Smart routing and firewall using client greetings for multipath secure access systems

By generating communication session identifiers associated with client devices in the routing device, the complexity of tunnel dynamic routing in multi-path and multi-tunnel secure access systems is solved, and the efficient functions of intelligent routing, load balancing and layer 3 firewall are realized.

CN120113192APending Publication Date: 2025-06-06CISCO TECHNOLOGY INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480002887.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-10-04
Filing Date
2024-09-25
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

When performing multipath and/or multi-tunnel secure access systems using DTLS client greetings and similar technologies, it is difficult to dynamically route tunnels to different data centers, resulting in management and maintenance complexity.

Method used

By generating a communication session identifier associated with the client device in the routing device, the target routing device is instructed to implement intelligent routing, load balancing and layer 3 firewall functions. The communication session identifier may contain bits indicating the workload and routing device, for pre-mapping the session to the desired destination, and, if necessary, quickly establishing an encrypted data plane session using the recovery handshake.

Benefits of technology

Line-speed mapping is implemented without termination of UDP sessions or searching for key/value data storage, reducing the routing cost of load balancing devices and intermediate network devices, and improving the routing efficiency and scalability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120113192A_ABST
    Figure CN120113192A_ABST
Patent Text Reader

Abstract

Techniques for utilizing a portion of a communication session identifier (e.g., session ID, SPI, CID, DCID, etc.) to instruct a target routing device (e.g., VPN and / or ZTNA termination device) to establish control plane session (s) and / or data plane session (s) at line speed in a networked computing environment. Routing device (s) of a networked computing environment may generate a communication session identifier and send the communication session identifier to a client device such that subsequent packets sent from the client device may be forwarded to an appropriate routing device indicated by the communication session identifier to establish one or more data plane sessions. In addition, the data plane session may be established using a Resumed Handshake instead of a full handshake that is typically required, as session resumes are mapped with the assigned communication session identifier.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. patent application No. 18 / 376,676, filed on October 4, 2023, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure generally relates to using (D)TLS Client Hello and similar techniques to perform intelligent routing, load balancing and layer 3 firewalling of multi-path and / or multi-tunnel secure access systems. Background Art

[0004] Cloud-based service provider networks (often described as "hyperscalers") provide cloud-based services to meet users' computing service needs without requiring users to invest in and maintain the computing infrastructure required to implement the services. For example, a cloud service provider may operate a network of data centers (e.g., public data centers) that house a large number of interconnected computing systems, which are configured by the service provider to provide cloud-based services to users (or "customers"). These service provider networks can provide network-based computing resources as needed. For example, a service provider network may allow users to purchase and utilize computing resources, such as virtual machine ("VM") instances, computing resources, data storage resources, database resources, networking resources, network services, and other types of computing resources. Users can configure the computing resources provided by the service provider network to achieve desired functions, such as providing network-based applications or another type of functionality to the user's enterprise. Although hyperscaler-based data centers are becoming increasingly popular, traditional enterprise-managed data centers are still widely used. The combination of these deployments is often described as a "hybrid" data center. Generally speaking, remote users are able to connect to these network-based applications and / or enterprise functions using zero-trust network access (ZTNA) and / or virtual private network (VPN) solutions.

[0005] Many VPN and / or ZTNA technologies have separate control plane and data plane protocols. For example, Internet Protocol Security (IPsec) has Internet Key Exchange (IKE) for the control plane and Encapsulating Security Payload (ESP) for the data plane. Similarly, Datagram Transport Layer Security (DTLS)-VPN has Transport Layer Security (TLS) for the control plane and DTLS for the data plane. Both VPN and ZTNA solutions can typically have many data plane sessions associated with a single control plane session. In addition, anycast networking introduces another layer of complexity because multiple data centers can host ZTNA and / or VPN termination points that share a public Internet Protocol (IP) address space with other data centers. In addition, to facilitate multipath routing, it is generally desirable to have the client initiate multiple data plane sessions and have the solution map each session to a different data center. This would be a common structure in cloud offerings, such as Secure Access Service Edge (SASE) solutions.

[0006] In this configuration, the client will have multiple data plane sessions, each of which is directed to a specific data center based on some intelligent load balancing scheme that ensures that each tunnel goes to a different data center (or a different region within a single data center). This allows multipath routing with both VPN and ZTNA to operate in an anycast ecosystem. In addition, it may be desirable to route traffic from a given endpoint to a specific termination point within a region and / or data center based on multiple factors. For example, it may be desirable to route a data plane session to the same termination node as a control plane session, to a different termination node within a region and / or data center due to load, and / or to a specific node to implement (one or more) security services and / or service links for a given session, and / or to a node with better proximity to a workload or application. However, the current problem is how to create such a system, because when anycast is used, the target domain of all tunnels will likely be the same, and the IP addresses associated with them will also be the same. Although in theory domain names and server name indicators (SNI) can be used to perform this dynamic routing, in practice it is difficult to manage and maintain a large number of unique domain name system (DNS) entries to create such a dynamic system. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] The detailed description is set forth below with reference to the accompanying drawings. In the drawings, the leftmost digit(s) of a reference number identifies the drawing in which the reference number first appears. The use of the same reference number in different drawings indicates similar or identical items. The systems depicted in the drawings are not drawn to scale, and components within the drawings may not be drawn to scale with respect to each other.

[0008] Figure 1A system architecture diagram illustrating an example environment of a networked computing environment for performing routing, load balancing, and / or firewall techniques in accordance with the techniques described herein.

[0009] Figure 2 A system architecture diagram illustrating another example environment of a networked computing environment for performing routing, load balancing, and / or firewall techniques in accordance with the techniques described herein.

[0010] Figure 3 An example data flow diagram between a client device and a control plane terminator and / or one or more data plane terminators is shown.

[0011] Figure 4A An example TLS Server Hello message is shown that can be used to perform the techniques described herein.

[0012] Figure 4B An example TLS Client Hello message is shown that can be used to perform the techniques described herein.

[0013] Figure 5A An example DTLS record is shown that may be used to perform the techniques described herein.

[0014] Figure 5B An example Encapsulating Security Payload (ESP) record is shown that may be used to perform the techniques described herein.

[0015] Fig. 6A An example QUIC long header is shown that can be used to perform the techniques described herein.

[0016] Figure 6B An example QUIC short header is shown that can be used to perform the techniques described herein.

[0017] Figure 7 A flowchart of an example method for one or more routing devices of a networked computing environment to generate and / or utilize (one or more) communication session identifiers is shown, where the communication session identifiers indicate a target routing device for routing a control plane session and / or (one or more) data plane sessions associated with a client device.

[0018] Figure 8 A flow chart of an example method for a routing device to establish a data plane session with a client device using a recovery handshake is shown.

[0019] Fig. 9 A block diagram illustrating an example packet-switching system that can be used to implement aspects of the techniques disclosed herein is shown.

[0020] Fig.10A block diagram illustrating certain components of an example node that may be used to implement aspects of the techniques disclosed herein is shown.

[0021] Fig.11 A computing system diagram is shown that illustrates the configuration of a data center that can be used to implement aspects of the techniques disclosed herein.

[0022] Fig.12 is a computer architecture diagram showing an illustrative computer hardware architecture for implementing a server device that can be used to implement aspects of the various techniques presented herein. DETAILED DESCRIPTION

[0023] Overview

[0024] Various aspects of the invention are set out in the independent claims and preferred features are set out in the dependent claims. Features of one aspect may be applicable to each aspect alone or in combination with other features.

[0025] The present disclosure describes (one or more) methods for performing intelligent routing, load balancing, and layer 3 firewalling of a multi-path and / or multi-tunnel secure access system using client hello. The method includes: receiving a first control packet from a client device at one or more routing devices of a networked computing environment. Additionally or alternatively, the method includes: generating a communication session identifier associated with the client device. In some examples, the communication session identifier may include one or more first bits indicating a workload associated with the client device and / or one or more second bits indicating a first routing device in one or more routing devices. Additionally or alternatively, the method includes: establishing a first control plane session between the first routing device and the client device. Additionally or alternatively, the method includes: sending a second control packet including an indication of the communication session identifier via the first control plane session. Additionally or alternatively, the method includes: receiving a first data packet including the communication session identifier at the first routing device. Additionally or alternatively, the method includes: establishing a first data plane session between the first routing device and the client device.

