IP Library Granted Patent US 10,157,287
Granted Patent B2
US 10,157,287 · App. 15/019,709 · Granted Dec 18, 2018

Secure access client

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,157,287
App. No.
15/019,709
Granted
Dec 18, 2018
Kind
B2
Abstract

A secure access client can be employed to enforce limitations on a user's access to a file while also allowing the user to access the file using an application of choice. To provide this functionality, the secure access client can implement an RDP client that is configured to create an RDP session with an RDP service executing on the same computing device. The RDP service can allow the secure access client to display the user interface of an application employed to open a file. The secure access client can be configured to selectively apply access limitations on a per file basis. This selective enforcement can be accomplished by only implementing a virtual channel extension to provide a particular type of access to the file when the file's access limitations would allow such access.

Claims (64)

1. A method for applying access limitations on a per file basis, the method comprising:

executing a remote display protocol (RDP) service that is configured to establish RDP sessions with RDP clients;

executing, within a browser sandbox on a computing device, a secure access client that implements an RDP client;

establishing an RDP session between the RDP service and the secure access client;

opening a file via the RDP session including displaying, by the secure access client, contents of the file to a user of the computing device;

in conjunction with opening the file, identifying, by the secure access client, one or more access limitations defined for the file, the one or more access limitations comprising a copy limitation;

while the file is open, identifying, by the secure access client, that the user has provided input to the computing device that has initiated an action that if completed would violate the one or more access limitations defined for the file; and

preventing, by the secure access client, the action from being completed by selectively failing to implement functionality of a virtual channel extension of the RDP session thereby ensuring that the one or more access limitations defined for the file are not violated;

wherein selectively failing to implement functionality of the virtual channel extension of the RDP session comprises failing to synchronize contents of a clipboard in an RDP session environment to a clipboard of the computing device.

2. The method of claim 1 , further comprising:

opening a second file via the RDP session;

in conjunction with opening the second file, identifying, by the secure access client, that one or more access limitations defined for the second file do not include a copy limitation;

while the file is open, identifying, by the secure access client, that a user has provided input that has initiated a copy action; and

implementing, by the secure access client, the copy action by implementing functionality of the virtual channel extension of the RDP session to cause synchronization of contents of the clipboard in the RDP session environment to the clipboard of the computing device.

3. The method of claim 2 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: Clipboard Virtual Channel Extension such that the secure access client selectively implements the RDP: Clipboard Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

4. The method of claim 1 , wherein the one or more access limitations also comprise a save limitation and selectively failing to implement functionality of the virtual channel extension of the RDP session comprises failing to save the file to a location outside an RDP session environment.

5. The method of claim 4 , further comprising:

opening a second file via the RDP session;

in conjunction with opening the second file, identifying, by the secure access client, that one or more access limitations defined for the second file do not include a save limitation;

while the file is open, identifying, by the secure access client, that a user has provided input that has initiated a save action; and

implementing, by the secure access client, the save action by implementing functionality of the virtual channel extension of the RDP session to cause the file to be saved outside the RDP session environment.

6. The method of claim 5 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: File System Virtual Channel Extension such that the secure access client selectively implements the RDP: File System Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

7. The method of claim 1 , wherein the one or more access limitations also comprise a print limitation and selectively failing to implement functionality of the virtual channel extension of the RDP session comprises failing to print the file to a printer accessible outside an RDP session environment.

8. The method of claim 7 , further comprising:

opening a second file via the RDP session;

in conjunction with opening the second file, identifying, by the secure access client, that one or more access limitations defined for the second file do not include a print limitation;

while the file is open, identifying, by the secure access client, that a user has provided input that has initiated a print action; and

implementing, by the secure access client, the print action by implementing functionality of the virtual channel extension of the RDP session to cause the file to be printed to a printer accessible outside the RDP session environment.

9. The method of claim 8 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: Print Virtual Channel Extension such that the secure access client selectively implements the RDP: Print Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

10. The method of claim 1 , wherein the RDP service is executed on the computing device such that the RDP session is established via localhost.

