IP Library Granted Patent US 8,782,755
Granted Patent B2
US 8,782,755 · App. 12/409,223 · Granted Jul 15, 2014

Systems and methods for selecting an authentication virtual server from a plurality of virtual servers

Inventors: James Harris (Santa Clara, CA); Rui Li (Santa Clara, CA); Arkesh Kumar (Santa Clara, CA); Ravindranath Thakur (Santa Clara, CA); Puneet Agarwal (Santa Clara, CA); Akshat Choudhary (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
G06F21/53G06F21/31H04L63/10H04L63/105H04L67/2814G06F2009/4557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,755
App. No.
12/409,223
Filed
Mar 23, 2009
Granted
Jul 15, 2014
Kind
B2
Art Unit
2493
USPC
726/5
Abstract

The present invention provides a system and method for dynamically selecting an authentication virtual server from a plurality of authentication virtual servers. A traffic management virtual server may determine from a request received from a client to access content of a server that the client has not been authenticated. The traffic management virtual server can identify a policy for selecting an authentication virtual server to provide authentication of the client. Responsive to the identification, the traffic management virtual server can select, via the policy, an authentication virtual server of the plurality of authentication virtual servers to authenticate the client. Responsive to the request, the traffic management virtual server may transmit a response to the client The response includes an instruction to redirect to the selected authentication virtual server.

Claims (40)

1. A method for dynamically selecting by a traffic management virtual server an authentication virtual server from a plurality of authentication virtual servers, the method comprising the steps of:

a) determining, by a traffic management virtual server of an appliance, from a request received from a client to access content of a server that the client has not been authenticated;

b) identifying, by the traffic management virtual server, a policy for selecting an authentication virtual server from a plurality of authentication virtual servers executing on the same appliance to provide authentication of the client;

c) selecting, by the traffic management virtual server, via the policy an authentication virtual server of the plurality of authentication virtual servers executing on the same appliance to authenticate the client;

d) transmitting, by the traffic management virtual server, to the client a response to the request, the response comprising an instruction to redirect to the selected authentication virtual server;

e) receiving, by the traffic management virtual server, a second request from the client, the second request comprising a session cookie identifying an authentication session of the authentication virtual server; and

f) determining, from the identified authentication session, one or more traffic management policies to apply to the second request.

2. The method of claim 1 , wherein step (a) further comprises determining, by the traffic management virtual server, that the request does not include a session cookie.

3. The method of claim 1 , wherein step (a) further comprises determining, by the traffic management virtual server, that the request does not include an index to a valid

authentication session.

4. The method of claim 1 , wherein step (b) further comprises identifying, by the traffic management virtual server, the policy for selecting the authentication virtual server based

on a user of the request.

5. The method of claim 1 , wherein step (b) further comprises identifying, by the traffic management virtual server, the policy for selecting the authentication virtual server based

on information collected about software installed on the client.

6. The method of claim 1 , wherein step (b) further comprises identifying, by the traffic management virtual server, the policy for selecting the authentication virtual server based

on information collected about an operating system on the client.

7. The method of claim 1 , wherein step (c) further comprises selecting, by the traffic management virtual server responsive to identification of the policy, the authentication

virtual server as a first type of authentication virtual server from a plurality of types of authentication virtual servers.

8. The method of claim 1 , wherein step (c) further comprises selecting, by the traffic management virtual server responsive to the policy, the authentication virtual server based on a type of authentication of a plurality of types of authentications.

9. The method of claim 1 , wherein step (c) further comprises selecting, by the traffic management virtual server responsive to the policy, the authentication virtual server based on negotiating with the client a type of authentication of a plurality of types of authentications.

10. A system for dynamically selecting by a traffic management virtual server an authentication virtual server from a plurality of authentication virtual servers, the system comprising:

a traffic management virtual server of an appliance determining from a request received from a client to access content of a server that the client has not been authenticated and identifying a policy for selecting an authentication virtual server from a plurality of authentication virtual servers executing on the same appliance to provide authentication of the client;

a policy engine of the appliance providing to the traffic management virtual server a policy to select an authentication virtual server of the plurality of authentication virtual servers executing on the same appliance to authenticate the client; and

a network engine of the traffic management virtual server transmitting to the client a response to the request, the response comprising an instruction to redirect to the selected authentication virtual server, wherein the traffic management virtual server receives a second request from the client, the second request comprising a session cookie identifying an authentication session of the authentication virtual server, and determines from the identified authentication session one or more traffic management policies to apply to the second request.

11. The system of claim 10 , wherein the traffic management virtual server determines that the request does not include a session cookie.

12. The system of claim 10 , wherein the traffic management virtual server determines that the request does not include an index to a valid authentication session.

13. The system of claim 10 , wherein the policy engine identifies the policy for selecting the authentication virtual server based on a user of the request.

14. The system of claim 10 , wherein the policy engine identifies the policy for selecting the authentication virtual server based on information collected about software installed on the client.

15. The system of claim 10 , wherein the policy engine identifies the policy for selecting the authentication virtual server based on information collected about an operating system on the client.

16. The system of claim 10 , wherein the traffic management virtual server selects,

responsive to identification of the policy, the authentication virtual server as a first type of authentication virtual server from a plurality of types of authentication virtual servers.

17. The system of claim 10 , wherein the traffic management virtual server selects,

responsive to the policy, the authentication virtual server based on a type of authentication of a plurality of types of authentications.

18. The system of claim 10 , wherein the traffic management virtual server selects, responsive to the policy, the authentication virtual server based on negotiating with the client a type of authentication of a plurality of types of authentications.

19. A method for dynamically selecting by a traffic management virtual server an authentication virtual server from a plurality of authentication virtual servers, the method comprising the steps of:

a) determining, by a traffic management virtual server of an appliance, from a first request received from a client to access content of a server that the client has not been authenticated;

b) selecting, by the traffic management virtual server, via a policy an authentication virtual server from a plurality of authentication virtual servers to authenticate the client;

c) transmitting, by the traffic management virtual server, to the client a response to the request, the response comprising an instruction to redirect to the selected authentication virtual server for authentication;

d) receiving, by the traffic management virtual server, a second request from the client to access the content of the server, the second request comprising a session cookie obtained from the selected authentication virtual server, the session cookie identifying an authentication session; and

e) determining, from the identified authentication session, one or more traffic management policies to apply to the second request.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2009
From: HARRIS, JAMES; KUMAR, ARKESH; LI, RUI; THAKUR, RAVINDRANATH; AGARWAL, PUNEET; CHOUDHARY, AKSHAT
To: CITRIX SYSTEMS, INC.
Reel/Frame 022733/0585 →
Continuity (2)
Provisional Application 61161918 · Mar 20, 2009
Related Publication 20100242092A1 · Sep 23, 2010