IP Library Granted Patent US 7,613,131
Granted Patent B2
US 7,613,131 · App. 11/271,077 · Granted Nov 3, 2009

Overlay network infrastructure

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,613,131
App. No.
11/271,077
Granted
Nov 3, 2009
Kind
B2
Abstract

A method and apparatus for processing an overlay network infrastructure. In one embodiment, the method comprises a plurality of transparent access points (TAPs). Each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the TAPs via permanently, established secure links. The overlay network also comprises a controller coupled to each of the TAPs via a secure connection to configure the TAPs with information to enable each TAP to know what services are available and from which of the TAPs each of the services can be accessed.

Claims (35)

1. An overlay network comprising:

a plurality of transparent access points (TAPs), wherein each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the plurality of TAPs via permanently, established secure links; a controller coupled to each of the plurality of TAPs via a secure connection to configure the plurality of TAPs with information to enable said each TAP to know what services are available and from which of the plurality of TAPs each of the services can be accessed, wherein the controller provides each TAP with routing and forwarding tables to indicate where one or more services are available, to specify one or more TAPs to which a service will be forwarded, and to indicate how to reach TAPs wherein the service is available.

2. The overlay network defined in claim 1 wherein the permanently, established secure links comprises virtual private networks (VPNs), such that a client communicates with a server over a VPN.

3. The overlay network defined in claim 1 wherein plurality of TAPs consists of one TAP per network segment.

4. The overlay network defined in claim 1 wherein the secure connection comprises an SSL/TLS connection.

5. The overlay network defined in claim 1 wherein the secure connection comprises a TCP connection.

6. The overlay network defined in claim 1 wherein one of the plurality of TAPs is communicably coupled to one of the one or more servers and is communicably coupled to the WAN via a firewall, such that the TAP and the one server are only accessible to TAPs in the plurality of TAPs through the firewall.

7. An overlay network comprising:

a plurality of transparent access points (TAPs), wherein each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the plurality of TAPs via permanently, established secure links; a controller coupled to each of the plurality of TAPs via a secure connection to configure the plurality of TAPs with information to enable said each TAP to know what services are available and from which of the plurality of TAPs each of the services can be accessed, during configuration, the administrator of the TAP and the controller cross-verify each other using the fingerprint of the TAP'S and controller's certificate.

8. An overlay network comprising:

a plurality of transparent access points (TAPs), wherein each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the plurality of TAPs via permanently, established secure links; a controller coupled to each of the plurality of TAPs via a secure connection to configure the plurality of TAPs with information to enable said each TAP to know what services are available and from which of the plurality of TAPs each of the services can be accessed, wherein at least one of the plurality of TAPs performs dictionary-based compression on at least one request or response prior to sending the least one request or response over the WAN to a receiving TAP of the plurality of TAPs, the dictionary-based compression replacing at least a portion of the at least one request or response with an index.

9. The overlay network defined in claim 8 wherein the receiving TAP uses a dictionary to reconstruct the at least one request or response that underwent dictionary-based compression.

10. The overlay network defined in claim 8 wherein the at least one TAP sends information to enable reconstruction of the at least a portion of the at least one request or response to the receiving TAP when substituting the index for the portion for the first time.

11. An overlay network comprising:

a plurality of transparent access points (TAPs), wherein each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the plurality of TAPs via permanently, established secure links; a controller coupled to each of the plurality of TAPs via a secure connection to configure the plurality of TAPs with information to enable said each TAP to know what services are available and from which of the plurality of TAPs each of the services can be accessed, wherein one TAP of the plurality of TAPS receives a request for a designated server from one of the clients and checks a cache to determine whether a response to the request is already stored in the cache, the one TAP sending the response from the cache to satisfy the request, instead of sending the response over the WAN toward the designated server.

12. The overlay network defined in claim 11 wherein the cache stores the response for a period of time.

13. The overlay network defined in claim 12 wherein the period of time is set by the designated server.

14. The overlay network defined in claim 12 wherein the period of time is set by the controller.

15. The overlay network defined in claim 14 wherein the controller over-rides the period of time set by the designated server and sets the period of time.

