IP Library › Granted Patent US 9,628,448
Granted Patent B2
US 9,628,448 · App. 14/816,000 · Granted Apr 18, 2017

User and device authentication in enterprise systems

Inventor: Richard Hayton (Cambridge, GB)
Assignee: Citrix Systems, Inc.
H04L63/0428G06F21/31G06F21/32G06F21/41H04L63/0815H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,628,448
App. No.
14/816,000
Filed
Aug 1, 2015
Granted
Apr 18, 2017
Kind
B2
Art Unit
2436
USPC
713/186
Abstract

Methods and systems for authenticating users of client devices to allow access of resources and services in enterprise systems are described herein. An authentication device may validate a user based on authentication credentials received from a client device. Validation data stored by the authentication device, and a corresponding access token transmitted to the client device, may be used to authenticate the user for future resource access requests. A user secret also may be stored by the authentication device and used to validate the user for future resource access requests. Additionally, after validating a user with a first set of authentication credentials, additional sets of credentials for the user may be retrieved and stored at an access gateway for future requests to access other services or resources in an enterprise system.

Claims (81)

1. A method comprising:

receiving, by a computing system associated with an enterprise mobility-management computing environment and from a client device associated with a user of the enterprise mobility-management computing environment, a first authentication request comprising authentication credentials for a resource of the enterprise mobility-management computing environment;

responsive to authenticating the client device with the resource based on the authentication credentials:

storing, by the computing system, validation data comprising the authentication credentials and an identifier corresponding to at least one of the client device or the user;

generating, by the computing system, an access token for the enterprise mobility-management computing environment comprising the identifier and a key utilized by the computing system to encrypt the authentication credentials; and

communicating, by the computing system and to the client device, the access token for subsequent authentication of the client device with the enterprise mobility-management computing environment based on the identifier, the key, and the validation data; and

responsive to receiving from the client device a second authentication request comprising the access token, authenticating the client device based on the access token.

2. The method of claim 1 , wherein authenticating the client device based on the access token comprises, responsive to receiving, by the computing system, data generated by the client device comprising the access token and a request to access the resource:

identifying, by the computing system, the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting, by the computing system, the authentication credentials using a portion of the data generated by the client device comprising the key; and

authenticating, by the computing system, the request using the authentication credentials.

3. The method of claim 2 , comprising, prior to receiving the request to access the resource, updating, by the computing system, the validation data based on a modification to the authentication credentials indicated by data received by the computing system from a different client device associated with the user, wherein authenticating the request comprises authenticating the request based on the modification.

4. The method of claim 1 , wherein authenticating the client device based on the access token comprises, responsive to receiving, by the computing system, data generated by the client device comprising the access token and a request to access a different resource of the enterprise mobility-management computing environment:

identifying, by the computing system, the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting, by the computing system, authentication credentials for the different resource using a portion of the data generated by the client device comprising the key; and

authenticating, by the computing system, the request using the authentication credentials for the different resource.

5. The method of claim 4 , comprising, prior to receiving the request to access the different resource:

receiving, by the computing system and from a different client device associated with the user, the authentication credentials for the different resource; and

responsive to authenticating the different client device with the resource based on the authentication credentials for the different resource, updating, by the computing system, the validation data to include the authentication credentials for the different resource.

6. The method of claim 4 , comprising, prior to receiving the request to access the different resource and responsive to a determination by the computing system that the user is authorized to utilize the different resource:

receiving, by the computing system, from the different resource, and responsive to a request generated by the computing system, the authentication credentials for the different resource; and

updating, by the computing system, the validation data to include the authentication credentials for the different resource.

7. The method of claim 1 , wherein the validation data comprises authentication information distinct from the authentication credentials, received by the computing system from the client device, and input by the user via the client device in response to a prompt generated by the computing system via the client device, the method further comprising:

responsive to receiving, by the computing system, data generated by the client device comprising the access token and a request to access a different resource of the enterprise mobility-management computing environment:

identifying, by the computing system, the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting, by the computing system, authentication credentials for the different resource using a portion of the data generated by the client device comprising the key; and

responsive to determining that a portion of the data generated by the client device comprises the authentication information, authenticating, by the computing system, the request using the authentication credentials for the different resource.

8. A system comprising:

at least one processor; and

a memory comprising instructions that when executed by the at least one processor cause the system to:

receive, from a client device associated with a user of an enterprise mobility-management computing environment, a first authentication request comprising authentication credentials for a resource of the enterprise mobility-management computing environment;

responsive to authenticating the client device with the resource based on the authentication credentials:

store validation data comprising the authentication credentials and an identifier corresponding to at least one of the client device or the user;

generate an access token for the enterprise mobility-management computing environment comprising the identifier and a key utilized by the system to encrypt the authentication credentials; and

communicate, to the client device, the access token for subsequent authentication of the client device with the enterprise mobility-management computing environment based on the identifier, the key, and the validation data; and

responsive to receiving from the client device a second authentication request comprising the access token, authenticating the client device based on the access token.

