IP Library Granted Patent US 8,638,795
Granted Patent B2
US 8,638,795 · App. 12/855,335 · Granted Jan 28, 2014

Systems and methods for quality of service of encrypted network traffic

Inventors: Steve Jackowski (Santa Cruz, CA); Seth Keith (Los Gatos, CA); Mike Ovsiannikov (Saratoga, CA); Daljit Singh (San Jose, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,638,795
App. No.
12/855,335
Granted
Jan 28, 2014
Kind
B2
Abstract

The present invention is directed towards systems and methods for providing classification of an encrypted network packet for performing QoS and acceleration techniques. Encrypted packets may be classified by a first classifier at a first portion of a network stack of a device as corresponding to a first predetermined application, and an application identifier may be included with the packet. In some embodiments, the packets may be decrypted in an order dependent on a first classification of the encrypted network packet. After decryption, packets may be reclassified as corresponding to a second predetermined application by a second classifier operating at a second portion of a network stack of the device above the first portion. Thus, network performance may be enhanced and optimized by providing QoS and acceleration engines with packet- or data-specific information corresponding to the application, while avoiding inefficiencies due to a lack of prioritization of decryption.

Claims (26)

1. A method for providing classification of encrypted network traffic, the method comprising:

(a) classifying, by a first classifier operating at a first portion of a network stack of a device, an encrypted packet received via a network port;

(b) including with the packet, by the first classifier, an application identifier corresponding to a first predetermined application identified by the classification;

(c) receiving, by a second classifier operating at a second portion of the network stack above the first portion, the application identifier and the encrypted packet;

(d) reclassifying, by the second classifier, the encrypted packet received from the first classifier to a second predetermined application based on decrypted content of the encrypted packet;

(e) replacing, by the second classifier, the application identifier with a second application identifier of the second predetermined application if the second classifier determines the second predetermined application is more granular than the first predetermined application; and

(f) maintaining the application identifier of the first classifier if the second classifier determines that the first predetermined application is more granular than the second predetermined application.

2. The method of claim 1 , wherein step (a) further comprises classifying, by the first classifier, the packet based on unencrypted portions of the packet.

3. The method of claim 1 , wherein step (a) further comprises receiving a packet comprising an encrypted payload and classifying the packet based on non-payload content.

4. The method of claim 1 , wherein step (b) further comprises attaching, by the first classifier, the application identifier to the packet.

5. The method of claim 1 , wherein step (b) further comprises modifying, by the first classifier, the packet to include the application identifier.

6. The method of claim 1 , wherein step (d) further comprises identifying, by the second classifier, the second predetermined application within a tunnel of encrypted network traffic.

7. The method of claim 1 , wherein step (d) further comprises determining, by the second classifier, that the first predetermined application has a child relationship to the second predetermined application.

8. The method of claim 1 , wherein step (d) further comprises determining, by the second classifier, whether to use the second predetermined application or the first predetermined application for classification of the packet.

9. A system for providing classification of encrypted network traffic, the system comprising:

a device intermediary to and receiving network traffic between a plurality of clients and a plurality of servers;

a first classifier operating at a first portion of a network stack of the device, the first classifier classifying an encrypted packet received via a network port and including with the packet an application identifier corresponding to a first predetermined application identified by the classification; and

a second classifier operating at a second portion of the network stack above the first portion, the second classifier: (i) receiving the application identifier and the encrypted packet, and (ii) reclassifying the encrypted packet received from the first classifier to a second predetermined application based on decrypted content of the encrypted packet;

wherein the second classifier replaces the application identifier with a second application identifier of the second predetermined application if the second classifier determines that the second predetermined application is more granular than the first predetermined application, and maintains the application identifier of the first classifier if the second classifier determines that the first predetermined application is more granular than the second predetermined application.

10. The system of claim 9 , wherein the first classifier classifies the packet based on unencrypted portions of the packet.

11. The system of claim 9 , wherein the device receives a packet comprising an encrypted payload and the first classifier classifies the packet based on non-payload content.

12. The system of claim 9 , wherein the first classifier attaches the application identifier to the packet.

13. The system of claim 9 , wherein the first classifier modifies the packet to include the application identifier.

14. The system of claim 9 , wherein the second classifier identifies the second predetermined application within a tunnel of encrypted network traffic.

15. The system of claim 9 , wherein the second classifier determines that the first predetermined application has a child relationship to the second predetermined application.

16. The system of claim 9 , wherein second classifier determines whether to use the second predetermined application or the first predetermined application for classification of the packet.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2013
From: JACKOWSKI, STEVE; KEITH, SETH; OVSIANNIKOV, MIKE; SINGH, DALJIT
To: CITRIX SYSTEMS, INC.
Reel/Frame 031824/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2013
From: JACKOWSKI, STEVE; KEITH, SETH; OVSIANNIKOV, MIKE; SINGH, DALJIT
To: FOLEY AND LARDNER LLP
Reel/Frame 029765/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2011
From: JACKOWSKI, STEVE; KEITH, SETH; OVSIANNIKOV, MIKE
To: CITRIX SYSTEMS, INC.
Reel/Frame 026920/0380 →
Continuity (1)
Related Publication 20120039337A1 · Feb 16, 2012