IP Library Granted Patent US 10,523,658
Granted Patent B2
US 10,523,658 · App. 15/695,793 · Granted Dec 31, 2019

Securing a data connection for communicating between two end-points

Inventors: Julien Brouchier (Great Cambourne, GB); Andrew David Cooper (Royston, GB); Richard James Cooper (Bedford, GB); Jean-Luc Claude Robert Giraud (Melbourn, GB); Ian Wright (Ramsey, GB); Christopher Morgan Mayers (Histon, GB)
Assignee: Citrix Systems, Inc.
H04L63/0823H04L9/0861H04L9/3234H04L9/3263H04L63/0281H04L63/0853H04L63/126H04L63/166H04L67/08H04L67/42H04L2209/64H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,658
App. No.
15/695,793
Granted
Dec 31, 2019
Kind
B2
Abstract

Methods and systems for securing a data connection for communicating between two end-points are described herein. One of the end-points may be a server and the other of the end-points may be a client that wants to communicate with the server. The data connection may be secured based on a previously-established secure connection and/or a self-signed or self-issued certificate. In some variations, by using the previously-established secure connection and/or a self-signed or self-issued certificate, the secure communication between the server and the client may be conducted without using a third-party authentication service and without requiring a third-party CA to issue a certificate for the server.

Claims (61)

1. A method comprising:

establishing a first secure data connection between a computing device and a client device;

generating, by a server, a self-signed or self-issued certificate for authenticating the server;

receiving, by the computing device, a request for an enterprise resource or enterprise service associated with the server;

generating first data to indicate an address of a gateway;

storing, in a location accessible to the gateway, the self-signed or self-issued certificate;

sending, to the client device via the first secure data connection, the first data;

based on a second secure data connection being established between the gateway and the client device, receiving, by the gateway and from the location, a first copy of the self-signed or self-issued certificate;

establishing, by the gateway, a third secure data connection between the gateway and the server;

receiving, by the gateway and from the server via the third secure data connection, a second copy of the self-signed or self-issued certificate;

authenticating, by the gateway, based on the first copy of the self-signed or self-issued certificate and the second copy of the self-signed or self-issued certificate, the server; and

sending, by the gateway and to the server via the third secure data connection, second data originally sent from the client device.

2. The method of claim 1 , wherein sending the first data is performed based on one or more integrity-protected messages.

3. The method of claim 1 , wherein receiving the request for the enterprise resource or the enterprise service is performed by receiving one or more integrity-protected messages.

4. The method of claim 1 , wherein the request for the enterprise resource or enterprise service comprises a request for a session of a remote desktop service;

wherein receiving the second copy of the self-signed or self-issued certificate is performed based on a request to a ticket authority; and

wherein the second data is associated with the session of the remote desktop service.

5. The method of claim 1 , wherein the third secure data connection is a confidentiality- and integrity-protected connection.

6. The method of claim 5 , wherein the third secure data connection is a Transport Layer Security (TLS) connection, and wherein the self-signed or self-issued certificate is a self-issued certificate.

7. The method of claim 1 , further comprising:

registering the server with a broker; and

assigning, by the broker, the server to a session for the enterprise resource or enterprise service.

8. The method of claim 7 , wherein the computing device is configured as an application store that enables download of one or more applications to the client device, and wherein the server, the broker, the location, and the application store are associated with an enterprise.

9. A method comprising:

establishing a first secure data connection between a computing device and a client device;

generating, by a server, a self-signed or self-issued certificate for authenticating the server;

receiving, by the computing device, a request for an enterprise resource or enterprise service associated with the server;

generating first data to indicate an address of a gateway;

sending, to the client device via the first secure data connection, the first data;

generating, by a ticket authority, a ticket that indicates address information for the server and the self-signed or self-issued certificate;

establishing a second secure data connection between the gateway and the client device;

retrieving, by the gateway and from the ticket authority, the ticket;

establishing, based on the address information indicated by the ticket, a third secure data connection, wherein the third secure data connection is between the gateway and the server;

receiving, by the gateway and from the server via the third secure data connection, a copy of the self-signed or self-issued certificate;

authenticating, by the gateway, based on the self-signed or self-issued certificate indicated by the ticket and the copy of the self-signed or self-issued certificate, the server; and

sending, by the gateway and to the server via the third secure data connection, second data originally sent from the client device.

10. The method of claim 9 , wherein sending the first data is performed based on one or more integrity-protected messages.

11. The method of claim 9 , wherein receiving the request for the enterprise resource or the enterprise service is performed by receiving one or more integrity-protected messages.

12. The method of claim 9 , wherein the request for the enterprise resource or enterprise service comprises a request for a session of a remote desktop service, and wherein the second data is associated with the session of the remote desktop service.

13. The method of claim 9 , wherein the third secure data connection is a confidentiality-and integrity-protected connection.

14. The method of claim 13 , wherein the third secure data connection is a Transport Layer Security (TLS) connection, and wherein the self-signed or self-issued certificate is a self-issued certificate.

15. The method of claim 9 , further comprising:

registering the server with a broker;

receiving, by the broker and from the server, the self-signed or self-issued certificate;

assigning, by the broker, the server to a session for the enterprise resource or enterprise service;

wherein the computing device is configured as an application store that enables download of one or more applications to the client device; and

wherein the server, the broker, the ticket authority, the gateway, and the application store are associated with an enterprise.

16. A method comprising:

generating, by a server associated with an enterprise, a self-signed or self-issued certificate for authenticating the server;

establishing a first secure data connection between a computing device associated with the enterprise and a client device;

receiving, by the computing device from the client device via the first secure data connection, a request for an enterprise resource or enterprise service associated with the server;

sending, by the computing device, first data that indicates an address of a gateway associated with the enterprise;

establish a second secure data connection between the gateway and the client device;

establishing, by the gateway, a third secure data connection between the gateway and the server;

authenticating, by the gateway, based on a first copy of the self-signed or self-issued certificate that is stored in a location associated with the enterprise and a second copy of the self-signed or self-issued certificate sent to the gateway from the server, the server; and

sending, by the gateway and to the server via the third secure data connection, second data originally sent from the client device.

17. The method of claim 16 , wherein sending the first data is performed based on one or more integrity-protected messages.

18. The method of claim 16 , wherein the self-signed or self-issued certificate is a self-issued certificate; wherein receiving the request for the enterprise resource or the enterprise service is performed by receiving one or more integrity-protected messages.

19. The method of claim 16 , wherein the request for the enterprise resource or enterprise service comprises a request for a session of a remote desktop service, and wherein the second data originally sent from the client device is associated with the session of the remote desktop service.

20. The method of claim 16 , wherein the third secure data connection is a confidentiality- and integrity-protected connection, and wherein the method further comprises:

based on establishing the third secure data connection, receiving, by the gateway and from the server via the third secure data connection, the second copy of the self-signed or self-issued certificate.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2017
From: BROUCHIER, JULIEN; COOPER, ANDREW DAVID; COOPER, RICHARD JAMES; GIRAUD, JEAN-LUC CLAUDE ROBERT; WRIGHT, IAN; MAYERS, CHRISTOPHER MORGAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 043491/0404 →
Continuity (1)
Related Publication 20190075099A1 · Mar 7, 2019