[0026] Additionally or alternatively, the method includes: establishing a first communication session between a client device and one or more routing devices of a networked computing environment, the first communication session including a control plane session and a data plane session. Additionally or alternatively, the method includes: sending a communication session identifier to the client device. In some examples, the communication session identifier may include one or more first bits indicating the first communication session and / or one or more second bits indicating a first routing device in one or more routing devices. Additionally or alternatively, the method includes: determining that a data plane session of the first communication session has been interrupted. Additionally or alternatively, the method includes: receiving a data packet including the communication session identifier at a first routing device in one or more routing devices of the networked computing environment. Additionally or alternatively, the method includes: reestablishing the first communication session between the client device and the first routing device based at least in part on the data packet by the first routing device. In some examples, reestablishing the first communication session may include reestablishing the data plane session.

[0027] Additionally, the techniques described herein may be performed by a system and / or device having a non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more processors, perform the methods described above.

[0028] Example Embodiments

[0029] As previously described, VPN and / or ZTNA technologies have independent control plane and data plane protocols, and may have many data plane sessions associated with a single control plane session. During the setup of each data plane session, a control plane message may be sent to the terminating device. The response to such configuration messages typically focuses on the various routing and DNS settings required for the (one or more) devices to set up the (one or more) appropriate tunnels for communication. The present disclosure describes techniques for associating a priori assignment of session IDs with a given tunnel through a network (e.g., with a given routing device as a target). In some examples, (one or more) routing devices (e.g., terminating devices, network gateways, secure access servers, co-location gateways, etc.) may be configured to receive control packets from a client device, generate (one or more) communication session identifiers (e.g., session IDs, connection IDs (CIDs), destination connection IDs (DCIDs), etc.) associated with the client device and indicating the target routing device for establishing a data plane session, and establish one or more data plane sessions based on receiving data packets and identifying the communication session identifiers. For example, a client device may establish a connection to an anycast IP address, and the connection may be load balanced to a load balancer node in a number of load balancer nodes, where a first communication session (e.g., a control plane session) may be established with a first routing device in one or more routing devices. The first routing device may generate a communication session identifier including one or more bits that identify a target routing device, which forwards the connection forward and sends the communication session identifier (or an indicator thereof) to the client device. The client device may then send a data packet including the communication session identifier, where the load balancer node may identify the target routing device based on one or more bits represented by the communication session identifier, and forward the data packet to the target routing device, where a second communication session (e.g., a data plane session) may be established with a second routing device. Additionally or alternatively, the techniques described herein provide a unique benefit of allowing a data plane session to be established using a recovery handshake rather than a full handshake (e.g., a DTLS handshake), which is typically required to establish a data plane session. For example, a first data plane session may be interrupted when a control plane session is resumed. However, because session recovery uses an assigned session ID for mapping, an encrypted data plane session may be quickly established as a result of identifying the communication session identifier in the data packet.

[0030] The (one or more) routing devices may be configured as VPN and / or ZTNA termination devices configured to establish (one or more) control plane sessions and / or (one or more) data plane sessions with (one or more) client devices using various protocols (e.g., IKE, TLS, QUIC transport protocol (over user datagram protocol (UDP)), etc. for control plane sessions, and ESP, DTLS, QUIC, etc. for data plane sessions). The routing device may then be configured to generate a communication session identifier associated with the client device. When IPsec ESP is used as the data plane protocol, the communication session identifier may be configured as a security parameter index (SPI); in an example where DTLS is used as the data plane protocol, the communication session identifier may be configured as a connection ID (CID); in an example where QUIC is used as the data plane protocol, the communication session identifier may be configured as a destination connection ID (DCID), etc. For example, one or more bits of the session ID, CID, and / or DCID may be reserved and utilized to indicate a given routing device (or network tunnel) used to route the data plane session. For example, the last digit(s) of the communication session identifier may be "5", indicating that the routing device corresponding to the indicator "5" is to establish a data plane session. That is, the one or more routing devices may determine a target routing device among the one or more routing devices, cause the target routing device to establish a first control session with the client device, generate a communication session identifier indicating the target routing device, and send an indication of the communication session identifier to the client device. In this way, the (one or more) data packets sent from the client device and including the communication session identifier will arrive at the load balancer node and be routed to the target routing device indicated by the communication session identifier to establish one or more data plane sessions. In an example where an encrypted client hello is used, the load balancing node may be equipped with an appropriate encryption key to decrypt at least the encrypted client hello header portion of the payload. Additionally or alternatively, the routing device may be configured to authenticate the client device before establishing a control session and / or data session, so that, for example, an authentication and configuration exchange may occur between the client device and the routing device.

[0031] By configuring communication session identifiers according to the techniques described herein (e.g., a priori assignment of session IDs, CIDs, and / or DCIDs associated with a given tunnel / routing device), the communication session identifiers can be used as routing indicators to pre-map sessions to desired destinations. The mapping can include load balancing and / or actual bootstrapping to a specified device (e.g., a specific VPN / ZTNA terminator). Additionally or alternatively, a recovery handshake can be used to quickly set up an encrypted data plane session. This is because session recovery uses the assigned session ID (or its equivalent) for mapping. To facilitate setting up the data plane using a recovery handshake, the routing device can propose a secret key as part of the control plane exchange so that boot cryptographic parameters facilitate session recovery. In some examples, the process can be similar to the zero round-trip time recovery (0-RTT) bootstrapping used in QUIC, QUIC encrypted multiplexed application substrate (MASQUE), and / or Hypertext Transfer Protocol version 3 (HTTP / 3) sessions, and can also provide a similar ecosystem for those protocol connections as well as DTLS, TLS, IPsec tunnels, etc. Additionally or alternatively, the IPsec ESP header SPI attribute may be used in a manner similar to the DTLS Client Hello Session ID.

[0032] The routing device may be configured to determine the target routing device and / or achieve various goals in various ways. In some examples, the routing device may be configured to determine the target routing device based on any load balancing technology. For example, a routing device that is determined to be at a first usage rate below a threshold usage rate (e.g., the load of each session processed by the routing device) may be a candidate for a target routing device for a given session with a client device. In addition, due to the load, the data plane session may be routed from the first routing device to the second routing device within a region or data center. Additionally or alternatively, the routing device may be configured to implement one or more policies for determining the target routing device. For example, the policy may be client-based (e.g., a given client requires a service link, a given client will be connected to a specific routing device, etc.), application-based (e.g., a given application requires a service link, a session associated with a given application will be established by a specific routing device, etc.), etc. Additionally or alternatively, the target routing device may be determined based on one or more services provided by the routing device (e.g., (one or more) firewall services (e.g., cloud delivery firewall (CDFW) service), data loss protection (DLP) service, etc.). For example, a communication session may require a first service provided by a first routing device but not by a second routing device, so the first routing device (rather than the second routing device) may be selected as a target routing device for the communication session. Additionally or alternatively, a given routing device (rather than the second routing device, which is not configured for service chaining) may be configured for service chaining and selected as a target routing device. In some examples, a target routing device may be determined for actual routing to a specified routing device.

[0033] In order to send a data channel connection to the correct routing device without the need for the technology described herein, the load balancer node must match the data channel connection to an existing control channel connection (possibly handled by another node). The available information for doing so is very limited. When the load balancer node examines the first DTLS packet, the information can only access the client source IP address and SNI extension in the DTLS client hello message. The source port is unreliable because it may be changed by the network address translation (NAT) gateway on the path. Therefore, a system not equipped with the technology described herein will need to send all connections from a given IP address and to the same SNI name to the same routing device. This results in a very unbalanced load on the routing device (for example, when workers may connect from the same office, they will all use the same routing device). In contrast, using the technology described herein, the session ID field (e.g., communication session identifier) ​​in the DTLS client hello message is present in the first packet of the data channel connection, and it can encode information that indicates to the load balancing node which routing device the connection should be forwarded to. Although key / value mapping can be used, an optimization is performed in which the identity of the routing device is inferred by the session ID value without the need for a lookup.

[0034] As described herein, computing, cloud-based solutions, routing devices may generally include any type of resources implemented by virtualization technology, such as containers, virtual machines, virtual storage, etc. In addition, although these techniques are described as being implemented in a data center and / or cloud computing network, these techniques are generally applicable to any network of devices managed by any entity that provides virtual resources. In some instances, these techniques may be performed by a scheduler or orchestrator, and in other examples, various components may be used in a system to perform the techniques described herein. The devices and components that perform the techniques herein are an implementation issue, and the described techniques are not limited to any particular architecture or implementation.

