IP Library Granted Patent US 10,063,595
Granted Patent B1
US 10,063,595 · App. 15/863,853 · Granted Aug 28, 2018

Secure execution of enterprise applications on mobile devices

Inventors: Waheed Qureshi (Pleasanton, CA); Thomas H. DeBenning (Mountain View, CA); Ahmed Datoo (Palo Alto, CA); Olivier Andre (Bry sur Marne, FR); Shafaq Abdullah (San Mateo, CA); John M. McGinty (Fremont, CA); Kelly Brian Roach (Palo Alto, CA)
Assignee: Citrix Systems, Inc.
H04L63/20H04L63/105H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,063,595
App. No.
15/863,853
Granted
Aug 28, 2018
Kind
B1
Abstract

A system is disclosed that includes components and features for enabling enterprise users to securely access enterprise resources (documents, data, application servers, etc.) using their mobile devices. An enterprise can use some or all components of the system to, for example, securely but flexibly implement a BYOD (bring your own device) policy in which users can run both personal applications and secure enterprise applications on their mobile devices. The system may, for example, implement policies for controlling mobile device accesses to enterprise resources based on device attributes (e.g., what mobile applications are installed), user attributes (e.g., the user's position or department), behavioral attributes, and other criteria. Client-side code installed on the mobile devices may further enhance security by, for example, creating a secure container for locally storing enterprise data, creating a secure execution environment for running enterprise applications, and/or creating secure application tunnels for communicating with the enterprise system.

Claims (54)

1. A method comprising:

generating, by an enterprise agent operable on a client device, a secure container in a first portion of a computer-readable storage of the client device, the secure container being encrypted and comprising a file system, wherein the first portion of the computer-readable storage is separate from a second portion of the computer-readable storage;

verifying, by the enterprise agent, a user of the client device based upon one or more enterprise credentials associated with the user;

establishing, by the enterprise agent, a secure tunnel between the enterprise agent and a server associated with an enterprise, the enterprise having one or more associated applications;

receiving, by the enterprise agent, enterprise data from the server, the enterprise data received via the secure tunnel; and

storing, by the enterprise agent, the enterprise data in the secure container in accordance with one or more data policies of the enterprise,

wherein the secure container is only accessible by a verified user and by the one or more applications associated with the enterprise.

2. The method of claim 1 , wherein access to the second portion of the computer-readable storage is provided independently of the one or more data policies of the enterprise.

3. The method of claim 1 , wherein private data associated with the user is stored in the second portion of the computer-readable storage, the private data associated with activity of the user that is outside of a role of the user in the enterprise, the second portion of the computer-readable storage being inaccessible to the enterprise agent.

4. The method of claim 1 , comprising:

deleting, by the enterprise agent, the enterprise data in the secure container in accordance with the one or more data policies of the enterprise.

5. The method of claim 4 , wherein, after the deleting, the second portion of the computer-readable storage is unmodified.

6. The method of claim 4 , wherein deleting the enterprise data in the secure container in accordance with the one or more data policies of the enterprise comprises deleting the enterprise data based upon at least one of: an expiration of a period of time, a time at which access to the secure container is requested, a geographic location of the client device, an indication that the client device is compromised, a configuration setting of the client device, detected behavior of the user, an indication that the user no longer has associated valid enterprise credentials, a number of times the one or more enterprise credentials associated with the user cannot be verified, or receiving a command from the enterprise to wipe the secure container.

7. The method of claim 1 , comprising:

restricting access, by the enterprise agent, to the secure container based upon a geographic location of the client device.

8. The method of claim 1 , comprising:

preventing, by the enterprise agent, enterprise data in the secure container from being copied and stored in the second portion of the computer-readable storage.

9. The method of claim 1 , wherein at least one of the one or more applications associated with the enterprise is downloaded to the client device from the server associated with the enterprise.

10. The method of claim 1 , wherein at least one of the one or more applications associated with the enterprise is a remote application operating on the server associated with the enterprise.

11. The method of claim 1 , wherein the server associated with the enterprise is a cloud server.

12. The method of claim 1 , wherein the secure tunnel employs protocol encapsulation to send data over a network.

13. The method of claim 12 , wherein storing the enterprise data in the secure container is based, at least in part, upon detecting by the enterprise agent that the enterprise data was received via the secure tunnel.

