IP Library Granted Patent US 8,892,778
Granted Patent B2
US 8,892,778 · App. 13/618,180 · Granted Nov 18, 2014

Method and systems for securing remote access to private networks

Inventors: Goutham P. Rao (San Jose, CA); Robert A. Rodriguez (San Jose, CA); Eric R. Brueggemann (Cupertino, CA)
Assignee: Citrix Systems, Inc.
H04L45/72H04L63/0272H04L63/164H04L63/166H04L29/12009H04L63/20H04L29/12367H04L12/2898H04L29/12481H04L61/2514H04L61/2557H04L12/2856H04L63/0227H04L45/00H04L63/101H04L47/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,892,778
App. No.
13/618,180
Granted
Nov 18, 2014
Kind
B2
Abstract

A method for securing remote access to private networks includes a receiver intercepting from a data link layer a packet in a first plurality of packets destined for a first system on a private network. A filter intercepts from the data link layer a packet in a second plurality of packets transmitted from a second system on the private network, destined for an system on a second network. A transmitter in communication with the receiver and the filter performing a network address translation on at least one intercepted packet and transmitting the at least one intercepted packet to a destination.

Claims (29)

1. A method of accessing a server via an intermediary device between a client in a first network and the server in a second network, the method comprising:

(a) establishing a secure application layer tunnel over a first transport layer connection between a client application executing on a client on a first network and a device intermediary between a server of a second network and the client, the device having a second transport layer connection between the device and the server;

(b) receiving, by the device from the client application via the secure application layer tunnel, a request of an application of the client to access the server, the client application receiving the request intercepted from a third transport layer connection of the application by a driver of the client,

(c) forwarding, by the device via the second transport layer connection, the request to the server; and

(d) intercepting, by the device at a data link layer of the device, a response to the request transmitted from the server to the client.

2. The method of claim 1 , wherein step (a) further comprises establishing the secure application layer tunnel comprising one of a secure socket layer (SSL) session or a Secure HypterText Transfer Protocol (HTTPS) session.

3. The method of claim 1 , wherein step (b) further comprises terminating, by the driver, the third transport layer connection of the application, the application transmitting requests to the server via the third transport layer connection.

4. The method of claim 1 , wherein step (a) further comprising transmitting, by the device to the client responsive to a communication of the client to the device, a remote process comprising the client application and the driver, the client automatically installing the client application and the driver of the remote process upon receipt.

5. The method of claim 1 , wherein step (b) further comprising receiving, by the client application, the request from the driver via a port of the client monitored by the client application.

6. The method of claim 1 , wherein step (b) further comprises intercepting, by the driver at a data link layer of the client, network traffic of the application destined for the server and forwards the intercepted network traffic to the client application.

7. The method of claim 1 , wherein step (c) further comprises performing, by the device, network address translation of a public internet protocol address of the request to a private internet protocol address of the client established by the device.

8. The method of claim 1 , wherein step (d) further comprises performing, by the device, network address translation of a private internet protocol address of the response to a public internet protocol address of the client.

9. The method of claim 1 , wherein step (d) further comprises intercepting, by a second driver of the device, the response and providing the response to a policy engine executing at an application layer of the device for applying one or more policies to the response before transmitting the response to the client.

10. The method of claim 9 , further comprising transmitting, by the device, responsive to the policy engine, the response to the client application via the secure application layer tunnel.

11. A system of accessing a server via an intermediary device between a client in a first network and the server in a second network, the system comprising:

a client application executing on a client on a first network;

a device intermediary between a server of a second network and the client

a secure application layer tunnel established over a first transport layer connection between the client and the device, the device having a second transport layer connection between the device and the server;

wherein the device receives from the client application via the secure application layer tunnel a request of an application of the client to access the server, the client application receiving the request intercepted from a third transport layer connection of the application by a driver of the client, and forwards the request to the server via the second transport layer connection; and

wherein the device intercepts, at a data link layer of the device, a response to the request transmitted from the server to the client.

12. The system of claim 11 , wherein the secure application layer tunnel comprises one of a secure socket layer (SSL) session or a Secure HypterText Transfer Protocol (HTTPS) session.

13. The system of claim 11 , wherein the driver of the client terminates the third transport layer connection of the application, the application transmitting requests to the server via the third transport layer connection.

14. The system of claim 11 , wherein the device transmits to the client, responsive to a communication of the client to the device, a remote process comprising the client application and the driver, the client automatically installing the client application and the driver of the remote process upon receipt.

15. The system of claim 11 , wherein the client application receives the request from the driver via a port of the client monitored by the client application.

16. The system of claim 11 , wherein the driver intercepts at a data link layer of the client network traffic of the application destined for the server and forwards the intercepted network traffic to the client application.

17. The system of claim 11 , wherein the device performs network address translation of a public internet protocol address of the request to a private internet protocol address of the client established by the device.

18. The system of claim 11 , wherein the device performs network address translation of a private internet protocol address of the response to a public internet protocol address of the client.

19. The system of claim 11 , wherein a second driver of the device intercepts the response and provides the response to a policy engine executing at an application layer of the device for applying one or more policies to the response before transmitting the response to the client.

20. The system of claim 19 , wherein the device, responsive to the policy engine, transmits the response to the client application via the secure application layer tunnel.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2013
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC R.
To: CITRIX SYSTEMS, INC.
Reel/Frame 030116/0110 →
Continuity (6)
Continuation 11161093 · Jul 22, 2005
Provisional Application 60590837 · Jul 23, 2004
Provisional Application 60601431 · Aug 13, 2004
Provisional Application 60607420 · Sep 3, 2004
Provisional Application 60634379 · Dec 7, 2004
Related Publication 20130014206A1 · Jan 10, 2013