IP Library Granted Patent US 10,595,202
Granted Patent B2
US 10,595,202 · App. 15/472,685 · Granted Mar 17, 2020

Dynamic access to hosted applications

Inventors: Georgy Momchilov (Parkland, FL); Ashish Gujarathi (Parkland, FL)
Assignee: Citrix Systems, Inc.
H04W12/08G06F9/452G06F9/45558G06F21/604G06F21/629H04L63/10H04L63/107H04W4/50H04W12/0027G06F2009/45587H04L63/0807H04L63/0876H04L63/20H04L67/08H04W12/00505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,595,202
App. No.
15/472,685
Granted
Mar 17, 2020
Kind
B2
Abstract

Methods, systems, and computer-readable media for providing an enrolled device with smart access to hosted applications are presented. In some embodiments, a computing platform having at least one processor, a memory, and a communication interface may receive, via the communication interface, end point analysis information associated with an enrolled device. Subsequently, the computing platform may analyze the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable hosted application functionality based on one or more smart access policies. Then, the computing platform may provide, via the communication interface, to the enrolled device, a hosted application experience based on analyzing the end point analysis information associated with the enrolled device and determining whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies.

Claims (43)

1. A virtualization server comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the virtualization server to:

receive, via the communication interface, end point analysis information associated with an enrolled device, wherein receiving the end point analysis information associated with the enrolled device comprises receiving one or more compliance tags generated by an enterprise mobility management server for the enrolled device, wherein the one or more compliance tags generated by the enterprise mobility management server for the enrolled device indicate whether the enrolled device is in compliance with a set of policies applicable to the enrolled device;

analyze the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable hosted application functionality based on one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device; and

provide, via the communication interface, to the enrolled device, a hosted application experience based on analyzing the end point analysis information associated with the enrolled device and determining whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device, wherein providing the hosted application experience to the enrolled device comprises:

executing, at the virtualization server, one or more hosted applications in accordance with the hosted application functionality selectively enabled or disabled based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device to generate virtualized user interface graphics associated with the one or more hosted applications; and

sending the virtualized user interface graphics associated with the one or more hosted applications to the enrolled device.

2. The virtualization server of claim 1 , wherein receiving the end point analysis information associated with the enrolled device comprises receiving the end point analysis information associated with the enrolled device from the enrolled device.

3. The virtualization server of claim 1 , wherein receiving the end point analysis information associated with the enrolled device comprises receiving the end point analysis information associated with the enrolled device from the enterprise mobility management server.

4. The virtualization server of claim 1 , wherein the enrolled device is registered with the enterprise mobility management server to enroll the enrolled device in at least one policy enforcement scheme implemented by the enterprise mobility management server prior to the end point analysis information associated with the enrolled device being received.

5. The virtualization server of claim 4 ,

wherein receiving the end point analysis information associated with the enrolled device comprises receiving a unique device identifier associated with the enrolled device, and

wherein the unique device identifier associated with the enrolled device is generated by the enterprise mobility management server during enrollment of the enrolled device in the at least one policy enforcement scheme implemented by the enterprise mobility management server.

6. The virtualization server of claim 1 , wherein the one or more compliance tags are generated by the enterprise mobility management server for the enrolled device based on a mobile device management (MDM) policy enforcement scheme.

7. The virtualization server of claim 1 , wherein the one or more compliance tags are generated by the enterprise mobility management server for the enrolled device based on a mobile application management (MAM) policy enforcement scheme.

8. The virtualization server of claim 1 , wherein the one or more compliance tags are generated by the enterprise mobility management server for the enrolled device based on a mobile content management (MCM) policy enforcement scheme.

9. The virtualization server of claim 1 , wherein analyzing the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device comprises determining to enable full hosted application functionality.

10. The virtualization server of claim 1 , wherein analyzing the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device comprises determining to enable partial hosted application functionality.

11. The virtualization server of claim 1 , wherein analyzing the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device comprises determining to disable partial hosted application functionality.

