IP Library Granted Patent US 12,641,122
Granted Patent B2
US 12,641,122 · App. 18/373,416 · Granted May 26, 2026

Methods for generating client-executable actions through TLS parameters and devices thereof

Inventors: John Ray Clark (Bedford, NH); Jason R. Adams (Spokane Valley, WA); Mudit Tyagi (Camas, WA); Judge K. Arora (Eastsound, WA)
Assignee: F5, Inc.
H04L63/166H04L63/062H04L63/0807H04L63/1425H04L63/20H04L65/1045G06F16/3329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,122
App. No.
18/373,416
Granted
May 26, 2026
Kind
B2
Abstract

Methods, non-transitory computer readable media, network traffic manager apparatuses, and systems that assist with generating client-executable actions with TLS parameters includes receiving a request from a client for establishing a TLS connection to a server, wherein the request comprises TLS parameters for the TLS connection. An identity of the client is determined based on the TLS parameters in the request unique to the client. A recommended client-executable action is generated based on the TLS parameters. The recommended client-executable action is an adjustment of a characteristic of a system of the client. The recommended client-executable action is transmitted to the client.

Claims (44)

1 . A method for generating client-executable actions for an identified client, the method implemented by a network traffic management system comprising one or more network traffic apparatuses, client devices, or server devices, the method comprising:

receiving a request from a client for establishing a TLS connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determining an identity of the client based on the TLS parameters in the request unique to the client by comparing the TLS parameters in the request to a database with known clients mapped to unique combinations of TLS parameters to identify a matching client in the database with a same combination of TLS parameters;

generating a recommended client-executable action based on the TLS parameters, wherein the recommended client-executable action is an adjustment of a characteristic of a system of the client; and

transmitting the recommended client-executable action to the client.

2 . The method as set forth in claim 1 , further comprising:

retrieving historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determining whether the identified client is a suspicious client based on the historical activity associated with the identified client, wherein the recommended client-executable action is a recommended client-executable security action when the identified client is a suspicious client.

3 . The method as set forth in claim 2 , wherein the recommended client-executable security action comprises changing an encryption policy, altering an encryption algorithm, updating a version of TLS handshake messages.

4 . The method as set forth in claim 1 , wherein the recommended client-executable action comprises recommending directing the request or a subsequent request from the identified client through specific hardware or a different service chain.

5 . The method as set forth in claim 1 , wherein the recommended client-executable action comprises recommending a modification of treatment of a plurality of subsequent requests from the identified client based on a predetermined category, wherein the identified client is classified into the predetermined category prior to generating the recommended client-executable action.

6 . A non-transitory computer readable medium having stored thereon instructions for establishing a connection to a server with a certificate comprising executable code which when executed by one or more processors, causes the processors to:

receive a request from a client for establishing a TLS connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client by comparing the TLS parameters in the request to a database with known clients mapped to unique combinations of TLS parameters to identify a matching client in the database with a same combination of TLS parameters;

generate a recommended client-executable action based on the TLS parameters, wherein the recommended client-executable action is an adjustment of a characteristic of a system of the client; and

transmit the recommended client-executable action to the client.

7 . The medium as set forth in claim 6 , wherein the executable code which when executed by the processors, further causes the processors to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client, wherein the recommended client-executable action is a recommended client-executable security action when the identified client is a suspicious client.

8 . The medium as set forth in claim 7 , wherein the recommended client-executable security action comprises changing an encryption policy, altering an encryption algorithm, updating a version of TLS handshake messages.

9 . The medium as set forth in claim 6 , wherein the recommended client-executable action comprises recommending directing the request or a subsequent request from the identified client through specific hardware or a different service chain.

10 . The medium as set forth in claim 6 , wherein the recommended client-executable action comprises recommending a modification of treatment of a plurality of subsequent requests from the identified client based on a predetermined category, wherein the identified client is classified into the predetermined category prior to generating the recommended client-executable action.

11 . A network traffic manager apparatus, comprising memory comprising programmed instructions stored in the memory and one or more processors configured to be capable of executing the programmed instructions stored in the memory to:

receive a request from a client for establishing a TLS connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client by comparing the TLS parameters in the request to a database with known clients mapped to unique combinations of TLS parameters to identify a matching client in the database with a same combination of TLS parameters;

generate a recommended client-executable action based on the TLS parameters, wherein the recommended client-executable action is an adjustment of a characteristic of a system of the client; and

transmit the recommended client-executable action to the client.

