IP Library Granted Patent US 8,392,982
Granted Patent B2
US 8,392,982 · App. 12/409,216 · Granted Mar 5, 2013

Systems and methods for selective authentication, authorization, and auditing in connection with traffic management

Inventors: James Harris (San Jose, CA); Rui Li (Santa Clara, CA); Arkesh Kumar (San Jose, CA); Ravindranath Thakur (Bangalore, IN); Puneet Agarwal (Bangalore, IN); Akshat Choudhary (Bangalore, IN)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,392,982
App. No.
12/409,216
Filed
Mar 23, 2009
Granted
Mar 5, 2013
Kind
B2
Art Unit
2493
USPC
726/12
Abstract

The present invention provides a system and method for authentication of network traffic managed by a traffic management virtual server. A traffic management virtual server may determine that a client has not been authenticated from a request of the client to access a server. Responsive to the request, the traffic management virtual server may transmit a response to the client with instructions to redirect to an authentication virtual server. The authentication virtual server may receive a second request from the client. The authentication virtual server may then authenticate credentials received from the client and establish an authentication session for the client. Further, the authentication virtual server may transmit a second response to redirect the client to the traffic management virtual server. The second response identifies the authentication session. The traffic management virtual server then receives a request from the client with an identifier to the authentication session.

Claims (31)

1. A method of authentication of network traffic managed by a traffic management virtual server, the method comprising:

a) determining, by a traffic management virtual server, from a request of a client to access a server that the client has not been authenticated, the request comprising a first uniform resource locator (URL);

b) transmitting, by the traffic management virtual server, to the client a response to the request, the response comprising the first URL and instructions to redirect to an authentication virtual server;

c) receiving, by the authentication virtual server, a second request from the client, the second request identifying the first URL;

d) authenticating, by the authentication virtual server, credentials received from the client, the authentication virtual server establishing an authentication session for the client, the authentication session identifying one or more policies comprising at least one traffic management policy;

e) transmitting, by the authentication virtual server, to the client a second response to redirect the client to the traffic management virtual server, the second response identifying the authentication session;

f) receiving, by the traffic management virtual server, a third request from the client, the third request comprising an identifier of the authentication session; and

g) forwarding, by the traffic management virtual server based on application of the one or more policies to the third request, traffic authorized by the one or more policies from the client to the server.

2. The method of claim 1 , wherein step (a) further comprises determining, by the traffic management virtual server, that the request does not comprise the identifier of the authentication session.

3. The method of claim 1 , wherein step (b) further comprises transmitting, by the traffic management virtual server, the response identifying the first URL via a hidden form.

4. The method of claim 1 , wherein step (b) further comprises transmitting, by the traffic management virtual server, the response comprising a script to trigger transmission of a POST request to the authentication virtual server.

5. The method of claim 1 , wherein step (c) comprises receiving, by the authentication virtual server the second request comprising a POST message to a predetermined URL.

6. The method of claim 1 , wherein step (d) further comprises storing, by the authentication virtual server, the first URL and domain of the traffic management virtual server with the authentication session.

7. The method of claim 1 , wherein step (f) further comprises validating, by the traffic management virtual server, the authentication session identified by the identifier.

8. The method of claim 1 , wherein step (f) further comprises identifying, by the traffic management virtual server, the one or more policies of the authentication session using the identifier.

9. The method of claim 1 , wherein step (f) further comprises applying, by the traffic management virtual server, an authorization policy of the one or more policies of the authentication session to the third request.

10. The method of claim 1 , wherein step (f) further comprises applying, by the traffic management virtual server, a traffic management policy of the one or more policies of the authentication session to the third request.

11. A system of authentication of network traffic managed by a traffic management virtual server, the system comprising:

a traffic management virtual server determining from a request of a client to access a server that the client has not been authenticated, the request comprising a first uniform resource locator (URL), transmitting to the client a response to the request, the response comprising the first URL and instructions to redirect to a second virtual server for authentication

an authentication virtual server receiving a second request from the client, the second request identifying the first URL, authenticating, credentials received from the client and establishing an authentication session for the client, the authentication session identifying one or more policies comprising at least one traffic management policy; and

wherein the authentication virtual server transmits to the client a second response to redirect the client to the traffic management virtual server, the second response identifying the authentication session;

the traffic management virtual server receives a third request from the client, the third request comprising an identifier of the authentication session, and forwards, based on application of the one or more policies to the third request, traffic authorized by the one or more policies from the client to the server.

12. The system of claim 11 , wherein the traffic management virtual server determines that the request does not comprise the identifier of the authentication session.

13. The system of claim 11 , wherein the traffic management virtual server transmits the response identifying the first URL via a hidden form.

14. The system of claim 11 , wherein the traffic management virtual server transmits the response comprising a script to trigger transmitting a POST request to the authentication virtual server.

15. The system of claim 11 , wherein the authentication virtual server receives the second request comprising a POST message to a predetermined URL.

16. The system of claim 11 , wherein the authentication virtual server stores the first URL and domain of the traffic management virtual server with the authentication session.

17. The system of claim 11 , wherein the traffic management virtual server validates the authentication session identified by the identifier.

18. The system of claim 11 , wherein the traffic management virtual server identifies the one or more policies of the authentication session using the identifier.

19. The system of claim 11 , wherein the traffic management virtual server applies an authorization policy of the one or more policies of the authentication session to the third request.

20. The system of claim 11 , wherein the traffic management virtual server applies a traffic management policy of the one or more policies of the authentication session to the third request.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2009
From: HARRIS, JAMES; LI, RUI; KUMAR, ARKESH; THAKUR, RAVINDRANATH; AGARWAL, PUNEET; CHOUDHARY, AKSHAT
To: CITRIX SYSTEMS, INC.
Reel/Frame 022989/0746 →
Continuity (2)
Provisional Application 61161918 · Mar 20, 2009
Related Publication 20100242105A1 · Sep 23, 2010