14. The method of claim 12 , wherein the secure tunnel employs Remote Desktop Protocol (RDP).

15. The method of claim 1 , comprising:

operating the one or more applications associated with the enterprise in one or more secure virtual machines of the client device, each of the one or more secure virtual machines separate from a virtual machine operating an operating system of the client device.

16. The method of claim 1 , wherein the enterprise data stored in the secure container comprises applications downloaded to the client device from the server associated with the enterprise.

17. The method of claim 1 , wherein the enterprise data stored in the secure container comprises one or more of: one or more data files associated with the enterprise, one or more credentials associated with the user, one or more certificates associated with the enterprise, or one or more encryption keys.

18. The method of claim 1 , comprising:

establishing, by the enterprise agent, one or more secure connections to the server associated with the enterprise; and

communicating over the one or more secure connections to maintain user authentication for access to the secure container.

19. The method of claim 1 , comprising:

establishing, by the enterprise agent, a connection from the client device to a secure application store associated with the enterprise; and

downloading the one or more applications associated with the enterprise from the secure application store to the client device.

20. The method of claim 1 , wherein the secure container is inaccessible to one or more applications not associated with the enterprise.

21. A method comprising:

generating a secure container in a first portion of a computer-readable storage of a client device, the secure container being encrypted and comprising a file system, and being separate from a second portion of the computer-readable storage;

verifying a user of the client device based upon one or more enterprise credentials associated with the user;

establishing a secure tunnel between the client device and a server associated with an enterprise, the enterprise having one or more associated applications; and

storing enterprise data in the secure container in accordance with one or more data policies of the enterprise, the enterprise data received from the server via the secure tunnel,

wherein the secure container is only accessible by a verified user and by the one or more applications associated with the enterprise.

22. The method of claim 21 , wherein access to the second portion of the computer-readable storage is provided independently of the one or more data policies of the enterprise, and wherein private data associated with the user is stored in the second portion of the computer-readable storage, the private data associated with activity of the user that is outside of a role of the user in the enterprise, the second portion of the computer-readable storage being inaccessible to the one or more applications associated with the enterprise.

23. The method of claim 21 , comprising:

deleting the enterprise data in the secure container in accordance with the one or more data policies of the enterprise, wherein, after the deleting, the second portion of the computer-readable storage is unmodified.

24. The method of claim 21 , comprising:

preventing enterprise data in the secure container from being copied and stored in the second portion of the computer-readable storage.

25. The method of claim 21 , comprising:

operating the one or more applications associated with the enterprise in one or more secure virtual machines of the client device, each of the one or more secure virtual machines separate from a virtual machine operating an operating system of the client device.

26. The method of claim 21 , comprising:

establishing a connection from the client device to a secure application store associated with the enterprise; and

downloading the one or more applications associated with the enterprise from the secure application store to the secure container of the client device.

27. A method comprising:

establishing a secure tunnel between a client device and a server associated with an enterprise, wherein the secure tunnel is established for a verified user of the client device based upon one or more enterprise credentials associated with the user;

determining one or more applications associated with the enterprise;

transmitting enterprise data from the server to the client device via the secure tunnel, wherein the enterprise data is stored in a secure container of the client device in accordance with one or more data policies of the enterprise, wherein the secure container is located in a first portion of a computer-readable storage of the client device, the secure container being encrypted and comprising a file system, wherein the first portion of the computer-readable storage is separate from a second portion of the computer-readable storage, and wherein the secure container is only accessible by the verified user and by the one or more applications associated with the enterprise.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2018
From: MCGINTY, JOHN M.; ROACH, KELLY BRIAN
To: ZENPRISE, INC.
Reel/Frame 046374/0409 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2018
From: QURESHI, WAHEED; DEBENNING, THOMAS H.; DATOO, AHMED; ANDRE, OLIVIER; ABDULLAH, SHAFAQ
To: ZENPRISE, INC.
Reel/Frame 044565/0512 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2018
From: ZENPRISE, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 044565/0526 →
Continuity (6)
Continuation 14875450 · Oct 5, 2015
Continuation 13649024 · Oct 10, 2012
Provisional Application 61702671 · Sep 18, 2012
Provisional Application 61649134 · May 18, 2012
Provisional Application 61546922 · Oct 13, 2011
Provisional Application 61546021 · Oct 11, 2011
Cited By (9)
US 12,242,599 US 12,265,460 US 12,348,519 US 12,355,770 US 12,423,418 US 12,432,242 US 12,603,921 US 12,670,246 US 12,695,793