IP Library › Granted Patent US 10,447,658
Granted Patent B2
US 10,447,658 · App. 15/004,598 · Granted Oct 15, 2019

System and method for providing improved optimization for secure session connections

Inventor: Paras Suresh Shah (Sunnyvale, CA)
Assignee: CITRIX SYSTEMS, INC.
H04L63/0428H04L63/0272H04L63/0281H04L63/061H04L63/0823H04L63/166H04L67/42H04L67/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,658
App. No.
15/004,598
Filed
Jan 22, 2016
Granted
Oct 15, 2019
Kind
B2
Art Unit
2491
USPC
713/151
Abstract

A system for optimizing network traffic is described. The system includes a plurality of appliances. An appliance comprises one or more network interfaces and a secure session connection optimizer module. The one or more network interfaces are configured to facilitate secure communications between a client device and a server, wherein the secure communications involve a plurality of secure session connections comprising a first secure session connection between the client device and the appliance and a second secure session connection between the appliance and another appliance. The secure session connection optimizer module is configured to receive a secure session connection request from the client device, determine, using information from the secure session connection request, whether a lookup table includes information that client authentication is required by the server, if the information indicates that client authentication is not required by the server, provide an instruction to the other appliance, and if the information indicates that client authentication is required by the server, provide the secure connection request to the other appliance over the second secure connection.

Claims (80)

1. An appliance comprising:

one or more network interfaces configured to facilitate secure communications between a client device and a server, wherein the secure communications involve a plurality of secure session connections comprising a first secure session connection between the client device and the appliance and a second secure session connection between the appliance and another appliance; and

a secure session connection optimizer module comprising a processor configured to:

receive a secure session connection request from the client device,

determine, using information from the secure session connection request, whether a lookup table includes information that client authentication is required by the server,

if the information indicates that client authentication is not required by the server, provide an instruction to the other appliance, and

if the information indicates that client authentication is required by the server, provide the secure connection request to the other appliance over the second secure connection via the appliance decrypting communications received from the first secure session connection using a key shared with the client device, and encrypting the decrypted communications to be sent via the second secure connection using a key shared with the other appliance.

2. The appliance of claim 1 , wherein the secure session connection optimizer module is further configured to access the lookup table upon receipt of the secure session connection request.

3. The appliance of claim 1 , wherein the information that client authentication is not required indicates that the appliance is acting as a split proxy mode.

4. The appliance of claim 1 , wherein the information that client authentication is required indicates that the appliance is acting as a transparent mode.

5. The appliance of claim 1 , wherein the instruction indicates that the other appliance is to initiate a secure session handshake procedure between the other appliance and the server.

6. The appliance of claim 1 , wherein the secure session connections are established based on a secure session layer (SSL) or a transport layer security (TLS) handshake protocol.

7. The appliance of claim 1 , wherein the secure session connection optimizer module is further configured to determine, using information from the secure session connection request, whether the lookup table includes certificate information.

8. The appliance of claim 7 , wherein the secure session connection optimizer module is further configured to establish the first secure session connection with the client device using the certificate information in response to the secure connection request.

9. The appliance of claim 1 , wherein the determination that the lookup table does not include information on client authentication or failing to access the lookup table further comprises the secure session connection optimizer module configured to forward the secure session connection request to the other appliance.

10. The appliance of claim 1 , wherein the secure session connection optimizer module is further configured to add an entry in the lookup table, if the entry does not exist for the server, wherein the entry is allocated to store at least one of: mode information, certificate information, information that client authentication is not required by the server, and premaster secret information.

11. The appliance of claim 10 , wherein the entry in the lookup table is distinguished based on IP address and port information of the server.

12. The appliance of claim 10 , wherein the mode information comprises one of a split proxy mode and a transparent mode.

13. The appliance of claim 1 , wherein the determination whether the lookup table does not include information on client authentication further comprises the secure session connection optimizer module configured to:

receive, from the other appliance, information that client authentication is not required by the server; and

store the information in the lookup table that client authentication is not required by the server.