[0035] The technology described herein provides various improvements and efficiencies in routing and / or firewalls in VPN and / or ZTNA solutions, increasing routing efficiency in the network. For example, the technology described herein includes a priori generation of a communication session identifier by a routing device (e.g., a VPN / ZTNA termination device), wherein a portion of the communication session identifier indicates a target routing device for establishing a data plane session. By configuring the routing device to generate and allocate a communication session identifier, line-speed mapping can be performed without terminating a UDP session or performing a lookup in a key / value data store. For example, a load balancing device can identify a target routing device indicated by a communication session identifier and forward subsequent control and / or data packets to the target routing device without performing a lookup, thereby reducing the routing cost of the load balancing device and / or other intermediate network devices in the network. Therefore, a recovery handshake including a communication session identifier can be used to establish a data plane session. This allows the ability to quickly establish an encrypted data plane session using session recovery. In addition, if a data plane session is interrupted, the data plane session can be reestablished without having to reconfigure the control plane again. In this way, network bandwidth and / or computing resources can be reserved by utilizing a priori allocation of communication session identifiers that are configured to target routing devices used to establish control plane and / or data plane sessions. Additionally, connections can be load balanced without constraints on routing device selection, resulting in a more balanced load and a more scalable system.

[0036] Certain embodiments and examples of the present disclosure will now be described more fully below with reference to the accompanying drawings, in which various aspects are shown. However, various aspects can be implemented in many different forms and should not be construed as being limited to the implementations set forth herein. As described herein, the present disclosure encompasses variations of the embodiments. Similar reference numerals refer to similar elements throughout.

[0037] Figure 1A system architecture diagram of an example environment 100 of a networked computing environment 102 for performing routing, load balancing, and / or firewall techniques according to the techniques described herein is shown. In general, the networked computing environment 102 may include devices housed or located in one or more data centers 104, which may be located in different physical locations. For example, the networked computing environment 102 may be supported by a network of devices in a public cloud computing platform, a dedicated / enterprise computing platform, and / or any combination thereof. One or more data centers 104 may be physical facilities or buildings located in a geographic area that are designated to store networked devices that are part of the networked computing environment 102. The data center 104 may include: various networked devices, as well as redundant or backup components and infrastructure for power supply, data communication connections, environmental control, and various security devices. In some examples, the data center 104 may include one or more virtual data centers, which are pools or collections of cloud infrastructure resources designed specifically for enterprise needs and / or cloud-based service provider needs. In general, the (physical and / or virtual) data center 104 may provide basic resources such as processors (CPUs), memory (RAM), storage devices (disks), and networking (bandwidth). However, in some examples, devices in networked computing environment 102 may not be located in a well-defined data center 104, but may be located in other locations or buildings.

[0038] The networked computing environment 102 can be accessed by a client device 106 through one or more networks 108 (e.g., the Internet). The networked computing environment 102 and the network 108 can each include one or more networks implemented by any feasible communication technology (e.g., wired and / or wireless means and / or technology). The networked computing environment 102 and the network 108 can each include any combination of the following items that are centralized and / or distributed: a personal area network (PAN), a local area network (LAN), a campus area network (CAN), a metropolitan area network (MAN), an extranet, an intranet, the Internet, a short-range wireless communication network (e.g., ZigBee, Bluetooth, etc.), a wide area network (WAN), and / or can include any combination, arrangement and / or aggregation of these items. The networked computing environment 102 can include devices, virtual resources, or other nodes that relay packets from one network segment to another network segment through nodes in a computer network.

[0039] In some examples, the networked computing environment 102 may provide, host, or otherwise support one or more application services for connection and use by client devices 106. Client devices 106 may include any type of device configured to communicate over network 108 using various communication protocols (e.g., VPN, SSL, TLS, DTLS, QUIC, IPsec, and / or any other protocol). For example, client devices 106 may include personal user devices (e.g., desktop computers, laptop computers, phones, tablet computers, wearable devices, entertainment devices (e.g., televisions), etc.), network devices (e.g., servers, routers, switches, access points, etc.), and / or any other type of computing device.

[0040] In some examples, the networked computing environment 102 may include one or more ingress routers 110 that may be configured to route incoming packets based on, for example, ECMP routing. For example, the ingress router 110 may use ECMP, which is a strategy whereby next-hop packet forwarding to a single destination may occur over multiple "best paths" that are tied for first place in a routing metric calculation. Additionally, the ingress router 110 may use routing strategies such as Open Shortest Path First (OSPF), Intermediate System to Intermediate System (ISIS), Enhanced Interior Gateway Routing Protocol (EIGRP), and / or Border Gateway Protocol (BGP) in conjunction with ECMP routing.

[0041] The ingress router(s) 110 may balance traffic to route packets to one or more load balancers 112(1)-(N) (hereinafter collectively referred to as “load balancers 112”, where N represents any number greater than or equal to 1) deployed in the networked computing environment 102. The load balancers 112 may be configured to load balance packets and route packets to one or more routing devices 114(1)-(N) (hereinafter collectively referred to as “routing devices 114”, where N represents any number greater than or equal to 1). The routing devices 114 may be configured as VPN termination devices and / or ZTNA termination devices. Additionally or alternatively, the routing devices 114 may be configured to establish one or more control plane sessions and / or data plane sessions with the client device(s) 106. In some examples, routing device 114 may be required to perform authentication of client device 106, which establishes connection(s) to one or more workloads 116(A)(1)-(N)(N) executing on one or more computing resources 118(A)-(N) of networked computing environment 102, where N may be any integer greater than 1. As shown, each computing resource 118 may include one or more workloads 116 executing thereon. Additionally or alternatively, each computing resource 118 may include one or more IP addresses, such as anycast IP addresses that are the same on all computing resource(s) 118.

[0042] The routing device(s) 114 may be configured as VPN and / or ZTNA termination devices configured to establish control plane session(s) and / or data plane session(s) with the client device(s) 106 using various protocols (e.g., IKE, TLS, QUIC transport protocol (over user datagram protocol (UDP)), etc. for control plane sessions, and ESP, DTLS, QUIC, etc. for data plane sessions). The routing device(s) 114 may be configured to provide various security functions 120 and / or service linking functions, such as a cloud delivery firewall (CDFW) service, a data loss prevention (DLP) service, etc. Additionally or alternatively, the routing device(s) 114 may implement authentication of the client device to access the workload 116 executed on the computing resources 118 of the networked computing environment 102. In addition, each routing device 114 may have a corresponding device identifier 122. In some examples, the device identifier 122 may be represented as an integer by one or more bits.

[0043] Take, for example, a client device 106 attempting to connect to a workload 116 hosted by a given computing resource 118 of a networked computing environment 102. For example, the workload(s) 116 may be associated with an anycast IP address, and the client device 106 may establish a connection to the anycast IP address. The connection may first be load balanced by the ingress router 110 to a given load balancer node 112 using ECMP. The load balancer node 112 that receives the connection then forwards the connection to the routing device 114.

[0044] In some examples, routing device 114 may determine that a target routing device 114 of one or more routing devices 114 (A)-(N) should handle the connection. Routing device 114 may be configured to determine target routing device 114 in various ways and / or to achieve various goals. In some examples, routing device 114 may be configured to determine target routing device 114 based on any load balancing technique. For example, a routing device 114 that is determined to be at a first usage rate (e.g., the load of individual sessions handled by the routing device) that is below a threshold usage rate may be a candidate for a target routing device 114 for a given session with client device 106. Additionally, due to the load, the data plane session may be routed (e.g., balanced) from a first routing device 114 (A) to a second routing device 114 (B) within a region or data center 104. Additionally or alternatively, routing device 114 may be configured to implement one or more policies for determining a target routing device 114. For example, the policy may be client-based (e.g., a given client requires service linking, a given client will connect to a particular routing device 114, etc.), workload-based (e.g., a given workload 116 requires service linking, a session associated with a given workload 116 will be established by a particular routing device 114, etc.), etc. Additionally or alternatively, the target routing device 114 may be determined based on one or more services 120 provided by the routing device 114 (e.g., (one or more) firewall services (e.g., a cloud delivery firewall (CDFW) service), a data loss prevention (DLP) service, etc.). For example, a communication session may require a first service (e.g., security function 120 (A)) provided by a first routing device 114 (A) but not by a second routing device 114 (B), and thus the first routing device 114 (A) (rather than the second routing device 114 (B)) may be selected as the target routing device 114 for the communication session. Additionally or alternatively, first routing device 114(A) (rather than second routing device 114(B), which is not configured for service chaining) may be configured for service chaining and selected as target routing device 114. In some examples, target routing device 114 may be determined for actual routing to the specified routing device 114.

