IP Library Granted Patent US 8,566,925
Granted Patent B2
US 8,566,925 · App. 11/462,350 · Granted Oct 22, 2013

Systems and methods for policy based triggering of client-authentication at directory level granularity

Inventors: Sivaprasad Udupa (Sunnyvale, CA); Tushar Kanekar (Santa Clara, CA); Tejus Ag (Bangalore, IN)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,566,925
App. No.
11/462,350
Filed
Aug 3, 2006
Granted
Oct 22, 2013
Kind
B2
Art Unit
2433
USPC
726/21
Abstract

Systems and methods are disclosed for an appliance to authenticate access of a client to a protected directory on a server via a connection, such as a secure SSL connection, established by the appliance. A method comprises the steps of: receiving, by an appliance, a first request from a client on a first network to access a server on a second network, the appliance providing the client a virtual private network connection from the first network to the second network; determining, by the appliance, the first request comprises access to a protected directory of the server; associating, by the appliance, an authentication policy with the protected directory, the authentication policy specifying an action to authenticate the client's access to the protected directory; and transmitting, by the appliance in response to the authentication policy, a second request to the client for an authentication certificate. Corresponding systems are also disclosed.

Claims (39)

1. A method for an appliance to authenticate access of a client to a protected resource on a server via the appliance, the method comprising the steps of:

(a) receiving, by an appliance, a client request to access a protected directory of a server, the appliance providing access to the server via a transport layer connection;

(b) determining, by the appliance, that the protected directory matches a predetermined directory specified in a client authentication policy of the appliance, the client authentication policy applied on a per-directory and per-request basis and identifying an action for the appliance to request a client authentication certificate from the client responsive to matching the predetermined directory;

(c) queuing, by the appliance in response to matching the predetermined directory, the client request to prevent access to the protected resource at the server via the transport layer connection until an authentication certificate of the client is validated in accordance with the client authentication policy; and

(d) transmitting, by the appliance in response to the action identified by the client authentication policy, a request to the client for the authentication certificate.

2. The method of claim 1 , comprising determining, by the appliance one or more of the following portions of the client request matches a corresponding specification of the client authentication policy: a Uniform Resource Locator (URL) pattern, an identifier of one of a method or function, a directory, a client network identifier, a server network identifier, a network port, and a Secure Socket Layer (SSL) parameter.

3. The method of claim 1 , comprising determining, by the appliance, the client has been previously authenticated to access the protected resource, and allowing access, by the appliance, to the protected resource.

4. The method of claim 1 , specifying, by the client authentication policy, that the authentication certificate is mandatory.

5. The method of claim 4 , comprising not transmitting, by the appliance, the client request to the server upon one of receiving an invalid authentication certificate or not receiving an authentication certificate.

6. The method of claim 1 , specifying, by the authentication policy, that the authentication certificate is optional.

7. The method of claim 6 , comprising transmitting, by the appliance, the client request to the server upon one of not receiving an authentication certificate from the client or receiving an invalid authentication certificate from the client.

8. The method of claim 6 , comprising inserting, by the appliance, into the client request a portion of the client's response to the request for the authentication certificate, and transmitting the client request to the server.

9. The method of claim 1 , comprising inserting, by the appliance in response to the client authentication policy, data related to the authentication certificate into a Hypertext Transfer Protocol (HTTP) header of the client request, and transmitting the client request to the server.

10. The method of claim 1 , comprising inserting, by the appliance in response to the client authentication policy, Secure Socket Layer (SSL) information into a Hypertext Transfer Protocol (HTTP) header of the client request, and transmitting the client request to the server.

11. The method of claim 1 , comprising identifying, by the client authentication policy, a pattern for associating a portion of the client request with the client authentication policy.

12. The method of claim 1 , wherein step (c) comprises preventing, by the appliance, establishment of a transport layer connection with the server.

13. An appliance for providing finer control for authenticating access of a client to a protected resource on a server, the appliance comprising:

means for receiving a client request to access a protected directory of a server, the appliance providing access to the server via a transport layer connection;

means for determining that the protected directory matches a predetermined directory specified in of a client authentication policy of the appliance, the client authentication policy applied on a per-directory and per-request basis and identifying an action for the appliance to request a client authentication certificate from the client responsive to matching the predetermined directory;

means for queuing in response to matching the predetermined director, the client request to prevent access to the protected resource at the server via the transport layer connection until an authentication certificate of the client is validated in accordance with the client authentication policy; and

means for transmitting, in response to the action identified by the client authentication policy, a request to the client for the authentication certificate.

14. The appliance of claim 13 , comprising means for determining one or more of the following portions of the client request matches a corresponding specification of the client authentication policy: a Uniform Resource Locator (URL) pattern, an identifier of one of a method or function, a directory, a client network identifier, a server network identifier, a network port, and a Secure Socket Layer (SSL) parameter.

15. The appliance of claim 13 , comprising means for determining the client has been previously authenticated to access the protected resource, and allowing access, by the appliance, to the protected resource.

16. The appliance of claim 13 , comprising means for specifying, by the client authentication policy, that the authentication certificate is mandatory.

17. The appliance of claim 16 , comprising means for not transmitting, by the appliance, the client request to the server upon one of receiving an invalid authentication certificate or not receiving an authentication certificate.

18. The appliance of claim 13 , comprising means for specifying, by the authentication policy, that the authentication certificate is optional.

19. The appliance of claim 18 , comprising means for transmitting the client request to the server upon one of not receiving an authentication certificate or receiving an invalid authentication certificate from the client.

20. The appliance of claim 18 , comprising means for inserting, into the client request a portion of the client's response to the request for the authentication certificate, and transmitting the client request to the server.

21. The appliance of claim 13 , comprising means for inserting, in response to the client authentication policy, data related to the authentication certificate into a Hypertext Transfer Protocol (HTTP) header of the client request, and transmitting the client request to the server.

22. The appliance of claim 13 , comprising means for inserting, by the appliance in response to the client authentication policy, Secure Socket Layer (SSL) information into a Hypertext Transfer Protocol (HTTP) header of the client request, and transmitting the client request to the server.

23. The appliance of claim 13 , comprising means for identifying, by the client authentication policy, a pattern for associating a portion of the client request with the client authentication policy.

24. The appliance of claim 13 , comprising means for preventing establishment of a transport layer connection with the server.

25. A method for an appliance to control access of a client to a protected directory on a server via the appliance, the method comprising:

(a) receiving, by an appliance, a request from a client to access a first protected directory of a server via the appliance;

(b) determining, by the appliance, that the first protected directory matches a predetermined directory specified in a client authentication policy of the appliance;

(c) determining, by the appliance, based on the first protected directory matching the predetermined directory specified in the client authentication policy, that the client authentication policy identifies an action for the appliance to request the authentication certificate from the client;

(d) transmitting, by the appliance in response to the action identified by the client authentication policy, a request to the client for the authentication certificate;

(e) receiving, by an appliance, a request from a client to access a second protected directory of the server via the appliance; and

(f) determining, by the appliance, that the second protected directory is not specified in the client authentication policy of the appliance, and that a request for the authentication certificate is not required by the client authentication policy.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2007
From: UDUPA, SIVAPRASAD; KANEKAR, TUSHAR; AG, TEJUS
To: CITRIX SYSTEMS, INC.
Reel/Frame 018752/0021 →
Continuity (1)
Related Publication 20080034410A1 · Feb 7, 2008