IP Library Granted Patent US 10,520,110
Granted Patent B2
US 10,520,110 · App. 15/289,472 · Granted Dec 31, 2019

Systems and methods for executing cryptographic operations across different types of processing hardware

Inventors: Abhishek Chauhan (Saratoga, CA); Tushar Kanekar (Freemont, CA); Ritesh Patani (Freemont, CA); Robert Kidd (Champaign, IL); Sergey Golubev (Mountain View, CA); Harpreet Singh (Pleasanton, CA)
Assignee: Citrix Systems, Inc.
F16K37/0091F15B5/006F15B19/005F15B20/008G06F21/602H04L63/0471H04L63/0485H04L63/166H04L63/168F15B20/00F15B2211/6306F15B2211/6313F15B2211/6658F15B2211/857F15B2211/8613F15B2211/8636F15B2211/8755H04L63/0281H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,520,110
App. No.
15/289,472
Granted
Dec 31, 2019
Kind
B2
Abstract

The present disclosure is directed towards systems and methods for executing cryptographic operations across different types of processing hardware. An intermediary device may identify a cryptographic function to be performed at the device, according to a message from a client or a server. The device may identify a sequence of cryptographic operations to be executed for performing the cryptographic function. The device may determine subsets of the cryptographic operations to be executed on across different types of processing hardware. The different types of processing hardware may reside on the device. Each of the types of processing hardware may execute, responsive to the determination, the respective subset of the cryptographic operations, according to the sequence of the cryptographic operations.

Claims (34)

1. A method for executing cryptographic operations across different types of processing hardware, the method comprising:

identifying, by a device intermediary to a client and a server, from a plurality of cryptographic functions, a cryptographic function to be performed at the device based on at least a type of a message from the client or the server;

generating, by the device, a sequence of cryptographic operations to be executed for performing the cryptographic function identified from the plurality of cryptographic functions based on at least the type of the message;

determining, by the device, from the generated sequence of cryptographic operations, a first subset of the cryptographic operations to be executed on a first type of processing hardware and a second subset of the cryptographic operations to be executed on a second type of processing hardware different from the first type to carry out the sequence of cryptographic operations for performing the cryptographic function, the first and the second types of processing hardware residing on the device; and

instructing, by the device responsive to the determination, the first type and the second type of processing hardware to execute the first subset and the second subset of the cryptographic operations respectively, according to the sequence of the cryptographic operations for performing the cryptographic function.

2. The method of claim 1 , wherein the determining comprises determining that a size of data undergoing one or more of the cryptographic operations is below a first threshold.

3. The method of claim 1 , wherein the determining comprises determining that the first type of processing hardware is executing at a utilization level below a predefined threshold.

4. The method of claim 1 , wherein the determining comprises determining an incoming rate of cryptographic functions to be performed at the device, relative to an expected rate of cryptographic functions or a predefined threshold.

5. The method of claim 1 , wherein the determining comprises determining, relative to a predefined threshold or range, a portion of processing resources of the first subset of cryptographic functions allocated to software cryptographic operations.

6. The method of claim 1 , further comprising instructing, by the device, both types of processing hardware to execute at least one of the cryptographic operations of the cryptographic function.

7. The method of claim 1 , further comprising determining, by the device, to queue or buffer one or more of the cryptographic operations responsive to determining that a utilization level of the first type of processing hardware is above a first predefined level and a utilization level of the second type of processing hardware is above a second predefined level.

8. The method of claim 1 , wherein the first type of processing hardware comprises an x86 processor and the second type of processing hardware comprises a cryptographic card.

9. The method of claim 1 , wherein the first type of processing hardware comprises a first type of cryptographic acceleration device and the second type of processing hardware comprises a second type of cryptographic acceleration device.

10. A method for executing handshake operations across different types of processing hardware, the method comprising:

identifying, by a device intermediary to a client and a server, from a plurality of handshakes, a handshake to be performed by the device based on at least a type of a message from the client or the server, the plurality of handshakes comprising a secure socket layer handshake (SSL) or a transport layer security (TLS) handshake;

generating, by the device, a sequence of handshake operations to be executed for performing the handshake identified from the plurality of cryptographic functions based on at least the type of the message;

determining, by the device, from the generated sequence of handshake operations, a first subset of the handshake operations to be executed on a first type of processing hardware and a second subset of the handshake operations to be executed on a second type of processing hardware different from the first type to carry out the sequence of handshake operations for performing the handshake, the first and the second types of processing hardware residing on the device; and

instructing, by the device responsive to the determination, the first type and the second type of processing hardware to execute the first subset and the second subset of the handshake operations respectively, according to the sequence of the cryptographic operations for performing the handshake.

11. A system for executing cryptographic operations across different types of processing hardware, the system comprising:

a first type of processing hardware and a second type of processing hardware for executing one or more cryptographic operations, the first type and the second type of processing hardware residing on a device intermediary to a client and a server; and

a packet engine of the device, the packet engine:

identifying, based on at least a type of a message from the client or the server, from a plurality of cryptographic functions, a cryptographic function to be performed at the device;

generating a sequence of cryptographic operations to be executed for performing the cryptographic function identified from the plurality of cryptographic functions based on at least the type of the message; and

determining a first subset of the cryptographic operations to be executed on the first type of processing hardware and a second subset of the cryptographic operations to be executed on the second type of processing hardware different from the first type to carry out the generated sequence of cryptographic operations for performing the cryptographic function;

instructing, responsive to the determination, the first type and the second type of processing hardware execute to execute the first subset and the second subset of the cryptographic operations respectively, according to the sequence of the cryptographic operations for performing the cryptographic function.

12. The system of claim 11 , wherein the packet engine determines that a size of data undergoing one or more of the cryptographic operations is below a first threshold.

13. The system of claim 11 , wherein the packet engine determines that the first type of processing hardware is executing at a utilization level below a predefined threshold.

14. The system of claim 11 , wherein the packet engine determines an incoming rate of cryptographic functions to be performed at the device, relative to an expected rate of cryptographic functions or a predefined threshold.

15. The system of claim 11 , wherein the packet engine determines, relative to a predefined threshold or range, a portion of processing resources of the first subset of cryptographic functions allocated to software cryptographic operations.

16. The system of claim 11 , wherein the packet engine instructs both types of processing hardware to execute at least one of the cryptographic operations of the cryptographic function.

17. The system of claim 11 , wherein the packet engine determines to queue or buffer one or more of the cryptographic operations responsive to determining that a utilization level of the first type of processing hardware is above a first predefined level and a utilization level of the second type of processing hardware is above a second predefined level.

18. The system of claim 11 , wherein the first type of processing hardware comprises an x86 processor and the second type of processing hardware comprises a cryptographic card.

19. The system of claim 11 , wherein the first type of processing hardware comprises a first type of cryptographic acceleration device and the second type of processing hardware comprises a second type of cryptographic acceleration device.

20. The system of claim 11 , wherein the message comprises a secure socket layer (SSL) or a transport layer security (TLS) message.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2016
From: CHAUHAN, ABHISHEK; KANEKAR, TUSHAR; PATANI, RITESH; KIDD, ROBERT; GOLUBEV, SERGEY; SINGH, HARPREET
To: CITRIX SYSTEMS, INC.
Reel/Frame 040391/0398 →
Continuity (1)
Related Publication 20180103018A1 · Apr 12, 2018