[0045] The routing device 114 may then be configured to generate a communication session identifier associated with the client device 106. When IPsec ESP is used as the data plane protocol, the communication session identifier may be configured as a security parameter index (SPI); in an example where DTLS is used as the data plane protocol, the communication session identifier may be configured as a connection ID (CID); in an example where QUIC is used as the data plane protocol, the communication session identifier may be configured as a destination connection ID (DCID), etc. For example, one or more bits of the session ID, CID, and / or DCID may be reserved and utilized to indicate a given routing device (or network tunnel) for routing a data plane session. For example, the last bit of the communication session identifier may be "5", indicating that the routing device 114 having a corresponding device identifier 122 of "5" is to establish a data plane session. That is, if a first routing device 114(A) of one or more routing devices 114 has a device identifier 122(A) of "5", the first routing device 114(A) may establish a first control session with the client device 106, generate a communication session identifier indicating the target routing device 114(A), and send an indication of the communication session identifier to the client device 106. In this way, (one or more) subsequent data packets sent from the client device 106 and including the communication session identifier will arrive at the load balancer node 112 and be routed to the target routing device 114(A) indicated by the communication session identifier to establish one or more data plane sessions. In examples where an encrypted client hello is used, the load balancing node 112 may be equipped with an appropriate encryption key to decrypt at least the encrypted client hello header portion of the payload. Additionally or alternatively, the routing device 114 may be configured to authenticate the client device 106 prior to establishing a control session and / or data session, so that, for example, an authentication and configuration exchange may occur between the client device 106 and the target routing device 114.

[0046] By configuring the communication session identifier according to the techniques described herein (e.g., a priori assignment of a session ID, CID, and / or DCID associated with a given tunnel / routing device), a portion of the communication session identifier indicating the device identifier 122 can be used to pre-map the session to the desired destination. The mapping can include load balancing and / or actual bootstrapping to a specified device (e.g., a specific VPN / ZTNA terminator). Additionally or alternatively, a resumption handshake can be used to quickly set up an encrypted data plane session. This is because session resumption uses the assigned session ID (or its equivalent) for mapping. To facilitate setting up the data plane using the resumption handshake, the routing device 114 can propose a secret key as part of the control plane exchange so that the bootstrap cryptographic parameters facilitate session resumption. In some examples, the process can be similar to the zero round trip time resumption (0-RTT) bootstrapping used in QUIC, QUIC encrypted multiplexed application substrate (MASQUE), and / or Hypertext Transfer Protocol version 3 (HTTP / 3) sessions, and can also provide a similar ecosystem for those protocol connections as well as DTLS, TLS, IPsec tunnels, etc. Additionally or alternatively, the IPsec ESP header SPI attribute may be used in a manner similar to the DTLS Client Hello Session ID.

[0047] Figure 2 2 is a system architecture diagram illustrating another example environment 200 of a networked computing environment 102 for performing routing, load balancing, and / or firewall techniques according to the techniques described herein. Figure 2 The networked computing environment 102 shown may correspond to the Figure 1The networked computing environment 102 described. In general, the networked computing environment 102 may include devices housed or located in one or more data centers 104, which may be located in different physical locations. For example, the networked computing environment 102 may be supported by a network of devices in a public cloud computing platform, a private / enterprise computing platform, and / or any combination thereof. One or more data centers 104 may be physical facilities or buildings located in a geographic area that are designated to store networked devices that are part of the networked computing environment 102. The data center 104 may include: various networked devices, as well as redundant or backup components and infrastructure for power supply, data communication connections, environmental control, and various security devices. In some examples, the data center 104 may include one or more virtual data centers, which are cloud infrastructure resource pools or collections specifically designed for enterprise needs and / or cloud-based service provider needs. In general, the (physical and / or virtual) data center 104 may provide basic resources such as processors (CPU), memory (RAM), storage devices (disks), and networking (bandwidth). However, in some examples, devices in networked computing environment 102 may not be located in a well-defined data center 104, but may be located in other locations or buildings.

[0048] The networked computing environment 102 can be accessed by a client device 106 through one or more networks 108 (e.g., the Internet). The networked computing environment 102 and the network 108 can each include one or more networks implemented by any feasible communication technology (e.g., wired and / or wireless means and / or technology). The networked computing environment 102 and the network 108 can each include any combination of the following items that are centralized and / or distributed: a personal area network (PAN), a local area network (LAN), a campus area network (CAN), a metropolitan area network (MAN), an extranet, an intranet, the Internet, a short-range wireless communication network (e.g., ZigBee, Bluetooth, etc.), a wide area network (WAN), and / or can include any combination, arrangement and / or aggregation of these items. The networked computing environment 102 can include devices, virtual resources, or other nodes that relay packets from one network segment to another network segment through nodes in a computer network.

[0049] In some examples, the networked computing environment 102 may provide, host, or otherwise support one or more application services for connection and use by client devices 106. Client devices 106 may include any type of device configured to communicate over network 108 using various communication protocols (e.g., VPN, SSL, TLS, DTLS, QUIC, IPsec, and / or any other protocol). For example, client devices 106 may include personal user devices (e.g., desktop computers, laptop computers, phones, tablet computers, wearable devices, entertainment devices (e.g., televisions), etc.), network devices (e.g., servers, routers, switches, access points, etc.), and / or any other type of computing device.

[0050] At "1", the client device 106 can connect to a workload hosted by a given computing resource of the networked computing environment 102. For example, the (one or more) workloads can be associated with an anycast IP address, and the client device 106 can establish a control channel connection 202 to the anycast IP address. The control channel connection 202 can first be load balanced by the ingress router 110 to the first load balancer node 112 (B) using ECMP. The first load balancer node 112 (B) receives the control channel connection 202 and can then forward the connection to the control plane terminator of the (one or more) routing devices 114 (D). The terminator and / or the (one or more) routing devices 114 (D) can then share tunnel parameters including a communication session identifier with the client device 106. Additionally or alternatively, authentication and configuration exchanges can occur between the client 106 and the (one or more) routing devices 114 (D).

[0051] At "2", the client 106 may establish one or more data channel 204 connections to the same anycast IP address. In some examples, the (one or more) data plane channels 204 may be load balanced by the ingress router 110 using ECMP to a second load balancer node 112 (N) selected from the set of available nodes. In some examples, the selected node may be the same load balancer node 112 (e.g., load balancer 112 (B)) or a different load balancer node (e.g., load balancer 112 (N)) that received the initial control channel connection. The second load balancer 112 (N) node may then forward the data channel 204 to a data plane terminator hosted on the same server instance (e.g., routing device 114 (D)) as the control plane terminator to which the initial control channel connection had been forwarded. For example, first load balancer node 112(B) may forward control channel 202 to routing device 114(D) indicated by the communication session identifier, and / or load balancer node 112(N) may forward data channel 204 to routing device 114(D) indicated by the communication session identifier.

[0052] Figure 3 An example data flow diagram 300 is shown between a client device 302 and a control plane terminator 304 and / or one or more data plane terminators 306. In some examples, the client 302 may correspond to reference Figure 1 The described (one or more) client devices 106. Additionally or alternatively, the control plane terminator 304 and / or the (one or more) data plane terminator 306 may correspond to reference Figure 1 The depicted routing device(s) 114(1)-(N). Although the control plane terminator 304 is shown as being separate from the data plane terminator(s) 306, it should be understood that the control plane terminator 304 may be executed on the same server instance as the data plane terminator(s) 306.

[0053] At 308, the client 302 can initiate a control plane initial setup. For example, the client 302 can establish a first control session connection to the anycast IP address. In some examples, the first control session can be load balanced to a load balancer node selected from the set of available nodes using equal cost multi-path (ECMP) technology. The load balancer node receiving the first control session connection forwards it to the control plane terminator 304. In some examples, the control plane terminator 304 can be from a plurality of available control plane terminators 304.

[0054] At 310, tunnel parameters including a session identifier (eg, a communication session identifier) ​​are shared between the client 302 and the control plane terminator, and a first control session connection is established. Additionally or alternatively, authentication and configuration exchanges may occur between the client 302 and the control plane terminator.

[0055] At 312, client 302 may establish one or more data plane session connections to the same anycast IP address. In some examples, ECMP may be used to load balance the one or more data plane sessions to a load balancer node selected from the set of available nodes. The selected node may be the same node or a different node that received the initial control channel connection. The selected load balancer node may then forward the data channel to a data plane terminator 306 hosted on the same server instance as the control plane terminator 304 to which the initial control channel connection was forwarded.