14. The appliance of claim 1 , wherein the determination whether the lookup table does not include information on client authentication further comprises the secure session connection optimizer module configured to:

receive, from the other appliance, certificate information;

establish the first secure session connection using the certificate information in response to the secure connection request; and

store the certificate information in the lookup table.

15. The appliance of claim 3 , wherein the secure session connection optimizer module is further configured to determine whether the lookup table includes premaster secret information, when determining that the appliance is acting as the split proxy mode.

16. The appliance of claim 15 , wherein the secure session connection optimizer module is further configured to send the other appliance a request to decrypt client key exchange, based on determining that the lookup table does not include premaster secret information.

17. The appliance of claim 16 , wherein the secure session connection optimizer module is further configured to obtain premaster secret information from the decrypted client key exchange.

18. The appliance of claim 17 , wherein the premaster secret information is used to derive a master secret, wherein the master secret is used to encrypt or decrypt data.

19. A method comprising:

facilitating secure communications between a client device and a server, wherein the secure communications involve a plurality of secure session connections comprising a first secure session connection between the client device and the appliance and a second secure session connection between the appliance and another appliance;

receiving a secure session connection request from the client device;

determining, using information from the secure session connection request, whether a lookup table includes information that client authentication is required by the server;

if the information indicates that client authentication is not required by the server, providing an instruction to the other appliance; and

if the information indicates that client authentication is required by the server, providing the secure connection request to the other appliance over the second secure connection via the appliance decrypting communications received from the first secure session connection using a key shared with the client device, and encrypting the decrypted communications to be sent via the second secure connection using a key shared with the other appliance.

20. The method of claim 19 , further comprising accessing to the lookup table upon receipt of the secure session connection request.

21. The method of claim 19 , wherein the information that client authentication is not required indicates that the appliance is acting as a split proxy mode.

22. The method of claim 19 , wherein the information that client authentication is required indicates that the appliance is acting as a transparent mode.

23. The method of claim 19 , wherein the instruction indicates the other appliance to initiate a secure session handshake procedure between the other appliance and the server.

24. The method of claim 19 , wherein the secure session connections are established based on a secure session layer (SSL) or a transport layer security (TLS) handshake protocol.

25. The method of claim 19 , further comprising determining, using information from the secure session connection request, whether the lookup table includes certificate information.

26. The method of claim 25 , further comprising establishing the first secure session connection with the client device using the certificate information in response to the secure connection request.

27. The method of claim 19 , further comprising forwarding the secure session connection request to the other appliance, based on determination that the lookup table does not include information on client authentication or failing to access the lookup table.

28. The method of claim 19 , further comprising adding an entry in the lookup table, if the entry not existing for the server, wherein the entry is allocated to store at least one of: mode information, certificate information, information that client authentication is not required by the server, and premaster secret information.

29. The method of claim 28 , wherein the entry in the lookup table is distinguished based on IP address and port information of the server.

30. The method of claim 28 , wherein the mode information comprises one of a split proxy mode and a transparent mode.

31. The method of claim 19 , further comprising, based on determination that the lookup table does not include information on client authentication:

receiving, from the other appliance, information that client authentication is not required by the server; and

storing the information in the lookup table that client authentication is not required by the server.

32. The method of claim 19 , further comprising, based on determination that the lookup table does not include information on client authentication:

receiving, from the other appliance, certificate information;

establishing the first secure session connection using the certificate information in response to the secure connection request; and

storing the certificate information in the lookup table.

33. The method of claim 21 , further comprising determining whether the lookup table includes premaster secret information, when determining that the appliance is acting as the split proxy mode.

34. The method of claim 33 , further comprising sending the other appliance a request to decrypt client key exchange, based on determining that the lookup table does not include premaster secret information.

