IP Library › Granted Patent US 7,978,714
Granted Patent B2
US 7,978,714 · App. 11/161,090 · Granted Jul 12, 2011

Methods and systems for securing access to private networks using encryption and authentication technology built in to peripheral devices

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,978,714
App. No.
11/161,090
Filed
Jul 22, 2005
Granted
Jul 12, 2011
Kind
B2
Art Unit
2463
USPC
370/401
Abstract

A method for routing packets from a peripheral device to a Virtual Private Network (VPN) gateway includes the step of implementing, by a peripheral device, a change to a routing table. The peripheral device receives an outbound packet. The peripheral device transmits information about the outbound packet to a VPN client application. The peripheral device modifies address information on the outbound packet with address information associated with the VPN client application. The peripheral device transmits the modified outbound packet to the VPN client application.

Claims (51)

1. A method for routing packets from a computer peripheral device to a Virtual Private Network (VPN) gateway, the method comprising:

(a) changing, by a computer peripheral device physically attached to and removable from a client computing device accessing a server via a VPN gateway, a routing table stored on the client computing device to instruct the client computing device to transmit an outbound packet to the computer peripheral device, the change received from the VPN gateway by a VPN client application program responsive to authenticating the computer peripheral device to the VPN gateway, the VPN client application program stored on the computer peripheral device and executing on a processor of the client computing device;

(b) receiving, by a receiver of the computer peripheral device, the outbound packet from the client computing device responsive to the change in the routing table;

(c) transmitting, by a transmitter on the computer peripheral device, information about the outbound packet to the VPN client application program, the VPN client application program establishing a secure communications tunnel with the VPN gateway;

(d) rewriting, by a packet rewriter on the computer peripheral device, address information on the outbound packet; and

(e) transmitting, by the transmitter on the computer peripheral device, the rewritten outbound packet to the VPN client application program to route to the VPN gateway.

2. The method of claim 1 , wherein step (a) further comprises retrieving a plurality of changes to make to the routing table from a VPN gateway.

3. The method of claim 2 , wherein step (a) further comprises authentication of the computer peripheral device to the VPN gateway.

4. The method of claim 1 , further comprising the step of encrypting, by the VPN client application program, the rewritten outbound packet.

5. The method of claim 1 , wherein step (a) further comprises transmitting, by the client computing device, the outbound packet to the computer peripheral device, responsive to the change to the routing table.

6. The method of claim 1 , wherein step (a) further comprises storing, on the computer peripheral device, a plurality of changes to make to the routing table.

7. The method of claim 1 , wherein step (c) further comprises transmitting, by the transmitter of the computer peripheral device, information comprising a unique source port to the VPN client application program.

8. The method of claim 1 , wherein step (d) further comprises rewriting, by the packet rewriter of the computer peripheral device, a destination address on the outbound packet with a destination address and destination port associated with the VPN client application program.

9. The method of claim 1 , wherein step (d) further comprises rewriting, by the computer peripheral device, a source port on the outbound packet with a unique source port.

10. The method of claim 1 , wherein step (e) further comprises transmitting, by the transmitter of the computer peripheral device, the rewritten outbound packet to a port monitored by the VPN client application program.

11. The method of claim 1 , further comprising the step of establishing, by the computer peripheral device, a secure sockets layer (SSL) tunnel to the VPN gateway.

12. The method of claim 1 , further comprising the step of transmitting, by the VPN client application program, an encrypted outbound packet, responsive to the information received about the outbound packet.

13. The method of claim 1 , further comprising the step of establishing, by the VPN client application program, a secure sockets layer (SSL) tunnel to the VPN gateway, responsive to a destination address associated with the outbound packet received from the computer peripheral device.

14. The method of claim 1 , further comprising the step of transmitting an encrypted outbound packet to the VPN gateway across a secure sockets layer (SSL) tunnel.

15. A computer peripheral device for routing packets to a virtual private network (VPN) gateway, the computer peripheral device physically attached to and removable from a client computing device accessing a server via the VPN gateway, comprising:

a routing element changing a routing table stored on the client computing device to instruct the client computing device to transmit an outbound packet to the computer peripheral device, the change received from the VPN gateway by a VPN client application program responsive to authenticating the computer peripheral device to the VPN gateway, the VPN client application program stored on the computer peripheral device and executing on a processor of the client computing device;

a receiver receiving the outbound packet from the client computing device responsive to the change in the routing table;

a transmitter, in communication with the receiver, transmitting information about the outbound packet to the VPN client application program, the VPN client application program establishing a secure communications tunnel with the VPN gateway; and

a packet rewriter, in communication with the receiver and the transmitter, rewriting an address information on the outbound packet, the transmitter transmitting the rewritten outbound packet to the VPN client application program to route to the VPN gateway.

