IP Library Granted Patent US 8,559,449
Granted Patent B2
US 8,559,449 · App. 13/149,383 · Granted Oct 15, 2013

Systems and methods for providing a VPN solution

Inventors: Goutham P. Rao (San Jose, CA); Robert Rodriguez (San Jose, CA); Eric Brueggemann (Cupertino, CA)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,559,449
App. No.
13/149,383
Granted
Oct 15, 2013
Kind
B2
Abstract

A system, apparatus and a method for implementing a secured communications link at a layer other than that at which packets are filtered are disclosed. In one embodiment, a computer system is configured to form a virtual private network (“VPN”) and comprises an address inspection driver to identify initial target packet traffic addressed to a target server. Also, the computer system includes a pseudo server module to receive rerouted initial target packet traffic from the address inspection driver. The pseudo server module is configured to convey packet regeneration instructions to a VPN gateway. The address inspection driver functions to identify additional target packet traffic addressed to the target server and routes the additional target packet traffic to the pseudo server. In one embodiment, the pseudo server is configured to strip header information from the additional target packet traffic to form a payload, and thereafter, to route the payload to the target.

Claims (28)

1. A method for securing a private network communications to a server, the method comprising:

(a) filtering, by an address inspection driver of a device, packets from outgoing network traffic generated by an application of the device, the filtered packets identified as destined for a server on a private network;

(b) reconfiguring, by the address inspection driver, the filtered packets as incoming packets that are rerouted to a port;

(c) receiving, by a pseudo server of the device, the filtered packets via the port; and

(d) transmitting, by the pseudo server, a payload of the filtered packets via a secure communications link to a gateway in communication with the server on a private network.

2. The method of claim 1 , wherein step (a) further comprises intercepting, by the address inspection driver, network traffic of the application.

3. The method of claim 1 , wherein step (a) further comprises filtering, by the address inspection driver, network traffic at a network layer of a network stack of the device.

4. The method of claim 1 , wherein step (a) further comprises filtering, by the address inspection driver, network traffic at a data link layer of a network stack of the device.

5. The method of claim 1 , wherein step (b) further comprises reconfiguring, by the address inspection driver, the filtered packets to identify a destination address of a local host.

6. The method of claim 1 , wherein step (b) further comprises reconfiguring, by the address inspection driver, the filtered packets to identify a loop back address of a network stack of the device.

7. The method of claim 1 , wherein step (c) further comprises listening, by the pseudo server, on the port for filtered packets.

8. The method of claim 1 , wherein step (d) further comprises stripping, by the pseudo server, header information from the filtered packets.

9. The method of claim 1 , wherein step (e) further comprises transmitting, by the pseudo server to the gateway, instructions on regenerating the stripped header information on the private network.

10. The method of claim 1 , wherein step (e) further comprises encrypting, by the pseudo server, the payload of the filtered packets.

11. A method for communicating packets from real time applications via a secure communications link, the method comprising:

(a) intercepting, by an address inspection driver of a device, packets from outgoing real-time packet traffic generated by a real-time application of the device, the packets comprising user datagram protocol (UDP) packets identified as destined for a server on a private network;

(b) communicating, by the address inspection driver, the packets to a pseudo server executing on the device and having a secure communications link to a gateway in communication with the server on the private network

(c) modifying, by a pseudo server, the packets to comprise UDP packets flagged as transport control protocol (TCP) packets; and

(d) transmitting, by the pseudo server, the modified packets via the secure communications link to the gateway.

12. The method of claim 11 , wherein step (a) further comprises intercepting, by the address inspection driver, packets from outgoing real-time packet traffic comprising one of video or audio data.

13. The method of claim 11 , wherein step (a) further comprises filtering, by the address inspection driver, network traffic at a network layer of a network stack of the device.

14. The method of claim 11 , wherein step (a) further comprises filtering, by the address inspection driver, network traffic at a data link layer of a network stack of the device.

15. The method of claim 11 , wherein step (b) further comprises reconfiguring, by the address inspection driver, the packets to identify a destination address of a local host.

16. The method of claim 11 , wherein step (b) further comprises reconfiguring, by the address inspection driver, the packets to identify a loop back address of a network stack of the device.

17. The method of claim 11 , wherein step (b) further comprises listening, by the pseudo server, on a port for packets communicated by the address inspection driver.

18. The method of claim 11 , wherein step (c) further comprises flagging, by the pseudo server, UDP packets as TCP packets by setting a flag in an Internet Protocol header of the UDP packets.

19. The method of claim 11 , wherein step (c) further comprises modifying, by the pseudo server, an Internet Protocol header of the UDP packets to masquerade the UDP packets as TCP packets.

20. The method of claim 11 , wherein step (d) further comprises transmitting, by the pseudo server, the modified packets via a raw socket connection.

Assignments (11)
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2014
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT A.; BRUEGGEMANN, ERIC R.
To: CITRIX SYSTEMS, INC.
Reel/Frame 034490/0849 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 15, 2011
From: NET6, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 027392/0202 →
CHANGE OF NAME Recorded Sep 1, 2011
From: NET6, INC.
To: CITRIX GATEWAYS,INC.
Reel/Frame 026844/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2011
From: RAO, GOUTHAM P.; RODRIGUEZ, ROBERT; BRUEGGEMANN, ERIC
To: NET6, INC.
Reel/Frame 026843/0321 →
Continuity (5)
Continuation 12336795 · Dec 17, 2008
Continuation 10988004 · Nov 12, 2004
Provisional Application 60518305 · Nov 11, 2003
Provisional Application 60524999 · Nov 24, 2003
Related Publication 20110231929A1 · Sep 22, 2011