URI) of the selected connector server to a connector client assigned to the selected connector server, which can enable the connector client to locate the selected connector server. For example, the URI can be a uniform resource locator (URL) or a uniform resource name (URN). According to this example, as a result of the URI being included in the notification, the registrar load balancer 532 can determine the URI.

[0103] The registration servers 530A-530V are configured to determine which connector server (e.g., the first connector server 512A or the second connector server 512B) is to receive each connection request received by the registration logic 524 from the private computer network 522 (e.g., the first connector server 514A or the second connector server 514B in the private computer network 522). After receiving the connection request from the registration server load balancer 532, the registration server queries the database 510 to determine the number of connections between the private computer network 522 and each of the connection servers 512A-512B. If the number of connections between the private computer network 522 and the first connection server 512A is less than the number of connections between the private computer network 522 and the second connection server 512B, the registration server selects the first connection server 512A to receive the connection request. If the number of connections between the private computer network 522 and the first connection server 512A is greater than the number of connections between the private computer network 522 and the second connector server 512B, the registration server selects the second connection server 512B to receive the connection request. If the number of connections between the private computer network 522 and the first connection server 512A is the same as the number of connections between the private computer network 522 and the second connector server 512B, the registration server may select any one of the first connection server 512A and the second connection server 512B to receive the connection request. The registration server notifies the registration server load balancer 532 of the selected connector server that the registration server has selected to receive the connection request. For example, the registration server may provide the registration server load balancer 532 with the URI of the selected connector server.

[0104] For non-limiting illustrative purposes, private computer network 522 is shown as including two connector clients. It will be appreciated that private computer network 522 may include any suitable number (e.g., 2, 3, or 4) of connector clients. For non-limiting illustrative purposes, public computer network 520 is shown as including two connector servers. It will be appreciated that public computer network 520 may include any suitable number (e.g., 2, 3, or 4) of connector servers.

[0105] Figure 6 is a block diagram of another exemplary connection establishment load balancing system 600 according to one embodiment. Figure 6 The connection establishment load balancing system 600 is basically the same as Figure 5The connection establishment load balancing system 500 shown in FIG. 5 is the same as the connection establishment load balancing system 500 shown in FIG. 5 , except that the connection establishment load balancing system 600 includes a first connector server load balancer 636A and a second connector server load balancer 636B, and a first group 634A and a second group 634B of connector servers, instead of a first connector server 512A and a second connector server 512B.

[0106] like Figure 6 As shown, the connection establishment load balancing system 600 includes a public computer network 620 and a private computer network 622. The private computer network 622 includes a first connector client 614A and a second connector client 614B, which can communicate with each other in a manner similar to that of FIG. Figure 5 614A and the second connector client 514B shown in FIG. 614B operate in a similar manner. For example, each of the connector clients 614A-614B is configured to provide connection requests generated by the corresponding connector client to the registration server load balancer 532, asking which group of the groups 634A-634B in the public computer network 520 each connection request is to be sent to. The connection requests generated by the first connector client 614A and the second connector client 614B and provided to the registration server load balancer 532 are collectively referred to herein as "combined connector requests."

[0107] The first connector client 614A is assigned to the first group 634A. The second connector client 614B is assigned to the second group 634B. The first connector client 614A being assigned to the first group 634A may mean that the only group of connector servers to which the first connector client 614A can provide connection requests is the first group 634A. The second connector client 614B being assigned to the second group 634B may mean that the only group of connection servers to which the second connector client 614B can provide connection requests is the second group 634B. Therefore, the first connector client 614A is configured to: in response to the notification received by the first connector client 614A from the registration server load balancer 632, send the connection request to the first group 634A instead of to the second group 634B. The second connector client 614B is configured to: in response to the notification received by the second connector client 614B from the registration server load balancer 632, send the connection request to the second group 634B instead of to the first group 634A.

[0108] The first connector client 614A receives a first notification from the registration server load balancer 632, which instructs the first connector client 614A to provide a first subset of combined connection requests to the first group 634A (e.g., via the first connector server load balancer 636A coupled between the first connector client 614A and the first group 634A). The second connector client 614B receives a second notification from the registration server load balancer 632, which instructs the second connector client 614B to provide a second subset of combined connection requests to the second group 634B (e.g., via the second connector server load balancer 636B coupled between the second connector client 614B and the second group 634B). It will be appreciated that each connection request in the first subset and each connection request in the second subset can be generated by either of the first connector client 614A and the second connector client 514B. Thus, the first notification may instruct the first connector client 614A to provide one or more of the connection requests generated by the second connector client 614B to the first group 634A to facilitate the establishment of one or more corresponding connections between the first connector client 614A and the first group 634A (e.g., any of the connector servers in the first group 634A). The second notification may instruct the second connector client 614B to provide one or more of the connection requests generated by the first connector client 614A to the second group 634B to facilitate the establishment of one or more corresponding connections between the second connector client 614B and the second group 634B (e.g., any of the connector servers in the second group 634B).

[0109] The public computer network 620 includes a computing device 602, a first group 634A and a second group 634B of connector servers, a registration logic 624, and a first connector server load balancer 636A and a second connector server load balancer 636B. The computing device 602 can be configured to communicate with the server in a manner similar to Figure 5634B. The computing device 602 may be operated in a manner similar to that of the computing device 502 shown in FIG. The computing device 602 may be irrelevant to the group 634A-634B. Therefore, the resource request provided by the computing device 602 may be routed to any suitable connector server, regardless of which group the connector server is assigned to for the purpose of establishing a connection between the private computer network 622 and the public computer network 620. For example, the group 634A-634B may be used to facilitate the establishment of a connection between the private computer network 622 and the public computer network 620, rather than facilitating the routing of resource requests after the connection is established. The first group 634A of the connection server includes the first connector server 612A and the second connector server 612B. The second group 634B of the connection server includes the third connector server 612C and the fourth connector server 612D. For non-limiting illustrative purposes, each group in the first group 634A and the second group 634B is shown as including two connector servers. It will be appreciated that each group in the first group 634A and the second group 634B may include any suitable number of (e.g., 2, 3 or 4) connector servers. Each of the connector servers 612A-612D may be configured similarly to Figure 5 , and operates in the manner of any one of the first connector server 514A and the second connector server 514B shown in FIG.

