IP Library Granted Patent US 11,997,080
Granted Patent B2
US 11,997,080 · App. 17/138,030 · Granted May 28, 2024

Uniform resource locator validation

Inventors: Praveen Raja Dhanabalan (Bangalore, IN); Krishna Kumar KB (Bangalore, IN)
Assignee: Citrix Systems, Inc.
H04L63/0823H04L9/3263H04L9/3268H04L63/083H04L67/02H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,080
App. No.
17/138,030
Granted
May 28, 2024
Kind
B2
Abstract

A method for validating a Uniform Resource Locator (URL) includes generating electronic media content including the URL, generating a Certificate Signing Request (CSR) including the URL, sending the CSR to a certificate signing server, receiving a signed certificate corresponding to the CSR from the certificate signing server, and encoding the signed certificate as metadata in the electronic media content and/or encoding a serial number associated with the signed certificate as metadata in the electronic media content. A user can send the URL to another user through a chat message, an email, a word processing document or other business application, or a document which has a URL through a pen drive, email, or chat message. The certificate-based mechanism is used to validate the origin (sender) of the URL so that the recipients know that the URL can be accessed without having to separately analyze the security risks.

Claims (55)

1. A method for validating a uniform resource locator (URL), the method comprising:

generating electronic media content including the URL;

generating a Certificate Signing Request (CSR) for the URL by encoding a username in a certificate common name of the CSR and encoding the URL in a Subject Alternative Name (SAN) field of the CSR;

sending the CSR to a certificate signing server;

receiving a signed certificate corresponding to the CSR from the certificate signing server, wherein the signed certificate includes data to authenticate that the URL is sent by a sender client;

encoding, according to a public key cryptographic standard, the signed certificate as metadata in the electronic media content and/or an identifier associated with the signed certificate as metadata in the electronic media content, wherein the electronic media content includes at least two URLs, wherein the SAN field includes the at least two URLs, and wherein the encoding includes encoding the metadata including the at least two URLs; and

validating the URL in the electronic media content without user intervention based on the signed certificate encoded as metadata to ensure that the URL is not modified since creation, wherein validating the URL comprises:

detecting, in the metadata, the encoded signed certificate and/or the encoded serial number associated with the signed certificate,

matching the URL in the electronic media content to a domain name in a SAN field of the encoded signed certificate, and

validating the encoded signed certificate prior to accessing the URL.

2. The method of claim 1 , further comprising validating the URL by at least one of:

detecting, in the metadata, the encoded signed certificate and/or the encoded serial number associated with the signed certificate; and/or

matching the URL to a domain name in the encoded signed certificate.

3. The method of claim 2 , further comprising validating the URL prior to accessing the URL.

4. The method of claim 1 , further comprising scanning the electronic media content to identify the URL.

5. The method of claim 1 , further comprising sending the electronic media content including the URL and the metadata to a receiver.

6. The method of claim 1 , further comprising matching the URL in the electronic media content to a valid URL in the SAN field of the encoded signed certificate.

7. The method of claim 1 , wherein the username is associated with the sender client, and the SAN comprises the URL which is being shared with the electronic media content.

8. The method of claim 1 , further comprising a step of tracking a source of the electronic media content by including the username in the certificate common name of the signed certificate.

9. A computer program product including one or more non-transitory machine-readable mediums having instructions encoded thereon that when executed by at least one processor cause a process to be carried out, the process comprising:

generating electronic media content including at least one Uniform Resource Locator (URL);

generating a Certificate Signing Request (CSR) for the at least one URL including a Subject Alternative Name (SAN) field, the SAN field including the at least one URL;

sending the CSR to a certificate signing server;

receiving a signed certificate corresponding to the CSR from the certificate signing server, wherein the signed certificate includes data to authenticate that the URL is sent by a sender client;

encoding, according to a public key cryptographic standard, the signed certificate and/or a serial number associated with the signed certificate as metadata in the electronic media content including the at least one URL,

wherein the electronic media content includes at least two URLs, wherein the SAN field includes the at least two URLs, and wherein the encoding includes encoding the metadata including the at least two URLs; and

validating the URL in the electronic media content without user intervention based on the signed certificate encoded as metadata to ensure that the URL is not modified since creation, wherein validating the URL comprises:

detecting, in the metadata, the encoded signed certificate and/or the encoded serial number associated with the signed certificate,

matching the URL in the electronic media content to a domain name in a SAN field of the encoded signed certificate and

validating the encoded signed certificate prior to accessing the URL.

10. The computer program product of claim 9 , wherein the process further comprises scanning the electronic media content to identify the at least one URL.

11. The computer program product of claim 9 , wherein the process further comprises sending the electronic media content including the at least one URL and the encoded metadata to a receiver.

12. The computer program product of claim 9 , wherein the process further comprises:

generating the CSR by including a username in a certificate common name of the CSR such that the username is to be included in the certificate common name of the signed certificate received from the certificate signing server; and

validating the at least one URL by matching the username in the certificate common name of the signed certificate with a username of a sender that generated the electronic media content.

13. The computer program product of claim 12 , wherein the process further comprises verifying a user password subsequent to generating the CSR and prior to sending the CSR to the certificate signing server.

14. A system comprising:

a storage; and

at least one processor operatively coupled to the storage, the at least one processor configured to execute instructions stored in the storage that when executed cause the at least one processor to carry out a process including:

generating a Certificate Signing Request (CSR) including a username in a certificate common name of the CSR and a Subject Alternative Name (SAN) field, the SAN field including a Uniform Resource Locator (URL);

sending the CSR to a certificate signing server;

receiving a signed certificate corresponding to the CSR from the certificate signing server, wherein the signed certificate includes data to authenticate that the URL is sent by a sender client;

encoding, according to a public key cryptographic standard, the signed certificate and/or a serial number associated with the signed certificate as metadata in electronic media content including the URL, wherein the electronic media content includes at least two URLs, wherein the SAN field includes the at least two URLs, and wherein the encoding includes encoding the metadata including the at least two URLs; and

validating the URL in the electronic media content without user intervention based on the signed certificate encoded as the metadata to ensure that the URL is not modified since creation, wherein validating the URL comprises:

detecting, in the metadata, the encoded signed certificate and/or the encoded serial number associated with the signed certificate,

matching the URL in the electronic media content to a domain name in a SAN field of the encoded signed certificate, and

validating the encoded signed certificate prior to accessing the URL.

15. The system of claim 14 , wherein the process further comprises generating the electronic media content including the URL.

16. The system of claim 14 , wherein the process further comprises opening an authenticated communication channel from the sender to a certificate signing server, wherein the CSR is sent to the certificate signing server via the authenticated communication channel.

17. The system of claim 14 , wherein the process further comprises:

validating the URL by detecting, in the metadata, the encoded signed certificate and/or the encoded serial number associated with the signed certificate;

matching the URL in the electronic media content to a SAN field of the encoded signed certificate in the metadata; and

validating the encoded signed certificate prior to accessing the URL.

18. The system of claim 14 , wherein the process further comprises generating the CSR by including a non-URL unique username to be used as a certificate common name associated with the signed certificate in addition to the URL in the SAN field.

19. The system of claim 18 , wherein the process further comprises verifying a user password associated with the unique username subsequent to generating the CSR and prior to sending the CSR to the certificate signing server.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2021
From: DHANABALAN, PREVEEN RAJA; KUMAR KB, KRISHNA
To: CITRIX SYSTEMS, INC.
Reel/Frame 054797/0486 →
Continuity (1)
Related Publication 20220210146A1 · Jun 30, 2022