US2022021532A1PendingUtilityA1

Tracking Tainted Connection Agents

Assignee: CITRIX SYSTEMS INCPriority: Jan 2, 2019Filed: Sep 30, 2021Published: Jan 20, 2022
Est. expiryJan 2, 2039(~12.4 yrs left)· nominal 20-yr term from priority
G06F 8/61G06F 21/53G06F 21/44G06F 9/452G06F 2009/45587H04L 63/126G06F 9/45558H04L 9/0894G06F 21/33G06F 21/57G06F 2009/45595H04L 2463/081H04L 9/30G06F 21/552H04L 63/0823
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for tracking tainted connection agents, such as without a trusted central authority, are described herein. During a server outage, a client device may verify that a connection agent is untainted based on a public-key encryption or certificate-based system. If the connection agent is untainted, a server may sign a public key or certificate associated with the connection agent. The server may provide, to the client device, a lease, a public key associated with the server. The connection agent may sign data generated by the client device. The client device may verify a signature of the signed public key, such as based on the public key associated with the server. The client device may verify a signature of the signed data, such as based on the verified public key associated with the connection agent.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by a client device and from one or more servers, a public key of the one or more servers;   receiving, by the client device and from a computing device, information comprising:
 a public key, of the computing device, signed by a private key of the one or more servers; and 
 data generated by the client device and signed by a private key of the computing device; and 
   determining, by the client device, whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.   
     
     
         2 . The method of  claim 1 , wherein the receiving the public key of the one or more servers comprises issuing, by the one or more servers to the client device, a connection lease. 
     
     
         3 . The method of  claim 2 , further comprising:
 based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connecting, by the client device, to a second computing device identified in the connection lease.   
     
     
         4 . The method of  claim 2 , further comprising:
 based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determining, by the client device, whether a signature of the signed data corresponds to the signed public key of the computing device.   
     
     
         5 . The method of  claim 4 , further comprising:
 based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connecting, by the client device, to a second computing device identified in the connection lease.   
     
     
         6 . The method of  claim 4 , further comprising:
 based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connecting, by the client device, to the computing device.   
     
     
         7 . The method of  claim 1 , further comprising:
 receiving, by the client device and from the one or more servers, a second public key of the one or more servers; and   verifying, by the client device and based on the second public key of the one or more servers, the signed public key of the computing device.   
     
     
         8 . The method of  claim 1 , wherein the signed public key of the computing device comprises one or more of a machine ID or an expiration date. 
     
     
         9 . One or more non-transitory computer readable media storing computer readable instructions that, when executed, cause a client device to:
 receive, from one or more servers, a public key of the one or more servers;   receive, from a computing device, information comprising:
 a public key, of the computing device, signed by a private key of the one or more servers; and 
 data generated by the client device and signed by a private key of the computing device; and 
   determine whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.   
     
     
         10 . The one or more non-transitory computer-readable media of  claim 9 , wherein the public key associated with the one or more servers is associated with a connection lease issued by the one or more servers to the client device. 
     
     
         11 . The one or more non-transitory computer-readable media of  claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
 based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connect to a second computing device identified in the connection lease.   
     
     
         12 . The one or more non-transitory computer-readable media of  claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
 based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and   based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connect to a second computing device identified in the connection lease.   
     
     
         13 . The one or more non-transitory computer-readable media of  claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
 based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and   based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connect to the computing device.   
     
     
         14 . The one or more non-transitory computer-readable media of  claim 9 , wherein the computer readable instructions, when executed, further cause the client device to:
 receive, from the one or more servers, a second public key associated with the one or more servers; and   verify, based on the second public key associated with the one or more servers, the signed public key of the computing device.   
     
     
         15 . An apparatus comprising:
 one or more processors; and   memory storing executable instructions that, when executed by the one or more processors, cause the apparatus to:   receive, from one or more servers, a public key of the one or more servers;   receive, from a computing device, information comprising:
 a public key, of the computing device, signed by a private key of the one or more servers; and 
 data generated by the apparatus and signed by a private key of the computing device; and 
   determine whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.   
     
     
         16 . The apparatus of  claim 15 , wherein the public key associated with the one or more servers is associated with a connection lease issued by the one or more servers to the apparatus. 
     
     
         17 . The apparatus of  claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
 based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connect to a second computing device identified in the connection lease.   
     
     
         18 . The apparatus of  claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
 based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and   based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connect to a second computing device identified in the connection lease.   
     
     
         19 . The apparatus of  claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
 based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and   based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connect to the computing device.   
     
     
         20 . The apparatus of  claim 15 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
 receive, from the one or more servers, a second public key associated with the one or more servers; and   verify, based on the second public key associated with the one or more servers, the signed public key of the computing device.

Join the waitlist — get patent alerts

Track US2022021532A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.