[0056] At 314, session resumption can be used with the provided session identifier to establish a data plane session connection. In some examples, a resumption handshake can be used to establish the data plane session connection. Additionally or alternatively, session resumption can be used to reestablish an interrupted data plane session connection without having to reconfigure the control plane.

[0057] 4A to 6B Example packet headers, messages, records, etc. are shown that can be used to perform the techniques described herein.

[0058] Figure 4A An example TLS Server Hello message 400 that can be used in a VPN session is shown. In some examples, a server (e.g., a routing device) can be selected and indicated by a server's random number session ID field 402 (of the TLS Server Hello message 400). The server's random number session ID field 402 can be included in the main structure of the TLS Server Hello message 400. In some examples, a communication session identifier can be encoded into the server's random number session ID field 402.

[0059] Figure 4B An example TLS Client Hello message 410 that can be used in a VPN session is shown. In some examples, a client device can receive a TLS Server Hello message 400 indicating a random number session ID field 402 (e.g., a communication session identifier) ​​of a server, and the client device can encode the communication session identifier into the random number session ID field 402 of the TLS Client Hello message 410. The random number session ID field 402 can be included in the main structure of the TLS Client Hello message 410.

[0060] Figure 5AAn example DTLS record 500 that can be used in a DTLS-VPN session is shown. In some examples, new fields can be added to the DTLS record 500, as shown. For example, a new field representing an opaque connection ID 502 can be added to the DTLS record. In some examples, the opaque connection ID 502 can be encoded with a communication session identifier. For example, one or more bits of the opaque connection ID 502 can be configured as a device identifier, e.g., reference Figure 1 The device identifier 122 is described.

[0061] Figure 5B An example Encapsulating Security Payload (ESP) record 510 that can be used in an IPsec session is shown. In some examples, the ESP record 510 can include a security parameter index 512. The ESP record 510 can be used in an initial IPsec packet used to establish an IPsec connection according to the techniques described herein. In some examples, a communication session identifier can be encoded into the security parameter index 512. For example, one or more bits of the security parameter index 512 can be configured as a device identifier, such as a reference Figure 1 The device identifier 122 is described.

[0062] Fig. 6A An example QUIC long header 600 for use in a QUIC packet is shown. In some examples, the QUIC long header 600 may include a destination connection ID (DCID) 602 and / or a source connection ID (SCID). The QUIC long header 600 may be used in an initial QUIC packet (e.g., an initial control packet, a client hello, etc.) for establishing a QUIC connection in accordance with the techniques described herein. In some examples, a communication session identifier may be encoded into the DCID 602. For example, one or more bits of the DCID 602 ​​may be configured as a device identifier, e.g., a reference Figure 1 The device identifier 122 is described.

[0063] Figure 6B An example QUIC short header 610 that may be used in a QUIC packet is shown. In some examples, the QUIC short header 610 may include only the DCID 602. The QUIC short header 610 may be used in subsequent QUIC packets (e.g., data packets) sent as a data stream via a QUIC connection and / or in a data plane session.

[0064] Figure 7 and Figure 8 Flowcharts of example methods 700 and 800 are shown and illustrate methods that are performed at least in part by (one or more) networked computing environments 102 and / or by Figure 1 and Figure 2The various aspects of the functions performed by the corresponding components described herein. Figure 7 and Figure 8 The described logical operations may be implemented as (1) a sequence of computer-implemented actions or program modules running on a computing system and / or (2) interconnected machine logic circuits or circuit modules within a computing system. In some examples, method(s) 700 and 800 may be performed by a system including one or more processors and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform method(s) 700 and / or 800.

[0065] The implementation of the various components described herein is selected based on the performance and other requirements of the computing system. Therefore, the logical operations described herein are variously referred to as operations, structural devices, actions, or modules. These operations, structural devices, actions, and modules can be implemented in software, firmware, dedicated digital logic, and any combination thereof. It should also be understood that more than one operation can be performed. Figure 7 and Figure 8 , and more or less operations as shown in and described in this article. These operations may also be performed in parallel, or in an order different from that described herein. Some or all of these operations may also be performed by components other than those specifically identified. Although the techniques described in this disclosure refer to specific components, in other examples, these techniques may be implemented by fewer components, more components, different components, or any configuration of components.

[0066] Figure 7 A flow chart of an example method 700 for one or more routing devices of a networked computing environment to generate and / or utilize (one or more) communication session identifiers, wherein the communication session identifier indicates a target routing device for routing a control plane session and / or (one or more) data plane session associated with a client device. In some examples, the networked computing environment and / or the routing device may correspond to a reference Figure 1 and Figure 2 The described networked computing environment 102 and / or routing device 114. Additionally or alternatively, the control plane session and / or the data plane session may correspond to reference Figure 2 A control channel 202 and / or a data channel 204 are depicted.

[0067] At 702, method 700 may include receiving, at one or more routing devices of a networked computing environment, a first control packet from a client device. In some examples, the client device may correspond to a reference Figure 1 and Figure 2The client device 106 described. In some examples, the load balancer (e.g., reference Figure 1 and Figure 2 The load balancer 112) is depicted as receiving a first control packet.

[0068] At 704, method 700 may include generating a communication session identifier associated with the client device. In some examples, the communication session identifier may include one or more first bits indicating a workload associated with the client device and / or one or more second bits indicating a first routing device among the one or more routing devices. In some examples, the workload and / or the one or more second bits may correspond to a reference Figure 1 Described workload 116 and / or device identifier 122. In some examples, the initiating routing device may receive the first control packet and share the communication session identifier with the client device so that the client device may establish a control session with the first routing device targeted by the communication session identifier.

[0069] At 706 , method 700 can include establishing a first control plane session between the first routing device and the client device.

[0070] At 708, method 700 can include sending, via the first control plane session, a second control packet including an indication of the communication session identifier.

[0071] At 710, method 700 can include receiving, at a first routing device, a first data packet including a communication session identifier.

[0072] At 712 , method 700 may include establishing a first data plane session between the first routing device and the client device.

[0073] In some examples, one or more first bits of the communication session identifier represent an anycast Internet Protocol (IP) address associated with the workload.

[0074] Additionally or alternatively, method 700 may include determining that the first data plane session has been interrupted. Additionally or alternatively, method 700 may include receiving, at the first routing device, one or more second data packets including a communication session identifier. Additionally or alternatively, method 700 may include reestablishing the first data plane session between the client device and the first routing device based at least in part on the communication session identifier.

[0075] Additionally or alternatively, method 700 may include: sending a request from the first routing device to the client device to authenticate the client device for access to the workload. Additionally or alternatively, method 700 may include: receiving a second control packet including a communication session identifier and an authentication credential, the authentication credential being configured to authenticate the client device for access to the workload. In some examples, establishing a data plane session between the client device and the first routing device is based at least in part on the authentication credential.

[0076] In some examples, the communication session identifier can be configured as at least one of the following: a Datagram Transport Layer Security (DTLS) client hello session ID, a Quick User Datagram Protocol (UDP) Internet Connection (QUIC) destination connection ID (DCID), or an Internet Protocol Security (IPsec) Encapsulating Security Payload (ESP) header Security Parameter Index (SPI) attribute.

[0077] Additionally or alternatively, method 700 may include receiving, at the first routing device, one or more second data packets including the communication session identifier. Additionally or alternatively, method 700 may include establishing, based at least in part on the computing resource identifier, one or more second data plane sessions between the client device and the first routing device.

[0078] Additionally or alternatively, method 700 may include determining that a first usage rate associated with a second routing device in the one or more routing devices exceeds a threshold usage rate. Additionally or alternatively, method 700 may include determining that a second usage rate associated with the first routing device in the one or more routing devices is below a threshold usage rate. In some examples, generating the communication session identifier is based at least in part on determining that the first usage rate exceeds the threshold usage rate and the second usage rate is below the threshold usage rate.

[0079] In some examples, one or more routing devices may be configured as at least one of a virtual private network (VPN) gateway and / or a zero trust network access (ZTNA) gateway.

[0080] Figure 8 A flowchart of an example method 800 for a routing device to establish a data plane session with a client device using a recovery handshake is shown. In some examples, the routing device and / or the client device may correspond to reference Figures 1 to 3 The routing device 114 (or control plane terminator 304 and / or data plane terminator(s) 306 ) and / or the client device 106 , client device 302 are depicted.