35. The method of claim 34 , further comprising obtaining premaster secret information from the decrypted client key exchange.

36. The method of claim 35 , wherein the premaster secret information is used to derive a master secret, wherein the master secret is used to encrypt or decrypt data.

37. A non-transitory computer readable storage medium that stores a set of instructions that is executable by at least one processor of an appliance to cause the appliance to perform a method, the method comprising:

facilitating secure communications between a client device and a server, wherein the secure communications involve a plurality of secure session connections comprising a first secure session connection between the client device and the appliance and a second secure session connection between the appliance and another appliance;

receiving a secure session connection request from the client device;

determining, using information from the secure session connection request, whether a lookup table includes information that client authentication is required by the server;

if the information indicates that client authentication is not required by the server, providing an instruction to the other appliance; and

if the information indicates that client authentication is required by the server, providing the secure connection request to the other appliance over the second secure connection via the appliance decrypting communications received from the first secure session connection using a key shared with the client device, and encrypting the decrypted communications to be sent via the second secure connection using a key shared with the other appliance.

38. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: accessing to the lookup table upon receipt of the secure session connection request.

39. The non-transitory computer readable storage medium of claim 37 , wherein the information that client authentication is not required indicates that the appliance is acting as a split proxy mode.

40. The non-transitory computer readable storage medium of claim 37 , wherein the information that client authentication is required indicates that the appliance is acting as a transparent mode.

41. The non-transitory computer readable storage medium of claim 37 , wherein the instruction indicates the other appliance to initiate a secure session handshake procedure between the other appliance and the server.

42. The non-transitory computer readable storage medium of claim 37 , wherein the secure session connections are established based on a secure session layer (SSL) or a transport layer security (TLS) handshake protocol.

43. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: determining, using information from the secure session connection request, whether the lookup table includes certificate information.

44. The non-transitory computer readable storage medium of claim 43 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: establishing the first secure session connection with the client device using the certificate information in response to the secure connection request.

45. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: forwarding the secure session connection request to the other appliance, based on determination that the lookup table does not include information on client authentication or failing to access the lookup table.

46. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: adding an entry in the lookup table, if the entry not existing for the server, wherein the entry is allocated to store at least one of: mode information, certificate information, information that client authentication is not required by the server, and premaster secret information.

47. The non-transitory computer readable storage medium of claim 46 , wherein the entry in the lookup table is distinguished based on IP address and port information of the server.

48. The non-transitory computer readable storage medium of claim 46 , wherein the mode information comprises one of a split proxy mode and a transparent mode.

49. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform, based on determination that the lookup table does not include information on client authentication: receiving, from the other appliance, information that client authentication is not required by the server; and storing the information in the lookup table that client authentication is not required by the server.

50. The non-transitory computer readable storage medium of claim 37 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform, based on determination that the lookup table does not include information on client authentication: receiving, from the other appliance, certificate information; establishing the first secure session connection using the certificate information in response to the secure connection request; and storing the certificate information in the lookup table.

51. The non-transitory computer readable storage medium of claim 39 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: determining whether the lookup table includes premaster secret information, when determining that the appliance is acting as the split proxy mode.

52. The non-transitory computer readable storage medium of claim 51 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: sending the other appliance a request to decrypt client key exchange, based on determining that the lookup table does not include premaster secret information.

53. The non-transitory computer readable storage medium of claim 52 , wherein the set of instructions that is executable by the at least one processor of the apparatus to cause the apparatus to further perform: obtaining premaster secret information from the decrypted client key exchange.

54. The non-transitory computer readable storage medium of claim 53 , wherein the premaster secret information is used to derive a master secret, wherein the master secret is used to encrypt or decrypt data.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2016
From: SHAH, PARAS SURESH
To: CITRIX SYSTEMS, INC.
Reel/Frame 037634/0250 →
Continuity (1)
Related Publication 20170214660A1 · Jul 27, 2017
Cited By (1)
US 12,445,301