IP Library › Granted Patent US 11,336,693
Granted Patent B2
US 11,336,693 · App. 16/203,120 · Granted May 17, 2022

Applying application layer policy to transport layer security requests systems and methods

Inventors: Andrew Penner (Savoy, IL); Tushar Kanekar (Fremont, CA)
Assignee: Citrix Systems, Inc.
H04L63/20H04L63/166H04L63/168G06F9/45533H04L67/02H04L67/141H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,693
App. No.
16/203,120
Filed
Nov 28, 2018
Granted
May 17, 2022
Kind
B2
Art Unit
2437
USPC
726/1
Abstract

Systems and methods for applying an application layer policy to a transport layer security request are provided. A device, intermediary to one or more clients and one or more servers, can receive a transport layer security (TLS) request to establish a TLS connection between a client of the one or more clients and a server of the one or more servers. The TLS request can include an application layer request to a resource of the server. The device can apply an application layer policy to the application layer request of the TLS request. The device can determine, responsive to applying the application layer policy, whether to one of accept or reject at least the application layer request of the TLS request.

Claims (27)

1. A method for applying an application layer policy to a transport layer security request, the method comprising:

(a) receiving, by a device intermediary to one or more clients and one or more servers, a transport layer security (TLS) request to establish a TLS connection between a client of the one or more clients and a server of the one or more servers, the TLS request including an application layer request to connect to a resource of the server;

(b) determining, by the device during a TLS handshake between the device and the client and prior to forwarding the application layer request to the resource of the server, whether the application layer request is replay-safe based on a pattern specified by an application layer policy matching a uniform resource identifier of the application layer request; and

(c) accepting or rejecting, by the device responsive to the determination as to whether the application layer request is replay-safe based on the pattern specified by the application layer policy, at least the application layer request of the TLS request, wherein accepting the application layer request causes the device to establish, responsive to the TLS request, the TLS connection between the client and the server.

2. The method of claim 1 , wherein (c) further comprises rejecting the application layer request but accepting the TLS request.

3. The method of claim 2 , further comprising omitting, by the device, an extension for early data during the TLS handshake with the client to indicate rejection of the application layer request.

4. The method of claim 1 , wherein (c) further comprises accepting both the TLS request and the application layer request.

5. The method of claim 4 , further comprising including, by the device, an extension for early data during the TLS handshake with the client to indicate allowing the application layer request.

6. The method of claim 1 , wherein (b) further comprises decrypting, by the device, the application layer request using at least one key included within the TLS request.

7. The method of claim 1 , further comprising identifying, by the device based at least on the TLS request, the application layer policy for accessing the resource.

8. The method of claim 1 , wherein the application layer policy specifies the pattern for matching against at least a portion of the application layer request.

9. The method of claim 1 , wherein the application layer request comprises a HyperText Transfer Protocol (HTTP) request.

10. The method of claim 1 , further comprising terminating, at the device, the TLS connection with the client and establishing a communication channel between the device and the server.

11. A system for applying an application layer policy to a transport layer security request, the system comprising:

a device intermediary to one or more clients and one or more servers, wherein the device is configured to:

receive a transport layer security (TLS) request to establish a TLS connection between a client of the one or more clients and a server of the one or more servers, wherein the TLS request includes an application layer request to connect to a resource of the server;

determine, during a TLS handshake between the device and the client and prior to forwarding the application layer request to the resource of the server, whether the application layer request is replay-safe based on a pattern specified by an application layer policy matching a uniform resource identifier of the application layer request; and

accept or reject, responsive to the determination as to whether the application layer request is replay-safe based on the pattern specified by the application layer policy, at least the application layer request of the TLS request, wherein accepting the application layer request causes the device to establish, responsive to the TLS request, the TLS connection between the client and the server.

12. The system of claim 11 , wherein the device is further configured to reject the application layer request but accept the TLS request.

13. The system of claim 12 , wherein the device is further configured to omit an extension for early data during the TLS handshake with the client to indicate rejection of the application layer request.

14. The system of claim 11 , wherein the device is further configured to accept both the TLS request and the application layer request.

15. The system of claim 14 , wherein the device is further configured to include an extension for early data during the TLS handshake with the client to indicate allowing the application layer request.

16. The system of claim 11 , wherein the device is further configured to decrypt the application layer request using at least one key included within the TLS request.

17. The system of claim 11 , wherein the device is further configured to identify, based at least on the TLS request, the application layer policy for accessing the resource.

18. The system of claim 11 , wherein the application layer policy is configured with the pattern for matching against at least a portion of the application layer request.

19. The system of claim 11 , wherein the application layer request comprises a HyperText Transfer Protocol (HTTP) request.

20. The system of claim 11 , wherein the device is further configured to terminate the TLS connection with the client and establishing a communication channel between the device and the server.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE LAST NAME OF SECOND ASSIGNOR PREVIOUSLY RECORDED ON REEL 047661 FRAME 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 20, 2018
From: PENNER, ANDREW; KANEKAR, TUSHAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 047967/0828 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2018
From: PENNER, ANDREW; KANEKA, TUSHAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 047661/0286 →
Continuity (1)
Related Publication 20200169584A1 · May 28, 2020