IP Library Granted Patent US 10,469,534
Granted Patent B2
US 10,469,534 · App. 15/946,692 · Granted Nov 5, 2019

Secure execution of enterprise applications on mobile devices

Inventors: Waheed Qureshi (Pleasanton, CA); Thomas H. DeBenning (Mountain View, CA); Ahmed Datoo (Palo Alto, CA); Olivier Andre (Bry sur Marne, FR); Shafaq Abdullah (San Mateo, CA)
Assignee: Citrix Systems, Inc.
H04L63/20H04L63/105H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,534
App. No.
15/946,692
Granted
Nov 5, 2019
Kind
B2
Abstract

A system is disclosed that includes components and features for enabling enterprise users to securely access enterprise resources (documents, data, application servers, etc.) using their mobile devices. An enterprise can use some or all components of the system to, for example, securely but flexibly implement a BYOD (bring your own device) policy in which users can run both personal applications and secure enterprise applications on their mobile devices. The system may, for example, implement policies for controlling mobile device accesses to enterprise resources based on device attributes (e.g., what mobile applications are installed), user attributes (e.g., the user's position or department), behavioral attributes, and other criteria. Client-side code installed on the mobile devices may further enhance security by, for example, creating a secure container for locally storing enterprise data, creating a secure execution environment for running enterprise applications, and/or creating secure application tunnels for communicating with the enterprise system.

Claims (54)

1. A method comprising:

receiving, by a web browser configured to be installed on a memory of a mobile device, application data from a web application, wherein the web browser is configured to regulate operation of at least one web application in accordance with one or more enterprise policies, the web browser comprising a secure cache;

encrypting, by the web browser, the application data;

storing the encrypted application data in the secure cache;

providing, by the web browser, an option for displaying a document from the application data stored in the secure cache;

receiving a selection of the option for displaying the document from the application data stored in the secure cache;

based on receiving the selection of the option for displaying the document from the application data stored in the secure cache, decrypting a portion of the application data stored in the secure cache associated with the document;

receiving, from a remote computer system, an instruction to make the application data stored in the secure cache inaccessible; and

deleting, by the web browser, the application data from the secure cache.

2. The method of claim 1 , comprising:

launching, by a mobile application configured to be installed on the memory of the mobile device, the web browser in response to receiving a command to initiate execution of the web application; and

after launching the web browser, continuing execution of the web application within an execution environment provided by the web browser.

3. The method of claim 1 , comprising:

encrypting communications between the mobile device and the web application.

4. The method of claim 1 , comprising:

encrypting, by the web browser, data received from the web application; and

storing, by the web browser, the encrypted data in at least one of a secure document container or the secure cache.

5. The method of claim 1 , comprising:

logging, by the web browser, performance measurements to an analytics service.

6. The method of claim 5 , comprising:

based on the performance measurements, determining the one or more enterprise policies.

7. The method of claim 1 , comprising:

after decrypting the portion of the application data stored in the secure cache associated with the document, preventing, by the web browser, copy and paste operations.

8. The method of claim 1 , comprising:

after decrypting the portion of the application data stored in the secure cache associated with the document, preventing, by the web browser, local save operations.

9. The method of claim 1 , wherein the one or more enterprise policies comprise document access policies governing access to the secure cache.

10. The method of claim 9 , wherein at least one document access policy of the document access policies governing access to the secure cache limits access to the secure cache based on a geographical position of the mobile device.

11. A non-transitory computer readable medium storing program instructions that are executable to:

receive, by a web browser configured to be installed on a memory of a mobile device, application data from a web application, wherein the web browser is configured to regulate operation of at least one web application in accordance with one or more enterprise policies, the web browser comprising a secure cache;

encrypt, by the web browser, the application data;

store the encrypted application data in the secure cache;

provide, by the web browser, an option for displaying a document from the application data stored in the secure cache;

receive a selection of the option for displaying the document from the application data stored in the secure cache;

based on receiving the selection of the option for displaying the document from the application data stored in the secure cache, decrypt a portion of the application data stored in the secure cache associated with the document;

receive, from a remote computer system, an instruction to make the application data stored in the secure cache inaccessible; and

delete, by the web browser, the application data from the secure cache.

12. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

launch, by a mobile application configured to be installed on the memory of the mobile device, the web browser in response to receiving a command to initiate execution of the web application; and

after launching the web browser, continue execution of the web application within an execution environment provided by the web browser.

13. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

encrypt communications between the mobile device and the web application.

14. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

encrypt, by the web browser, data received from the web application; and

store, by the web browser, the encrypted data in at least one of a secure document container or the secure cache.

15. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

log, by the web browser, performance measurements to an analytics service.

16. The non-transitory computer readable medium of claim 15 , storing additional program instructions that are executable to:

based on the performance measurements, determine the one or more enterprise policies.

17. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

after decrypting the portion of the application data stored in the secure cache associated with the document, prevent, by the web browser, copy and paste operations.

18. The non-transitory computer readable medium of claim 11 , storing additional program instructions that are executable to:

after decrypting the portion of the application data stored in the secure cache associated with the document, prevent, by the web browser, local save operations.

19. The non-transitory computer readable medium of claim 11 , wherein the one or more enterprise policies comprise document access policies governing access to the secure cache.

20. The non-transitory computer readable medium of claim 19 , wherein at least one document access policy of the document access policies governing access to the secure cache limits access to the secure cache based on a geographical position of the mobile device.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2018
From: ZENPRISE, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 045538/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2018
From: QURESHI, WAHEED; DEBENNING, THOMAS H.; DATOO, AHMED; ANDRE, OLIVIER; ABDULLAH, SHAFAQ
To: ZENPRISE, INC.
Reel/Frame 045538/0762 →
Continuity (7)
Continuation 14875450 · Oct 5, 2015
Continuation 13649024 · Oct 10, 2012
Provisional Application 61702671 · Sep 18, 2012
Provisional Application 61649134 · May 18, 2012
Provisional Application 61546922 · Oct 13, 2011
Provisional Application 61546021 · Oct 11, 2011
Related Publication 20190238592A1 · Aug 1, 2019
Cited By (1)
US 12,481,748