IP Library › Granted Patent US 8,230,214
Granted Patent B2
US 8,230,214 · App. 11/466,014 · Granted Jul 24, 2012

Systems and methods for optimizing SSL handshake processing

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,230,214
App. No.
11/466,014
Granted
Jul 24, 2012
Kind
B2
Abstract

A method for enabling efficient SSL handshakes through precomputing of handshake messages, the method includes: receiving, by an appliance, a server certificate identifying a server; generating, by the appliance, at least one of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message; storing, by the appliance, the generated messages; receiving, by the appliance from a client, an SSL client hello message identifying the server; and transmitting, by the appliance to the client, an SSL server hello message and at least one of the stored messages. Corresponding systems are also described.

Claims (30)

1. A method for enabling efficient SSL handshakes through precomputing of handshake messages, the method comprising:

(a) receiving, by a device intermediary to a client and a server, a server certificate of the server;

(b) generating, by the device , one or more of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message;

(c) storing, by the device , the one or more generated messages prior to receiving an SSL client hello message identifying the server;

(d) receiving, by the device from the client, an SSL client hello message identifying the server; and

(e) transmitting, by the device to the client, an SSL server hello message and at least one of the one or more stored messages.

2. The method of claim 1 , wherein step (a) comprises receiving, by the device intermediary to the client and the server and providing access to the server, a server certificate identifying the server.

3. The method of claim 1 , wherein step (a) comprises receiving, by a device providing access to a plurality of servers, a plurality of server certificates, each identifying one of the plurality of servers.

4. The method of claim 1 , wherein step (b) comprises generating, by the device , (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

5. The method of claim 1 , wherein step (b) comprises generating, by the device for each of a plurality of received server certificates, (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

6. The method of claim 1 , wherein step (b) comprises generating, by the device prior to receiving an SSL client hello message, at least one of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

7. The method of claim 1 , wherein step (b) comprises generating, by the device prior to receiving an SSL client hello message, (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

8. The method of claim 1 , wherein step (b) comprises generating, by the device prior to receiving an SSL client hello message identifying the server, (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

9. The method of claim 1 , wherein step (e) comprises transmitting, by the device to the client, an SSL server hello message and at least two of the stored messages, wherein at least two of the stored messages are transmitted in a single transport layer packet.

10. The method of claim 1 , wherein step (e) comprises transmitting, by the device to the client, an SSL server hello message and at least two of the stored messages, wherein at least two of the stored messages are transmitted in a single network layer packet.

11. A computer implemented system for enabling efficient SSL handshakes through precomputing of handshake messages, the system comprising: a network device intermediary to a client and a server which

receives a server certificate of the server;

generates one or more of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message;

stores the one or more generated messages prior to receiving an SSL client hello message identifying the server;

receives, from a client, an SSL client hello message identifying the server; and

transmits, to the client, an SSL server hello message and at least one of the one or more stored messages.

12. The system of claim 11 wherein the device provides access to the server.

13. The system of claim 11 wherein the device provides access to a plurality of servers, and receives a plurality of server certificates, each identifying one of the plurality of servers.

14. The system of claim 11 wherein the device generates (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

15. The system of claim 11 wherein the device generates, for each of a plurality of received server certificates, (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

16. The system of claim 11 wherein the device generates, prior to receiving an SSL client hello message, at least one of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

17. The system of claim 11 wherein the device generates, prior to receiving an SSL client hello message, (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

18. The system of claim 11 wherein the device generates, prior to receiving an SSL client hello message identifying the server, at least one of: (i) an SSL server certificate message comprising the received server certificate, (ii) an SSL client certificate request message, and (iii) an SSL hello done message.

19. The system of claim 11 wherein the device transmits, to the client, an SSL server hello message and at least two of the stored messages, wherein at least two of the stored messages are transmitted in a single transport layer packet.

20. The system of claim 11 wherein the device transmits, to the client, an SSL server hello message and at least two of the stored messages, wherein at least two of the stored messages are transmitted in a single network layer packet.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2012
From: KANEKAR, TUSHAR; UDUPA, SIVAPRASAD
To: CITRIX SYSTEMS, INC.
Reel/Frame 028438/0932 →
Continuity (1)
Related Publication 20080046717A1 · Feb 21, 2008