IP Library › Granted Patent US 11,095,688
Granted Patent B2
US 11,095,688 · App. 16/153,045 · Granted Aug 17, 2021

Systems and methods for responsible intermediation of privacy policies

Inventor: Abhishek Chauhan (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L63/205G06F21/6245H04L63/0471H04L63/10H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,095,688
App. No.
16/153,045
Granted
Aug 17, 2021
Kind
B2
Abstract

Embodiments described include a method for implementing a privacy policy by a device intermediary to a plurality of clients and one or more servers. The method can include identifying, by a device intermediary to a plurality of clients and one or more servers, network traffic of a user that has not selected an option of a plurality of options of a privacy policy managed by the device. The method can include receiving, by the device, an indicator of a selection by the user of the option from the plurality of options of the privacy policy. The method can include handling, by the device, network traffic of the user according to the selected option of the privacy policy.

Claims (31)

1. A method for implementing a privacy policy by a device intermediary to a plurality of clients and one or more servers, the method comprising:

(a) identifying, by a device intermediary to a plurality of clients and one or more servers, network traffic of a user that has not been inspected by the device, the identification based on a lack of selection of an option of a privacy policy to inspect the network traffic, the privacy policy managed by the device, and the option specifies at least one of a type of data of the network traffic or a type of inspection to perform on the data;

(b) receiving, by the device via a graphical user interface provided responsive to identification of the lack of selection of the option of the privacy policy to inspect the network traffic, an indication of a selection by the user of the option of the privacy policy, the graphical user interface being provided to a second device by a portal of an entity, and the portal including information about the privacy policy and user interface elements to enable selection of the option; and

(c) handling, by the device, the network traffic of the user to inspect the data of the network traffic according to the selected option of the privacy policy.

2. The method of claim 1 , wherein (a) further comprises:

identifying the network traffic comprising a domain name service request from a second device of the user; and

prompting, by the device subsequent to the identifying the network traffic of the user and responsive to the lack of selection of the option of the privacy policy, the user to select the option of the privacy policy.

3. The method of claim 1 , wherein (b) further comprises redirecting the second device of the user to the portal of the entity providing the graphical user interface.

4. The method of claim 1 , wherein (b) further comprises receiving, by the device, the indication of the selection of the option comprising to opt-out of the privacy policy and wherein (c) further comprises blocking the network traffic of the user.

5. The method of claim 1 , wherein (b) further comprises receiving, by the device, the indication of the selection of the option comprising to opt-out of the privacy policy by using a secure hosted browser service and wherein (c) further comprises causing, by the device, the secure hosted browser service to be executed on the one or more servers for the user and provide access to the secure hosted browser service to the user.

6. The method of claim 1 , wherein (b) further comprises receiving, by the device, the indication of the selection of the option comprising to opt-in of the privacy policy.

7. The method of claim 6 , further comprising specifying for the opt-in option what data can be inspected by what inspector.

8. The method of claim 6 , wherein (c) further comprises decrypting, by the device, the network traffic of the user and redacting portions of the network traffic according to the privacy policy.

9. The method of claim 8 , further comprising communicating, by the device, the redacted network traffic re-encrypted to one or more inspectors allowed by the privacy policy.

10. The method of claim 9 , further comprising receiving, by the device, results from each of the one or more inspectors to determine whether or not to forward the network traffic to the one or more servers, the device logging the network traffic and results from the one or more inspectors.

11. A system for implementing a privacy policy by a device intermediary to a plurality of clients and one or more servers, the system comprising:

a device comprising one or more processors, coupled to memory and intermediary to a plurality of clients and one or more servers, the device configured to:

identify network traffic of a user that has not been inspected by the device, the identification based on a lack of selection of an option of a privacy policy to inspect the network traffic, the privacy policy managed by the device, and the option specifies at least one of a type of data of the network traffic or a type of inspection to perform on the data;

receive, via a graphical user interface provided responsive to the identification based on the lack of selection of the option of the privacy policy to inspect the network traffic, an indication of a selection by the user of the option of the privacy policy, the graphical user interface being provided to a second device by a portal of an entity, and the portal including information about the privacy policy and user interface elements to enable selection of the option; and

handle the network traffic of the user to inspect the data of the network traffic according to the selected option of the privacy policy.

12. The system of claim 11 , wherein the device is further configured to:

identify the network traffic comprising a domain name service request from a second device of the user; and

prompt, subsequent to the identification of the network traffic of the user and responsive to the lack of selection of the option of the privacy policy, the user to select the option of the privacy policy.

13. The system of claim 11 , wherein the device is further configured to redirect the second device of the user to the portal of the entity providing the graphical user interface.

14. The system of claim 11 , wherein the device is further configured to receive the indication of the selection of the option comprising to opt-out of the privacy policy and responsive to the selected option, block the network traffic of the user.

15. The system of claim 11 , wherein the device is further configured to receive the indication of the selection of the option comprising to opt-out of the privacy policy by using a secure hosted browser service and wherein responsive to the selected option cause the secure hosted browser service to be executed on the one or more servers for the user and provide access to the secure hosted browser service to the user.

16. The system of claim 11 , wherein the device is further configured to receive the indication of the selection of the option comprising to opt-in of the privacy policy.

17. The system of claim 16 , wherein the opt-in option specifies what data can be inspected by what inspector.

18. The system of claim 16 , wherein the device is further configured to decrypt the network traffic of the user and redact portions of the network traffic according to the privacy policy.

19. The system of claim 18 , wherein the device is further configured to communicate the redacted network traffic re-encrypted to one or more inspectors allowed by the privacy policy.

20. The system of claim 19 , wherein the device is further configured to receive results from each of the one or more inspectors to determine whether or not to forward the network traffic to the one or more servers, wherein the device is further configured to log the network traffic and results from the one or more inspectors.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2019
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 048896/0073 →
Continuity (1)
Related Publication 20200112589A1 · Apr 9, 2020
Cited By (1)
US 12,238,101