12 . The device as set forth in claim 11 , wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client, wherein the recommended client-executable action is a recommended client-executable security action when the identified client is a suspicious client.

13 . The device as set forth in claim 12 , wherein the recommended client-executable security action comprises changing an encryption policy, altering an encryption algorithm, updating a version of TLS handshake messages.

14 . The device as set forth in claim 11 , wherein the recommended client-executable action comprises recommending directing the request or a subsequent request from the identified client through specific hardware or a different service chain.

15 . The device as set forth in claim 11 , wherein the recommended client-executable action comprises recommending a modification of treatment of a plurality of subsequent requests from the identified client based on a predetermined category, wherein the identified client is classified into the predetermined category prior to generating the recommended client-executable action.

16 . A network traffic management system, comprising one or more traffic management apparatuses, client devices, or server devices, the network traffic management system comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to:

receive a request from a client for establishing a TLS connection to a server, wherein the request comprises TLS parameters for the TLS connection;

determine an identity of the client based on the TLS parameters in the request unique to the client by comparing the TLS parameters in the request to a database with known clients mapped to unique combinations of TLS parameters to identify a matching client in the database with a same combination of TLS parameters;

generate a recommended client-executable action based on the TLS parameters, wherein the recommended client-executable action is an adjustment of a characteristic of a system of the client; and

transmit the recommended client-executable action to the client.

17 . The network traffic management system of claim 16 , wherein the one or more processors are further configured to be capable of executing the programmed instructions stored in the memory to:

retrieve historical activity from a database associated with the identified client, wherein the historical activity comprises historical requests or historical transactions of the identified client; and

determine whether the identified client is a suspicious client based on the historical activity associated with the identified client, wherein the recommended client-executable action is a recommended client-executable security action when the identified client is a suspicious client.

18 . The network traffic management system of claim 17 , wherein the recommended client-executable security action comprises changing an encryption policy, altering an encryption algorithm, updating a version of TLS handshake messages.

19 . The network traffic management system of claim 16 , wherein the recommended client-executable action comprises recommending directing the request or a subsequent request from the identified client through specific hardware or a different service chain.

20 . The network traffic management system of claim 16 , wherein the recommended client-executable action comprises recommending a modification of treatment of a plurality of subsequent requests from the identified client based on a predetermined category, wherein the identified client is classified into the predetermined category prior to generating the recommended client-executable action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: CLARK, JOHN RAY; ADAMS, JASON R.; TYAGI, MUDIT; ARORA, JUDGE K.
To: F5, INC.
Reel/Frame 066654/0749 →
Continuity (1)
Related Publication 20250106254A1 · Mar 27, 2025
References Cited (20)
US 7369537B1 · Kirchhoff · 2008 [cited by examiner]
US 10432406B1 · Amdahl · 2019 [cited by applicant]
US 10951652B1 · Sharifi Mehr · 2021 [cited by examiner]
US 12107878B1 · Mathews · 2024 [cited by applicant]
US 20020129236A1 · Nuutinen · 2002 [cited by applicant]
US 20130080475A1 · Gillen · 2013 [cited by examiner]
US 20140093081A1 · Hawkes · 2014 [cited by examiner]
US 20160179494A1 · Pavlov · 2016 [cited by examiner]
US 20190279073A1 · Adibowo · 2019 [cited by examiner]
US 20200036114A1 · Wang · 2020 [cited by applicant]
US 20200236114A1 · Patil · 2020 [cited by applicant]
US 20210382924A1 · Aaltonen · 2021 [cited by examiner]
US 20220070193A1 · Konda · 2022 [cited by applicant]
US 20220255839A1 · Dhanabalan et al. · 2022 [cited by applicant]
US 20230156038A1 · Konda · 2023 [cited by applicant]
EP 3767916A1 · 2021 [cited by applicant]
WO 2015080661A1 · 2015 [cited by applicant]
WO 2020140114A1 · 2020 [cited by applicant]
European Search Report Dated Jan. 13, 2025. European Patent Application No. 24202623.5. [cited by applicant]
European Search Report for EP 24202604.5. European Patent Office. Search Report. Jan. 21, 2025. Entire Report. The European Search Report for EP24202604.5 cites prior art references that are relevant to the claims of th… [cited by applicant]