9. The system of claim 8 , wherein authenticating the client device based on the access token comprises, responsive to receiving data generated by the client device comprising the access token and a request to access the resource:

identifying the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting the authentication credentials using a portion of the data generated by the client device comprising the key; and

authenticating the request using the authentication credentials.

10. The system of claim 9 , wherein the instructions, when executed by the at least one processor, cause the system to:

prior to receiving the request to access the resource, update the validation data based on a modification to the authentication credentials indicated by data received by the system from a different client device associated with the user; and

authenticate the request based on the modification.

11. The system of claim 8 , wherein authenticating the client device based on the access token comprises, responsive to receiving data generated by the client device comprising the access token and a request to access a different resource of the enterprise mobility-management computing environment:

identifying the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting authentication credentials for the different resource using a portion of the data generated by the client device comprising the key; and

authenticating the request using the authentication credentials for the different resource.

12. The system of claim 11 , wherein the instructions, when executed by the at least one processor, cause the system to:

receive, from a different client device associated with the user, the authentication credentials for the different resource; and

responsive to authenticating the different client device with the resource based on the authentication credentials for the different resource, update the validation data to include the authentication credentials for the different resource.

13. The system of claim 11 , wherein the instructions, when executed by the at least one processor, cause the system to, prior to receiving the request to access the different resource and responsive to a determination by the system that the user is authorized to utilize the different resource:

receive, from the different resource and responsive to a request generated by the system, the authentication credentials for the different resource; and

update the validation data to include the authentication credentials for the different resource.

14. The system of claim 8 , wherein the validation data comprises authentication information distinct from the authentication credentials, received by the system from the client device, and input by the user via the client device in response to a prompt generated by the system via the client device, and wherein the instructions, when executed by the at least one processor, cause the system to, responsive to receiving data generated by the client device comprising the access token and a request to access a different resource of the enterprise mobility-management computing environment:

identify the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypt authentication credentials for the different resource using a portion of the data generated by the client device comprising the key; and

responsive to determining that a portion of the data generated by the client device comprises the authentication information, authenticate the request using the authentication credentials for the different resource.

15. One or more non-transitory computer-readable media comprising instructions that when executed by one or more computers cause the one or more computers to:

receive, from a client device associated with a user of an enterprise mobility-management computing environment, a first authentication request comprising authentication credentials for a resource of the enterprise mobility-management computing environment;

responsive to authenticating the client device with the resource based on the authentication credentials:

store validation data comprising the authentication credentials and an identifier corresponding to at least one of the client device or the user;

generate an access token for the enterprise mobility-management computing environment comprising the identifier and a key utilized by the one or more computers to encrypt the authentication credentials; and

communicate, to the client device, the access token for subsequent authentication of the client device with the enterprise mobility-management computing environment based on the identifier, the key, and the validation data; and

responsive to receiving from the client device a second authentication request comprising the access token, authenticating the client device based on the access token.

16. The one or more non-transitory computer-readable media of claim 15 , wherein authenticating the client device based on the access token comprises, responsive to receiving data generated by the client device comprising the access token and a request to access the resource:

identifying the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting the authentication credentials using a portion of the data generated by the client device comprising the key; and

authenticating the request using the authentication credentials.

17. The one or more non-transitory computer-readable media of claim 16 , wherein the instructions, when executed by the one or more computers, cause the one or more computers to:

prior to receiving the request to access the resource, update the validation data based on a modification to the authentication credentials indicated by data received by the one or more computers from a different client device associated with the user; and

authenticate the request based on the modification.

18. The one or more non-transitory computer-readable media of claim 15 , wherein authenticating the client device based on the access token comprises, responsive to receiving data generated by the client device comprising the access token and a request to access a different resource of the enterprise mobility-management computing environment:

identifying the validation data based on a portion of the data generated by the client device comprising the identifier;

decrypting authentication credentials for the different resource using a portion of the data generated by the client device comprising the key; and

authenticating the request using the authentication credentials for the different resource.

19. The one or more non-transitory computer-readable media of claim 18 , wherein the instructions, when executed by the one or more computers, cause the one or more computers to:

receive, from a different client device associated with the user, the authentication credentials for the different resource; and

responsive to authenticating the different client device with the resource based on the authentication credentials for the different resource, update the validation data to include the authentication credentials for the different resource.

20. The one or more non-transitory computer-readable media of claim 18 , wherein the instructions, when executed by the one or more computers, cause the one or more computers to, prior to receiving the request to access the different resource and responsive to a determination by the one or more computers that the user is authorized to utilize the different resource:

receive, from the different resource and responsive to a request generated by the one or more computers, the authentication credentials for the different resource; and

update the validation data to include the authentication credentials for the different resource.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2015
From: HAYTON, RICHARD
To: CITRIX SYSTEMS, INC.
Reel/Frame 036233/0834 →
Continuity (2)
Continuation 13886518 · May 3, 2013
Related Publication 20150350168A1 · Dec 3, 2015