IP Library Granted Patent US 7,978,716
Granted Patent B2
US 7,978,716 · App. 12/336,795 · Granted Jul 12, 2011

Systems and methods for providing a VPN solution

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,978,716
App. No.
12/336,795
Granted
Jul 12, 2011
Kind
B2
Abstract

A system, apparatus and a method for implementing a secured communications link at a layer other than that at which packets are filtered are disclosed. In one embodiment, a computer system is configured to form a virtual private network (“VPN”) and comprises an address inspection driver to identify initial target packet traffic addressed to a target server. Also, the computer system includes a pseudo server module to receive rerouted initial target packet traffic from the address inspection driver. The pseudo server module is configured to convey packet regeneration instructions to a VPN gateway. The address inspection driver functions to identify additional target packet traffic addressed to the target server and routes the additional target packet traffic to the pseudo server. In one embodiment, the pseudo server is configured to strip header information from the additional target packet traffic to form a payload, and thereafter, to route the payload to the target.

Claims (29)

1. A method for securing, by a client, private network communications to a server via a gateway, the method comprising:

(a) establishing, by a pseudo server of a device, a secure communications link to a gateway in communication with a server on a private network, the pseudo server operating at a transport layer of a network stack of the device;

(b) receiving, by an address inspection driver of the device, network traffic generated by an application running on the device, the address inspection driver operating at a layer of the network stack below the transport layer;

(c) identifying, by the address inspection driver, that the network traffic is addressed to the server;

(d) communicating, by the address inspection driver, to the pseudo server the network traffic addressed to the server; and

(e) modifying, by the pseudo server, the network traffic for transmission via the transport layer to the gateway.

2. The method of claim 1 , wherein step (a) further comprises establishing by the pseudo server a secure tunnel over the transport layer to the gateway.

3. The method of claim 1 , wherein step (b) further comprises operating the address inspection driver at a network layer of the network stack.

4. The method of claim 1 , wherein step (b) further comprises operating the address inspection driver at a data link layer of the network stack.

5. The method of claim 1 , wherein step (b) further comprises intercepting, by the address inspection driver, the network traffic of the application.

6. The method of claim 1 , wherein step (c) further comprises identifying, by the address inspection driver, that the network traffic of the application is destined to the private network.

7. The method of claim 1 , wherein step (d) further comprises rerouting, by the address inspection driver, the network traffic to a port listened to by the pseudo server.

8. The method of claim 7 , further comprising sending, by the address inspection driver, control information via control packets to the pseudo server, the control information identifying one or more of the following: a local device address, and modifications to a packet to form a rerouted packet.

9. The method of claim 1 , wherein step (e) further comprises stripping, by the pseudo server, header information to form the modified network traffic and transmitting the modified network traffic to the gateway.

10. The method of claim 1 , wherein step (e) further comprises adding, by the pseudo server, to the modified network traffic regeneration instructions to instruct the gateway on regenerating the stripped header information on the private network.

11. A system for securing by a client communications to a server on a private network via a gateway, the system comprising:

a pseudo server of a device establishing a secure communications link to a gateway in communication with a server on a private network, the pseudo server operating at a transport layer of a network stack of the device;

an address inspection driver of the device receiving network traffic generated by an application running on the device, the address inspection driver operating at a layer of the network stack below the transport layer;

wherein the address inspection driver identifies that the network traffic is addressed to the server and communicates to the pseudo server the network traffic addressed to the server; and

wherein the pseudo server modifies the network traffic for transmission via the transport layer to the gateway.

12. The system of claim 11 , wherein the pseudo server establishes a secure tunnel over the transport layer to the gateway.

13. The system of claim 11 , wherein the address inspection driver operates at a network layer of the network stack.

14. The system of claim 11 , wherein the address inspection driver operates at a data link layer of the network stack.

15. The system of claim 11 , wherein the address inspection driver intercepts the network traffic of the application.

16. The system of claim 11 , wherein the address inspection driver identifies that the network traffic of the application is destined to the private network.

17. The system of claim 11 , wherein the address inspection driver reroutes the network traffic to a port listened to by the pseudo server.

18. The system of claim 17 , wherein the address inspection driver sends control information via control packets to the pseudo server, the control information identifying one or more of the following: a local device address, and modifications to a packet to form a rerouted packet.

19. The system of claim 11 , wherein the pseudo server strips header information to form the modified network traffic and transmits the modified network traffic to the gateway.

20. The system of claim 19 , wherein the pseudo server adds to the modified network traffic regeneration instructions to instruct the gateway on regenerating the stripped header information on the private network.

Assignments (10)
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2014
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC R.
To: CITRIX SYSTEMS, INC.
Reel/Frame 034490/0849 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 15, 2011
From: NET6, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 027392/0202 →
CHANGE OF NAME Recorded Apr 30, 2010
From: NET6, INC.
To: CITRIX GATEWAYS, INC.
Reel/Frame 024316/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2010
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT; BRUEGGEMANN, ERIC
To: NET6, INC.
Reel/Frame 024269/0451 →
Continuity (3)
Continuation 10988004 · Nov 12, 2004
Provisional Application 60524999 · Nov 24, 2003
Related Publication 20090158418A1 · Jun 18, 2009