IP Library Granted Patent US 12,652,313
Granted Patent B2
US 12,652,313 · App. 18/373,465 · Granted Jun 9, 2026

Methods for generating an action based on TLS parameters and devices thereof

Inventors: John Ray Clark (Bedford, NH); Jason R. Adams (Spokane Valley, WA); Mudit Tyagi (Camas, WA); Judge K. Arora (Eastsound, WA)
Assignee: F5, Inc.
H04L63/166H04L63/0435H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,313
App. No.
18/373,465
Granted
Jun 9, 2026
Kind
B2
Abstract

Methods, non-transitory computer readable media, network traffic manager apparatuses, and systems that assist with generating insights with TLS parameters includes receiving a request from a client for establishing a TLS connection to a server. In some examples, the request comprises parameters for the TLS connection. Next, the network traffic manager apparatus determines an identity of the client based on the TLS parameters in the request unique to the client and executes an action based on the TLS parameters which alters a handling of the request.

Claims (58)

1 . A method for generating customized actions for an identified client, the method implemented by a network traffic management system comprising network traffic apparatuses, client devices, or server devices, the method comprising:

receiving a request from a client for establishing a transport layer security (TLS) connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determining an identity of the client based on the TLS parameters in the request unique to the client using a database of known clients by accessing the database to match the TLS parameters in the request to the corresponding unique combination of TLS parameters for one of the known clients to determine the identity of the client; and

executing an action with respect to the request or the identified client based on stored rules associated with the identified client in the database.

2 . The method as set forth in claim 1 , further comprising:

retrieving historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determining whether the identified client is a suspicious client based on the historical activity associated with the identified client;

wherein the action is a security action when the identified client is a suspicious client; and

wherein the executed security action is an additional inspection of the request, an additional inspection of a subsequent request from the client, dropping the request, or dropping the subsequent request from the client.

3 . The method as set forth in claim 2 , wherein the action comprises a redirect of the request through a different traffic path.

4 . The method as set forth in claim 2 , wherein the action comprises:

altering an encryption policy or an encryption algorithm of the client for the request or the subsequent request from the client; or

adjusting a quality of service for the identified client, and wherein adjusting the quality of service comprises selecting a corresponding bandwidth, throughput, latency, or jitter for the request or the subsequent request from the client.

5 . The method as set forth in claim 2 , wherein the action comprises:

classifying the identified client into a predetermined category; and

modifying a treatment of a plurality of subsequent requests from the identified client based on the predetermined category.

6 . A non-transitory computer readable medium having stored thereon instructions for establishing a connection to a server with a certificate comprising executable code which when executed by processors, causes the processors to:

receive a request from a client for establishing a transport layer security (TLS) connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client using a database of known clients by accessing the database to match the TLS parameters in the request to the corresponding unique combination of TLS parameters for one of the known clients to determine the identity of the client; and

execute an action with respect to the request or the identified client based on stored rules associated with the identified client in the database.

7 . The medium as set forth in claim 6 , wherein the executable code which when executed by the processors, further causes the processors to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client;

wherein the action is a security action when the identified client is a suspicious client; and

wherein the executed security action is an additional inspection of the request, an additional inspection of a subsequent request from the client, dropping the request, or dropping the subsequent request from the client.

8 . The medium as set forth in claim 6 , wherein the action comprises a redirect of the request through a different traffic path.

9 . The medium as set forth in claim 6 , wherein the action comprises:

altering an encryption policy or an encryption algorithm of the client for the request or the subsequent request from the client; or

adjusting a quality of service for the identified client, and wherein adjusting the quality of service comprises selecting a corresponding bandwidth, throughput, latency, or jitter for the request or the subsequent request from the client.

10 . The medium as set forth in claim 6 , wherein the action comprises: classifying the identified client into a predetermined category; and modifying a treatment of a plurality of subsequent requests from the identified client based on the predetermined category.

