IP Library Granted Patent US 10,778,684
Granted Patent B2
US 10,778,684 · App. 15/482,423 · Granted Sep 15, 2020

Systems and methods for securely and transparently proxying SAAS applications through a cloud-hosted or on-premise network gateway for enhanced security and visibility

Inventors: Punit Gupta (San Jose, CA); Saurabh Singh (Bengaluru, IN); Ravi Ganesh, V (Bengaluru, IN); Jong Kann (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L63/10H04L63/029H04L63/0272H04L63/0281H04L63/0435H04L63/0815H04L63/166H04L63/168H04L67/02H04L67/28H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,684
App. No.
15/482,423
Granted
Sep 15, 2020
Kind
B2
Abstract

Disclosed embodiments provide access to an application. An intermediary device may provide access to an application hosted by the server. The access may be provided to the client via a link that generates a first HTTP request for the application. The device may receive, from the client, the first HTTP request generated via the provided link. The device may rewrite an absolute URL of the application indicated in the first HTTP request, by replacing a first hostname of the server included in the absolute URL, with a URL segment generated by combining a unique string assigned to the first hostname with a second hostname of the device. The device may redirect the client to the rewritten absolute URL of the application.

Claims (33)

1. A method for providing access to an application, the method comprising:

providing, by a device intermediary between a client and a server, access to an application hosted by the server, the access provided to the client via a link that generates a first hypertext transfer protocol (HTTP) request for the application;

receiving, by the device from the client, the first HTTP request generated via the provided link;

rewriting, by the device, an absolute uniform resource locator (URL) of the application indicated in the first HTTP request by replacing a server hostname of the server included in the absolute URL with a URL segment to obfuscate the server hostname in the rewritten absolute URL and hide the server hostname from at least the client, the URL segment generated by prefixing a unique string assigned to the obfuscated server hostname to a device hostname of the device; and

redirecting, by the device, the client to the rewritten absolute URL with the server hostname obfuscated, wherein a domain name system (DNS) server for the client is configured with a DNS entry comprising an expression, the expression of the DNS entry including a wildcard prefixed to the device hostname, to cause the DNS server to resolve the rewritten absolute URL to an internet protocol (IP) address of the device.

2. The method of claim 1 , wherein the link comprises a link presented in a browser executing on the client, and the first HTTP request for the application is received from the browser.

3. The method of claim 1 , registering, by the device, the DNS server with the DNS entry comprising the expression, the expression of the DNS entry including the wildcard prefixed to the device hostname of the device.

4. The method of claim 1 , further comprising receiving, by the device, a second HTTP request from the client comprising the rewritten absolute URL, the rewritten absolute URL causing the DNS to direct the second HTTP request to the device.

5. The method of claim 1 , further comprising identifying, by the device, the unique string from a host header of a second HTTP request from the client, and decoding the unique string to obtain the server hostname of the server.

6. The method of claim 5 , further comprising performing, by the device, single sign-on (SSO) for a user of the client by sending a security assertion mark-up language (SAML) assertion to the server.

7. The method of claim 6 , further comprising receiving, by the device in response to the SAML assertion, an authentication token from the server.

8. The method of claim 4 , further comprising:

identifying, by the device from the rewritten absolute URL, a URL portion identifying the application; and

sending, by the device, a third HTTP request comprising the identified URL portion to the server to access the application.

9. The method of claim 8 , further comprising:

receiving, by the device, a response to the third HTTP request comprising the identified URL portion;

rewriting, by the device, a second absolute URL identified in the response, by replacing a hostname in the second absolute URL with a second URL segment generated by combining a second unique string assigned to the hostname, with the device hostname of the device; and

sending, by the device, the response updated with the rewritten second absolute URL, to the client.

10. The method of claim 1 , wherein providing the unique string comprises generating the unique string from the server hostname using an encoding scheme comprising one of: symmetric key encryption or base-32 encoding.

11. A system for providing access to an application, the system comprising:

a device that is intermediary between a client and a server, the device having a memory and at least one processor configured to:

provide access to an application hosted by the server, the access provided to the client via a link that generates a first hypertext transfer protocol (HTTP) request for the application; receive from the client the first HTTP request generated via the provided link;

rewrite an absolute uniform resource locator (URL) of the application indicated in the first HTTP request by replacing a server hostname of the server included in the absolute URL with a URL segment to obfuscate the server hostname in the rewritten absolute URL and hide the server hostname from at least the client, the URL segment generated by prefixing a unique string assigned to the obfuscated server hostname to a device hostname of the device; and

redirect the client to the rewritten absolute URL with the server hostname obfuscated, wherein a domain name system (DNS) server for the client is configured with a DNS entry comprising an expression, the expression of the DNS entry including a wildcard prefixed to the device hostname, to cause the DNS server to resolve the rewritten absolute URL to an internet protocol (IP) address of the device.

12. The system of claim 11 , wherein the link comprises a link presented in a browser executing on the client, and the first HTTP request for the application is received from the browser.

13. The system of claim 11 , wherein the device is further configured to register the DNS server with the DNS entry comprising the expression, the expression of the DNS entry including the wildcard prefixed to the device hostname of the device.

14. The system of claim 11 , wherein the device is further configured to receive a second HTTP request from the client comprising the rewritten absolute URL, the rewritten absolute URL causing the DNS to direct the second HTTP request to the device.

15. The system of claim 11 , wherein the device is further configured to identify the unique string from a host header of a second HTTP request from the client, and decode the unique string to obtain the server hostname of the server.

16. The system of claim 15 , wherein the device is further configured to perform single sign-on (SSO) for a user of the client by sending a security assertion mark-up language (SAML) assertion to the server.

17. The system of claim 16 , wherein the device is further configured to receive, in response to the SAML assertion, an authentication token from the server.

18. The system of claim 14 , wherein the device is further configured to identify, from the rewritten absolute URL, a URL portion identifying the application, and send a third HTTP request comprising the identified URL portion to the server to access the application.

19. The system of claim 18 , wherein the device is further configured to receive a response to the third HTTP request comprising the identified URL portion, rewrite a second absolute URL identified in the response by replacing a hostname in the second absolute URL with a second URL segment generated by combining a second unique string assigned to the hostname, with the device hostname of the device, and send the response updated with the rewritten second absolute URL to the client.

20. The system of claim 11 , wherein the device is further configured to generate the unique string from the server hostname using an encoding scheme comprising one of: symmetric key encryption or base-32 encoding.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2017
From: GUPTA, PUNIT; SINGH, SAURABH; GANESH, RAVI, V; KANN, JONG
To: CITRIX SYSTEMS, INC.
Reel/Frame 043796/0836 →
Continuity (1)
Related Publication 20180295134A1 · Oct 11, 2018
Cited By (1)
US 12,395,468