[0110] The first connector server load balancer 636A is assigned to a first group 634A of connector servers. The first connector server load balancer 636A is configured to determine which of the first connector servers 612A and the second connector servers 612B in the first group 634A is to receive each connection request received from the first connector client 614A, depending on how many connection requests the first connection server load balancer 636A has provided to each of the first connection servers 612A and the second connection servers 612B. The first connector server load balancer 636A provides each connection request to a connector server that has received no more connection requests from the first connector server load balancer 636A than any other connector server in the group 634A. Figure 6In an embodiment, if the first connector server load balancer 636A provides more connection requests to the first connector server 612A than to the second connector server 612B, the first connector server load balancer 636A provides the corresponding connection requests to the second connector server 612B. If the first connector server load balancer 636A provides fewer connection requests to the first connector server 612A than to the second connector server 612B, the first connector server load balancer 636A provides the corresponding connection requests to the first connector server 612A. If the first connector server load balancer 636A provides the same number of connection requests to the first connector server 612A and the second connector server 612B, the first connector server load balancer 636A may provide the corresponding connection requests to either the first connector server 612A or the second connector server 612B.

[0111] The second connector server load balancer 636B is assigned to the second group 634B of connector servers. The second connector server load balancer 636B is configured to determine which of the third connector server 612C and the fourth connector server 612D in the second group 634B is to receive each connection request received from the second connector client 614B, depending on how many connection requests the second connection server load balancer 636B has provided to each of the third connection server 612C and the fourth connection server 612D. The second connector server load balancer 636B provides each connection request to a connector server that receives no more connection requests from the second connector server load balancer 636B than any other connector server in the group 634B. Figure 6 In an embodiment of the present invention, if the second connector server load balancer 636B provides more connection requests to the third connector server 612C than to the fourth connector server 612D, the second connector server load balancer 636B provides the corresponding connection requests to the fourth connector server 612D. If the second connector server load balancer 636B provides fewer connection requests to the third connector server 612C than to the fourth connector server 612D, the second connector server load balancer 636B provides the corresponding connection requests to the third connector server 612C. If the second connector server load balancer 636B provides the same number of connection requests to the third connector server 612C and the fourth connector server 612D, the second connector server load balancer 636B may provide the corresponding connection requests to any one of the third connector server 612C and the fourth connector server 612D.

[0112] Registration logic 624 can be similar to Figure 5 634A-634B。The registration logic 624 is shown to include a database 610, a plurality of registration servers 630A-630V and a registration server load balancer 632。The database 610 stores the state of each group in the group 634A-634B of the connector server。The state of each group indicates the number of connections between the private computer network 622 (e.g., the first connector client 614A or the second connector client 614B in the private computer network 622) and the group (e.g., any connector server in the group).By storing the state of each group in the group 634A-634B, the database 610 is able to establish a stateful load balancing of the connection between the connector client 614A-614B and the group 634A-634B。For example, the database 610 can be configured to synchronize the registration servers 630A-630V to share a common state, which includes knowledge of the number of connections between the private computer network 622 and each group in the group 634A-634B。 The database 610 may determine the number of connections between the private computer network 622 and each group based on notifications received from the connector servers in the group. Each notification received from the connector server indicates that one or more connections are established between the private computer network 622 and the connection server. For example, each notification may indicate that a corresponding connection is established. In one example implementation, the database 610 counts the number of notifications received from the connector servers in each group to determine the number of connections between the private computer network 622 and the corresponding group (e.g., based on the number of connections between the private computer network 622 and the group being equal to the number of notifications received from the connector servers in the group). In another embodiment, the database 610 counts (e.g., sums) the number of connections indicated by the corresponding notifications received from the connection servers in each group to determine the number of connections between the private computer network 622 and the corresponding group.

[0113] exist Figure 6In the embodiment of , for non-limiting illustrative purposes, the database 610 is shown as receiving connection information 628 from the first group 634A. The connection information 628 indicates the number of connections established between the private computer network 622 and the first group 634A (e.g., the first connector server 612A or the second connector server 612B in the first group 634A). The database 610 can receive such connection information from each group, which indicates the number of connections between the private computer network 622 and the corresponding group. It will be appreciated that such connection information does not necessarily have to be received from each group. For example, the database 610 can receive connection information about each group from any one or more of the registration servers 630A-630V, the registration server load balancer 632, or any one or more of the connector server load balancers 636A-636B. If connection information about the group is received from a group, the connection information may confirm that the connection indicated by the connection information is established; while if connection information about the group is received from one or more of the registration servers 630A-630V, the registration server load balancer 632, or one or more of the connector server load balancers 636A-636B, the connection information indicates that the connection indicated by the connection information will be established, rather than actually establishing the connection. Therefore, if the group associated with the connection or the connector server (or corresponding connector client) in the group is down after the connection information is provided by one or more of the registration servers 630A-630V, the registration server load balancer 632, or one or more of the connector server load balancers 636A-636B but before the connection is established (for example, the database 610 receives registration information about the connection from the connection server), the database 610 may store an inaccurate calculation of the number of connections between the private computer network 622 and the group.

[0114] The registration server load balancer 632 receives connection requests from the first connector client 614A and the second connector client 614B and load balances the connection requests across the registration servers 630A-630V, as described above with respect to Figure 5As described by the registration server load balancer 532 of the registration server. Upon receiving a notification from any of the registration servers 630A-630V indicating that a selected group of connection servers has been selected to receive a connection request, the registration server load balancer 632 instructs the connector client assigned to the selected group to provide the connection request to the selected group, which causes the connector client to provide the connection request to the selected group (e.g., through the connector server load balancer assigned to the selected group). For example, the registration server load balancer 632 can provide the connector client assigned to the selected group with a uniform resource identifier (URI) of the connector server load balancer assigned to the selected group, which can enable the connector client to locate the connector server load balancer. For example, the URI can be a uniform resource locator (URL) or a uniform resource name (URN). According to this example, as a result of the URI being included in the notification, the registration server load balancer 632 can determine the URI.

[0115] The registration servers 630A-630V are configured to distribute the connector servers 612A-612D between the first group 634A and the second group 634B. Figure 6 In the embodiment of the present invention, the registration servers 630A-630V assign the first connector server 612A and the second connector server 612B to the first group 634A, which is associated with the first connector server load balancer 636A and the first connector client 614A. The registration servers 630A-630V assign the third connector server 612C and the fourth connector server 612D to the second group 634B, which is associated with the second connector server load balancer 636B and the second connector client 614B. The registration servers 630A-630V may be further configured to assign the first connector server load balancer 636A and the second connector server load balancer 636B to the respective groups 634A-634B such that the first connector server load balancer 636A is configured to provide connection requests to the first group 634A instead of to the second group 634B, and such that the second connector server load balancer 636B is configured to provide connection requests to the second group 634B instead of to the first group 634A.

