IP Library › Granted Patent US 8,561,155
Granted Patent B2
US 8,561,155 · App. 11/462,300 · Granted Oct 15, 2013

Systems and methods for using a client agent to manage HTTP authentication cookies

Inventors: Junxiao He (Saratoga, CA); Charu Venkatraman (Bangalore, IN); Ajay Soni (San Jose, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,561,155
App. No.
11/462,300
Granted
Oct 15, 2013
Kind
B2
Abstract

Systems and methods are described for using a client agent to manage HTTP authentication cookies. One method includes intercepting, by a client agent executing on a client, a connection request from the client; establishing, by the client agent, a transport layer virtual private network connection with a network appliance; transmitting, by the client agent via the established connection, an HTTP request comprising an authentication cookie; and transmitting, by the client agent via the connection, the connection request. A second method includes intercepting, by a client agent executing on a client, an HTTP communication comprising a cookie from an appliance on a virtual private network to the client; removing, by the client agent, the cookie from the HTTP communication; storing, by the client agent, the received cookie; transmitting, by the client agent, the modified HTTP communication to an application executing on the client; intercepting, by the client agent, an HTTP request from the client; inserting, by the client agent in the HTTP request, the received cookie; and transmitting the modified HTTP request to the appliance. Corresponding systems are also described.

Claims (29)

1. A method for using a client agent to enable HTTP cookie authentication in non-HTTP communications from a client, the method comprising:

(a) intercepting, by a client agent executing on a client, a non-HTTP connection request to a server from an application executing on the client, the non-HTTP connection request comprising a request to establish a transport layer connection with the server;

(b) establishing, by the client agent, a transport layer virtual private network connection between the client agent and a network appliance intermediary to the client and the server;

(c) transmitting, from the client agent via the established transport layer virtual private network connection responsive to the interception of the non-HTTP connection request, an HTTP request comprising an authentication cookie to the network appliance to authenticate the non-HTTP connection request prior to transmitting the non-HTTP connection request of the application to the network appliance; and

(d) transmitting, by the client agent via the transport layer virtual private network connection responsive to receiving from the network appliance an HTTP response comprising acceptance of the authentication cookie by the network appliance, the non-HTTP connection request to the server via the network appliance and any data for the non-HTTP connection queued by the client agent while waiting for receipt of the HTTP response indicating acceptance of the authentication cookie by the network appliance.

2. The method of claim 1 , wherein the client agent executes transparently with respect to one of the following network layers: the application layer, the presentation layer, the session layer, or the transport layer.

3. The method of claim 1 , wherein step (a) comprises intercepting, by a client agent executing on a client, a transport layer connection request from the client, wherein the interception occurs at one of the following network layers: the transport layer, the network layer, or the data layer.

4. The method of claim 1 , wherein step (a) comprises intercepting, by a client agent executing on a client, a TCP SYN packet.

5. The method of claim 1 , wherein step (c) comprises transmitting, by the client agent via the established connection, an HTTP request comprising an authentication cookie prior to any data being transmitted via the connection.

6. The method of claim 1 , wherein step (c) comprises transmitting by the client agent, in response to the determination that the connection has been established, an HTTP request comprising an authentication cookie, the cookie comprising user authentication credentials.

7. The method of claim 1 , wherein step (c) comprises transmitting, by the client agent via the established connection, an HTTP request comprising an authentication cookie, the cookie comprising application-specific authentication credentials.

8. The method of claim 1 , wherein step (c) further comprises receiving, by the client agent, an HTTP response, the HTTP response comprising an acceptance of the authentication cookie.

9. A computer implemented system for using a client agent to enable HTTP cookie authentication in non-HTTP communications from a client, the system comprising:

a client computing device; and

a client agent executing on the client, which intercepts a non-HTTP connection request to a server from an application on the client; establishes a transport layer virtual private network connection between the client agent and a network appliance intermediary to the client and the server, the non-HTTP connection request comprising a request to establish a transport layer connection with the server;

transmits, from the client agent via the established transport layer virtual private network connection responsive to the interception of the non-HTTP connection request, an HTTP request comprising an authentication cookie to the network appliance to authenticate the non-HTTP connection request prior to transmitting the non-HTTP connection request of the application to the network appliance; and

transmits, by the client agent via the transport layer virtual private network connection, responsive to receiving from the network appliance an HTTP response comprising acceptance of the authentication cookie by the network appliance, the non-HTTP connection request to the server via the network appliance and any data for the non-HTTP connection queued by the client agent while waiting for receipt of the HTTP response indicating acceptance of the authentication cookie by the network appliance.

10. The system of claim 9 , wherein the client agent executes transparently with respect to one of the following network layers: the application layer, the presentation layer, the session layer, or the transport layer.

11. The system of claim 9 , wherein the client agent intercepts a transport-layer connection request from the client, wherein the interception occurs at one of the following network layers: the transport layer, the network layer, or the data layer.

12. The system of claim 9 , wherein the client agent intercepts a TCP SYN packet.

13. The system of claim 9 , wherein the client agent transmits, via the established connection, an HTTP request comprising an authentication cookie prior to any data being transmitted via the connection.

14. The system of claim 9 , wherein the client agent transmits, via the established connection, an HTTP request comprising an authentication cookie, the cookie comprising user authentication credentials.

15. The system of claim 9 , wherein the client agent transmits, via the established connection, an HTTP request comprising an authentication cookie, the cookie comprising application-specific authentication credentials.

16. The system of claim 9 , wherein the client agent receives an HTTP response, the HTTP response comprising an acceptance of the authentication cookie.

17. A method for using a client agent to enable HTTP cookie authentication in non-HTTP communications from a client, the method comprising:

(a) receiving, by a client agent executing on a client, an authentication cookie from a network appliance intermediary to the client and a server;

(b) intercepting, by the client agent, a first request of an application on the client to establish a non-HTTP connection with the server, the non-HTTP connection comprising a transport layer connection with the server;

(c) transmitting, from the client agent via an established transport layer connection between the client agent and the network appliance, responsive to the interception of the first request of the application, a HTTP request comprising the authentication cookie to authenticate the non-HTTP connection for the first request by the network appliance prior to transmitting the first request of the application via the network appliance to the server; and

(d) transmitting, by the client agent via the established transport layer connection, responsive to receiving a HTTP response identifying acceptance of the authentication cookie by the network appliance, the first request for the non-HTTP connection to the server via the network appliance and any data for the non-HTTP connection queued by the client agent while waiting for the receipt of the HTTP response.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2006
From: HE, JUNXIAO; VENKATRAMAN, CHARU; SONI, AJAY
To: CITRIX SYSTEMS, INC.
Reel/Frame 018544/0171 →
Continuity (1)
Related Publication 20080034198A1 · Feb 7, 2008