[0081] At 802, method 800 can include establishing a first communication session between a client device and one or more routing devices of a networked computing environment. In some examples, the first communication session can include a control plane session and a data plane session.

[0082] At 804, method 800 can include sending a communication session identifier to a client device. In some examples, the communication session identifier can include one or more first bits indicating a first communication session and / or one or more second bits indicating a first routing device of the one or more routing devices.

[0083] At 806, method 800 can include determining that a data plane session of the first communication session has been interrupted.

[0084] At 808, method 800 can include receiving, at a first routing device of the networked computing environment, a data packet including a communication session identifier.

[0085] At 810, method 800 may include reestablishing, by the first routing device, the first communication session between the client device and the first routing device based at least in part on the data packet. In some examples, reestablishing the first communication session may include reestablishing a data plane session.

[0086] In some examples, one or more first bits of the communication session identifier may also indicate an anycast Internet Protocol (IP) address associated with a workload associated with the client device.

[0087] In some examples, the communication session identifier is configured as at least one of: a Datagram Transport Layer Security (DTLS) client hello session ID, a Quick User Datagram Protocol (UDP) Internet Connection (QUIC) destination connection ID (DCID), and / or an Internet Protocol Security (IPsec) Encapsulating Security Payload (ESP) header Security Parameter Index (SPI) attribute.

[0088] In some examples, one or more routing devices may be configured as at least one of a virtual private network (VPN) gateway associated with a networked computing environment and / or a zero trust network access (ZTNA) gateway associated with the networked computing environment.

[0089] In some examples, the communication session identifier can be generated by one or more routing devices. For example, the communication session identifier can be generated by an initial routing device that receives an initial control packet from a load balancer. Additionally or alternatively, a control plane terminator associated with one or more routing devices can be configured to generate the communication session identifier.

[0090] Fig. 9A block diagram illustrating an example packet switching device (or system) 900 that can be used to implement various aspects of the technology disclosed herein is shown. In some examples, the network can be used in various networks (e.g., respectively, refer to Figure 1 and Figure 2

[0066] The described networked computing environment 102) uses (one or more) packet switching devices 900.

[0091] In some examples, the packet switching system 900 may include multiple line cards 902, 910, each line card having one or more network interfaces for sending and receiving packets over a communication link (e.g., which may be part of a link aggregation group). The packet switching device 900 may also have a control plane having one or more processing elements 904 for managing the control plane and / or control plane packet processing associated with packet forwarding in the network. The packet switching device 900 may also include other cards 908 (e.g., service cards, blades), which include processing elements for processing (e.g., forwarding / sending, discarding, manipulating, changing, modifying, receiving, creating, copying, applying services) packets associated with packet forwarding in the network. The packet switching device 900 may include a hardware-based communication mechanism 906 (e.g., a bus, a switching structure and / or a matrix, etc.) to allow its different entities 902, 904, 908 and 910 to communicate. For a number of other specific packets and / or packet flows received by or sent from the packet switch device 900 , the line card(s) 902 , 910 may generally perform the actions of both an ingress and / or egress line card 902 , 910 .

[0092] Fig.10 A block diagram showing certain components of an example node 1000 that can be used to implement various aspects of the techniques disclosed herein is shown. In some examples, the nodes 1000 can be used to implement various aspects of the techniques disclosed herein. Figure 1 and Figure 2 Node(s) 1000 are used in the described networked computing environment 102 ).

[0093] In some examples, node 1000 may include any number of line cards 1002 (e.g., line cards 1002(1)-(N), where N may be any integer greater than 1) that are communicatively coupled to forwarding engines 1010 (also referred to as packet forwarders) and / or processors 1020 via data bus 1030 and / or result bus 1040. Line cards 1002(1)-(N) may include any number of port processors 1050(1)(A)-(N)(N) controlled by port processor controllers 1060(1)-(N), where N may be any integer greater than 1. Additionally or alternatively, forwarding engines 1010 and / or processors 1020 may be coupled to each other not only via data bus 1030 and result bus 1040, but may also be communicatively coupled to each other via communication links 1070.

[0094] The processors of each line card 1002 (e.g., port processor(s) 1050 and / or port processor controller(s) 1060) may be mounted on a single printed circuit board. When a packet or packet and header is received, the packet or packet and header may be identified and analyzed by the node 1000 (also referred to herein as a router) in the following manner. Upon receipt, the packet (or some or all of its control information) or packet and header may be sent from one of the port processor(s) 1050(1)(A)-(N)(N) that received the packet or packet and header and sent to one or more of those devices coupled to the data bus 1030 (e.g., other port processors 1050(1)(A)-(N)(N), forwarding engine 1010, and / or processor 1020). Processing of the packet or packet and header may be determined, for example, by the forwarding engine 1010. For example, forwarding engine 1010 may determine that a packet or a packet and a header should be forwarded to one or more of port processors 1050(1)(A)-(N)(N). This may be accomplished by indicating to a corresponding port processor controller(s) in port processor controllers 1060(1)-(N) that a copy of the packet or a packet and a header stored in a given port processor(s) in port processors 1050(1)(A)-(N)(N) should be forwarded to an appropriate port processor in port processor(s) 1050(1)(A)-(N)(N). Additionally or alternatively, once a packet or a packet and a header has been identified for processing, forwarding engine 1010, processor 1020, etc. may be used to process the packet or a packet and a header in some manner and / or packet security information may be added to protect the packet. On the node 1000 that obtains such a packet or a packet and a header, the processing may include, for example, encrypting some or all of the information in the packet or the packet and the header, adding a digital signature and / or some other information, and / or processing that can protect the packet or the packet and the header. On the node 1000 that receives such a processed packet or a packet and a header, corresponding processing may be performed to restore or verify the information of the protected packet or the packet and the header.

[0095] Fig.11 is a computing system diagram illustrating a configuration of a data center 1100 that can be used to implement aspects of the technology disclosed herein. Fig.11 The illustrated example data center 1100 includes several server computers 1102A-1102E (which may be referred to herein as "a server computer 1102" in the singular or "server computers 1102" in the plural) for providing computing resources. In some examples, the server computers 1102 may include or correspond to the server computers 1102A-1102E, respectively, as referenced herein. Figure 1 , Fig. 9 and Fig.10 The depicted site (or data center) 104 , packet switching system 900 , and / or servers associated with node 1000 .

[0096] The server computer 1102 may be a standard tower, rack, or blade server computer that is appropriately configured to provide the computing resources described herein. As described above, the computing resources provided by the networked computing environment 102 may be data processing resources, such as VM instances or hardware computing systems, database clusters, computing clusters, storage clusters, data storage resources, database resources, networking resources, and the like. Some servers 1102 may also be configured to execute a resource manager that can instantiate and / or manage computing resources. For example, in the case of a VM instance, the resource manager may be a hypervisor or another type of program that is configured to be able to execute multiple VM instances on a single server computer 1102. The server computers 1102 in the data center 1100 may also be configured to provide network services and other types of services.

[0097] exist Fig.11 In the example data center 1100 shown, an appropriate LAN 1108 is also utilized to interconnect the server computers 1102A-1102E. It should be understood that the configuration and network topology described herein have been greatly simplified, and that more computing systems, software components, networks, and networking devices may be utilized to interconnect the various computing systems disclosed herein and provide the functionality described above. Appropriate load balancing devices or other types of network infrastructure components may also be utilized to balance the load between the data centers 1100, between each server computer 1102A-1102E in each data center 1100, and potentially between the computing resources in each server computer 1102. It should be understood that reference Fig.11 The described configuration of data center 1100 is illustrative only, and other implementations may be used.

[0098] In some examples, server computers 1102 may each execute routing device 114 , load balancer 112 , and / or workload 116 .

[0099] In some instances, the networked computing environment 102 can provide computing resources, such as application containers, VM instances, and storage, on a permanent or on-demand basis. Among other types of functionality, the computing resources provided by the networked computing environment 102 can be used to implement the various services described above. The computing resources provided by the networked computing environment 102 may include various types of computing resources, such as data processing resources (e.g., application containers and VM instances), data storage resources, networking resources, data communication resources, network services, etc.

[0100] Each type of computing resource provided by the networked computing environment 102 may be general purpose or may be available in a number of specific configurations. For example, data processing resources may be used as physical computers or VM instances in a variety of different configurations. VM instances may be configured to execute applications including web servers, application servers, media servers, database servers, some or all of the above network services, and / or other types of programs. Data storage resources may include file storage devices, block storage devices, etc. The networked computing environment 102 may also be configured to provide other types of computing resources not specifically mentioned herein.

