IP Library Granted Patent US 12,224,998
Granted Patent B2
US 12,224,998 · App. 17/488,663 · Granted Feb 11, 2025

Selection of gateways for reconnection upon detection of reachability issues with backend resources

Inventors: Vinay Kumar Kothiyal (San Jose, CA); Kevin Brock (Santa Clara, CA); Manoj Kumar Andol (San Jose, CA)
H04L63/0823H04L63/083H04L63/0876H04L67/01H04L67/1008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,224,998
App. No.
17/488,663
Granted
Feb 11, 2025
Kind
B2
Abstract

Described embodiments provide system and methods for selecting a device via which a client is to connect with a server. A client may identify a server and a plurality of devices intermediary to the client and the server via one of which the client is authenticated to connect to access the server using a certificate. The client may detect that the server is unreachable from the client authenticated to use a first connection via a first device of the plurality of devices using the certificate. The client may select, responsive to detecting that the server is unreachable, a second device of the plurality of devices via which the client is to access the server. The client may authenticate, using the certificate used to authenticate with the first device, the client to establish a second connection with the second device to access the server.

Claims (37)

1. A method of selecting a device via which a client is to connect to a server, comprising:

identifying, by a client, a server and a plurality of devices intermediary to the client and the server via one of which the client is authenticated to connect to access the server using a certificate;

detecting that the server is unreachable from the client authenticated to use a first connection via a first device of the plurality of devices using the certificate;

selecting, by the device responsive to detecting that the server is unreachable, a second device of the plurality of devices via which the client is to access the server; and

authenticating, by the client using the certificate used to authenticate with the first device, the client to establish a second connection with the second device to access the server.

2. The method of claim 1 , further comprising receiving, by the client, for establishing the first connection with the first device, the certificate to authenticate the client to connect with a network for secure communications.

3. The method of claim 1 , wherein identifying the server and the plurality of devices further comprises receiving a profile associated with the certificate for the client, the profile identifying a plurality of servers which the client is to access via the plurality of devices.

4. The method of claim 1 , wherein detecting that the server is unreachable further comprises monitoring for at least one response from the server to a message transmitted by at least one of the client or the first device.

5. The method of claim 1 , wherein detecting that the server is unreachable further comprises receiving, from the first device, an indication that the first device is unable to connect with the server.

6. The method of claim 1 , wherein selecting the second device further comprises selecting the second device from the plurality of device in accordance with a profile, the profile identifying a sequence for selection of the plurality of devices.

7. The method of claim 1 , wherein selecting the second device further comprises selecting the second device from the plurality of devices based at least on a network load of at least one of the plurality of devices.

8. The method of claim 1 , wherein establishing the second connection further comprises re-using the certificate used to authenticate the client in the first connection to authenticate the client for the second connection, without providing a prompt to a user of the client to enter authentication credentials.

9. The method of claim 1 , wherein establishing the second connection further comprises providing a prompt to a user of the client to enter authentication credentials for establishing the second connection.

10. The method of claim 1 , further comprising:

determining, by the client, that the server is unreachable from the client via none of the plurality of devices; and

providing, by the client, an indication that the server is unreachable via none of the plurality of devices.

11. A system for selecting a device via which a client is to connect to a server, comprising:

a client having one or more processors coupled with memory, configured to:

identify a server and a plurality of devices intermediary to the client and the server via one of which the client is authenticated to connect to access the server using a certificate;

detect that the server is unreachable from the client authenticated to use a first connection via a first device of the plurality of devices using the certificate;

select, responsive to detecting that the server is unreachable, a second device of the plurality of devices via which the client is to access the server; and

authenticate, using the certificate used to authenticate with the first device, the client to establish a second connection with the second device to access the server.

12. The system of claim 11 , wherein the client is further configured to receive a profile associated with the certificate for the client, the profile identifying a plurality of servers which the client is to access via the plurality of devices.

13. The system of claim 11 , wherein the client is further configured to select the second device from the plurality of device in accordance with a profile, the profile identifying a sequence for selection of the plurality of devices.

14. The system of claim 11 , wherein the client is further configured to select the second device from the plurality of devices based at least on a network load of at least one of the plurality of devices.

15. The system of claim 11 , wherein the client is further configured to re-use the certificate used to authenticate the client in the first connection to authenticate the client for the second connection, without providing a prompt to a user of the client to enter authentication credentials.

16. The system of claim 11 , wherein the client is further configured to provide a prompt to a user of the client to enter authentication credentials for establishing the second connection.

17. The system of claim 11 , wherein the client is further configured to:

determine that the server is unreachable from the client via none of the plurality of devices; and

provide an indication that the server is unreachable via none of the plurality of devices.

18. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

identify a server and a plurality of devices intermediary to the client and the server via one of which the client is authenticated to connect to access the server using a certificate;

detect that the server is unreachable from the client authenticated to use a first connection via a first device of the plurality of devices using the certificate;

select, responsive to detecting that the server is unreachable, a second device of the plurality of devices via which the client is to access the server; and

authenticate, using the certificate used to authenticate with the first device, the client to establish a second connection with the second device to access the server.

19. The non-transitory computer readable medium of claim 18 , wherein the program instructions further cause the one or more processors to receive a profile associated with the certificate for the client, the profile identifying a plurality of servers which the client is to access via the plurality of devices.

20. The non-transitory computer readable medium of claim 18 , wherein the program instructions further cause the one or more processors to re-use the certificate used to authenticate the client in the first connection to authenticate the client for the second connection, without providing a prompt to a user of the client to enter authentication credentials.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2021
From: KOTHIYAL, VINAY KUMAR; BROCK, KEVIN; ANDOL, MANOJ KUMAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 057641/0812 →
Continuity (1)
Related Publication 20230097099A1 · Mar 30, 2023
References Cited (5)
US 20100011126A1 · Hsu · 2010 [cited by examiner]
US 20110090842A1 · Hirano · 2011 [cited by examiner]
US 20170085651A1 · Harrison · 2017 [cited by examiner]
US 20200076801A1 · Funane · 2020 [cited by examiner]
US 20200252389A1 · Cao · 2020 [cited by examiner]