[0116] The registration servers 630A-630V are further configured to determine which group of connection servers (e.g., the first group 634A or the second group 634B) is to receive each connection request received by the registration logic 624 from the private computer network 622 (e.g., the first connector server 614A or the second connector server 614B in the private computer network 622). After receiving the connection request from the registration server load balancer 632, the registration server queries the database 610 to determine the number of connections between the private computer network 622 and each of the groups 634A-634B. If the number of connections between the private computer network 622 and the first group 634A is less than the number of connections between the private computer network 622 and the second group 634B, the registration server selects the first group 634A to receive the connection request. If the number of connections between the private computer network 622 and the first group 634A is greater than the number of connections between the private computer network 622 and the second group 634B, the registration server selects the second group 634B to receive the connection request. If the number of connections between the private computer network 622 and the first group 634A is the same as the number of connections between the private computer network 622 and the second group 634B, the registration server may select any one of the first group 634A and the second group 634B to receive the connection request. The registration server notifies the registration server load balancer 632 of the selected group, which the registration server has selected to receive the connection request. For example, the registration server may provide the registration server load balancer 632 with the URI of the connector server load balancer assigned to the selected group.

[0117] For purposes of non-limiting illustration, private computer network 622 is shown as including two connector clients. It will be appreciated that private computer network 622 may include any suitable number (e.g., 2, 3, or 4) of connector clients. For purposes of non-limiting illustration, public computer network 620 is shown as including two groups 634A-634B of connector servers. It will be appreciated that public computer network 620 may include any suitable number (e.g., 2, 3, or 4) of groups of connector servers.

[0118] Figure 7 A flowchart 700 of an example method for load balancing connection establishment according to one embodiment is described. Flowchart 700 may be provided by, for example, a corresponding Figure 1 to Figure 2 , FIG. 3A to FIG. 3B and Figures 5 and 6 124, 224, 324, 524, and 624 shown in the flowchart 700. For the purpose of illustration, the flowchart 700 is about Figure 8700. The registration logic 800 may be an example implementation of any one of the registration logics 124, 224, 324, 524, and 624. The registration logic 800 includes an allocation logic 802, a determination logic 804, a selection logic 806, a provision logic 808, and a memory 810. Based on the discussion regarding the flowchart 700, additional structural embodiments and operational embodiments will be apparent to those skilled in the relevant art.

[0119] like Figure 7 As shown, the method of flowchart 700 starts at step 702. In step 702, connector servers included in a public computer network are allocated between groups. Each group includes one or more connector servers. In an example implementation, allocation logic 802 allocates connector servers between groups. According to the implementation, allocation logic 802 can generate allocation information that indicates (e.g., specifies) which connector servers are allocated to each of the multiple groups. For example, allocation information 816 can indicate: a first subset of connector servers is allocated to a first group, a second subset of connector servers is allocated to a second group, and so on. According to this example, each of the multiple groups includes one or more connector servers in the connector server. The groups can be mutually exclusive so that no group includes a connector server included in another group.

[0120] In step 704, a connection request is received from a connector client included in a private computer network. The connection request requests to establish a connection between the connector client and one of the connector servers in the public computer network. The public computer network is external to the private computer network. For example, the connector request can distinguish the private computer network from (multiple) other computer networks. According to this example, the connector request may include a network identifier that uniquely identifies the private computer network. The network identifier may include a name of the private computer network and / or a tenant identifier that identifies the owner of the private computer network. In an example implementation, the determination logic 804 receives a connection request 814 from the connector client. According to the implementation, the connection request 814 requests to establish a connection.

[0121] At step 706, the number of connections between the private computer network and each group is determined. In one example implementation, determination logic 804 determines the number of connections between the private computer network and each group. For example, determination logic 804 may make the determination based on assignment information 816 (e.g., based on assignment information 816 indicating which of the connector servers are assigned to each of the plurality of groups). Depending on the implementation, determination logic 804 may generate number information 818 indicating the number of connections between the private computer network and each group.

[0122] In step 708, the identified group is selected from the group to receive the connection request, based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group. In an example implementation, selection logic 806 selects the identified group from the group. For example, selection logic 806 may select the identified group based on number information 818. According to this example, selection logic 806 may review (e.g., analyze) number information to determine the number of connections between the private computer network and each group. Also according to this example, selection logic 806 may compare the number of connections between the private computer network and each group to determine that the number of connections between the private computer network and the identified group is less than or equal to the number of connections between the private computer network and each other group. Also according to this implementation, selection logic 806 may select the identified group based on this determination. According to this implementation, selection logic 806 may generate a group flag 820 indicating that the identified group has been selected from the group to receive the connection request 814.

[0123] At step 710, a connection request is provided to the identified group, which enables (e.g., causes) establishment of a connection between the connector client and a connector server in the identified group (e.g., rather than a connector server in another group) based at least in part on the identified group being selected from the group. In one example implementation, the providing logic 808 may provide the connection request 814 to the identified group. For example, the providing logic 808 may provide the connection request 814 to the identified group based on the group flag 820 (e.g., based on the group flag 820 indicating that the identified group has been selected from the group to receive the connection request 814). For example, the providing logic 808 may provide the connection request 814 directly to the identified group. In another example, the providing logic 808 may provide the connection request 814 indirectly to the identified group (e.g., through one or more other components, such as a registration server load balancer, a connector client, and / or a connector server load balancer).

[0124] In an example embodiment, providing the connection request at step 710 causes the connector client to provide the connection request to the identified group. For example, the connector request can be provided to the connector client, which then forwards the connection request to the identified group (e.g., directly or indirectly through another component, such as a connector server load balancer). According to this example, providing the connection request to the connector client can cause the connector client to provide the connection request to the connector server load balancer to cause the connector server load balancer to select one of the multiple connector servers in the identified group to receive the connection request (e.g., based on the number of connections processed by the selected connection server being less than or equal to the number of connections processed by each other connection server in the identified group).