11. The method of claim 1 , further comprising:

establishing an RDP session between the RDP service and an administer device;

receiving, from the administrator device and via the RDP session, updates to access limitations defined for one or more files; and

modifying the access limitations defined for the one or more files in accordance with the received updates.

12. The method of claim 1 , wherein the access limitations are stored as one or more of:

one or more headers to the file to which the access limitations pertain;

one or more files associated with the file to which the access limitations pertain; or

one or more data structures maintained by the RDP service for defining the access limitations for the files to which the RDP service provides access.

13. One or more computer storage media storing computer executable instructions which when executed by one or more processors implement a method comprising:

executing, within a browser sandbox on a computing device, a secure access client that implements a remote display protocol (RDP) client;

establishing an RDP session between the secure access client and an RDP service;

opening a file via the RDP session including displaying, by the secure access client, contents of the file to a user of the computing device;

in conjunction with opening the file, identifying, by the secure access client, one or more access limitations defined for the file, the one or more access limitations comprising a copy limitation;

while the file is open, identifying, by the secure access client, that the user has provided input to the computing device that has initiated an action that if completed would violate the one or more access limitations defined for the file; and

preventing, by the secure access client, the action from being completed by selectively failing to implement functionality of a virtual channel extension of the RDP session thereby ensuring that the one or more access limitations defined for the file are not violated;

wherein selectively failing to implement functionality of the virtual channel extension of the RDP session comprises failing to synchronize contents of a clipboard in an RDP session environment to a clipboard of the computing device.

14. The computer storage media of claim 13 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: Clipboard Virtual Channel Extension such that the secure access client selectively implements the RDP: Clipboard Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

15. The computer storage media of claim 13 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: File System Virtual Channel Extension such that the secure access client selectively implements the RDP: File System Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

16. The computer storage media of claim 13 , wherein implementing functionality of the virtual channel extension of the RDP session comprises implementing the RDP: Print Virtual Channel Extension such that the secure access client selectively implements the RDP: Print Virtual Channel Extension on a per file basis depending on the access limitations defined for the particular file.

17. A system comprising:

one or more processors; and

computer storage media storing computer executable instructions which when executed by the one or more processors implement a method for applying access limitations on a per file basis, the method comprising:

executing, within a browser sandbox on a computing device, a secure access client that implements a remote display protocol (RDP) client;

establishing an RDP session between the secure access client and an RDP service;

opening a file via the RDP session including displaying, by the secure access client, contents of the file to a user of the computing device;

in conjunction with opening the file, identifying, by the secure access client, one or more access limitations defined for the file, the one or more access limitations comprising a copy limitation;

while the file is open, identifying, by the secure access client, that the user has provided input to the computing device that has initiated an action that if completed would violate the one or more access limitations defined for the file; and

preventing, by the secure access client, the action from being completed by selectively failing to implement functionality of a virtual channel extension of the RDP session thereby ensuring that the one or more access limitations defined for the file are not violated;

wherein selectively failing to implement functionality of the virtual channel extension of the RDP session comprises failing to synchronize contents of a clipboard in an RDP session environment to a clipboard of the computing device.

18. The system of claim 17 , wherein the access limitations that are selectively enforced also include one or more of save access or print access.

19. The system of claim 17 , wherein the virtual channel extension comprises one of:

the RDP: Clipboard Virtual Channel Extension;

the RDP: Print Virtual Channel Extension; or

the RDP: File System Virtual Channel Extension.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
MERGER Recorded May 9, 2022
From: WYSE TECHNOLOGY L.L.C.
To: DELL MARKETING CORPORATION
Reel/Frame 059912/0109 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2016
From: FAUSAK, ANDREW; ROMBAKH, OLEG; ROBBINS, WARREN; BURKE, JAMES; TESTERMAN, DARRELL; BURCHETT, CHRIS
To: WYSE TECHNOLOGY L.L.C.
Reel/Frame 037750/0698 →