IP Library › Granted Patent US 10,826,905
Granted Patent B2
US 10,826,905 · App. 15/368,876 · Granted Nov 3, 2020

Secure access to on-premises web services from multi-tenant cloud services

Inventor: Ashish Gujarathi (Parkland, FL)
Assignee: Citrix Systems, Inc.
H04L63/10H04L9/006H04L63/0281H04L63/0823H04L63/168H04L67/02H04L67/10H04L67/16H04L67/2838H04L61/1511H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,826,905
App. No.
15/368,876
Granted
Nov 3, 2020
Kind
B2
Abstract

Methods, systems, and computer-readable media for using a multi-tenant web relay service to provide secure access to on-premises web services from a tenant-specific cloud service are described herein. In one or more embodiments, a multi-tenant web relay service may receive from a tenant-specific cloud service a connection request to an on-premises web service hosted within a tenant datacenter. The connection request may comprise data indicating a display-friendly name of the web service and the tenant datacenter. Responsive to receiving the request, the web relay service may forward the connection request to the on-premises web service via a rendezvous support service and a web relay agent. Responsive to receiving the connection request, the on-premises web service may generate a response which may be relayed back to the tenant-specific cloud service by the multi-tenant web relay service.

Claims (92)

1. A method comprising:

receiving, by a multi-tenant web relay service and from a tenant-specific cloud service, a Hypertext Transfer Protocol (HTTP) request to connect to a web service hosted within a tenant datacenter, wherein the HTTP request comprises: data indicating a display-friendly name of the web service, data identifying the tenant datacenter, and a tenant-specific signature generated by the tenant-specific cloud service using a tenant-specific private key for authenticating the tenant-specific cloud service to the multi-tenant web relay service;

responsive to receiving the HTTP request from the tenant-specific cloud service, authenticating, by the multi-tenant web relay service, the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key;

responsive to authenticating the HTTP request, establishing, by the multi-tenant web relay service, and via a rendezvous support service, a communication channel with a web relay agent, wherein the web relay agent is located at the tenant datacenter;

creating, by the multi-tenant web relay service, a modified HTTP request, wherein creating the modified HTTP request comprises removing the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key from the HTTP request received from the tenant-specific cloud service;

forwarding, by the multi-tenant web relay service and to the web relay agent, the modified HTTP request via the communication channel;

causing, by the multi-tenant web relay service, the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service, wherein causing the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service comprises:

causing the web relay agent to determine a service-account credential using only the display-friendly name of the web service; and

causing the web relay agent to authenticate to the web service with the service-account credential;

receiving, by the multi-tenant web relay service and from the web relay agent, a response to the modified HTTP request; and

relaying, by the multi-tenant web relay service and to the tenant-specific cloud service, the received response to the modified HTTP request.

2. The method of claim 1 ,

wherein authenticating the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key comprises authenticating, by the multi-tenant web relay service, that the HTTP request received from the tenant-specific cloud service comes from a valid tenant that is authorized to connect to the tenant datacenter using only the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key.

3. The method of claim 1 ,

wherein the web service hosted within the tenant datacenter comprises an on-premises Public Key Infrastructure (PKI) service; and

wherein the response to the modified HTTP request comprises an end-user certificate.

4. The method of claim 1 ,

wherein the web service hosted within the tenant datacenter comprises an enterprise storefront service; and

wherein the response to the modified HTTP request comprises a listing indicative of applications available on the enterprise storefront service.

5. The method of claim 1 ,

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to authenticate to the web service using only the service-account credential.

6. The method of claim 1 ,

wherein the HTTP request received from the tenant-specific cloud service comprises a partial address relative to a base address of the web service; and

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to determine the base address to the web service using only the display-friendly name of the web service; and

causing the web relay agent to determine a network address to the web service using the base address to the web service and the partial address relative to the base address of the web service.

7. The method of claim 1 ,

wherein creating the modified HTTP request comprises encapsulating the HTTP request received from the tenant-specific cloud service into a byte-array, and

wherein forwarding the modified HTTP request via the communication channel comprises transmitting the byte-array to the web relay agent.

8. A system comprising:

a web relay agent, located at a tenant datacenter, configured to receive HTTP requests directed to a web service hosted within the tenant datacenter and configured to transmit responses to the HTTP requests; and

a multi-tenant web relay service configured to:

receive, from a tenant-specific cloud service, a Hypertext Transfer Protocol (HTTP) request to connect to the web service, wherein the HTTP request comprises: data indicating a display-friendly name of the web service, data identifying the tenant datacenter, and a tenant-specific signature generated by the tenant-specific cloud service using a tenant-specific private key for authenticating the tenant-specific cloud service to the multi-tenant web relay service;

responsive to receiving the HTTP request from the tenant-specific cloud service, authenticate the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key;

responsive to authenticating the HTTP request, establish, via a rendezvous support service, a communication channel with the web relay agent;

create a modified HTTP request, wherein creating the modified HTTP request comprises removing the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key from the HTTP request received from the tenant-specific cloud service;

forward, to the web relay agent, the modified HTTP request via the communication channel;

cause the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service, wherein causing the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service comprises:

causing the web relay agent to determine a service-account credential using only the display-friendly name of the web service; and

causing the web relay agent to authenticate to the web service with the service-account credential;

receive, from the web relay agent, a response to the modified HTTP request; and

relay, to the tenant-specific cloud service, the received response to the modified HTTP request.