[0125] In another example embodiment, determining the number of connections between the private computer network and each group at step 706 includes providing a plurality of inquiries to a corresponding connector server load balancer. Each of the connector server load balancers is configured to load balance connections between connector servers in the group to which the corresponding connector server load balancer is assigned. Each inquiry requests the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned. According to this embodiment, determining the number of connections between the private computer network and each group at step 706 also includes receiving a response to the corresponding inquiry from the corresponding connector server load balancer. Each response indicates the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned. Also according to this embodiment, providing a connection request at step 710 may include providing a connection request to a connector server load balancer assigned to the identified group, which enables the connector server load balancer to select one of the plurality of connector servers in the identified group to receive the connection request (e.g., based on the number of connections processed by the selected connection server being less than or equal to the number of connections processed by each other connection server in the identified group).

[0126] In some example embodiments, one or more steps 702, 704, 706, 708, and / or 710 of flowchart 700 may not be performed. In addition, steps in addition to or in place of steps 702, 704, 706, 708, and / or 710 may be performed. For example, in an example embodiment, the method of flowchart 700 further includes: storing the number of connections between the private computer network and each group in a memory of a registration server, which allocates connector servers between the groups (e.g., based on the registration server being the only registration server in the registration logic). For example, memory 810 may store the number of connections between the private computer network and each group. According to this embodiment, determining the number of connections between the private computer network and each group in step 706 includes: retrieving the number of connections between the private computer network and each group from the memory of the registration server. For example, determination logic 804 may retrieve the number of connections between the private computer network and each group from memory 810.

[0127] In another example embodiment, determining the number of connections between the private computer network and each group at step 706 includes providing a query to a database configured to synchronize multiple registration servers to share a common state. The common state includes knowledge of the number of connections between the private computer network and each group. According to this embodiment, determining the number of connections between the private computer network and each group at step 706 also includes receiving a response to the query from the database. The response indicates the number of connections between the private computer network and each group.

[0128] In a first aspect of this embodiment, the common state includes knowledge of the number of connections between the private computer network and each group based at least in part on connection notifications provided to the database by each connector server each time a connection is established between the private computer network and the corresponding connector server.

[0129] In a second aspect of this embodiment, the common state includes knowledge of the number of connections between the private computer network and each group based at least in part on connection notifications provided to the database by each registration server each time the corresponding registration server provides a connection request to establish a connection to the group.

[0130] In a third aspect of this embodiment, the common state includes knowledge of a number of connections between the private computer network and each group based at least in part on a connection notification provided to a database by each of the plurality of connector server load balancers each time the corresponding connector server load balancer provides to the group a connection request received from a connector client and requesting establishment of a connection. Each connector server load balancer load balances the connections between the connector servers in the group to which the corresponding connector server load balancer is assigned.

[0131] In a fourth aspect of this embodiment, the method of flowchart 700 also includes: providing a confirmation notification to the database for each periodic time instance for each connection in a plurality of periodic time instances, and the connector client and the connector server remain connected via the corresponding connection in the corresponding periodic time instance. Each confirmation notification confirms that the corresponding connector client and the corresponding connector server remain connected via the corresponding connection in the corresponding periodic time instance. For example, providing logic 808 can provide a confirmation notification to the database for each periodic time instance for each connection in a plurality of periodic time instances, and the connector client and the connector server remain connected via the corresponding connection in the corresponding periodic time instance in the periodic time instance. According to this aspect, the number of connections between the private computer network and each group does not take into account each of the following connections between the private computer network and the corresponding group, for which no confirmation notification is provided within a specified duration greater than the time period between adjacent periodic time instances. For example, the time period can be defined by adjacent periodic time instances.

[0132] It will be appreciated that the registration logic 800 may not include one or more of the allocation logic 802, the determination logic 804, the selection logic 806, the provision logic 808, and / or the memory 810. Furthermore, the registration logic 800 may include components in addition to or in place of the allocation logic 802, the determination logic 804, the selection logic 806, the provision logic 808, and / or the memory 810.

[0133] Although some operations in the disclosed methods are described in a specific, sequential order for ease of presentation, it should be understood that this description includes rearrangement unless a specific order is required by specific language specified herein. For example, operations described in sequence may be rearranged or performed simultaneously in some cases. In addition, for simplicity, the accompanying drawings may not show various ways in which the disclosed methods can be used in combination with other methods.

[0134] Any one or more of connector clients 114A-114R, any one or more of resources 116A-116T, browser 110, client-side connection load balancing logic 118A, server-side connection load balancing logic 118B, registration logic 124, database 126, any one or more of connector clients 214A-214R, any one or more of resources 216A-216T, proxy-side connection load balancing logic 218C, server-side connection load balancing logic 218B, registration logic 224, database 226, connector client 314, registration logic 324, database 310, connector client 414, database 410, any one or more of connector clients 514A-514B, registration logic 524, database 510, registration server load balancer 532, any one or more of connector clients 614A-614B, registration logic 624, database 610, registration server load balancer 632, allocation logic 802, determination logic 804, selection logic 806, provision logic 808, activity diagram 300, activity diagram 400 and / or flowchart 700 can be implemented in hardware, software, firmware or any combination thereof.

[0135] For example, any one or more of connector clients 114A-114R, any one or more of resources 116A-116T, browser 110, client-side connection load balancing logic 118A, server-side connection load balancing logic 118B, registration logic 124, database 126, any one or more of connector clients 214A-214R, any one or more of resources 216A-216T, proxy-side connection load balancing logic 218C, server-side connection load balancing logic 218B, registration logic 224, database 226, connector client 314, registration logic 324, database 310, connector client 414, database 410, any one or more of connector clients 514A-514B, registration logic 524, database 510, registration server load balancer 532, any one or more of connector clients 614A-614B, registration logic 624, database 610, registration server load balancer 632, allocation logic 802, determination logic 804, selection logic 806, provision logic 808, activity diagram 300, activity diagram 400 and / or flowchart 700 can be implemented at least in part as computer program code configured to be executed in one or more processors.