11 . A network traffic manager apparatus, comprising memory comprising programmed instructions stored in the memory and processors configured to be capable of executing the programmed instructions stored in the memory to:

receive a request from a client for establishing a transport layer security (TLS) connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client using a database of known clients by accessing the database to match the TLS parameters in the request to the corresponding unique combination of TLS parameters for one of the known clients to determine the identity of the client; and

execute an action with respect to the request or the identified client based on stored rules associated with the identified client in the database.

12 . The device as set forth in claim 11 , wherein the processors are further configured to be capable of executing the programmed instructions stored in the memory to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client;

wherein the action is a security action when the identified client is a suspicious client; and

wherein the executed security action is an additional inspection of the request, an additional inspection of a subsequent request from the client, dropping the request, or dropping the subsequent request from the client.

13 . The device as set forth in claim 11 , wherein the action comprises a redirect of the request through a different traffic path.

14 . The device as set forth in claim 11 , wherein the action comprises:

altering an encryption policy or an encryption algorithm of the client for the request or the subsequent request from the client; or

adjusting a quality of service for the identified client, and wherein adjusting the quality of service comprises selecting a corresponding bandwidth, throughput, latency, or jitter for the request or the subsequent request from the client.

15 . The device as set forth in claim 11 , wherein the action comprises: classifying the identified client into a predetermined category; and modifying a treatment of a plurality of subsequent requests from the identified client based on the predetermined category.

16 . A network traffic management system, comprising traffic management apparatuses, client devices, or server devices, the network traffic management system comprising memory comprising programmed instructions stored thereon and processors configured to be capable of executing the stored programmed instructions to:

receive a request from a client for establishing a transport layer security (TLS) connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client using a database of known clients by accessing the database to match the TLS parameters in the request to the corresponding unique combination of TLS parameters for one of the known clients to determine the identity of the client; and

execute an action with respect to the request or the identified client based on stored rules associated with the identified client in the database.

17 . The network traffic management system of claim 16 , wherein the processors are further configured to be capable of executing the programmed instructions stored in the memory to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client;

wherein the action is a security action when the identified client is a suspicious client; and

wherein the executed security action is an additional inspection of the request, an additional inspection of a subsequent request from the client, dropping the request, or dropping the subsequent request from the client.

18 . The network traffic management system of claim 16 , wherein the action comprises a redirect of the request through a different traffic path.

19 . The network traffic management system of claim 16 , wherein the action comprises:

altering an encryption policy or an encryption algorithm of the client for the request or the subsequent request from the client; or

adjusting a quality of service for the identified client and wherein adjusting the quality of service comprises selecting a corresponding bandwidth, throughput, latency, or jitter for the request or the subsequent request from the client.

20 . The network traffic management system of claim 16 , wherein the action comprises: classifying the identified client into a predetermined category; and modifying a treatment of a plurality of subsequent requests from the identified client based on the predetermined category.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: CLARK, JOHN RAY; ADAMS, JASON R.; TYAGI, MUDIT; ARORA, JUDGE K.
To: F5, INC.
Reel/Frame 066653/0190 →
Continuity (1)
Related Publication 20250106255A1 · Mar 27, 2025
References Cited (14)
US 7369537B1 · Kirchhoff · 2008 [cited by applicant]
US 10432406B1 · Amdahl · 2019 [cited by examiner]
US 12107878B1 · Mathews · 2024 [cited by examiner]
US 20020129236A1 · Nuutinen · 2002 [cited by examiner]
US 20160179494A1 · Pavlov · 2016 [cited by examiner]
US 20200236114A1 · Patil · 2020 [cited by examiner]
US 20220070193A1 · Konda · 2022 [cited by examiner]
US 20220255839A1 · Dhanabalan et al. · 2022 [cited by applicant]
US 20230156038A1 · Konda · 2023 [cited by examiner]
EP 3767916A1 · 2021 [cited by applicant]
WO WO2015080661A1 · 2015 [cited by examiner]
WO WO2020140114A1 · 2020 [cited by examiner]
European Search Report Dated Jan. 13, 2025. European Patent Application No. 24202623.5. [cited by applicant]
European Search Report for EP 24202604.5. European Patent Office. Search Report. Jan. 21, 2025. [cited by applicant]