16. The overlay network defined in claim 11 wherein the cache stores the response until an event occurs.

17. A method comprising:

configuring a plurality of transparent access points (TAPs), using a controller, to enable the one or more clients to communicate with the one or more servers over a wide area network (WAN), where each TAP is communicably coupled between the one or more clients and servers and is coupled to other of the plurality of TAPs via permanently, established secure links, and further wherein the controller is coupled to each of the plurality of TAPs via a secure connection, including providing information to enable said each TAP to know what services are available and from which of the plurality of TAPS each of the services can be accessed, and providing each TAP with routing and forwarding tables to indicate where one or more services are available, to specify one or more TAPs to which a service will be forwarded, and to indicate how to reach TAPs wherein the service is available.

18. A method comprising:

configuring a plurality of transparent access points (TAPs), using a controller, to enable the one or more clients to communicate with the one or more servers over a wide area network (WAN), where each TAP is communicably coupled between the one or more clients and servers and is coupled to other of the plurality of TAPs via permanently, established secure links, and further wherein the controller is coupled to each of the plurality of TAPs via a secure connection, including providing information to enable said each TAP to know what services are available and from which of the plurality of TAPS each of the services can be accessed, the administrator of the TAP and the controller cross-verifying each other using the fingerprint of the TAP's and controller's certificate during configuration.

19. A method comprising:

configuring a plurality of transparent access points (TAPs), using a controller, to enable the one or more clients to communicate with the one or more servers over a wide area network (WAN), where each TAP is communicably coupled between the one or more clients and servers and is coupled to other of the plurality of TAPs via permanently, established secure links, and further wherein the controller is coupled to each of the plurality of TAPs via a secure connection, including providing information to enable said each TAP to know what services are available and from which of the plurality of TAPS each of the services can be accessed, at least one of the plurality of TAPs performing dictionary-based compression on at least one request or response and then sending the least one request or response over the WAN to a receiving TAP of the plurality of TAPs, the dictionary-based compression replacing at least a portion of the at least one request or response with an index.

20. The method defined in claim 19 further comprising the receiving TAP using a dictionary to reconstruct the at least one request or response that underwent dictionary-based compression.

21. The method defined in claim 19 further comprising the at least one TAP sending information to enable reconstruction of the at least a portion of the at least one request or response to the receiving TAP when substituting the index for the portion for the first time.

22. A method comprising:

configuring a plurality of transparent access points (TAPs), using a controller, to enable the one or more clients to communicate with the one or more servers over a wide area network (WAN), where each TAP is communicably coupled between the one or more clients and servers and is coupled to other of the plurality of TAPs via permanently, established secure links, and further wherein the controller is coupled to each of the plurality of TAPs via a secure connection, including providing information to enable said each TAP to know what services are available and from which of the plurality of TAPS each of the services can be accessed, one TAP of the plurality of TAPs receiving a request for a designated server from one of the clients and checks a cache to determine whether a response to the request is already stored in the cache, the one TAP sending the response from the cache to satisfy the request, instead of sending the response over the WAN toward the designated server.

23. The method defined in claim 22 wherein the cache stores the response for a period of time.

24. The method defined in claim 23 wherein the period of time is set by the designated server.

25. The method defined in claim 23 wherein the period of time is set by the controller.

26. The method defined in claim 25 further comprising the controller over-riding the period of time set by the designated server and sets the period of time.

27. The method defined in claim 25 wherein the cache stores the response until an event occurs.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 15, 2011
From: ORBITAL DATA CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 027392/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2006
From: JIBE NETWORKS, INC.
To: ORBITAL DATA CORPORATION
Reel/Frame 017931/0124 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2006
From: DECASPER, DAN; DITTIA, ZUBIN; MUNDKUR, PRASHANTH; GHOSH, RAJIB
To: JIBE NETWORKS, INC.
Reel/Frame 017835/0380 →
Continuity (1)
Related Publication 20070104115A1 · May 10, 2007