IP Library › Granted Patent US 10,218,734
Granted Patent B2
US 10,218,734 · App. 15/148,374 · Granted Feb 26, 2019

Systems and methods for improving security of secure socket layer (SSL) communications

Inventors: Anoop Reddy (San Jose, CA); Kenneth Bell (Sunnyvale, CA); Georgios Oikonomou (Patras, GR); Kurt Roemer (Grayslake, IL)
Assignee: Citrix Systems, Inc.
H04L63/1433G06F9/45533G06F9/45558H04L9/002H04L9/3268H04L61/1511H04L63/0428H04L63/06H04L63/0884H04L63/14H04L63/1416H04L63/166H04L67/42G06F2009/45587H04L61/6013
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,218,734
App. No.
15/148,374
Granted
Feb 26, 2019
Kind
B2
Abstract

The disclosure is directed to a system for improving security of SSL communications. The system can include an device intermediary between one or more servers, one or more clients, a plurality of agents, and a web service. The servers can be configured to receive SSL connections and issue SSL certificates. The device can include a virtual server associated with a respective one of the servers, such that the SSL certificate of the respective server is transmitted through the device. The device can generate service fingerprints for the one or more servers. Each service fingerprint can include information corresponding to an SSL certificate of the virtual server, one or more DNS aliases for a virtual IP address of the respective virtual server, one or more port numbers serving the SSL certificate, and an IP address serviced by the device. The device also can transmit the service fingerprints to a web service.

Claims (33)

1. A method for improving security of secure socket layer (SSL) communication, the method comprising:

determining, by a device intermediary to a plurality of clients and one or more servers, a configuration change associated with a virtual server executing on the device, the virtual server configured as a named entity of the device that at least one client of the plurality of clients uses to access applications hosted on a server of the one or more servers;

generating, by the device, responsive to determining the configuration change associated with the virtual server, a service fingerprint for the virtual server, the service fingerprint including a domain name service (DNS) alias for a virtual internet protocol (IP) address of the virtual server, a port number of the virtual server serving a secure socket layer (SSL) certificate of the virtual server, an IP address serviced by the device, and the SSL certificate;

transmitting, by the device, the generated service fingerprint to a web service to identify whether the device is under attack; and

receiving, by the device from the web service, a notification that the device is under attack, responsive to the web service comparing the generated service fingerprint with data received by the web service from an agent.

2. The method of claim 1 , wherein receiving the notification that the device is under attack is further responsive to the web service determining that i) the SSL certificate does not match a second SSL certificate received from the agent that attempted to establish a secure connection with the virtual server, or ii) that the IP address of the virtual server does not match a second IP address received from the agent.

3. The method of claim 2 , wherein the notification indicates that the attack is a man-in-the-middle (MITM) attack.

4. The method of claim 1 , wherein determining the configuration change associated with the virtual server comprises determining, by the device, that the SSL certificate of the virtual server has replaced an expired SSL certificate of the virtual server.

5. The method of claim 1 , wherein determining the configuration change associated with the virtual server comprises determining, by the device, that the virtual server is associated with a new IP address not previously serviced by the virtual server.

6. The method of claim 1 , wherein determining the configuration change associated with the virtual server comprises determining, by the device, that the virtual server services a new DNS name not previously serviced by the virtual server.

7. The method of claim 1 , wherein the service fingerprint does not include a private key corresponding to the SSL certificate.

8. The method of claim 1 , further comprising generating, by the device, a unique verification key to allow the virtual server to implement a private extension of an SSL handshake when the SSL certificate is served based on the unique verification key.

9. The method of claim 8 , wherein generating the service fingerprint further comprises generating, by the device, the service fingerprint including the unique verification key.

10. The method of claim 8 , further comprising:

receiving, from the agent, a request to establish a secure connection between the agent and the virtual server; and

transmitting, by the device, the SSL certificate and the unique verification key to the agent, responsive to receiving the request to establish the secure connection.

11. A system for improving security of secure socket layer (SSL) communication, comprising:

a device including one or more processors and a memory and intermediary to a plurality of clients and one or more servers, the device configured to:

determine a configuration change associated with a virtual server executing on the device, the virtual server configured as a named entity of the device that at least one client of the plurality of clients uses to access applications hosted on a server of the one or more servers;

generate, responsive to determining the configuration change associated with the virtual server, a service fingerprint for the virtual server, the service fingerprint including a domain name service (DNS) alias for a virtual internet protocol (IP) address of the virtual server, a port number of the virtual server serving a secure socket layer (SSL) certificate of the virtual server, an IP address serviced by the device, and the SSL certificate;

transmit the generated service fingerprint to a web service to identify that the device is under attack; and

receive, from the web service, a notification that the device is under attack, responsive to the web service comparing the generated service fingerprint with data received by the web service from an agent.

12. The system of claim 11 , wherein to receive the notification that the device is under attack, the device is further configured to receive the notification responsive to the web service determining that i) the SSL certificate does not match a second SSL certificate received from the agent that attempted to establish a secure connection with the virtual server, or ii) that the IP address of the virtual server does not match a second IP address received from the agent.

13. The system of claim 12 , wherein the notification indicates that the attack is a man-in-the-middle (MITM) attack.

14. The system of claim 11 , wherein the device is further configured to determine that the SSL certificate of the virtual server has replaced an expired SSL certificate of the virtual server.

15. The system of claim 11 , wherein the device is further configured to determine that the virtual server is associated with a new IP address not previously serviced by the virtual server.

16. The system of claim 11 , wherein the device is further configured to determine that the virtual server services a new DNS name not previously serviced by the virtual server.

17. The system of claim 11 , wherein the service fingerprint does not include a private key corresponding to the SSL certificate.

18. The system of claim 11 , wherein the device is further configured to generate a unique verification key to allow the virtual server to implement a private extension of an SSL handshake when the SSL certificate is served based on the unique verification key.

19. The system of claim 18 , wherein the device is further configured to generate the service fingerprint to include the unique verification key.

20. The system of claim 18 , wherein the device further comprises a secure connection interface configured to:

receive, from the agent, a request to establish a secure connection between the agent and the virtual server; and

transmit the SSL certificate and the unique verification key to the agent, responsive to receiving the request to establish the secure connection.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2016
From: REDDY, ANOOP; BELL, KENNETH; OIKONOMOU, GEORGIOS; ROEMER, KURT
To: CITRIX SYSTEMS, INC.
Reel/Frame 038917/0032 →
Continuity (2)
Provisional Application 62158876 · May 8, 2015
Related Publication 20160330230A1 · Nov 10, 2016
Cited By (1)
US 12,625,720