IP Library Granted Patent US 11,258,780
Granted Patent B2
US 11,258,780 · App. 16/696,758 · Granted Feb 22, 2022

Securing a data connection for communicating between two end-points

Inventors: Julien Brouchier (Great Cambourne, GB); Andrew David Cooper (Royston, GB); Richard James Cooper (Bedford, GB); Jean-Luc Claude Robert Giraud (Melbourn, GB); Ian Wright (Ramsey, GB); Christopher Morgan Mayers (Histon, GB)
Assignee: Citrix Systems, Inc.
H04L63/0823H04L9/0861H04L9/3234H04L9/3263H04L63/0281H04L63/0853H04L63/126H04L63/166H04L67/08H04L67/42H04L2209/64H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,258,780
App. No.
16/696,758
Granted
Feb 22, 2022
Kind
B2
Abstract

Methods and systems for securing a data connection for communicating between two end-points are described herein. One of the end-points may be a server and the other of the end-points may be a client that wants to communicate with the server. The data connection may be secured based on a previously-established secure connection and/or a self-signed or self-issued certificate. In some variations, by using the previously-established secure connection and/or a self-signed or self-issued certificate, the secure communication between the server and the client may be conducted without using a third-party authentication service and without requiring a third-party CA to issue a certificate for the server.

Claims (36)

1. A method comprising:

receiving, by a client device, first data from a computing device, the first data including a certificate of a server and at least one parameter of a communications channel between the client device and the server;

establishing, by the client device, the communications channel with the server based on the at least one parameter of the first data, the channel configured to transmit data between the client device and the server;

determining, by the client device, that credentials received from the server via the communications channel are valid based on a comparison of the received credentials with that of the certificate of the first data; and

sending, by the client device, second data via the communications channel to access a resource of the server in response to validation of the credentials received from the server via the communications channel.

2. The method of claim 1 , wherein the communications channel is for a session of a remote desktop service.

3. The method of claim 2 , wherein the first data comprises an Independent Computing Architecture (ICA) file associated with the session of the remote desktop service.

4. The method of claim 2 , wherein the server is a virtual delivery agent associated with the session of the remote desktop service.

5. The method of claim 1 , wherein the communications channel is a confidentiality- and integrity-protected connection.

6. The method of claim 5 , wherein the communications channel is a Transport Layer Security (TLS) connection.

7. The method of claim 5 , wherein the first data is received via an integrity-protected connection.

8. The method of claim 1 , wherein the credentials received from the server include a self-signed or self-issued certificate for the server, and wherein determining that credentials received from the server via the communications channel are valid is performed based on determining that the self-signed or self-issued certificate for the server matches the certificate of the first data.

9. An apparatus comprising:

one or more processors; and

memory storing executable instructions that, when executed by the one or more processors, cause the apparatus to:

receive, from a computing device, first data that includes a certificate of a server and at least one parameter of a communications channel between the apparatus and the server;

establish the communications channel with the server based on the at least one parameter of the first data, the channel configured to transmit data between the apparatus and the server;

determine that credentials received from the server via the communications channel are valid based on a comparison of the received credentials with that of the certificate of the first data; and

send second data via the communications channel to access a resource of the server in response to validation of the credentials received from the server via the communications channel.

10. The apparatus of claim 9 , wherein the communications channel is for a session of a remote desktop service.

11. The apparatus of claim 10 , wherein the first data comprises an Independent Computing Architecture (ICA) file associated with the session of the remote desktop service.

12. The apparatus of claim 10 , wherein the server is a virtual delivery agent associated with the session of the remote desktop service.

13. The apparatus of claim 9 , wherein the communications channel is a confidentiality- and integrity-protected connection.

14. The apparatus of claim 13 , wherein the communications channel is a Transport Layer Security (TLS) connection.

15. The apparatus of claim 13 , wherein the first data is received via an integrity-protected connection.

16. The apparatus of claim 9 , wherein the credentials received from the server include a self-signed or self-issued certificate for the server, and wherein the executable instructions that, when executed by the one or more processors, cause the apparatus to determine that credentials received from the server via the communications channel are valid based on determining that the self-signed or self-issued certificate for the server matches the certificate of the first data.

17. A computing device comprising:

one or more processors; and

a memory storing second executable instructions that, when executed by the one or more processors, cause the computing device to:

establish a connection between the computing device and a server;

authenticate, based on a comparison of a first copy of a self-signed or self-issued certificate and a second copy of the self-signed or self-issued certificate, the server, the second copy of the self-signed or self-issued certificate being received from the server via the connection; and

provide, by the computing device and to the server via the connection, data associated with a session of a remote desktop service so as to enable a client device to access a resource executable on the server.

18. The computing device of claim 17 , wherein the server is a virtual delivery agent associated with the session of the remote desktop service.

19. The computing device of claim 17 , wherein the connection is a confidentiality- and integrity-protected connection, and wherein the executable instructions, when executed by the one or more processors, cause the computing device to:

based on establishing the connection, receive, from the server and based on one or more confidentiality- and integrity-protected messages, the second copy of the self-signed or self-issued certificate.

20. The computing device of claim 17 , wherein the communications channel is a Transport Layer Security (TLS) connection.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2019
From: BROUCHIER, JULIEN; COOPER, ANDREW DAVID; COOPER, RICHARD JAMES; GIRAUD, JEAN-LUC CLAUDE ROBERT; WRIGHT, IAN; MAYERS, CHRISTOPHER MORGAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 051123/0437 →
Continuity (2)
Continuation 15695793 · Sep 5, 2017
Related Publication 20200099678A1 · Mar 26, 2020