IP Library › Granted Patent US 8,543,805
Granted Patent B2
US 8,543,805 · App. 12/764,633 · Granted Sep 24, 2013

Systems and methods for split proxying of SSL via WAN appliances

Inventor: Michael Ovsiannikov (San Mateo, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,543,805
App. No.
12/764,633
Filed
Apr 21, 2010
Granted
Sep 24, 2013
Kind
B2
Art Unit
2434
USPC
713/151
Abstract

The present invention is directed towards systems and methods for split proxying Secure Socket Layer (SSL) communications via intermediaries deployed between a client and a server. The method includes establishing, by a server-side intermediary, a SSL session with a server. A client-side intermediary may establish a second SSL session with a client using SSL configuration information received from the server-side intermediary. Both intermediaries may communicate via a third SSL session. The server-side intermediary may decrypt data received from the server using the first SSL session's session key. The server-side intermediary may transmit to the client-side intermediary, via the third SSL session, data encrypted using the third SSL session's session key. The client-side intermediary may decrypt the encrypted data using the third SSL session's session key. The client-side intermediary may transmit to the client the data encrypted using the second SSL session's session key.

Claims (36)

1. A method for split proxying Secure Socket Layer (SSL) communications across intermediaries deployed between a client and a server, the method comprising:

a) establishing, by a first intermediary device in communication with a server, a first Secure Socket Layer (SSL) session with the server;

b) establishing, by a second intermediary device in communication with one or more clients, a second Secure Socket Layer (SSL) session with a client using SSL configuration information received from the first intermediary device, the second intermediary device and the first intermediary device communicating via a third SSL session established between the first intermediary device and the second intermediary device;

c) decrypting, by the first intermediary device, encrypted data received, via the first SSL session, from the server using a first session key of the first SSL session;

d) transmitting, by the first intermediary device to the second intermediary device via the third SSL session, the data encrypted using a third session key of the third SSL session;

e) decrypting, by the second intermediary device, the data encrypted via the third SSL session using the third session key; f) transmitting, by the second intermediary device to the client via the second SSL session, the data encrypted using the second session key of the second SSL session;

g) receiving by the second intermediary device from the first intermediary device SSL configuration information identifying a type of SSL proxying to be provided by the first intermediary device and the second intermediary device; and

h) establishing by the first intermediary device and the second intermediary device the type of SSL proxying.

2. The method of claim 1 , wherein step (a) further comprises transmitting, by the second intermediary device to the first intermediary device, a request from the client to establish a transport layer connection with the server, the first intermediary device modifying the request to indicate to the second intermediary device to perform Secure Socket Layer (SSL) acceleration.

3. The method of claim 1 , wherein step (b) further comprises transmitting, by the first intermediary device to the second intermediary, device a message identifying SSL configuration for client-side SSL proxying.

4. The method of claim 3 , wherein step (b) further comprises transmitting, by the second intermediary device, to the client a server hello, a server certificate and a server hello done message using the SSL configuration received from the first intermediary device.

5. The method of claim 3 , wherein step (b) further comprises transmitting, by the first intermediary device to the second intermediary device, a request to perform split SSL proxying.

6. The method of claim 1 , further comprising transmitting, by the second intermediary device to the first intermediary device, a request for a crypto operation.

7. The method of claim 6 , further comprising performing, by the first intermediary device, the requested crypto operation on behalf of the second intermediary device and communicating to second intermediary device a response to the request.

8. The method of claim 1 , wherein step (c) further comprises compressing by the first intermediary device the received data using a compression history stored on the first intermediary device.

9. The method of claim 1 , wherein step (e) further comprises decompressing by the second intermediary device the received data using the compression history stored on the second intermediary device.

10. The method of claim 1 , further comprising identifying, by the first intermediary device and the second intermediary device, the third SSL session from a pool of pre-established SSL sessions maintained by each of the first intermediary device and the second intermediary device.

11. A system for split proxying Secure Socket Layer (SSL) communications across intermediaries deployed between a client and a server, comprising:

means for establishing, by a first intermediary device in communication with a server, a first Secure Socket Layer (SSL) session with the server;

means for establishing, by a second intermediary device in communication with one or more clients, a second Secure Socket Layer (SSL) session with a client using SSL configuration information received from the first intermediary device, the second intermediary device and the first intermediary device communicating via a third SSL session established between the first intermediary device and the second intermediary device;

means for decrypting, by the first intermediary device, encrypted data received, via the first SSL session, from the server using a first session key of the first SSL session;

means for transmitting, by the first intermediary device to the second intermediary device via the third SSL session, the data encrypted using a third session key of the third SSL session;

means for decrypting, by the second intermediary device, the data encrypted via the third SSL session using the third session key;

means for transmitting, by the second intermediary device to the client via the second SSL session, the data encrypted using a second session key of the second SSL session;

means for receiving by the second intermediary device from the first intermediary device SSL configuration information identifying a type of SSL proxying to be provided by the first intermediary device and the second intermediary device; and

means for establishing by the first intermediary device and the second intermediary device the type of SSL proxying.

12. The system of claim 1 , further comprising means for transmitting, by the second intermediary device to the first intermediary device, a request from the client to establish a transport layer connection with the server, the first intermediary device modifying the request to indicate to the second intermediary device to perform Secure Socket Layer (SSL) acceleration.

13. The system of claim 1 , further comprising means for transmitting, by the first intermediary device to the second intermediary device, a message identifying SSL configuration for client-side SSL proxying.

14. The system of claim 3 , further comprising means for transmitting, by the second intermediary device, to the client a server hello, a server certificate and a server hello done message using the SSL configuration received from the first intermediary device.

15. The system of claim 3 , further comprising means for transmitting, by the first intermediary device to the second intermediary device, a request to perform split SSL proxying.

16. The system of claim 1 , further comprising means for transmitting, by the second intermediary device to the first intermediary device, a request for a crypto operation.

17. The system of claim 6 , further comprising means for performing, by the first intermediary device, the requested crypto operation on behalf of the second intermediary device and communicating to second intermediary a response to the request.

18. The system of claim 1 , further comprising means for compressing, by the first intermediary device, the received data using a compression history stored on the first intermediary device.

19. The system of claim 1 , further comprising means for decompressing, by the second intermediary device, the received data using the compression history stored on the second intermediary device.

20. The system of claim 1 , further comprising means for identifying, by the first intermediary device and the second intermediary device, the third SSL session from a pool of pre-established SSL sessions maintained by each of the first intermediary device and the second intermediary device.

21. The method of claim 1 , comprising receiving the SSL configuration information identifying the type of SSL proxying, the type of SSL proxying comprising split proxying or spoofing proxying.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2011
From: OVSIANNIKOV, MICHAEL
To: CITRIX SYSTEMS, INC.
Reel/Frame 025885/0863 →
Continuity (1)
Related Publication 20110264905A1 · Oct 27, 2011