IP Library Granted Patent US 9,152,799
Granted Patent B2
US 9,152,799 · App. 13/975,145 · Granted Oct 6, 2015

System and method for allowing secure remote server access using data prevention code

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,152,799
App. No.
13/975,145
Granted
Oct 6, 2015
Kind
B2
Abstract

Systems and methods are provided for providing users at remote access devices with conditional access to server-based applications. Requests for access to server-based applications (e.g., requests to launch or obtain data associated with the server-based applications) by remote access devices may be prevented or allowed based on device compliance with one or more policies including whether data-retention prevention code can be downloaded to and operational on the remote access devices. The data-retention prevention code may be used to both determine whether data can be automatically deleted from a cache or file directory at the remote access device and to delete potentially retention-sensitive data once the data is downloaded to the remote access device from the server-based application.

Claims (37)

1. A method comprising:

providing a data-retention prevention code and data to a remote device, the data-retention prevention code to cause the remote device to delete the data from a cache;

notifying the remote device to launch the data-retention prevention code;

receiving an indication from the remote device that the data-retention prevention code is enabled;

preventing the remote device from accessing server-based applications when the data has not been deleted from the cache using the data-retention prevention code; and

receiving an indication from the remote device that the data has been deleted from the cache.

2. The method of claim 1 , further comprising allowing the remote device to access the server-based applications in response to receiving the indication from the remote device that the data has been deleted.

3. The method of claim 1 , wherein when the data is deleted from the cache, the data-retention prevention code uninstalls itself from the remote device.

4. The method of claim 1 , wherein when the data is not deleted from the cache the data-retention prevention code retries to delete the data until successful.

5. The method of claim 1 , further comprising receiving a request from the remote device to launch the server-based applications before providing the data-retention prevention code.

6. The method of claim 1 , wherein the remote device is an untrusted remote device.

7. The method of claim 1 , wherein the remote device is a trusted remote device.

8. The method of claim 1 , further comprising preventing the remote device from accessing the server-based applications when the data has not been deleted from a file directory of the remote device.

9. A computer-readable storage device storing instructions which when executed by one or more processors, cause the one or more processors to:

provide sample data to a remote access device, the sample data being associated with a server-based application;

provide a data-retention prevention code to the remote access device to cause the remote access device to delete the sample data;

receive a signal indicating that the data-retention prevention code is enabled;

notify the server-based application that the data-retention prevention code is enabled;

provide a signal to the remote access device to cause the remote access device to attempt to delete the sample data;

receive an indication from the remote access device that the sample data has been deleted using the data-retention prevention code; and

based at least in part on receiving the indication, provide the remote access device with access to the server-based application.

10. The computer-readable storage device of claim 9 , further comprising instructions which when executed by the one or more processors, cause the one or more processors to determine whether the remote access device is a trusted device or an untrusted device.

11. The computer-readable storage device of claim 9 , wherein the sample data is deleted from a cache.

12. The computer-readable storage device of claim 9 , wherein the sample data is deleted from a file directory.

13. A system comprising:

one or more processors; and

a computer-readable storage device storing executable instructions which when executed by one or more processors, cause the one or more processors to:

provide sample data to a remote access device, the sample data being associated with a server-based application;

provide a data-retention prevention code to the remote access device to cause the remote access device to delete the sample data;

receive an indication from the remote access device that the sample data has been deleted using the data-retention prevention code; and

based at least in part on receiving the indication, provide the remote access device with access to the server-based application.

14. The system of claim 13 , wherein the computer-readable storage device stores executable instructions, which when executed by one or more processors, cause the one or more processors to disallow the remote access device from accessing the server-based application when the data-retention prevention code is disabled.

15. The system of claim 13 , wherein the computer-readable storage device stores executable instructions, which when executed by one or more processors, cause the one or more processors to notify the server-based application when the data-retention prevention code fails to download on the remote access device.

16. The system of claim 13 , wherein the remote access device comprises an untrusted device.

17. The system of claim 13 , wherein the remote access device comprises a trusted device.

18. The system of claim 13 , wherein the sample data is deleted from a cache.

19. The system of claim 13 , wherein the sample data is deleted from a file directory.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2015
From: KOHAVI, LIOR
To: MICROSOFT TECHNOLOGY LICENSING, LLC.
Reel/Frame 035423/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0541 →