16. The computer peripheral device of claim 15 wherein the VPN client application program resides on the computer peripheral device and executes on the client computing device.

17. The computer peripheral device of claim 15 , wherein the VPN client application program transmits the rewritten outbound packet to the VPN gateway.

18. The computer peripheral device of claim 15 , wherein the packet rewriter generates a mapping table, the mapping table associating information in the outbound packet with information in the rewritten outbound packet.

19. The computer peripheral device of claim 15 , wherein the packet rewriter generates a unique source port to replace a source port on the outbound packet.

20. The computer peripheral device of claim 15 , wherein the packet rewriter replaces a destination address and a destination port on the outbound packet with a destination address and destination port associated with the VPN client application program.

21. A system for routing packets to a virtual private network (VPN) gateway, the system comprising:

a client computing device receiving at least one outbound packet and storing a routing table; and

a computer peripheral device, physically attached to and removable from the client computing device accessing a server via the VPN gateway, comprising:

a routing element changing the routing table to instruct the client computing device to transmit an outbound packet to the computer peripheral device, the change received from the VPN gateway by a VPN client application program responsive to authenticating the computer peripheral device to the VPN gateway, the VPN client application program stored on the computer peripheral device and executing on a processor of the client computing device;

a receiver receiving the at least one outbound packet from the client computing device responsive to the change in the routing table;

a transmitter transmitting information about the at least one outbound packet to the VPN client application program, the VPN client application program establishing a secure communications tunnel with the VPN gateway; and

a packet rewriter, in communication with the receiver and the transmitter, the packet rewriter replacing address information on the outbound packet with a destination address and a destination port associated with the VPN client application, the transmitter transmitting the rewritten outbound packet to the VPN client application program to route to the VPN gateway.

22. The system of claim 21 , wherein the VPN client application program resides on the computer peripheral device.

23. The system of claim 21 , wherein the VPN client application program executes on the client computing device.

24. The system of claim 21 , wherein the computer peripheral device comprises a universal serial bus (USB) key storage device.

25. The system of claim 21 , wherein the computer peripheral device further comprises a reporting element, the reporting element identifying the computer peripheral device to the client computing device as a mass storage device.

26. The system of claim 21 , wherein the computer peripheral device further comprises a reporting element, the reporting element identifying the computer peripheral device to the client computing device as a networking device.

27. The system of claim 21 , wherein the client computing device further comprises a device driver, the device driver enabling communication with the computer peripheral device.

28. The system of claim 27 , wherein the device driver comprises a Remote-Network Driver Interface Specification driver for universal serial bus (USB) devices.

29. The computer peripheral device of claim 15 , wherein the computer peripheral device comprises a Universal Serial Bus (USB) that is physically attached to and removable from a bus of the client computing device.

30. The system of claim 21 , wherein the computer peripheral device comprises a Universal Serial Bus (USB) that is physically attached to and removable from a bus of the client computing device.

31. A method for routing packets from a universal serial bus (USB) device to a Virtual Private Network (VPN) gateway, the method comprising:

(a) changing, by a USB device physically attached to and removable from a client computing device accessing a server via a VPN gateway, a routing table stored in memory on the client computing device to instruct the client computing device to transmit an outbound packet to the computer peripheral device, the change received from the VPN gateway by a VPN client application program responsive to authenticating the computer peripheral device to the VPN gateway, the VPN client application program stored on the computer peripheral device and executing on a processor of the client computing device;

(b) receiving, by a receiver of the USB device, the outbound packet from the client computing device responsive to the change in the routing table;

(c) transmitting, by a transmitter on the USB device, information about the outbound packet to the VPN client application program, the VPN client establishing a secure communications tunnel with the VPN gateway;

(d) rewriting, by a packet rewriter on the USB device, address information on the outbound packet; and

(e) transmitting, by the transmitter on the USB device, the rewritten outbound packet to the VPN client application program to route to the VPN gateway.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2005
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC R.
To: CITRIX SYSTEMS, INC.
Reel/Frame 016950/0103 →
Continuity (5)
Provisional Application 60590837 · Jul 23, 2004
Provisional Application 60601431 · Aug 13, 2004
Provisional Application 60607420 · Sep 3, 2004
Provisional Application 60634379 · Dec 7, 2004
Related Publication 20060029062A1 · Feb 9, 2006