IP Library Granted Patent US 11,792,174
Granted Patent B2
US 11,792,174 · App. 17/322,501 · Granted Oct 17, 2023

Method to save computational resources by detecting encrypted payload

Inventors: Praveen Raja Dhanabalan (Bengaluru, IN); Surya Prakash Patel (Bengaluru, IN); J Mohan Rao Arisankala (Bengaluru, IN)
H04L63/0478H04L9/0643H04L12/4633H04L63/029H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,174
App. No.
17/322,501
Granted
Oct 17, 2023
Kind
B2
Abstract

Described embodiments provide systems and methods for remapping connections to tunnels selected based on a security level of the communications. A first network device may be in communication with a second network device via a plurality of communication tunnels. The plurality of communication tunnels may include an encrypted communication tunnel and an unencrypted communication tunnel. The first network device may receive a packet, the packet including header information and a payload. The first network device may determine whether the received packet is encrypted to meet a threshold level of security. The first network device may, responsive to determining that the packet is to meet the threshold level of security, communicate an identifier of the payload and the header information to the second network device via the encrypted communication tunnel, and communicate the payload to the second network device via the unencrypted communication tunnel.

Claims (30)

1. A computer-implemented method comprising:

determining that a level of encryption of a packet meets a threshold, the packet comprising a header and a payload;

communicating, responsive to the level of encryption meeting the threshold, the payload from the packet to a device via an unencrypted communication tunnel; and

communicating an identifier of the payload and the header from the packet to the device via an encrypted communication tunnel, thereby causing the device to combine the header received via the encrypted communication tunnel with the payload of the packet received via the unencrypted communication tunnel.

2. The method of claim 1 , wherein the encrypted communication tunnel and the unencrypted communication tunnel are established between the device and another device.

3. The method of claim 1 , wherein the device is intermediary to a client and a server and the packet is communicated between the client and the server.

4. The method of claim 1 , wherein the identifier of the payload comprises a digest of at least a portion of the payload.

5. The method of claim 1 , wherein the threshold comprises a type of encryption and encryption level.

6. The method of claim 1 , further comprising determining that the level of encryption of the packet meets the threshold in accordance with a communication protocol identified for the packet.

7. The method of claim 1 , further comprising determining that the header of the packet identifies an existing connection.

8. A system comprising:

a device in communication with another device via an encrypted communication tunnel and unencrypted communication tunnel, the first device to:

determine that a level of encryption of a packet meets a threshold, the packet comprising a header and a payload;

communicate, responsive to the level of encryption meeting the threshold, the payload from the packet to the another device via the unencrypted communication tunnel; and

communicate an identifier of the payload and the header from the packet to the another device via an encrypted communication tunnel, the second device to combine the header received via the encrypted communication tunnel with the payload of the packet received via the unencrypted communication tunnel.

9. The system of claim 8 , wherein the encrypted communication tunnel and the unencrypted communication tunnel are established between the device and the another device.

10. The system of claim 8 , wherein the device and the another device are intermediary to a client and a server and the packet is communicated between the client and the server.

11. The system of claim 8 , wherein the identifier of the payload comprises a digest of at least a portion of the payload.

12. The system of claim 8 , wherein the threshold comprises a type of encryption and encryption level.

13. The system of claim 8 , wherein the device is to determine that the level of encryption of the packet meets the threshold in accordance with a communication protocol identified for the packet.

14. The system of claim 8 , wherein the device is to determine that the header of the packet identifies an existing connection.

15. A non-transitory computer readable medium storing program instructions for causing one or more processors of a device to:

determine that a level of encryption of a packet meets a threshold, the packet comprising a header and a payload;

communicate, responsive to the level of encryption meeting the threshold, the payload from the packet to another device via an unencrypted communication tunnel; and

communicate an identifier of the payload and the header from the packet to the another device via an encrypted communication tunnel, the another device to combine the header received via the encrypted communication tunnel with the payload of the packet received via the unencrypted communication tunnel.

16. The non-transitory computer readable medium of claim 15 , wherein the identifier of the payload comprises a digest of at least a portion of the payload.

17. The non-transitory computer readable medium of claim 15 , wherein the threshold comprises a type of encryption and encryption level.

18. The non-transitory computer readable medium of claim 15 , wherein the packet is communicated between a client and server and received by the device.

19. The non-transitory computer readable medium of claim 15 , storing program instructions for causing the one or more processors of the device to determine that the level of encryption of the packet meets the threshold in accordance with a communication protocol identified for the packet.

20. The non-transitory computer readable medium of claim 15 , storing program instructions for causing the one or more processors of the device to determine that the header of the packet identifies an existing connection.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2021
From: DHANABALAN, PRAVEEN RAJA; PATEL, SURYA PRAKASH; ARISANKALA, J MOHAN RAO
To: CITRIX SYSTEMS, INC.
Reel/Frame 056267/0043 →
Continuity (2)
Continuation 16210793 · Dec 5, 2018
Related Publication 20210273927A1 · Sep 2, 2021