[0101] In one embodiment, the computing resources provided by the networked computing environment 102 may be implemented through one or more data centers 1100 (which may be referred to herein as "a data center 1100" in the singular or "data centers 1100" in the plural). A data center 1100 is a facility for housing and operating computer systems and related components. A data center 1100 typically includes redundant and backup power, communications, cooling, and security systems. Data centers 1100 may also be located in geographically different locations. Fig.12 One illustrative embodiment of a data center 1100 that can be used to implement the techniques disclosed herein is described.

[0102] Fig.12 An example computer architecture is shown for a computing device (or network routing device) 1102 capable of executing program components for implementing the functionality described above. Fig.12 The computer architecture shown illustrates a conventional server computer, workstation, desktop computer, laptop computer, tablet computer, web appliance, e-reader, smart phone, or other computing device, and can be used to execute any software components presented herein. In some examples, computing device 1102 can correspond to any of the software components described herein. Figure 1 , Fig. 9 and Fig.10 The physical servers of data center 104, packet switching system 900 and / or node 1000 are depicted.

[0103] The computing device 1102 includes a baseboard 1202, or "motherboard", which is a printed circuit board to which many components or devices may be connected by way of a system bus or other electrical communication paths. In one illustrative configuration, one or more central processing units ("CPUs") 1204 operate in conjunction with a chipset 1206. The CPU 1204 may be a standard programmable processor that performs the arithmetic and logic operations necessary for the operation of the computing device 1102.

[0104] The CPU 1204 performs operations by transitioning from one discrete physical state to the next, where the state transitions are achieved by manipulating switching elements that distinguish and change these states. Switching elements generally include electronic circuits that maintain one of two binary states, such as flip-flops, and electronic circuits that provide output states based on logical combinations of the states of one or more other switching elements, such as logic gates. These basic switching elements can be combined to create more complex logic circuits, including registers, adders and subtractors, arithmetic logic units, floating point units, and the like.

[0105] Chipset 1206 provides an interface between CPU 1204 and the rest of the components and devices on baseboard 1202. Chipset 1206 may provide an interface with RAM 1208, which is used as main memory in computing device 1102. Chipset 1206 may also provide an interface with computer-readable storage media, such as read-only memory ("ROM") 1210 or non-volatile RAM ("NVRAM"), for storing basic routines that help boot computing device 1102 and transfer information between various components and devices. ROM 1210 or NVRAM may also store other software components necessary for operation of computing device 1102 according to the configurations described herein.

[0106] The computing device 1102 can operate in a networked environment using logical connections to remote computing devices and computer systems through a network, such as the network 1224 (1108). The chipset 1206 may include functionality for providing network connectivity through a NIC 1212 (e.g., a Gigabit Ethernet adapter). The NIC 1212 is capable of connecting the computing device 1102 to other computing devices through the network 1224. It should be appreciated that multiple NICs 1212 may be present in the computing device 1102, connecting the computer to other types of networks and remote computer systems.

[0107] The computing device 1102 can be connected to a storage device 1218 that provides non-volatile storage for the computing device 1102. The storage device 1218 can store an operating system 1220, programs 1222, and data, which are described in more detail herein. The storage device 1218 can be connected to the computing device 1102 via a storage controller 1214 connected to the chipset 1206. The storage device 1218 can be composed of one or more physical storage units. The storage controller 1214 can be connected to the physical storage unit via a serial attached SCSI ("SAS") interface, a serial advanced technology attachment ("SATA") interface, a fiber channel ("FC") interface, or other types of interfaces for physically connecting and transmitting data between a computer and a physical storage unit.

[0108] The computing device 1102 may store data on the storage device 1218 by transforming the physical state of the physical storage unit to reflect the information being stored. In different embodiments of the present specification, the specific transformation of the physical state may depend on various factors. Examples of such factors may include, but are not limited to, the technology used to implement the physical storage unit, whether the storage device 1218 is characterized as primary storage or secondary storage, etc.

[0109] For example, the computing device 1102 can store information to the storage device 1218 by issuing instructions through the storage controller 1214 to change the magnetic properties of a specific location in the disk drive unit, the reflective or refractive properties of a specific location in the optical storage unit, or the electrical properties of a specific capacitor, transistor, or other discrete component in the solid-state storage unit. Other transformations of the physical medium are possible without departing from the scope and spirit of the present specification, and the foregoing examples are provided only for the convenience of the present specification. The computing device 1102 can further read information from the storage device 1218 by detecting the physical state or characteristics of one or more specific locations in the physical storage unit.

[0110] In addition to the mass storage device 1218 described above, the computing device 1102 can access other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. It should be understood by those skilled in the art that computer-readable storage media are any available media that provide non-transitory storage of data and can be accessed by the computing device 1102. In some examples, the operations performed by the networked computing environment 102 and / or any components included therein can be supported by one or more devices similar to the computing device 1102. In other words, some or all of the operations performed by the networked computing environment 102 and / or any components included therein can be performed by one or more computing devices 1102 operating in a cloud-based arrangement.

[0111] By way of example, and not limitation, computer-readable storage media may include volatile and nonvolatile, removable and non-removable media implemented in any method or technology. Computer-readable storage media include, but are not limited to, RAM, ROM, erasable programmable ROM ("EPROM"), electrically-erasable programmable ROM ("EEPROM"), flash memory or other solid-state memory technology, compact disc ROM ("CD-ROM"), digital versatile disk ("DVD"), high definition DVD ("HD-DVD"), Blu-ray disc (BLU-RAY) or other optical storage, cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information in a non-transitory manner.

[0112] As briefly mentioned above, the storage device 1218 may store an operating system 1220 that is utilized to control the operation of the computing device 1102. According to one embodiment, the operating system comprises the L1NUX operating system. According to another embodiment, the operating system comprises the UNIX operating system from MICROSOFT Corporation of Redmond, Washington. SERVER operating system. According to another embodiment, the operating system may include a UNIX operating system or one of its variants. It should be understood that other operating systems may also be utilized. Storage device 1218 may store other systems or applications and data utilized by computing device 1102.

[0113] In one embodiment, the storage device 1218 or other computer-readable storage medium is encoded with computer-executable instructions that, when loaded into the computing device 1102, transform the computer from a general-purpose computing system into a special-purpose computer capable of implementing the embodiments described herein. As described above, these computer-executable instructions transform the computing device 1102 by specifying how the CPU 1204 transitions between states. According to one embodiment, the computing device 1102 is able to access a computer-readable storage medium storing computer-executable instructions that, when executed by the computing device 1102, perform the above-described Figure 7 and Figure 8 The computing device 1102 may also include a computer-readable storage medium having stored thereon instructions for performing any other computer-implemented operations described herein.

[0114] The computing device 1102 may also include one or more input / output controllers 1216 for receiving and processing input from a number of input devices, such as a keyboard, a mouse, a touch pad, a touch screen, an electronic stylus, or other types of input devices. Similarly, the input / output controller 1216 may provide output to a display, such as a computer monitor, a flat-panel display, a digital projector, a printer, or other types of output devices. It will be appreciated that the computing device 1102 may not include Fig.12 All components shown in the Fig.12 Other components not explicitly shown may be used in conjunction with Fig.12 A completely different architecture is shown in .

[0115] The server computer 1102 may support a virtualization layer 1226, such as one or more components associated with the networked computing environment 102, such as a routing device 114(B) of the one or more routing devices 114. The routing device 114(A) may be configured to generate a communication session identifier including an indication of the routing device 114 or a network tunnel associated with the routing device 114, for establishing a control plane session and / or one or more data plane sessions between the routing device 114(A) and the client device 106. That is, the load balancer 112 may utilize the communication session identifier, or a portion thereof, to forward the one or more control sessions and / or data sessions to the routing device 114(A) indicated by the communication session identifier.

[0116] In summary, techniques are described for utilizing a portion of a communication session identifier (e.g., a session ID, SPI, CID, DCID, etc.) to instruct a target routing device (e.g., a VPN and / or ZTNA termination device) to establish control plane session(s) and / or data plane session(s) at line rate in a networked computing environment. The routing device(s) of the networked computing environment may generate a communication session identifier and send the communication session identifier to a client device so that subsequent packets sent from the client device may be forwarded to the appropriate routing device indicated by the communication session identifier to establish one or more data plane sessions. Additionally, a resumed handshake may be used to establish a data plane session instead of the full handshake typically required because session resumption is mapped using the assigned communication session identifier.

