IP Library Granted Patent US 8,844,040
Granted Patent B2
US 8,844,040 · App. 12/409,322 · Granted Sep 23, 2014

Systems and methods for using end point auditing in connection with traffic management

Inventors: James Harris (San Jose, CA); Rui Li (Santa Clara, CA); Arkesh Kumar (San Jose, CA); Ravindranath Thakur (Karnataka, IN); Puneet Agarwal (Karnataka, IN); Akshat Choudhary (Karnataka, IN); Punit Gupta (Karnataka, IN)
Assignee: Citrix Systems, Inc.
H04L63/20H04L63/08H04L63/166H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,844,040
App. No.
12/409,322
Granted
Sep 23, 2014
Kind
B2
Abstract

The present invention provides a system and method of managing traffic traversing an intermediary based on a result of end point auditing. An authentication virtual server of an intermediary may determine a result of an end point analysis scan of a client. Responsive to the determination, the traffic management virtual server can obtain the result from the authentication virtual server. Further, the traffic management virtual server may apply the result in one or more traffic management policies to manage network traffic of a connection of the client traversing the intermediary. In some embodiments, the authentication virtual server may receive one or more expressions evaluated by the client. The one or more expressions identifies one or more attributes of the client. The traffic management virtual server can also determine a type of compression or encryption for the connection based on applying the one or more traffic management policies using the result.

Claims (26)

1. A method of managing traffic traversing an intermediary based on a result of end point analysis, the method comprising:

a) determining, by an authentication virtual server of an intermediary device between at least one client device and at least one server, a result of an end point analysis scan of a client device initiated by the authentication virtual server and processing the result of the end point analysis scan before forwarding, by the authentication virtual server, to a separate and differently configured traffic management virtual server of the intermediary device, the authentication virtual server further configured to perform authentication of a user or the client device;

b) obtaining, by the traffic management virtual server, the result from the authentication virtual server; and

c) applying, by the traffic management virtual server, the result in one or more traffic management policies to manage network traffic of a connection of the client device traversing the intermediary.

2. The method of claim 1 , wherein step (a) further comprises receiving, by the authentication virtual server, from the client an expression identifying a presence on the client of one of the following: a version of an operating system, a service pack of the operating system, a running service, a running process, and a file.

3. The method of claim 1 , wherein step (a) further comprises receiving, by the authentication virtual server, from the client an expression identifying one of a presence or a version of one of the following: antivirus software, personal firewall software, anti-spam software, and internet security software.

4. The method of claim 1 , wherein step (a) further comprises receiving, by the authentication virtual server, one or more expressions evaluated by the client, the one or more expressions identifying one or more attributes of the client.

5. The method of claim 1 , wherein step (b) further comprises providing, by the authentication virtual server, as the result an evaluation of one or more expressions identifying one or more attributes of the client.

6. The method of claim 1 , wherein step (b) further comprises providing the result, by the authentication virtual server, as input to the one or more traffic management policies of the traffic management virtual server.

7. The method of claim 1 , wherein step (c) further comprises determining, by the traffic management virtual server, a type of compression for the connection based on applying the one or more traffic management policies using the result.

8. The method of claim 1 , wherein step (c) further comprises determining, by the traffic management virtual server, a type of encryption for the connection based on applying the one or more traffic management policies using the result.

9. The method of claim 1 , wherein step (c) further comprises determining, by the traffic management virtual server, one or more file type associations for the connection based on applying the one or more traffic management policies using the result.

10. The method of claim 1 , wherein step (c) further comprises determining, by the traffic management virtual server, to one of use or not use a single-sign on for the connection based on applying the result via the one or more traffic management policies.

11. An intermediary for managing traffic traversing the intermediary based on a result of end point analysis, the intermediary comprising:

a device between at least one client device and at least one server,

an authentication virtual server of the device for performing authentication of a user or the client device, the authentication virtual server further configured for determining a result of an end point analysis scan of the client device initiated by the authentication virtual server, and for processing the result of the end point analysis scan before forwarding to a separate and differently configured traffic management virtual server of the intermediary;

the traffic management virtual server obtaining the result forwarded from the authentication virtual server, and applying the result in one or more traffic management policies to manage a connection of the client device traversing the intermediary.

12. The intermediary of claim 11 , wherein the authentication virtual server receives from the client an expression identifying a presence on the client of one of the following: a version of an operating system, a service pack of the operating system, a running service, a running process, and a file.

13. The intermediary of claim 11 , wherein the authentication virtual server receives from the client an expression identifying one of a presence or a version of one of the following: antivirus software, personal firewall software, anti-spam software, and internet security software.

14. The intermediary of claim 11 , wherein the authentication virtual server receives one or more expressions evaluated by the client, the one or more expressions identifying one or more attributes of the client.

15. The intermediary of claim 11 , wherein the authentication virtual server provides as the result an evaluation of one or more expressions identifying one or more attributes of the client.

16. The intermediary of claim 11 , wherein the authentication virtual server provides the result as input to the one or more traffic management policies of the traffic management virtual server.

17. The intermediary of claim 11 , wherein the traffic management virtual server determines a type of compression for the connection based on applying the one or more traffic management policies using the result.

18. The intermediary of claim 11 , wherein the traffic management virtual server determines a type of encryption for the connection based on applying the one or more traffic management policies using the result.

19. The intermediary of claim 11 , wherein the traffic management virtual server determines one or more file type associations for the connection based on applying the one or more traffic management policies using the result.

20. The intermediary of claim 11 , wherein the traffic management virtual server determines to use or not use a single-sign on for the connection based on applying the result via the one or more traffic management policies.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2010
From: GUPTA, PUNIT
To: CITRIX SYSTEMS, INC.
Reel/Frame 023732/0903 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2009
From: HARRIS, JAMES; KUMAR, ARKESH; LI, RUI; THAKUR, RAVINDRANATH; AGARWAL, PUNEET; CHOUDHARY, AKSHAT
To: CITRIX SYSTEMS, INC.
Reel/Frame 022733/0639 →
Continuity (2)
Provisional Application 61161918 · Mar 20, 2009
Related Publication 20100242106A1 · Sep 23, 2010