12. The virtualization server of claim 1 , wherein analyzing the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device comprises determining to disable full hosted application functionality.

13. The virtualization server of claim 1 , wherein the one or more compliance tags generated by the enterprise mobility management server for the enrolled device are signed by the enterprise mobility management server using a signing certificate of the enterprise mobility management server.

14. The virtualization server of claim 1 , wherein at least one smart access policy of the one or more smart access policies defines circumstances in which local drive mapping features are selectively disabled in a hosted session with the enrolled device.

15. A method comprising:

at a virtualization server comprising at least one processor, a communication interface, and memory:

receiving, by the at least one processor, via the communication interface, end point analysis information associated with an enrolled device, wherein receiving the end point analysis information associated with the enrolled device comprises receiving one or more compliance tags generated by an enterprise mobility management server for the enrolled device, wherein the one or more compliance tags generated by the enterprise mobility management server for the enrolled device indicate whether the enrolled device is in compliance with a set of policies applicable to the enrolled device;

analyzing, by the at least one processor, the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable hosted application functionality based on one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device; and

providing, by the at least one processor, via the communication interface, to the enrolled device, a hosted application experience based on analyzing the end point analysis information associated with the enrolled device and determining whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device, wherein providing the hosted application experience to the enrolled device comprises:

executing, at the virtualization server, one or more hosted applications in accordance with the hosted application functionality selectively enabled or disabled based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device to generate virtualized user interface graphics associated with the one or more hosted applications; and

sending the virtualized user interface graphics associated with the one or more hosted applications to the enrolled device.

16. The method of claim 15 , wherein receiving the end point analysis information associated with the enrolled device comprises receiving the end point analysis information associated with the enrolled device from the enrolled device.

17. The method of claim 15 , wherein receiving the end point analysis information associated with the enrolled device comprises receiving the end point analysis information associated with the enrolled device from the enterprise mobility management server.

18. The method of claim 15 , wherein the enrolled device is registered with the enterprise mobility management server to enroll the enrolled device in at least one policy enforcement scheme implemented by the enterprise mobility management server prior to the end point analysis information associated with the enrolled device being received.

19. The method of claim 18 ,

wherein receiving the end point analysis information associated with the enrolled device comprises receiving a unique device identifier associated with the enrolled device, and

wherein the unique device identifier associated with the enrolled device is generated by the enterprise mobility management server during enrollment of the enrolled device in the at least one policy enforcement scheme implemented by the enterprise mobility management server.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a virtualization server comprising at least one processor, memory, and a communication interface, cause the virtualization server to:

receive, via the communication interface, end point analysis information associated with an enrolled device, wherein receiving the end point analysis information associated with the enrolled device comprises receiving one or more compliance tags generated by an enterprise mobility management server for the enrolled device, wherein the one or more compliance tags generated by the enterprise mobility management server for the enrolled device indicate whether the enrolled device is in compliance with a set of policies applicable to the enrolled device;

analyze the end point analysis information associated with the enrolled device to determine whether to selectively enable or disable hosted application functionality based on one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device; and

provide, via the communication interface, to the enrolled device, a hosted application experience based on analyzing the end point analysis information associated with the enrolled device and determining whether to selectively enable or disable the hosted application functionality based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device, wherein providing the hosted application experience to the enrolled device comprises:

executing, at the virtualization server, one or more hosted applications in accordance with the hosted application functionality selectively enabled or disabled based on the one or more smart access policies and the one or more compliance tags generated by the enterprise mobility management server for the enrolled device to generate virtualized user interface graphics associated with the one or more hosted applications; and

sending the virtualized user interface graphics associated with the one or more hosted applications to the enrolled device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2017
From: MOMCHILOV, GEORGY; GUJARATHI, ASHISH
To: CITRIX SYSTEMS, INC.
Reel/Frame 042110/0671 →
Continuity (2)
Provisional Application 62340025 · May 23, 2016
Related Publication 20170339564A1 · Nov 23, 2017