IP Library Granted Patent US 9,996,688
Granted Patent B1
US 9,996,688 · App. 12/914,767 · Granted Jun 12, 2018

Systems and methods for controlling access to computer applications or data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,996,688
App. No.
12/914,767
Filed
Oct 28, 2010
Granted
Jun 12, 2018
Kind
B1
Art Unit
2491
USPC
726/7
Abstract

Solutions for controlling access to computer applications or data are disclosed. For instance, certain systems advantageously secure access to applications and data by not allowing the file to launch if conditions acceptable to opening the file are not met, even when the user or computer has the authority to access the file. In other instances, certain systems advantageously secure access to applications and data by not allowing the file to launch if the user credentials are not validated, even when the conditions acceptable to opening the file are met.

Claims (47)

1. A computer executable method in a client-server environment for securing access to a virtualized application on at least one client system, the method on the client system comprising:

receiving via a network on a client system from a server system a first file comprising one or more first environmental conditions, wherein the first environmental conditions are determined after the client system has started;

running a monitoring agent at a virtualization layer on the client system to detect when a user logon to the client system occurs;

verifying, in response to the detected user logon, whether the one or more first environmental conditions are met;

authorizing, in response to the one or more first environmental conditions being met, the client system to access a virtualized application;

storing the authorized virtualized application and associated data in memory of the client system as an encrypted file;

wherein the virtualization layer encapsulates the stored authorized virtualized application from an operating system of the client system on which the stored authorized virtualized application is executed and intercepts and redirects at least one of file operations and registry operations of the stored authorized virtualized application;

receiving via a network on the client system from the server system a second file comprising one or more second environmental conditions;

wherein the second environmental conditions are determined after the client system has requested access to the stored authorized virtualized application, wherein the second environmental conditions are based on hardware and software components of the client system, wherein the second environmental conditions are independent of user input, and wherein at least one of the second environmental conditions is previously set graphically on the server system using a graphical user interface with one or more user selectable selections;

running the monitoring agent at the virtualization layer on the client system to detect when the client system has requested access to the stored authorized virtualized application;

determining, in response to the detected access request, whether the one or more second environmental conditions are met;

receiving, in response to the one or more second environmental conditions being met, on the client system from the server system a security file comprising one or more security conditions;

requesting, in response to receiving the security file, one or more user credentials from a user;

receiving from the user the one or more user credentials;

determining whether the one or more received user credentials meet the one or more security conditions;

automatically permitting the client system to launch the stored authorized virtualized application when the one or more security conditions are met;

periodically detecting whether the launched virtualized application is executing, wherein the period is previously set graphically on the server system using the graphical user interface with one or more user selectable selections;

determining, in response to the detected running virtualized application, whether the one or more second environmental conditions are met; and

automatically permitting the detected executing virtualized application to continue to execute when the one or more second environmental conditions are met.

2. The method of claim 1 further comprising automatically preventing the client system from launching the stored authorized virtualized application when the one or more second environmental conditions are not met.

3. The method of claim 1 further comprising automatically preventing the client system from launching the stored authorized virtualized application when the one or more security conditions are not met.

4. The method of claim 1 , wherein the second environmental conditions are selected from the group consisting of class of machine, operating system, connection type, computer information, terminal services, custom validation functions, timing information, and event information.

5. The method of claim 1 , wherein the second environmental conditions are selected from the group consisting of computer domain, computer group, computer organizational unit, user organizational unit, primary group, site, user group, and user name.

6. The method of claim 1 further comprising automatically stopping the detected executing virtualized application when the one or more second environmental conditions are not met.

7. A non-transitory computer readable storage medium comprising computer executable instructions configured to implement a method in a client-server environment for securing access to a virtualized application on at least one client system, the method on the client system comprising:

receiving via a network on a client system from a server system a first file comprising one or more first environmental conditions, wherein the first environmental conditions are determined after the client system has started;

running a monitoring agent at a virtualization layer on the client system to detect when a user logon to the client system occurs;

verifying, in response to the detected user logon, whether the one or more first environmental conditions are met;

authorizing, in response to a first environmental condition being met, the client system to access a virtualized application;

storing the authorized virtualized application and associated data in memory of the client system as an encrypted file;

wherein the virtualization layer encapsulates the stored authorized virtualized application from an operating system of the client system on which the stored authorized virtualized application is executed and intercepts and redirects at least one of file operations and registry operations of the stored authorized virtualized application;

receiving via a network on the client system from the server system a second file comprising one or more second environmental conditions;

wherein the second environmental conditions are determined after the client system has requested access to the stored authorized virtualized application, wherein the second environmental conditions are based on hardware and software components of the client system, wherein the second environmental conditions are independent of user input, and wherein of the second environmental conditions is previously set graphically on the server system using a graphical user interface with one or more user selectable selections;

running the monitoring agent at the virtualization layer on the client system to detect when the client system has requested access to the stored authorized virtualized application;

determining, in response to the detected access request, whether the one or more second environmental conditions are met;

receiving, in response to a second environmental condition being met, on the client system from the server system a security file comprising one or more security conditions;

requesting, in response to receiving the security file, one or more user credentials from a user;

receiving from the user the one or more user credentials;

determining whether the one or more received user credentials meet the one or more security conditions;

automatically permitting the client system to open the stored authorized virtualized application when the one or more security requirements are met;

periodically detecting whether the opened virtualized application is running, wherein the period is previously set graphically on the server system using the graphical user interface with one or more user selectable selections;

determining, in response to the detected running virtualized application, whether the one or more second environmental conditions are met; and

automatically permitting the client system to continue to execute the detected running virtualized application when the one or more second environmental conditions are met.

8. The medium of claim 7 further comprising automatically preventing the client system from opening the stored authorized virtualized application when the one or more second environmental conditions are not met.

9. The medium of claim 7 further comprising automatically preventing the client system from opening the stored authorized virtualized application when the one or more security requirements are not met.

10. The medium of claim 7 , wherein the second environmental conditions are selected from the group consisting of computer name, host address, media access control (MAC) address, transmission control protocol/Internet protocol (TCP/IP) address, file existence, file version, IP v4 range, IP v6 range, registry key existence, and registry value.

11. The medium of claim 7 further comprising automatically stopping the client system from executing the detected running virtualized application when the one or more second environmental conditions are not met.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL USA L.P.; DELL SOFTWARE INC.; DELL INC.; DELL PRODUCTS L.P.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →