IP Library Granted Patent US 11,722,422
Granted Patent B2
US 11,722,422 · App. 16/588,616 · Granted Aug 8, 2023

Systems and methods for managing streams of packets via intermediary devices

Inventors: Georgy Momchilov (Parkland, FL); Derek Thorslund (San Jose, CA); Daljit Singh (San Jose, CA); Vladimir Vysotsky (Fremont, CA)
H04L47/2441H04L47/2458H04L47/2475H04L47/31H04L47/746H04L47/76H04L47/781H04L47/805H04L47/822H04L69/22H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,422
App. No.
16/588,616
Granted
Aug 8, 2023
Kind
B2
Abstract

Virtual application and desktop delivery may be optimized by supplying application metadata and user intent to the device between a client and a server hosting resources for the delivery. The data packets used to deliver the virtual application or desktop may be also tagged with references to the application. By supplying the metadata and tagging packets with the metadata, an intermediary network device may provide streams of data packets at the target QoS. In addition, the device may apply network resource allocation rules (e.g., firewalls and QoS configuration) for redirected content retrieved by the client out of band relative to a virtual channel such as the Internet. The network resource allocation rules may differ for different types of resources accessed. The device may also control a delivery agent on the server to modify communication sessions established through the virtual channels based on network conditions.

Claims (34)

1. A method comprising:

receiving, by a network device intermediary between a client device and a server, from a delivery agent via a first virtual channel separate from a plurality of virtual channels, metadata of an application hosted on the server and accessible by the client device;

receiving, by the network device from the delivery agent via the first virtual channel, an identifier, the identifier configured to redirect the client device to access web content from a web server via the network device over a second virtual channel of the plurality of virtual channels;

determining, by the network device according to the received metadata, an allocation of network resources to provide a quality of service (QoS) to the client device to be redirected, via the identifier, to access the web content from the web server via the network device; and

providing, by the network device, over the second virtual channel separate from the first virtual channel, network resources to the client device according to the QoS for accessing the web content from the web server to which the client device is redirected via the network device based at least on the determined allocation of network resources.

2. The method of claim 1 , wherein the metadata comprises at least one of: an identification of the application, or interaction data indicative of user interaction with the application.

3. The method of claim 1 , wherein receiving the identifier comprises receiving, by the network device, updated metadata from the delivery agent that includes a uniform resource locator (URL).

4. The method of claim 1 , wherein the network device supports the plurality of virtual channels of the application, each of the plurality of virtual channels for communicating a corresponding stream of packets.

5. The method of claim 4 , wherein a Uniform Resource Locator (URL)-redirection request including the identifier is transmitted via the first virtual channel, from the delivery agent to the client device, the URL-redirection request causing the client device to access the web content from the web server.

6. The method of claim 1 , wherein determining the allocation of network resources comprises determining, by the network device according to the received metadata, at least one rule for allocating network resources for accessing the web content from the web server.

7. The method of claim 6 , wherein the at least one rule for allocating network resources for accessing the web content from the web server comprises at least one of: a firewall rule or a QoS rule.

8. The method of claim 6 , wherein applying the allocation of network resources comprises applying, by the network device, the at least one rule for allocating network resources for a stream of packets communicated via at least one of the plurality of channels for the client device redirected, using the identifier, to access the web content via the network device.

9. The method of claim 1 , comprising receiving, by the network device, the metadata of the application via a cloud service or another network device.

10. The method of claim 1 , further comprising causing the web content and data of the application to be rendered at the client device.

11. The method of claim 10 , further comprising causing the web content to be integrated with the data of the application for rendering at the client device.

12. The method of claim 1 , further comprising receiving, by the network device intermediary, from a workspace application of the client device, metadata about activity at the client device.

13. The method of claim 12 , further comprising determining, by the network device according to the metadata of the application and the metadata about activity at the client device, the allocation of network resources for accessing the web content from the web server.

14. A network device comprising:

at least one processor configured to:

receive, from a delivery agent via a first virtual channel separate from a plurality of virtual channels, metadata of an application hosted on the server and accessible by the client device;

receive, from the delivery agent via the first virtual channel, an identifier, the identifier configured to redirect the client device to access web content from a web server via the network device over a second virtual channel of the plurality of virtual channels;

determine, according to the received metadata, an allocation of network resources to provide a quality of service (QoS) to the client device to be redirected, via the identifier, to access the web content from the web server via the network device; and

provide, over the second virtual channel separate from the first virtual channel, network resources to the client device according to the QoS for accessing the web content from the web server to which the client device is redirected via the network device based on the determined allocation of network resources.

15. The network device of claim 14 , wherein the at least one processor is configured to receive updated metadata from the delivery agent that includes a uniform resource locator (URL).

16. The network device of claim 14 , wherein the at least one processor is configured to support the plurality of virtual channels of the application, each of the plurality of virtual channels for communicating a corresponding stream of packets.

17. The network device of claim 16 , wherein a Uniform Resource Locator (URL)-redirection request including the identifier is transmitted via the first virtual channel, from the delivery agent to the client device, the URL-redirection request causing the client device to access the web content from the web server.

18. The network device of claim 14 , wherein the at least one processor is configured to determine the allocation of network resources, by determining, according to the received metadata, at least one rule for allocating network resources for accessing the web content from the web server, and

wherein the at least one rule for allocating network resources for accessing the web content from the web server comprises at least one of: a firewall rule or a QoS rule.

19. The network device of claim 14 , wherein the at least one processor is configured to receive the metadata of the application via a cloud service or another network device.

20. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

receive, from a delivery agent via a first virtual channel separate from a plurality of virtual channels, metadata of an application hosted on a server and accessible by a client device;

receive, from the delivery agent via the first virtual channel, an identifier, the identifier configured to redirect the client device to access web content from a web server via the one or more processors over a second virtual channel of the plurality of virtual channels;

determine, according to the received metadata, an allocation of network resources to provide a quality of service (QoS) to the client device to be redirected, via the identifier, to access the web content from the web server via the network device; and

provide, over the second virtual channel separate from the first virtual channel, network resources to the client device according to the QoS for accessing the web content from the web server to which the client device is redirected via the network device based on the determined allocation of network resources.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2019
From: MOMCHILOV, GEORGY; THORSLUND, DEREK; SINGH, DALJIT; VYSOTSKY, VLADIMIR
To: CITRIX SYSTEMS, INC.
Reel/Frame 050616/0298 →
Continuity (3)
Continuation 16588280 · Sep 30, 2019
Provisional Application 62850348 · May 20, 2019
Related Publication 20200374234A1 · Nov 26, 2020
Cited By (1)
US 12,301,466