IP Library Granted Patent US 9,253,193
Granted Patent B2
US 9,253,193 · App. 14/049,918 · Granted Feb 2, 2016

Systems and methods for policy based triggering of client-authentication at directory level granularity

Inventors: Sivaprasad R. Udupa (Sunnyvale, FL); Tushar Kanekar (Santa Clara, CA); Tejus Ag (Bangalore, IN)
Assignee: CITRIX SYSTEMS, INC.
H04L63/10H04L63/0272H04L63/0428H04L63/0823H04L63/166H04L63/20H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,253,193
App. No.
14/049,918
Filed
Oct 9, 2013
Granted
Feb 2, 2016
Kind
B2
Art Unit
2433
USPC
726/21
Abstract

Systems and methods are disclosed for an appliance to authenticate access of a client to a protected directory on a server via a connection, such as a secure SSL connection, established by the appliance. A method comprises the steps of: receiving, by an appliance, a first request from a client on a first network to access a server on a second network, the appliance providing the client a virtual private network connection from the first network to the second network; determining, by the appliance, the first request comprises access to a protected directory of the server; associating, by the appliance, an authentication policy with the protected directory, the authentication policy specifying an action to authenticate the client's access to the protected directory; and transmitting, by the appliance in response to the authentication policy, a second request to the client for an authentication certificate. Corresponding systems are also disclosed.

Claims (23)

1. A method comprising:

(a) receiving, by a device intermediary to a client and a server, a first request from the client to access a protected resource of the server;

(b) determining, by the device, that a predetermined portion of the first request matches a corresponding portion specified by a policy, the policy applied responsive to the first request to access the protected resource and specifying an action for the device to request an authentication certificate from the client responsive to the determination that the predetermined portion of the first request matches the corresponding portion specified by the policy, wherein the predetermined portion of the first request includes at least one of a uniform resource locator (URL) pattern, an identifier of one of a method or function, a directory identifier, a client network identifier, a server network identifier, a network port, and a secure socket layer (SSL) parameter; and

(c) transmitting, by the device responsive to the action specified by the policy and while queuing the first request, a second request to the client for the authentication certificate.

2. The method of claim 1 , wherein the protected resource comprises a directory.

3. The method of claim 1 , wherein step (a) further comprises receiving, by the device, the first request via an established first transport layer connection between the device and the client.

4. The method of claim 3 , wherein step (c) further comprises preventing, by the device, access to the protected resource via a second transport layer connection between the device and the server until validation of an authentication certificate of the client.

5. The method of claim 1 , wherein step (b) further comprises determining, by the device, whether each request of the client matches the policy.

6. The method of claim 1 , further comprising receiving, by the device, the authentication certificate from the client responsive to the second request.

7. The method of claim 6 , further comprising validating, by the device, the authentication certificate and responsive to validation, transmitting the queued first request to the server.

8. The method of claim 6 , further comprising inserting, by the device responsive to the policy, into the first request for transmission to the server, a portion of the client's response to the request for the authentication certificate.

9. The method of claim 1 , further comprising inserting, by the device responsive to the policy, into the first request for transmission to the server, data related to the authentication certificate.

10. A system comprising:

a device intermediary to a client and a server, the device is configured to receive a first request from the client to access a protected resource of the server, determine that a predetermined portion of the first request matches a corresponding portion specified by a policy, the policy applied responsive to the first request to access the protected resource and specifying an action for the device to request an authentication certificate from the client responsive to determining that the predetermined portion of the first request matches the corresponding portion specified by the policy, wherein the predetermined portion of the first request includes at least one of a uniform resource locator (URL) pattern, an identifier of one of a method or function, a directory identifier, a client network identifier, a server network identifier, a network port, and a secure socket layer (SSL) parameter; and

wherein the device is configured to transmit, responsive to the action specified by the policy and while queuing the first request, a second request to the client for the authentication certificate.

11. The system of claim 10 , wherein the protected resource comprises a directory.

12. The system of claim 10 , wherein the device is further configured to receive the first request via an established first transport layer connection between the device and the client.

13. The system of claim 12 , wherein the device is further configured to prevent access to the protected resource via a second transport layer connection between the device and the server until validation of an authentication certificate of the client.

14. The system of claim 10 , wherein the device is further configured to determine whether each request of the client matches the policy.

15. The system of claim 10 , wherein the device is further configured to receive the authentication certificate from the client responsive to the second request.

16. The system of claim 15 , wherein the device is further configured to validate the authentication certificate and responsive to validation, transmitting the queued first request to the server.

17. The system of claim 15 , further comprising inserting, by the device responsive to the policy, into the first request for transmission to the server, a portion of the client's response to the request for the authentication certificate.

18. The system of claim 10 , further comprising inserting, by the device responsive to the policy, into the first request for transmission to the server, data related to the authentication certificate.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2013
From: UDUPA, SIVAPRASAD; KANEKAR, TUSHAR; AG, TEJUS
To: CITRIX SYSTEMS, INC
Reel/Frame 031661/0760 →
Continuity (2)
Continuation 11462350 · Aug 3, 2006
Related Publication 20140041010A1 · Feb 6, 2014