IP Library › Granted Patent US 9,838,398
Granted Patent B2
US 9,838,398 · App. 15/006,348 · Granted Dec 5, 2017

Validating the identity of an application for application management

Inventors: Gary Barton (Boca Raton, FL); Zhongmin Lang (Parkland, FL); James Robert Walker (Deerfield Beach, FL)
Assignee: Citrix Systems, Inc.
H04L63/102G06F21/33G06F21/44G06F21/51G06F21/53H04L63/10H04W12/06H04W12/08G06F2221/033G06F2221/2103G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,398
App. No.
15/006,348
Granted
Dec 5, 2017
Kind
B2
Abstract

A method of managing access to enterprise resources is provided. An access manager may operate at a mobile device to validate a mobile application installed at that mobile device. If the access manager does not successfully validate the mobile application, the access manager may prevent the mobile application from accessing computing resource. If the access manager does successfully validate the mobile application, then the access manager may identify the mobile application as a trusted mobile application. The access manager may thus permit the trusted mobile application to access the computing resource.

Claims (59)

1. A computer-implemented method comprising:

installing an application at a first location of a computing device, at least one token being embedded in the application;

storing, at a second location of the computing device and separately from the application, application metadata comprising at least one corresponding token, wherein each of the at least one corresponding token corresponds to one of the at least one token embedded in the application;

challenging the application to provide a response prior to granting the application access to a computing resource;

obtaining the at least one corresponding token from the application metadata stored at the computing device;

generating an expected response that is based, at least in part, on the at least one corresponding token obtained from the application metadata;

comparing the expected response to the response received from the application; and

either granting or denying the application access to the computing resource based on whether the expected response matches the response received.

2. The computer-implemented method of claim 1 , wherein:

challenging the application to provide the response comprises challenging the application responsive to receipt, from the application, of a request to access the computing resource.

3. The computer-implemented method of claim 1 , wherein:

challenging the application to provide the response comprises challenging the application responsive to a launch of the application at the computing device.

4. The computer-implemented method of claim 1 , wherein:

generating the expected response comprises generating an expected application signature for the application.

5. The computer-implemented method of claim 4 , wherein:

generating the expected application signature further comprises obtaining at least one first corresponding token from the application metadata.

6. The computer-implemented method of claim 5 , wherein:

generating the expected application signature further comprises deriving at least one second token from the application.

7. The computer-implemented method of claim 6 , wherein:

deriving the at least one second token comprises hashing a component of the application.

8. The computer-implemented method of claim 7 , wherein:

the component comprises one of a binary of the application, an icon of the application, or a framework of the application.

9. The computer-implemented method of claim 6 , wherein:

generating the expected application signature further comprises arranging, in a predetermined order, the at least one first corresponding token and the at least one second token.

10. The computer-implemented method of claim 4 , further comprising:

providing a nonce to the application;

wherein generating the expected response further comprises generating an expected hash value based on the application signature and the nonce; and

wherein comparing the expected response to the response received from the application comprises comparing the expected hash value to a hash value received from the application.

11. A computer-implemented method comprising:

receiving, at an application installed at a first location of a computing device, a challenge to provide a response prior to obtaining access to a computing resource;

generating, by the application, a response that is based, at least in part, on a token embedded in the application;

providing, by the application, the response for comparison to an expected response that has been generated based, at least in part, on a corresponding token obtained from application metadata stored at a second location of the computing device separately from the application installed at the computing device, wherein the corresponding token obtained from the application metadata corresponds to the token embedded in the application; and

obtaining, by the application, access to the computing resource responsive to a determination that the expected response matches the response provided by the application.

12. The computer-implemented method of claim 11 , wherein:

generating the response comprises generating, by the application, an application signature.

13. The computer-implemented method of claim 12 , wherein:

generating the application signature comprises extracting, by the application, the token embedded in the application.

14. The computer-implemented method of claim 13 , wherein:

generating the application signature comprises deriving at least one second token from the application.

15. The computer-implemented method of claim 14 wherein:

deriving the at least one second token comprises hashing a component of the application; and

the component comprises one of a binary of the application, an icon of the application, or a framework of the application.

16. The computer-implemented method of claim 14 , wherein:

generating the application signature comprises arranging, in a predetermined order, the token extracted from the application and at least one of the second tokens.

17. The computer-implemented method of claim 12 , further comprising:

receiving a nonce; and

wherein generating the response further comprises generating a hash value based on the application signature and the nonce; and

wherein providing the response for comparison to the expected response comprises providing the hash value to an expected hash value.

18. A computer-implemented method comprising:

embedding a token in an application;

providing, to a computing device for storage at a first location of the computing device, application metadata comprising a corresponding token that corresponds to the token embedded in the application;

including, in the application, a management framework that configures the application to:

(i) generate, in response to receiving a challenge, a response that is based, at least in part, on the token embedded in the application, and

(ii) provide the response for comparison to an expected response that has been generated at the computing device based, at least in part, the corresponding token that has been obtained from the application metadata stored at the computing device; and

providing the application to the computing device for installation at a second location of the computing device and separately from the application metadata.

19. The computer-implemented method of claim 18 , wherein:

the management framework configures the application to generate the response by generating an application signature based, at least in part, on the token embedded in the application.

20. The computer-implemented method of claim 19 , wherein:

the management framework configures the application to generate the application signature by extracting the token embedded in the application and arranging, in a predetermined order, the token extracted from the application and at least one second token derived from the application.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2016
From: BARTON, GARY; LANG, ZHONGMIN; WALKER, JAMES ROBERT
To: CITRIX SYSTEMS, INC.
Reel/Frame 037588/0919 →
Continuity (3)
Continuation 13898167 · May 20, 2013
Provisional Application 61806557 · Mar 29, 2013
Related Publication 20160142418A1 · May 19, 2016