[0136] In another example, any one or more of the connector clients 114A-114R, any one or more of the resources 116A-116T, the browser 110, the client-side connection load balancing logic 118A, the server-side connection load balancing logic 118B, the registration logic 124, the database 126, any one or more of the connector clients 214A-214R, any one or more of the resources 216A-216T, the proxy-side connection load balancing logic 218C, the server-side connection load balancing logic 218B, the registration logic 224, the database 226, the connector client 314, the registration logic The registration logic 324, the database 310, the connector client 414, the database 410, any one or more of the connector clients 514A-514B, the registration logic 524, the database 510, the registration server load balancer 532, any one or more of the connector clients 614A-614B, the registration logic 624, the database 610, the registration server load balancer 632, the allocation logic 802, the determination logic 804, the selection logic 806, the provision logic 808, the activity diagram 300, the activity diagram 400 and / or the flowchart 700 can be implemented at least in part as a hardware logic / electrical circuit device. Such a hardware logic / electrical circuit device may include one or more hardware logic components. Examples of hardware logic components include, but are not limited to, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on chip (SoCs), complex programmable logic devices (CPLDs), etc. For example, a SoC may include an integrated circuit chip that includes one or more processors (e.g., a microcontroller, a microprocessor, a digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or additional circuits, and / or embedded firmware to perform its functions.

[0137] III. Further Discussion of Some Example Embodiments

[0138] An example system includes a memory and one or more processors coupled to the memory. The one or more processors are configured to load balance the establishment of multiple connections between multiple groups by performing operations, each group including one or more connector servers in a plurality of connector servers included in a public computer network. The operations include: receiving a connection request from a connector client included in a private computer network. The connection request requests to establish a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network. The operations further include: determining the number of connections between the private computer network and each group. The operations further include: selecting an identified group from the plurality of groups to receive the connection request, based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group. The operations further include: providing a connection request to the identified group, which implements the establishment of a connection between the connector client and the connector servers in the identified group based at least in part on the identified group being selected from the plurality of groups.

[0139] In a first aspect of an example system, one or more processors are configured to perform operations including providing a connection request to a connector client, which causes the connector client to provide the connection request to an identified group.

[0140] In a second aspect of the example system, one or more processors are configured to determine the number of connections between the private computer network and each group by performing the following items: providing a plurality of queries to a plurality of corresponding connector server load balancers, each of the plurality of corresponding connector server load balancers being configured to: load balance connections between connector servers in the group to which the corresponding connector server load balancer is assigned, each query requesting the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned; and receiving a plurality of responses to the corresponding plurality of queries from the plurality of corresponding connector server load balancers, each response indicating the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned. The second aspect of the example system can be implemented in combination with the first aspect of the example system, although the example embodiments are not limited in this respect.

[0141] In an embodiment of the second aspect of the example system, one or more processors are configured to perform operations including providing a connection request to a connector server load balancer assigned to an identified group, which enables the connector server load balancer to select one of a plurality of connector servers in the identified group to receive the connection request.

[0142] In a third aspect of the example system, the one or more processors are configured to perform operations including: storing the number of connections between the private computer network and each group in a memory of a registration server, the registration server selecting the identified group from a plurality of groups; and determining the number of connections between the private computer network and each group by retrieving the number of connections between the private computer network and each group from the memory of the registration server. The third aspect of the example system may be implemented in conjunction with the first and / or second aspect of the example system, although the example embodiments are not limited in this respect.

[0143] In a fourth aspect of the example system, the one or more processors are configured to determine the number of connections between the private computer network and each group by performing the following: providing a query to a database, the database configured to synchronize multiple registration servers to share a common state, the common state including knowledge of the number of connections between the private computer network and each group; and receiving a response to the query from the database, the response indicating the number of connections between the private computer network and each group. The fourth aspect of the example system can be implemented in conjunction with the first, second, and / or third aspects of the example system, although the example embodiments are not limited in this respect.

[0144] In a first implementation of the fourth aspect of the example system, knowledge of the number of connections between the private computer network and each group is based at least in part on transmission of a connection notification by each connector server to a database each time a connection is established between the private computer network and the corresponding connector server.

[0145] In a second implementation of the fourth aspect of the example system, knowledge of the number of connections between the private computer network and each group is based at least in part on transmission of a connection notification to a database by each registration server each time the corresponding registration server provides a connection request to establish a connection to one of the plurality of groups.

[0146] In a third implementation of the fourth aspect of the example system, knowledge of the number of connections between the private computer network and each group is based at least in part on transmission of a connection notification to a database by each of the plurality of connector server load balancers each time the corresponding connector server load balancer provides a connection request received from a connector client and requesting to establish a connection to one of the plurality of groups, wherein each connector server load balancer load balances the connections between the connector servers in the group to which the corresponding connector server load balancer is assigned.

[0147] In a fourth implementation of the fourth aspect of the example system, one or more processors are configured to perform operations, the operations also including: providing a confirmation notification to a database for each periodic time instance for each connection in a plurality of periodic time instances, during which the connector client and the connector server remain connected via the corresponding connection at the corresponding periodic time instance. Each confirmation notification confirms that the corresponding connector client and the corresponding connector server remain connected via the corresponding connection at the corresponding periodic time instance. According to the fourth implementation, the number of connections between the private computer network and each group does not take into account each of the following connections between the private computer network and the corresponding group, for which no confirmation notification is provided within a specified duration, and the specified duration is greater than a time period between adjacent periodic time instances in the plurality of periodic time instances.

[0148] In a fifth aspect of the example system, the connection request includes a network identifier that uniquely identifies the private computer network.The fifth aspect of the example system may be implemented in conjunction with the first, second, third, and / or fourth aspects of the example system, although the example embodiments are not limited in this respect.

[0149] In one implementation of the fifth aspect of the example system, the network identifier includes a name of the private computer network and a tenant identifier identifying an owner of the private computer network.

[0150] In an example method for load balancing connection establishment, a plurality of connector servers included in a public computer network are allocated among a plurality of groups. Each group includes one or more connector servers from the plurality of connector servers. A connection request is received from a connector client included in a private computer network. The connection request requests establishment of a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network. The number of connections between the private computer network and each group is determined. Based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group, an identified group is selected from the plurality of groups to receive the connection request. A connection request is provided to the identified group, which implements establishment of a connection between the connector client and the connector servers in the identified group based at least in part on the selection of the identified group from the plurality of groups.

[0151] In a first aspect of the example method, providing a connection request includes providing the connection request to a connector client, which causes the connector client to provide the connection request to the identified group.

[0152] In a second aspect of the example method, determining the number of connections between the private computer network and each group includes: providing multiple queries to a plurality of corresponding connector server load balancers, each of the plurality of corresponding connector server load balancers being configured to: load balance connections between connector servers in the group to which the corresponding connector server load balancer is assigned. Each query requests the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned. According to the second aspect, determining the number of connections between the private computer network and each group also includes: receiving multiple responses to the corresponding multiple queries from the plurality of corresponding connector server load balancers. Each response indicates the number of connections between the private computer network and the group to which the corresponding connector server load balancer is assigned. The second aspect of the example method may be implemented in conjunction with the first aspect of the example method, although the example embodiments are not limited in this respect.

