IP Library Granted Patent US 9,264,429
Granted Patent B2
US 9,264,429 · App. 14/462,204 · Granted Feb 16, 2016

Systems and methods for using end point auditing in connection with traffic management

Inventors: James Harris (San Jose, CA); Rui Li (Santa Clara, CA); Arkesh Kumar (San Jose, CA); Ravindranath Thakur (Bangalore, IN); Puneet Agarwal (Bangalore, IN); Akshat Choudhary (Bangalore, IN); Punit Gupta (Bangalore, IN)
Assignee: CITRIX SYSTEMS, INC.
H04L63/0876G06F21/31G06F21/53H04L63/08H04L63/0884H04L63/10H04L63/105H04L63/20G06F2009/4557H04L63/166H04L67/2814
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,264,429
App. No.
14/462,204
Filed
Aug 18, 2014
Granted
Feb 16, 2016
Kind
B2
Art Unit
2431
USPC
726/25
Abstract

The present invention provides a system and method of managing traffic traversing an intermediary based on a result of end point auditing. An authentication virtual server of an intermediary may determine a result of an end point analysis scan of a client. Responsive to the determination, the traffic management virtual server can obtain the result from the authentication virtual server. Further, the traffic management virtual server may apply the result in one or more traffic management policies to manage network traffic of a connection of the client traversing the intermediary. In some embodiments, the authentication virtual server may receive one or more expressions evaluated by the client. The one or more expressions identifies one or more attributes of the client. The traffic management virtual server can also determine a type of compression or encryption for the connection based on applying the one or more traffic management policies using the result.

Claims (28)

1. A method comprising:

a) determining, by a first virtual server of an intermediary device external to a client device and a target server, a result of an end point scan of the client device initiated by the first virtual server responsive to an access request from the client device to the target server, the first virtual server configured to perform authentication of client device to allow access to the target server;

b) establishing, by the first virtual server, an authentication session upon authentication of the client device;

c) receiving, by a second virtual server of the intermediary device different from the first virtual server, a request from the client that identifies the authentication session, wherein the second virtual server is configured to manage traffic of the client device; and

d) using, by the second virtual server, information from the authentication session to make a decision on controlling traffic of a connection of the client device based on one or more traffic management policies.

2. The method of claim 1 , wherein (a) further comprises initiating, by the first virtual server, the end point scan of the client device responsive to the client device requesting access to the server via the intermediary device.

3. The method of claim 1 , wherein (b) further comprises storing, by the first virtual server, in the authentication session one of a uniform resource locator or domain of the second virtual server.

4. The method of claim 1 , wherein (b) further comprises storing, by the first virtual server, the result of the end point scan in the authentication session.

5. The method of claim 1 , wherein (c) further comprises receiving, by the second virtual server, a cookie with the request, the cookie created by the first virtual server and configured to identify the authentication session.

6. The method of claim 1 , wherein (d) further comprises applying, by the second virtual server, the result of the end point scan stored in the authentication session in one or more policies to control traffic of the connection of the client device.

7. The method of claim 1 , wherein (d) further comprises identifying, by the second virtual server, a policy from the authentication session from which to make the decision on controlling traffic.

8. The method of claim 7 , further comprising applying, by the second virtual server, the policy identified from the authentication session to control traffic of the connection of the client device.

9. The method of claim 1 , wherein (d) further comprises determining, by the second virtual server based on information in the authentication session, one of a type of encryption or type of compression to use for the connection of the client device.

10. The method of claim 1 , wherein (d) further comprises using, by the second virtual server, the result of the end point scan stored in the authentication session in one or more policies to control traffic of the connection of the client device.

11. A system comprising:

An intermediary device external to a client device and a target server,

a first virtual server configured on the intermediary device to perform authentication of the client device to allow access to the target server and further configured to determine a result of an end point scan of the client device initiated by the first virtual server responsive to an access request from the client device to the target server and establish an authentication session upon authentication of the client;

a second virtual server, different from the first virtual server, configured on the intermediary, wherein the second virtual server is configured to manage traffic of the client device and to receive a request from the client device that identifies the authentication session; and

wherein the second virtual server is configured to use information from the authentication session to make a decision on controlling traffic of a connection of the client device based on one or more traffic management policies.

12. The system of claim 11 , wherein the first virtual server is further configured to initiate the end point scan of the client device responsive to the client device requesting access to the target server via the intermediary device.

13. The system of claim 11 , wherein the first virtual server is further configured store in the authentication session one of a uniform resource locator or domain of the second virtual server.

14. The system of claim 11 , wherein the first virtual server is further configured to store the result of the end point scan in the authentication session.

15. The system of claim 11 , wherein the second virtual server is further configured to receive a cookie with the request, the cookie established by the first virtual server and configured to identify the authentication session.

16. The system of claim 11 , wherein the second virtual server is further configured to apply the result of the end point scan stored in the authentication session in one or more policies to control traffic of the connection of the client device.

17. The system of claim 11 , wherein the second virtual server is further configured identify a policy from the authentication session from which to make the decision on controlling traffic.

18. The system of claim 17 , wherein the second virtual server is further configured to apply the policy identified from the authentication session to control traffic of the connection of the client device.

19. The system of claim 11 , wherein the second virtual server is further configured to determine one of a type of encryption or type of compression to use for the connection of the client device.

20. The system of claim 11 , wherein the second virtual server is further configured to use the result of the end point scan stored in the authentication session in one or more policies to control traffic of the connection of the client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2015
From: THAKUR, RAVINDRANATH; AGARWAL, PUNEET; CHOUDHARY, AKSHAT; GUPTA, PUNIT; HARRIS, JAMES; LI, RUI; KUMAR, ARKESH
To: CITRIX SYSTEMS, INC.
Reel/Frame 035462/0072 →
Continuity (3)
Continuation 12409322 · Mar 23, 2009
Provisional Application 61161918 · Mar 20, 2009
Related Publication 20140359728A1 · Dec 4, 2014