[0117] Although the present invention is described with respect to specific examples, it is to be understood that the scope of the present invention is not limited to these specific examples. Since other modifications and changes made to adapt to specific operating requirements and environments are obvious to those skilled in the art, the present invention is not considered to be limited to the examples selected for the purpose of disclosure, and covers all changes and modifications that do not constitute a departure from the true spirit and scope of the present invention.

[0118] Although the present application describes embodiments with specific structural features and / or method actions, it is to be understood that the claims are not necessarily limited to the specific features or actions described. Rather, the specific features and actions are only examples of some embodiments falling within the scope of the claims of the present application.

Claims

1. A method comprising: receiving, at one or more routing devices of the networked computing environment, a first control packet from a client device; generating a communication session identifier associated with the client device, the communication session identifier comprising one or more first bits indicating a workload associated with the client device and one or more second bits indicating a first routing device of the one or more routing devices; establishing a first control plane session between the first routing device and the client device; sending, via the first control plane session, a second control packet including an indication of the communication session identifier; receiving, at the first routing device, a first data packet including the communication session identifier; as well as A first data plane session is established between the first routing device and the client device.

2. The method according to claim 1, wherein: The one or more first bits of the communication session identifier represent an anycast Internet Protocol (IP) address associated with the workload.

3. The method according to claim 1 or 2, further comprising: determining that the first data plane session has been interrupted; receiving, at the first routing device, one or more second data packets including the communication session identifier; as well as The first data plane session is re-established between the client device and the first routing device based at least in part on the communication session identifier.

4. The method according to any one of claims 1 to 3, further comprising: sending, from the first routing device to the client device, a request to authenticate the client device to access the workload; as well as receiving a second control packet including the communication session identifier and an authentication credential configured to authenticate the client device to access the workload; Wherein establishing the data plane session between the client device and the first routing device is based at least in part on the authentication credentials.

5. The method according to any one of claims 1 to 4, wherein: The communication session identifier is configured as one of: Datagram Transport Layer Security (DTLS) client hello session ID; Quick User Datagram Protocol (UDP) Internet Connections (QUIC) Destination Connection ID (DCID); or Internet Protocol Security (IPsec) Encapsulating Security Payload (ESP) header Security Parameters Index (SPI) attribute.

6. The method according to any one of claims 1 to 5, further comprising: receiving, at the first routing device, one or more second data packets including the communication session identifier; as well as One or more second data plane sessions are established between the client device and the first routing device based at least in part on the computing resource identifier.

7. The method according to any one of claims 1 to 6, further comprising: determining that a first usage rate associated with a second routing device of the one or more routing devices exceeds a threshold usage rate; as well as determining that a second usage rate associated with the first routing device of the one or more routing devices is below the threshold usage rate; Wherein generating the communication session identifier is based at least in part on determining that the first usage rate exceeds the threshold usage rate and the second usage rate is below the threshold usage rate.

8. The method according to any one of claims 1 to 7, wherein: The one or more routing devices are configured to at least one of: a virtual private network (VPN) gateway; or Zero Trust Network Access (ZTNA) Gateway.

9. A system comprising: one or more processors; as well as One or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving, at one or more routing devices of the networked computing environment, a first control packet from a client device; generating a communication session identifier associated with the client device, the communication session identifier comprising one or more first bits indicating a workload and one or more second bits indicating a first target routing device among the one or more routing devices; establishing a first communication session between the first target routing device and the client device; sending, via the first communication session, a second control packet including an indication of the communication session identifier; receiving, at the first destination routing device, one or more first data packets including the communication session identifier; and One or more second communication sessions are established between the first target routing device and the client device.

10. The system according to claim 9, wherein: The communication session identifier is configured as one of: Datagram Transport Layer Security (DTLS) client hello session ID; Quick User Datagram Protocol (UDP) Internet Connections (QUIC) Destination Connection ID (DCID); or Internet Protocol Security (IPsec) Encapsulating Security Payload (ESP) header Security Parameters Index (SPI) attribute.

11. The system according to claim 9 or 10, wherein the operation further comprises: determining that a third communication session of the one or more second communication sessions has been interrupted; receiving, at the first routing device, one or more second data packets including the communication session identifier; as well as The third communication session is reestablished based at least in part on the communication session identifier.

12. A system according to any one of claims 9 to 11, wherein: The one or more routing devices are configured to at least one of: a virtual private network (VPN) gateway associated with the networked computing environment; or A Zero Trust Network Access (ZTNA) gateway is associated with the networked computing environment.

13. A system according to any one of claims 9 to 12, wherein: The first communication session is a control plane session and the one or more second communication sessions are data plane sessions.

14. The system according to any one of claims 9 to 13, wherein the operations further comprise: sending, from the first routing device to the client device, a request to authenticate the client device to access the workload; as well as receiving a second control packet including the communication session identifier and an authentication credential configured to authenticate the client device to access the workload; Wherein establishing the one or more second communication sessions between the client device and the first routing device is based at least in part on the authentication credentials.

15. The system according to any one of claims 9 to 14, wherein the operations further comprise: determining that a first usage rate associated with a second routing device of the one or more routing devices exceeds a threshold usage rate; as well as determining that a second usage rate associated with the first routing device of the one or more routing devices is below the threshold usage rate; Wherein generating the communication session identifier is based at least in part on determining that the first usage rate exceeds the threshold usage rate and the second usage rate is below the threshold usage rate.

16. A method comprising: establishing a first communication session between a client device and one or more routing devices of a networked computing environment, the first communication session comprising a control plane session and a data plane session; sending a communication session identifier to the client device, the communication session identifier comprising one or more first bits indicating the first communication session and one or more second bits indicating a first routing device of the one or more routing devices; determining that the data plane session of the first communication session has been interrupted; receiving, at the first routing device of the networked computing environment, a data packet including the communication session identifier; as well as The first communication session is reestablished, by the first routing device, between the client device and the first routing device based at least in part on the data packets, wherein reestablishing the first communication session includes reestablishing the data plane session.

17. The method according to claim 16, wherein: The one or more first bits of the communication session identifier also indicate an anycast Internet Protocol (IP) address associated with a workload associated with the client device.

18. The method according to claim 16 or 17, wherein: The communication session identifier is configured as one of: Datagram Transport Layer Security (DTLS) client hello session ID; Quick User Datagram Protocol (UDP) Internet Connections (QUIC) Destination Connection ID (DCID); or Internet Protocol Security (IPsec) Encapsulating Security Payload (ESP) header Security Parameters Index (SPI) attribute.

19. The method according to any one of claims 16 to 18, wherein: The one or more routing devices are configured to at least one of: a virtual private network (VPN) gateway associated with the networked computing environment; or A Zero Trust Network Access (ZTNA) gateway is associated with the networked computing environment.

20. The method according to any one of claims 16 to 19, wherein: The communication session identifier is generated by the one or more routing devices.

21. An apparatus comprising: means for receiving, at one or more routing devices of a networked computing environment, a first control packet from a client device; means for generating a communication session identifier associated with the client device, the communication session identifier comprising one or more first bits indicative of a workload associated with the client device and one or more second bits indicative of a first routing device of the one or more routing devices; means for establishing a first control plane session between the first routing device and the client device; means for sending, via said first control plane session, a second control packet including an indication of said communications session identifier; means for receiving, at said first routing device, a first data packet including said communication session identifier; as well as Means for establishing a first data plane session between the first routing device and the client device.

22. The apparatus of claim 21, further comprising means for implementing the method of any one of claims 2 to 8.

23. An apparatus comprising: means for establishing a first communication session between a client device and one or more routing devices of a networked computing environment, the first communication session comprising a control plane session and a data plane session; means for sending a communication session identifier to the client device, the communication session identifier comprising one or more first bits indicating the first communication session and one or more second bits indicating a first routing device of the one or more routing devices; means for determining that the data plane session of the first communication session has been interrupted; means for receiving, at said first routing device of said networked computing environment, a data packet including said communication session identifier; as well as Means for reestablishing, by the first routing device, the first communication session between the client device and the first routing device based at least in part on the data packets, wherein reestablishing the first communication session comprises reestablishing the data plane session.

24. The apparatus of claim 23, further comprising means for implementing the method of any one of claims 17 to 20.

25. A computer program, a computer program product or a computer readable medium comprising instructions which, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 8 or the steps of the method according to any one of claims 16 to 20.