[0153] In one implementation of the second aspect of the example method, providing a connection request includes providing the connection request to a connector server load balancer assigned to the identified group, enabling the connector server load balancer to select one of a plurality of connector servers in the identified group to receive the connection request.

[0154] In a third aspect of the example method, the example method further includes: storing the number of connections between the private computer network and each group in a memory of a registration server, the registration server allocating a plurality of connector servers among the plurality of groups. According to the third aspect, determining the number of connections between the private computer network and each group includes: retrieving the number of connections between the private computer network and each group from the memory of the registration server. The third aspect of the example method may be implemented in conjunction with the first and / or second aspect of the example method, although the example embodiments are not limited in this respect.

[0155] In a fourth aspect of the example method, determining the number of connections between the private computer network and each group includes providing a query to a database configured to synchronize a plurality of registration servers to share a common state, the common state including knowledge of the number of connections between the private computer network and each group. According to the fourth aspect, determining the number of connections between the private computer network and each group further includes receiving a response to the query from the database, the response indicating the number of connections between the private computer network and each group. The fourth aspect of the example method may be implemented in conjunction with the first, second, and / or third aspect of the example method, although the example embodiments are not limited in this respect.

[0156] In a first implementation of the fourth aspect of the example method, the common state includes knowledge of the number of connections between the private computer network and each group based at least in part on connection notifications provided to the database by each connector server each time a connection is established between the private computer network and the corresponding connector server.

[0157] In a second implementation of the fourth aspect of the example method, the common state includes: knowledge of the number of connections between the private computer network and each group based at least in part on a connection notification provided to the database by each registration server each time the corresponding registration server provides a connection request to establish a connection to one of the multiple groups.

[0158] In a third implementation of the fourth aspect of the example method, the common state includes: knowledge of the number of connections between the private computer network and each group based at least in part on a connection notification provided to a database by each of the multiple connector server load balancers each time the corresponding connector server load balancer provides a connection request received from a connector client and requesting to establish a connection to one of the multiple groups, wherein each connector server load balancer load balances the connections between the connector servers in the group to which the corresponding connector server load balancer is assigned.

[0159] In a fourth embodiment of the fourth aspect of the example method, the example method further comprises: providing a confirmation notification to a database at each periodic time instance for each connection in a plurality of periodic time instances, during which the connector client and the connector server remain connected via the corresponding connection at the corresponding periodic time instance. Each confirmation notification confirms that the corresponding connector client and the corresponding connector server remain connected via the corresponding connection at the corresponding periodic time instance. According to the fourth aspect, the number of connections between the private computer network and each group does not take into account each of the following connections between the private computer network and the corresponding group, for which no confirmation notification is provided within a specified duration, the specified duration being greater than a time period between adjacent periodic time instances in the plurality of periodic time instances.

[0160] In a fifth aspect of the example method, the connection request includes a network identifier that uniquely identifies the private computer network.The fifth aspect of the example method may be implemented in conjunction with the first, second, third, and / or fourth aspect of the example method, although the example embodiments are not limited in this respect.

[0161] In one implementation of the fifth aspect of the example method, the network identifier includes a name of the private computer network and a tenant identifier identifying an owner of the private computer network.

[0162] An example computer program product includes a computer-readable storage medium having instructions recorded thereon, the instructions for causing a processor-based system to perform operations. The operations include load balancing the establishment of multiple connections between multiple groups, each group including one or more connector servers from a plurality of connector servers included in a public computer network by performing the following items: receiving a connection request from a connector client included in a private computer network, the connection request requesting the establishment of a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network; determining the number of connections between the private computer network and each group; selecting an identified group from the plurality of groups to receive the connection request based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group; and providing the connection request to the identified group, which implements the establishment of a connection between the connector client and the connector servers in the identified group based at least in part on the identified group being selected from the plurality of groups.

[0163] IV. Example Computer System

[0164] Fig. 9 An example computer 900 is depicted in which embodiments may be implemented. Figure 1 Any one or more of the user devices 102A-102M, any one or more of the network servers 106A-106N, the authentication server 108, any one or more of the connector servers 112A-112P, any one or more of the connector clients 114A-114R, any one or more of the resources 116A-116T, and / or the registration logic 124 shown in FIG. Figure 2 3 ; any one or more of the user devices 202A-202M, any one or more of the network servers 206A-206N, the authentication server 208, any one or more of the connector servers 212A-212P, any one or more of the connector clients 214A-214R, any one or more of the resources 216A-216T, the registration logic 224, and / or the proxy server 228 shown in FIG. 3 ; the connector client 314, the registration logic 324, the connector server 312, the authentication server 308, and / or the database 310 shown in FIG. 3 ; Figure 4 The computing device 402, connector client 414, connector server 412, authentication server 408 and / or database 410 shown in; Figure 5, computing device 502, any one or more of connector servers 512A-512B, any one or more of connector clients 514A-514B, database 510, any one or more of registration servers 530A-530V, and / or registration server load balancer 532 shown in ; Figure 6 , any one or more of connector servers 612A-612D, any one or more of connector clients 614A-614B, database 610, any one or more of registration servers 630A-630V, and / or registration server load balancer 632; and / or Figure 8 The registration logic 800 shown in the can be implemented using a computer 900, including one or more features and / or alternative features of the computer 900. The computer 900 can be a general-purpose computing device in the form of, for example, a conventional personal computer, a mobile computer, or a workstation, or the computer 900 can be a special-purpose computing device. The description of the computer 900 provided herein is for illustrative purposes and is not intended to be limiting. The embodiments can be implemented in more types of computer systems, as known to those skilled in the relevant art.

[0165] like Fig. 9 As shown, the computer 900 includes a processing unit 902, a system memory 904, and a bus 906 that couples various system components including the system memory 904 to the processing unit 902. The bus 906 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. The system memory 904 includes a read-only memory (ROM) 908 and a random access memory (RAM) 910. A basic input / output system 912 (BIOS) is stored in the ROM 908.

