IP Library › Granted Patent US 11,153,306
Granted Patent B2
US 11,153,306 · App. 16/184,676 · Granted Oct 19, 2021

Systems and methods for secure SaaS redirection from native applications

Inventor: Abhishek Chauhan (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L63/0853H04L63/20H04L67/146H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,306
App. No.
16/184,676
Filed
Nov 8, 2018
Granted
Oct 19, 2021
Kind
B2
Art Unit
2432
USPC
726/1
Abstract

Systems and methods discussed for redirection of launch requests for local applications to corresponding remote applications, such as SaaS or network applications provided by an application server, and access of the corresponding remote application via an embedded browser of a client application. A client application executed by a client device may detect a request of a user to launch a local application of the client device. The client application may determine that the local application corresponds to a network application provided by an application server. The client application may intercept the request to launch the local application, responsive to the determination. An embedded browser of the client application may access the network application from the application server, responsive to interception of the request.

Claims (34)

1. A method for secure redirection to network versions of applications, comprising:

detecting, by a client application executed by a client device, a request of a user to launch a local version of an application of the client device;

determining, by the client application, a network version of the application executable by an application server that corresponds to the local version of the application;

intercepting, by the client application, the request to launch the local version of the application, responsive to the determination; and

accessing, by an embedded browser of the client application, the network version of the application from the application server, responsive to interception of the request.

2. The method of claim 1 , wherein intercepting the request to launch the local version of the application further comprises preventing launch of the local version of the application, by the client application, responsive to the determination.

3. The method of claim 1 , wherein accessing the network version of the application from the application server further comprises providing an authentication token of the user to the application server.

4. The method of claim 3 , wherein accessing the network version of the application from the application server further comprises:

transmitting a request for an authentication token to an identity provider service, the request comprising credentials of the user; and

receiving the authentication token from the identity provider service.

5. The method of claim 4 , wherein receiving the authentication token from the identity provider service further comprises receiving a redirect uniform resource locator (URL) from the identity provider service corresponding to the network version of the application.

6. The method of claim 5 , wherein the redirect URL comprises a protocol identifier of the client application.

7. The method of claim 6 , wherein the protocol identifier identifies a secure container protocol.

8. The method of claim 1 , wherein interception of the request to launch the local version of the application is performed transparently to the user.

9. The method of claim 1 , wherein intercepting the request to launch the local version of the application is performed responsive to a policy identified in a database of the client application.

10. The method of claim 9 , wherein the policy identifies the user of the client device and the network version of the application.

11. A system for secure redirection to network versions of applications, comprising:

a client device comprising a network interface, a memory storing a local version of an application, and a processor circuit executing a client application comprising an embedded browser;

wherein the client application is configured to:

detect a request of a user to launch the local version of the application,

determine a network version of the application executable by an application server that corresponds to the local version of the application, and

intercept the request to launch the local version of the application, responsive to the determination; and

wherein the embedded browser is configured to access the network version of the application from the application server via the network interface, responsive to interception of the request.

12. The system of claim 11 , wherein the client application is further configured to prevent launch of the local version of the application, by the client application, responsive to the determination.

13. The system of claim 11 , wherein the embedded browser is further configured to provide an authentication token of the user to the application server.

14. The system of claim 13 , wherein the embedded browser is further configured to:

transmit a request for an authentication token to an identity provider service via the network interface, the request comprising credentials of the user; and

receive the authentication token from the identity provider service.

15. The system of claim 14 , wherein the embedded browser is further configured to receive a redirect uniform resource locator (URL) from the identity provider service corresponding to the network version of the application.

16. The system of claim 15 , wherein the redirect URL comprises a protocol identifier of the client application.

17. The system of claim 16 , wherein the protocol identifier identifies a secure container protocol.

18. The system of claim 11 , wherein the client application is further configured to intercept the request to launch the local version of the application transparently to the user.

19. The system of claim 11 , the client application is further configured to intercept the request to launch the local version of the application responsive to a policy identified in a database of the client application.

20. The system of claim 19 , wherein the policy identifies the user of the client device and the network version of the application.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2019
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 048911/0557 →
Continuity (1)
Related Publication 20200153818A1 · May 14, 2020
Cited By (5)
US 12,238,101 US 12,407,730 US 12,413,624 US 12,445,493 US 12,452,306