IP Library › Granted Patent US 8,949,591
Granted Patent B2
US 8,949,591 · App. 14/028,133 · Granted Feb 3, 2015

Systems and methods for split proxying of SSL via WAN appliances

Inventor: Michael Ovsiannikov (San Mateo, CA)
Assignee: Citrix Systems, Inc.
H04L63/168H04L29/08792H04L63/0281H04L63/166H04L63/0464H04L67/2876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,949,591
App. No.
14/028,133
Granted
Feb 3, 2015
Kind
B2
Abstract

The present invention is directed towards systems and methods for split proxying Secure Socket Layer (SSL) communications via intermediaries deployed between a client and a server. The method includes establishing, by a server-side intermediary, a SSL session with a server. A client-side intermediary may establish a second SSL session with a client using SSL configuration information received from the server-side intermediary. Both intermediaries may communicate via a third SSL session. The server-side intermediary may decrypt data received from the server using the first SSL session's session key. The server-side intermediary may transmit to the client-side intermediary, via the third SSL session, data encrypted using the third SSL session's session key. The client-side intermediary may decrypt the encrypted data using the third SSL session's session key. The client-side intermediary may transmit to the client the data encrypted using the second SSL session's session key.

Claims (26)

1. A method for Secure Socket Layer (SSL) communications across devices intermediary to a client and a server, the method comprising:

a) establishing between a first device and a second device, a first secure socket layer (SSL) session, the first device intermediary to a client and the second device and the second device intermediary to the first device and a server, the second device having a second SSL session with the server;

b) receiving, by the first device from the second device, an indication to perform a type of SSL proxying of a plurality of SSL proxying types between the first device and the second device, the plurality of SSL proxying types comprising split proxying and spoof proxying; and

c) establishing by the first device and the second device, the type of SSL proxying.

2. The method of claim 1 , wherein step (b) further comprises receiving by the first device the indication to perform the type of SSL proxying comprising split proxying.

3. The method of claim 2 , wherein step (c) further comprises receiving, by the first device via the first SSL session, the second SSL session key with the server from the second device.

4. The method of claim 3 , further comprising establishing, by the first device, a third Secure Socket Layer (SSL) session with the client using the second SSL session key.

5. The method of claim 2 , further comprising transmitting, by the first device via the first SSL session, a request to the second device to perform a cryptographic operation, the second device configured to perform crypto operations for the first device.

6. The method of claim 5 , further comprising performing, by the second device, the cryptographic operation using a session key of a third SSL session between the first device and the client.

7. The method of claim 1 , wherein step (b) further comprises receiving by the first device the indication to perform the type of SSL proxying comprising spoof proxying.

8. The method of claim 7 , wherein step (c) further comprises receiving by the first device via the first SSL session SSL configuration information from the second device.

9. The method of claim 8 , further comprising establishing, by the first device, a third SSL session with the client based on the SSL configuration information.

10. The method of claim 7 , further comprising the first device encrypting data received from the client using a key of the SSL configuration information, and transmitting the encrypted data via the third SSL session to the device and wherein the second device decrypts the encrypted data using the key from the SSL configuration information.

11. A system for Secure Socket Layer (SSL) communications across devices intermediary to a client and a server, the system comprising:

a first device and a second device, wherein first device is configured to be intermediary to a client and the second device and the second device is configured to be intermediary to the first device and a server; the second device configured to establish a second SSL session with the server;

wherein the first device is configured to receive from the second device, an indication to perform a type of SSL proxying of a plurality of SSL proxying types between the first device and the second device, the plurality of SSL proxying types comprising split proxying and spoof proxying; and

wherein the first device and the second device are configured to establish the type of SSL proxying.

12. The system of claim 11 , wherein the indication to perform the type of SSL proxying comprises split proxying.

13. The system of claim 12 , wherein the first device is configured to receive via the first SSL session, the second SSL session key with the server from the second device.

14. The system of claim 13 , wherein the first device is configured to establish a third Secure Socket Layer (SSL) session with the client using the second SSL session key.

15. The system of claim 12 , wherein first device is configured to transmit via the first SSL session a request to the second device to perform a cryptographic operation, the second device configured to perform crypto operations for the first device.

16. The system of claim 15 , wherein the second device is configured to perform the cryptographic operation using a session key of a third SSL session between the first device and the client.

17. The system of claim 11 , wherein the indication to perform the type of SSL proxying comprises spoof proxying.

18. The system of claim 17 , wherein by the first device is configured to receive via the first SSL session SSL configuration information from the second device.

19. The system of claim 18 , wherein the first device is configured to establish a third SSL session with the client based on the SSL configuration information.

20. The system of claim 17 , wherein the first device is configured to encrypt data received from the client using a key of the SSL configuration information, and transmit the encrypted data via the third SSL session to the device and wherein the second device is configured to decrypt the encrypted data using the key from the SSL configuration information.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2013
From: OSVIANNIKOV, MICHAEL
To: CITRIX SYSTEMS, INC.
Reel/Frame 031233/0246 →
Continuity (2)
Continuation 12764633 · Apr 21, 2010
Related Publication 20140122865A1 · May 1, 2014