[0166] The computer 900 also has one or more of the following drives: a hard disk drive 914 for reading from and writing to a hard disk, a disk drive 916 for reading or writing from a removable disk 918, and an optical drive 920 for reading or writing from a removable optical disk 922, such as a CDROM, DVDROM, or other optical media. The hard disk drive 914, the disk drive 916, and the optical drive 920 are connected to the bus 906 via a hard disk drive interface 924, a disk drive interface 926, and an optical drive interface 928, respectively. These drives and their associated computer-readable storage media provide non-volatile storage of readable instructions, data structures, program modules, and other data for the computer. Although a hard disk, a removable disk, and a removable optical disk are described, other types of computer-readable storage media may also be used to store data, such as flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), and the like.

[0167] Some program modules may be stored on a hard disk, a disk, an optical disk, a ROM, or a RAM. These programs include an operating system 930, one or more application programs 932, other program modules 934, and program data 936. The application program 932 or the program module 934 may include, for example, computer program logic for implementing any one or more of the following (e.g., at least a portion): any one or more of the connector clients 114A-114R, any one or more of the resources 116A-116T, the browser 110, the client-side connection load balancing logic 118A, the server-side connection load balancing logic 118B, the registration logic 124, the database 126, any one or more of the connector clients 214A-214R, any one or more of the resources 216A-216T, the proxy-side connection load balancing logic 218C, the server-side connection load balancing logic 218B, the registration logic 224, the database 226, the connector Client 314, registration logic 324, database 310, connector client 414, database 410, any one or more of connector clients 514A-514B, registration logic 524, database 510, registration server load balancer 532, any one or more of connector clients 614A-614B, registration logic 624, database 610, registration server load balancer 632, allocation logic 802, determination logic 804, selection logic 806, provision logic 808, activity diagram 300 (including any activity of activity diagram 300), activity diagram 400 (including any activity of activity diagram 400) and / or flowchart 700 (including any steps of flowchart 700), as described herein.

[0168] A user may enter commands and information into the computer 900 through input devices such as a keyboard 938 and a pointing device 940. Other input devices (not shown) may include a microphone, a joystick, a game pad, a satellite dish, a scanner, a touch screen, a camera, an accelerometer, a gyroscope, or the like. These and other input devices are typically connected to the processing unit 902 through a serial port interface 942 coupled to the bus 906, but may be connected through other interfaces, such as a parallel port, a game port, or a universal serial bus (USB).

[0169] A display device 944 (eg, a monitor) is also connected to bus 906 via an interface, such as a video adapter 946. In addition to display device 944, computer 900 may include other peripheral output devices (not shown), such as speakers and printers.

[0170] The computer 900 is connected to a network 948 (eg, the Internet) via a network interface or adapter 950, a modem 952, or other means for establishing communications over the network. The modem 952 may be internal or external and is connected to the bus 906 via the serial port interface 942.

[0171] As used herein, the terms "computer program medium" and "computer-readable storage medium" are used to generally refer to media (e.g., non-transitory media) such as a hard disk associated with hard disk drive 914, removable disk 918, removable optical disk 922, etc., and other media such as flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc. Such computer-readable storage media are distinguished from and do not overlap with (do not include) communication media. Communication media embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal (such as a carrier wave). The term "modulated data signal" refers to a signal having one or more characteristics of the signal set or changed to encode information in the signal. By way of example and not limitation, communication media include wireless media such as acoustic, radio frequency, infrared, and other wireless media, as well as wired media. Example embodiments are also directed to such communication media.

[0172] As described above, computer programs and modules (including application programs 932 and other program modules 934) can be stored on a hard disk, disk, optical disk, ROM or RAM. Such computer programs can also be received through the network interface 950 or the serial port interface 942. Such computer programs enable the computer 900 to implement the features of the embodiments discussed herein when executed or loaded by the application. Therefore, such computer programs represent the controller of the computer 900.

[0173] Example embodiments are also directed to a computer program product comprising software (e.g., computer-readable instructions) stored on any computer-usable medium. Such software, when executed in one or more data processing devices, causes (multiple) data processing devices to operate as described herein. Embodiments may employ any computer-usable medium or computer-readable medium known now or in the future. Examples of computer-readable media include, but are not limited to, storage devices such as RAM, hard disks, floppy disks, CDROMs, DVDROMs, compressed disks, magnetic tapes, magnetic storage devices, optical storage devices, MEMS-based storage devices, nanotechnology-based storage devices, and the like.

[0174] It will be appreciated that the disclosed technology is not limited to any particular computer or hardware type. Certain details of suitable computers and hardware are well known and need not be set forth in detail in this disclosure.

[0175] V. Conclusion

[0176] Although the subject matter has been described in language specific to structural features and / or actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Instead, the specific features and actions described above are disclosed as examples of implementing the claims, and other equivalent features and actions are also considered to be within the scope of the claims.

Claims

1. A system, include: Memory; as well as One or more processors coupled to the memory, the one or more processors configured to load balance establishment of a plurality of connections between a plurality of groups, each group including one or more connector servers of a plurality of connector servers included in a common computer network, by performing operations comprising: receiving a connection request from a connector client included in a private computer network, the connection request requesting establishment of a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network; determining a number of connections in the plurality of connections between the private computer network and each group, the plurality of connections including a single connection to each connector client in a plurality of connector clients included in the private computer network; selecting the identified group from the plurality of groups to receive the connection request based at least in part on a number of connections in the plurality of connections between the private computer network and the identified group being less than or equal to a number of connections in the plurality of connections between the private computer network and each other group; and The connection request is provided to the identified group based at least in part on the identified group being selected from the plurality of groups, the connection request being configured to effectuate establishment of a connection between the connector client and a connector server in the identified group.

2. The system of claim 1 , wherein the one or more processors are configured to perform operations comprising: By providing the connection request to the connector client, the connector client provides the connection request to the identified group.

3. The system of claim 1 , wherein the one or more processors are configured to determine the number of connections between the private computer network and each group by performing: providing a plurality of queries to a plurality of respective connector server load balancers, each of the plurality of respective connector server load balancers being configured to: load balance connections between connector servers in a group to which the respective connector server load balancer is assigned, each query requesting a number of connections between the private computer network and the group to which the respective connector server load balancer is assigned; and A plurality of responses to the respective plurality of queries are received from the respective plurality of connector server load balancers, each response indicating a number of connections between the private computer network and the group to which the respective connector server load balancer is assigned.

4. The system of claim 3, wherein the one or more processors are configured to perform operations comprising: By providing the connection request to the connector server load balancer assigned to the identified group, the connector server load balancer is enabled to select one of a plurality of connector servers in the identified group to receive the connection request.

