IP Library Granted Patent US 7,876,712
Granted Patent B2
US 7,876,712 · App. 12/565,401 · Granted Jan 25, 2011

Overlay network infrastructure

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,876,712
App. No.
12/565,401
Granted
Jan 25, 2011
Kind
B2
Abstract

A method and apparatus for processing an overlay network infrastructure. In one embodiment, the method comprises a plurality of transparent access points (TAPs). Each TAP is communicably coupled between one or more clients and servers and a wide area network (WAN) to enable the one or more clients to communicate with the one or more servers, and is coupled to other of the TAPs via permanently, established secure links. The overlay network also comprises a controller coupled to each of the TAPs via a secure connection to configure the TAPs with information to enable each TAP to know what services are available and from which of the TAPs each of the services can be accessed.

Claims (28)

1. A method for routing network traffic between a client and server using a plurality of access point devices intermediary to the client and the server, the method comprising:

(a) receiving, by a first access point device in communication with a plurality of a clients, a request from a client to access an application;

(b) selecting, by the first access point device, a route from a plurality of routes between the first access point device and one or more access point devices that provide access to the application via one or more servers, the first access point device maintaining a secure transport layer connection to each of the one or more access point devices;

(c) transmitting, by the first access point device to a second access point identified from the selected route, the request via the secure transport layer connection between the first access point device and the second access point device;

(d) determining, by the second access point responsive to receiving the request from the first access point, via a forwarding table a server from a plurality of servers to which to send the request; and

(e) forwarding, by the second access point responsive to the determination, the request to the server.

2. The method of claim 1 , wherein step (a) further comprises transparently intercepting, by the first access point, the request from the client.

3. The method of claim 1 , wherein step (a) further comprises determining, by the first access point, whether the request is acceptable based on applying one or more rules to properties of the request.

4. The method of claim 1 , wherein step (b) further comprises obtaining, by the first access point, a list of routes to the second access point, excluding routes that are not usable at this time and selecting the route from the usable routes.

5. The method of claim 1 , wherein step (b) further comprises selecting the route from the plurality of routes by load-balancing the plurality of routes.

6. The method of claim 1 , wherein step (b) further comprises selecting the route from the plurality of routes as a failover route to the second access point device.

7. The method of claim 1 , wherein step (d) further comprises selecting, by the second access point, the server from the plurality of servers by load-balancing the plurality of servers.

8. The method of claim 1 , wherein step (d) further comprises selecting, by the second access point, the server from the plurality of servers as a failover server from an ordered list of the plurality of servers.

9. The method of claim 1 , further comprising receiving, by the second access point, a response to the request from the server and transmitting the response to the first access point via the secure transport layer connection.

10. The method of claim 1 , further comprising compressing and uncompressing, by the first access point device and the second access point device, client and server communications over a wide area network between the first access point device and the second point device using a compression dictionary.

11. A system for routing network traffic between a client and server using a plurality of access point devices intermediary to the client and the server, the system comprising:

a first access point device in communication with a plurality of a clients receiving a request from a client to access an application, selecting a route from a plurality of routes between the first access point device and one or more access point devices that provide access to the application via one or more servers, the first access point device maintaining a secure transport layer connection to each of the one or more access point devices;

a second access point identified from the selected route receiving the request transmitted by the first access point device via the secure transport layer connection between the first access point device and the second access point device;

wherein the second access point, responsive to receiving the request from the first access point, determines via a forwarding table a server from a plurality of servers to which to send the request; and forwards, responsive to the determination, the request to the server.

12. The system of claim 11 , wherein the first access point transparently intercepts the request from the client.

13. The system of claim 11 , wherein the first access point determines whether the request is acceptable based on applying one or more rules to properties of the request.

14. The system of claim 11 , wherein the first access point obtains a list of routes to the second access point, excluding routes that are not usable at this time and selecting the route from the usable routes.

15. The system of claim 11 , wherein the first access point selects the route from the plurality of routes by load-balancing the plurality of routes.

16. The system of claim 11 , wherein the first access point selects the route from the plurality of routes as a failover route to the second access point device.

17. The system of claim 11 , wherein the second access point selects the server from the plurality of servers by load-balancing the plurality of servers.

18. The system of claim 11 , wherein the second access point selects the server from the plurality of servers as a failover server from an ordered list of the plurality of servers.

19. The system of claim 11 , wherein the second access point receives a response to the request from the server and transmits the response to the first access point via the secure transport layer connection.

20. The system of claim 11 , the first access point device and the second access point device compress and uncompress client and server communications over a wide area network between the first access point device and the second point device using a compression dictionary.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 15, 2011
From: ORBITAL DATA CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 027392/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2010
From: JIBE NETWORKS, INC.
To: ORBITAL DATA CORPORATION
Reel/Frame 025504/0779 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2010
From: DECASPER, DAN; DITTIA, ZUBIN; MUNDKUR, PRASHANTH; GHOSH, RAJIB
To: JIBE NETWORKS, INC.
Reel/Frame 025492/0976 →
Continuity (2)
Continuation 1127107700 · Nov 10, 2005
Related Publication 20100074147A1 · Mar 25, 2010