IP Library Granted Patent US 11,153,284
Granted Patent B2
US 11,153,284 · App. 16/183,226 · Granted Oct 19, 2021

Systems and methods for transparent SaaS data encryption and tokenization

Inventor: Abhishek Chauhan (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L63/0428G06F16/95G06F21/602H04L9/0861H04L63/20H04L67/14H04L67/2823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,284
App. No.
16/183,226
Granted
Oct 19, 2021
Kind
B2
Abstract

Embodiments described include systems and methods for encoding and decoding data for a network application. A client application may include an embedded browser. The embedded browser may establish a session with a network application. The client application may identify a policy specifying a type of data to encode upon input. The embedded browser may detect the type of data of an input field of the network application being displayed in the embedded browser. The embedded browser may, responsive to the detection and the policy, encode the data inputted into the input field or decode encoded data displayed in the input field.

Claims (30)

1. A method for encoding data for a network application, the method comprising:

(a) establishing, by a client application executing on a client device, a session with a network application via an embedded browser within the client application;

(b) identifying, by the client application, a policy for the network application specifying a type of data to encode upon input;

(c) detecting, by the embedded browser, the type of data of an input field of the network application being displayed in the embedded browser;

(d) encoding, by the embedded browser responsive to the detection, the data inputted into the input field using encryption, the data being encoded in a format recognizable to the client application; and

(e) storing, by the embedded browser, the encoded data in the input field and the data to a data repository.

2. The method of claim 1 , wherein (b) further comprises identifying the policy based on one or more of the following: user, membership, location, device, device enrollment status and mode of authentication.

3. The method of claim 1 , wherein (d) further comprises encoding the data by generating a token and replacing the data inputting into the input field with the token.

4. The method of claim 1 , wherein (d) further comprises encoding the data with a predetermined format.

5. The method of claim 1 , wherein (d) further comprises encoding the data as the data is inputted into the input field.

6. A method for decoding encoded data for a network application, the method comprising:

(a) establishing, by a client application executing on a client device, a session with a network application via an embedded browser within the client application;

(b) identifying, by the client application, a policy for the network application specifying a type of data to decode;

(c) detecting, by the embedded browser, encoded data corresponding to the type of data of an input field of the network application being displayed in the embedded browser, the encoded data having a format recognizable by the client application;

(d) decrypting, by the embedded browser responsive to the detection, the encoded data; and

(e) displaying, by the embedded browser responsive to the policy, the decoded data in the input field.

7. The method of claim 6 , wherein (b) further comprises identifying the policy based on one or more of the following: user, membership, location, device, device enrollment status and mode of authentication.

8. The method of claim 6 , wherein (c) further comprises detecting that the encoded data has a predetermined format or tag recognizable by the client application.

9. The method of claim 6 , wherein (d) further comprises decoding the data by replacing a token of the encoded data with original data retrieved from a data repository.

10. A system for encoding and decoding data for a network application, the system comprising:

a client application executable on one or more processors of a client device, the client application comprising an embedded browser configured to establish a session with a network application;

wherein the client application is configured to identify a policy for the network application specifying a type of data to encode upon input;

wherein the embedded browser is configured to detect the type of data of an input field of the network application being displayed in the embedded browser; and

wherein the embedded browser is configured, responsive to the detection and in accordance with the policy, to one of encode, using encryption, the data inputted into the input field in a format recognizable by the client application or decode, using decryption, encoded data to display in the input field.

11. The system of claim 10 , wherein the embedded browser is further configured to store, responsive to data being inputted into the input field, the encoded data in the input field and the data being inputted to a data repository.

12. The system of claim 10 , wherein the policy is identified based on one or more of the following: user, membership, location, device, device enrollment status and mode of authentication, and the network application.

13. The system of claim 10 , wherein the embedded browser is further configured to encode the data by one of encryption or generation of a token and replacement of the data with the token.

14. The system of claim 10 , wherein the encoded data comprises a predetermined format.

15. The system of claim 10 , wherein the embedded browser is further configured to decode the data by decrypting the encoded data.

16. The system of claim 10 , wherein the embedded browser is further configured to decode the data by replacing a token of the encoded data with original data retrieved from a data repository.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 048766/0658 →
Continuity (1)
Related Publication 20200145384A1 · May 7, 2020
Cited By (1)
US 12,730,915