IP Library › Granted Patent US 7,606,902
Granted Patent B2
US 7,606,902 · App. 11/161,092 · Granted Oct 20, 2009

Method and systems for routing packets from an endpoint to a gateway

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,606,902
App. No.
11/161,092
Granted
Oct 20, 2009
Kind
B2
Abstract

A method for routing packets from an endpoint to a gateway includes the step of receiving a filtering table. An outbound packet is intercepted. The outbound packet is transmitted to a client application, responsive to the filtering table. The client application transmits the outbound packet to a gateway responsive to an application of a policy to the outbound packet.

Claims (37)

1. A method for routing packets from an endpoint to a gateway, the method comprising:

(a) receiving, by a driver of a process for providing secure communications to a gateway from an endpoint, a filtering table;

(b) intercepting, by the driver, an outbound packet, the driver terminating a first transport layer connection with an application of the endpoint;

(c) transmitting, by the driver, the outbound packet to a client application, responsive to the filtering table, the client application providing a second transport layer connection from the endpoint to the gateway; and

(d) transmitting, by the client application, the outbound packet to the gateway responsive to an application of a policy to the outbound packet.

2. The method of claim 1 , wherein step (a) further comprises receiving the filtering table from a client application.

3. The method of claim 1 , wherein step (c) further comprises transmitting information about the outbound packet to the client application.

4. The method of claim 1 , wherein step (c) further comprises transmitting the outbound packet to the client application, responsive to a routing table.

5. The method of claim 1 , wherein step (c) further comprises transmitting the outbound packet to a port monitored by the client application.

6. The method of claim 1 , wherein step (d) further comprises authentication, by the client application, of the endpoint to the gateway.

7. The method of claim 1 , wherein step (d) further comprises encrypting, by the client application, the outbound packet.

8. The method of claim 1 , wherein step (d) further comprises establishing, by the client application, a secure sockets layer (SSL) tunnel via the second transport layer connection to the gateway.

9. The method of claim 1 , further comprising the step of transmitting an encrypted outbound packet to the gateway via an SSL tunnel to the gateway.

10. A device for routing packets to a gateway, the device comprising:

a filter of a process for providing secure communications to a gateway, intercepting an outbound packet and transmitting the outbound packet, responsive to a filter table, the filter terminating a first transport layer connection of an application; and

a client application, in communication with the filter, receiving the outbound packet, the client application providing a second transport layer connection to the gateway and determining to transmit the outbound packet to the gateway, responsive to applying a policy to the outbound packet.

11. The device of claim 10 , wherein the filter comprises a driver.

12. The device of claim 11 , wherein the driver complies with a Network Driver Interface Specification (NDIS).

13. The device of claim 10 , wherein the filter transmits the outbound packet to the client application, responsive to a routing table.

14. The device of claim 10 , wherein the filter and the client application reside on a computer system.

15. The device of claim 10 , wherein the filter executes in kernel mode.

16. The device of claim 10 , wherein the process executes in kernel mode.

17. The device of claim 10 , wherein the client application is a second process.

18. The device of claim 17 , wherein the second process executes in user mode.

19. A system for routing packets to a gateway, the system comprising:

a computer system providing a gateway, comprising a kernel and an application space, receiving at least one outbound packet; and

a device, in communication with the computer system, comprising:

a filter of a process for providing secure communications to a gateway from the device, intercepting an outbound packet and transmitting the outbound packet, responsive to a filter table, the filter terminating a first transport layer connection of an application; and

a client application, in communication with the filter, receiving the outbound packet, the client application providing a second transport layer connection to the gateway and determining to transmit the outbound packet to the gateway, responsive to applying a policy to the outbound packet.

20. The system of claim 19 , wherein the filter comprises a driver.

21. The system of claim 20 , wherein the driver complies with a Network Driver Interface Specification (NDIS).

22. The system of claim 19 , wherein the filter transmits the outbound packet to the client application, responsive to a routing table.

23. The system of claim 19 , wherein the filter and the client application reside on a computer system.

24. The system of claim 19 , wherein the filter executes in kernel mode.

25. The system of claim 19 , wherein the process executes in kernel mode.

26. The system of claim 19 , wherein the client application is a second process.

27. The system of claim 26 , wherein the second process executes in user mode.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2005
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC R.
To: CITRIX SYSTEMS, INC.
Reel/Frame 016950/0030 →
Continuity (5)
Provisional Application 6059083700 · Jul 23, 2004
Provisional Application 6060143100 · Aug 13, 2004
Provisional Application 6060742000 · Sep 3, 2004
Provisional Application 6063437900 · Dec 7, 2004
Related Publication 20060029064A1 · Feb 9, 2006