9. The system of claim 8 ,

wherein authenticating the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key comprises authenticating that the HTTP request received from the tenant-specific cloud service comes from a valid tenant that is authorized to connect to the tenant datacenter using only the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key.

10. The system of claim 8 ,

wherein the web service hosted within the tenant datacenter comprises an on-premises Public Key Infrastructure (PKI) service; and

wherein the response to the modified HTTP request comprises an end-user certificate.

11. The system of claim 8 ,

wherein the web service hosted within the tenant datacenter comprises an enterprise storefront service; and

wherein the response to the modified HTTP request comprises a listing indicative of applications available on the enterprise storefront service.

12. The system of claim 8 ,

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to authenticate to the web service using only the service-account credential.

13. The system of claim 8 ,

wherein the HTTP request received from the tenant-specific cloud service comprises a partial address relative to a base address of the web service; and

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to determine the base address to the web service using only the display-friendly name of the web service; and

causing the web relay agent to determine a network address to the web service using the base address to the web service and the partial address relative to the base address of the web service.

14. The system of claim 8 ,

wherein creating the modified HTTP request comprises encapsulating the HTTP request received from the tenant-specific cloud service into a byte-array, and

wherein forwarding the modified HTTP request via the communication channel comprises transmitting the byte-array to the web relay agent.

15. One or more non-transitory computer readable media storing computer readable instructions that, when executed by an apparatus, cause the apparatus to:

receive, by a multi-tenant web relay service and from a tenant-specific cloud service, a Hypertext Transfer Protocol (HTTP) request to connect to a web service hosted within a tenant datacenter, wherein the HTTP request comprises: data indicating a display-friendly name of the web service, data identifying the tenant datacenter, and a tenant-specific signature generated by the tenant-specific cloud service using a tenant-specific private key for authenticating the tenant-specific cloud service to the multi-tenant web relay service;

responsive to receiving the HTTP request from the tenant-specific cloud service, authenticate, by the multi-tenant web relay service, the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key;

responsive to authenticating the HTTP request, establish, by the multi-tenant web relay service, and via a rendezvous support service, a communication channel with a web relay agent, wherein the web relay agent is located at the tenant datacenter;

create, by the multi-tenant web relay service, a modified HTTP request, wherein creating the modified HTTP request comprises removing the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key from the HTTP request received from the tenant-specific cloud service;

forward, by the multi-tenant web relay service and to the web relay agent, the modified HTTP request via the communication channel;

cause, by the multi-tenant web relay service, the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service, wherein causing the web relay agent to access the web service hosted within the tenant datacenter based on the display-friendly name of the web service comprises:

causing the web relay agent to determine a service-account credential using only the display-friendly name of the web service; and

causing the web relay agent to authenticate to the web service with the service-account credential;

receive, by the multi-tenant web relay service and from the web relay agent, a response to the modified HTTP request; and

relay, by the multi-tenant web relay service and to the tenant-specific cloud service, the received response to the modified HTTP request.

16. The one or more non-transitory computer readable media of claim 15 ,

wherein authenticating the HTTP request using the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key comprises authenticating, by the multi-tenant web relay service, that the HTTP request received from the tenant-specific cloud service comes from a valid tenant that is authorized to connect to the tenant datacenter using only the tenant-specific signature generated by the tenant-specific cloud service using the tenant-specific private key.

17. The one or more non-transitory computer readable media of claim 15 ,

wherein the web service hosted within the tenant datacenter comprises an on-premises Public Key Infrastructure (PKI) service; and

wherein the response to the modified HTTP request comprises an end-user certificate.

18. The one or more non-transitory computer readable media of claim 15 ,

wherein the web service hosted within the tenant datacenter comprises an enterprise storefront service; and

wherein the response to the modified HTTP request comprises a listing indicative of applications available on the enterprise storefront service.

19. The one or more non-transitory computer readable media of claim 15 ,

wherein the HTTP request received from the tenant-specific cloud service comprises a partial address relative to a base address of the web service; and

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to determine the base address to the web service using only the display-friendly name of the web service; and

causing the web relay agent to determine a network address to the web service using the base address to the web service and the partial address relative to the base address of the web service.

20. The one or more non-transitory computer readable media of claim 15 ,

wherein the causing the web relay agent to access the web service comprises:

causing the web relay agent to authenticate to the web service using only the service-account credential.

21. The one or more non-transitory computer readable media of claim 15 ,

wherein creating the modified HTTP request comprises encapsulating the HTTP request received from the tenant-specific cloud service into a byte-array, and

wherein forwarding the modified HTTP request via the communication channel comprises transmitting the byte-array to the web relay agent.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: GUJARATHI, ASHISH
To: CITRIX SYSTEMS, INC.
Reel/Frame 040829/0344 →
Continuity (1)
Related Publication 20180159856A1 · Jun 7, 2018
Cited By (2)
US 12,289,321 US 12,615,241