5. The system of claim 1 , wherein the one or more processors are configured to perform operations comprising: storing the number of connections between the private computer network and each group in a memory of a registration server, the registration server selecting the identified group from the plurality of groups; and The number of connections between the private computer network and each group is determined by retrieving the number of connections between the private computer network and each group from the memory of the registration server.

6. The system of claim 1, wherein the one or more processors are configured to determine the number of connections between the private computer network and each group by performing the following: providing a query to a database configured to synchronize a plurality of registration servers to share a common state, the common state comprising knowledge of a number of connections between the private computer network and each group; and A response to the query is received from the database, the response indicating a number of connections between the private computer network and each group.

7. The system of claim 6, wherein the one or more processors are configured to perform the operations, the operations further comprising: include: providing a confirmation notification to the database for each periodic time instance for each connection in a plurality of periodic time instances during which the connector client and the connector server remain connected via the corresponding connection at the corresponding periodic time instance, each confirmation notification confirming that the corresponding connector client and the corresponding connector server remain connected via the corresponding connection at the corresponding periodic time instance; and The number of connections between the private computer network and each group does not take into account each connection between the private computer network and the corresponding group for which no confirmation notification is provided within a specified duration, wherein the specified duration is greater than a time period between adjacent periodic time instances in the multiple periodic time instances.

8. The system of claim 1, wherein the connection request includes a network identifier that uniquely identifies the private computer network.

9. The system of claim 8, wherein the network identifier comprises a name of the private computer network and a tenant identifier identifying an owner of the private computer network.

10. A method for load balancing connection establishment, the method include: distributing a plurality of connector servers included in a common computer network among a plurality of groups, each group including one or more connector servers of the plurality of connector servers; receiving a connection request from a connector client included in a private computer network, the connection request requesting establishment of a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network; determining a number of connections in the plurality of connections between the private computer network and each group, the plurality of connections including a single connection to each connector client in a plurality of connector clients included in the private computer network; selecting the identified group from the plurality of groups to receive the connection request based at least in part on a number of connections in the plurality of connections between the private computer network and the identified group being less than or equal to a number of connections in the plurality of connections between the private computer network and each other group; as well as The connection request is provided to the identified group based at least in part on selecting the identified group from the plurality of groups, the connection request being configured to effectuate establishment of a connection between the connector client and a connector server in the identified group.

11. The method of claim 10, wherein providing the connection request include: By providing the connection request to the connector client, the connector client provides the connection request to the identified group.

12. The method of claim 10, wherein determining the number of connections between the private computer network and each group include: providing a plurality of queries to a plurality of respective connector server load balancers, each connector server load balancer of the plurality of respective connector server load balancers being configured to: load balance connections between connector servers in a group to which the respective connector server load balancer is assigned, each query requesting a number of connections between the private computer network and the group to which the respective connector server load balancer is assigned; as well as A plurality of responses to the respective plurality of queries are received from the respective plurality of connector server load balancers, each response indicating a number of connections between the private computer network and the group to which the respective connector server load balancer is assigned.

13. The method of claim 12, wherein providing the connection request include: By providing the connection request to the connector server load balancer assigned to the identified group, the connector server load balancer is enabled to select one of a plurality of connector servers in the identified group to receive the connection request.

14. The method according to claim 10, further comprising: include: storing the number of connections between the private computer network and each group in a memory of a registration server, the registration server allocating the plurality of connector servers among the plurality of groups; Wherein determining the number of connections between the private computer network and each group comprises: The number of connections between the private computer network and each group is retrieved from the memory of the registration server.

15. The method of claim 10, wherein determining the number of connections between the private computer network and each group include: providing a query to a database configured to synchronize a plurality of registration servers to share a common state, the common state comprising knowledge of a number of connections between the private computer network and each group; as well as A response to the query is received from the database, the response indicating a number of connections between the private computer network and each group.

16. The method of claim 15, wherein the common state include: The knowledge of the number of connections between the private computer network and each group is based at least in part on connection notifications provided to the database by each connector server each time a connection is established between the private computer network and a corresponding connector server.

17. The method of claim 15, wherein the common state include: Based at least in part on the knowledge of the number of connections between the private computer network and each group, a connection notification provided to the database by each registration server each time the corresponding registration server provides a connection request to establish a connection to one of the plurality of groups.

18. The method of claim 15, wherein the common state include: Based at least in part on the knowledge of the number of connections between the private computer network and each of the groups, each connector server load balancer in the plurality of connector server load balancers provides a connection notification to the database each time the corresponding connector server load balancer provides a connection request received from a connector client and requesting to establish a connection to one of the plurality of groups, wherein each connector server load balancer load balances the connections between the connector servers in the group to which the corresponding connector server load balancer is assigned.

19. The method according to claim 15, further comprising: include: providing a confirmation notification to the database for each periodic time instance for each connection in a plurality of periodic time instances during which the connector client and the connector server remain connected via the corresponding connection at the corresponding periodic time instance, each confirmation notification confirming that the corresponding connector client and the corresponding connector server remain connected via the corresponding connection at the corresponding periodic time instance; The number of connections between the private computer network and each group does not take into account each connection between the private computer network and the corresponding group for which no confirmation notification is provided within a specified duration, wherein the specified duration is greater than a time period between adjacent periodic time instances in the multiple periodic time instances.

20. A computer program product comprising a computer-readable storage medium having recorded thereon instructions for causing a processor-based system to perform operations, the operations include: The establishment of the plurality of connections is load balanced among a plurality of groups, each group including one or more connector servers of a plurality of connector servers included in a common computer network, by performing the following: receiving a connection request from a connector client included in a private computer network, the connection request requesting establishment of a connection between the connector client and one of the plurality of connector servers in the public computer network, the public computer network being external to the private computer network; determining a number of connections between the private computer network and each group, wherein each connection between the private computer network and a corresponding group enables a connector server in the corresponding group to provide a request for access to a resource in the private computer network to a corresponding connector client in the private computer network; selecting the identified group from the plurality of groups to receive the connection request based at least in part on the number of connections between the private computer network and the identified group being less than or equal to the number of connections between the private computer network and each other group; as well as The connection request is provided to the identified group based at least in part on the identified group being selected from the plurality of groups, the connection request being configured to effectuate establishment of a connection between the connector client and a connector server in the identified group.

Citation Information

Patent Citations

  • Power transmission system server load balancing method

    CN109788062A