IP Library › Granted Patent US 11,005,891
Granted Patent B2
US 11,005,891 · App. 16/188,176 · Granted May 11, 2021

Systems and methods for live SaaS objects

Inventor: Abhishek Chauhan (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L63/20G06F16/986H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,005,891
App. No.
16/188,176
Granted
May 11, 2021
Kind
B2
Abstract

Embodiments described include systems and methods for generating and displaying live objects for network applications. Live objects may be created from applications (apps) that are served from and/or hosted on one or more servers, such as web applications and software-as-a-service (SaaS) applications, and shared with one or more recipients. The objects may be loaded or accessed as if they were normal network applications, and the recipients may see the latest or “live” version of content as shown to the live object creator, including user- or device-specific data of the creator, under full access policy control, without requiring access to credentials of the live object creator.

Claims (42)

1. A method, comprising:

receiving, by an application server from a first client application comprising a first embedded browser executed by a first client device, a request to share a portion of a network application with a second client device;

generating, by the application server, a contained application object consisting of the portion of the network application and associated with authentication credentials of the first client device, the contained application object provided to the second client device;

subsequently receiving, by the application server from a second client application comprising a second embedded browser executed by the second client device, the contained application object;

executing, by the application server, the portion of the network application using the authentication credentials of the first client device, responsive to the association between the contained application object and the authentication credentials of the first client device; and

providing, by the application server, an output of the portion of the network application to the second embedded browser of the second client application for display.

2. The method of claim 1 , wherein the portion of the network application comprises a sub-element of a document object model (DOM) tree of a web application.

3. The method of claim 1 , wherein the portion of the network application comprises a web application having one or more elements removed.

4. The method of claim 1 , wherein the request from the first client application comprises a selection of the portion of the network application.

5. The method of claim 1 , wherein the contained application object comprises an identification of a user of the first client device and an identification of the portion of the network application.

6. The method of claim 1 , wherein the output of the portion of the network application is protected by a password provided by a user of the first client device.

7. The method of claim 1 , wherein the output of the portion of the network application comprises current information of the portion of the network application.

8. The method of claim 1 , wherein the second client device receives the contained application object from either the first client device via the first client application or the application server.

9. The method of claim 1 , wherein the network application comprises a document object model (DOM) tree, and the method further comprises:

identifying a portion of the DOM tree corresponding to the portion of the network application; and

extracting, responsive to identifying the portion, the portion of the DOM tree corresponding to the portion of the network application, and

wherein generating the contained application object further comprises generating a second network application consisting essentially of the extracted portion of the DOM tree.

10. The method of claim 1 , wherein receiving the contained application object from the second client application further comprises receiving authentication credentials of the second client device; and

wherein executing the portion of the network application using the authentication credentials of the first client device further comprises accessing data of the network application associated with the first client device, responsive to a determination that a security policy applied to the authentication credentials of the second client device does not prevent the second client device from accessing the data.

11. A system, comprising:

an application server comprising a memory device storing a network application and a processor executing a sharing engine;

wherein the sharing engine is configured to:

receive, from a first client application comprising a first embedded browser executed by a first client device, a request to share a portion of the network application with a second client device, and

generate a contained application object consisting of the portion of the network application and associated with authentication credentials of the first client device, the contained application object provided to the second client device; and

wherein the application server is configured to:

subsequently receive, from a second client application comprising a second embedded browser executed by the second client device, the contained application object,

execute the portion of the network application using the authentication credentials of the first client device, responsive to the association between the contained application object and the authentication credentials of the first client device, and

provide an output of the portion of the network application to the second embedded browser of the second client application for display.

12. The system of claim 11 , wherein the portion of the network application comprises a sub-element of a document object model (DOM) tree of a web application.

13. The system of claim 11 , wherein the portion of the network application comprises a web application having one or more elements removed.

14. The system of claim 11 , wherein the request from the first client application comprises a selection of the portion of the network application.

15. The system of claim 11 , wherein the contained application object comprises an identification of a user of the first client device and an identification of the portion of the network application.

16. The system of claim 11 , wherein the output of the portion of the network application is protected by a password provided by a user of the first client device.

17. The system of claim 11 , wherein the output of the portion of the network application comprises current information of the portion of the network application.

18. The system of claim 11 , wherein the second client device receives the contained application object from either the first client device via the first client application or the application server.

19. The system of claim 11 , wherein the network application comprises a document object model (DOM) tree, and wherein the sharing engine is further configured to:

identify a portion of the DOM tree corresponding to the portion of the network application; and

extract, responsive to identifying the portion, the portion of the DOM tree corresponding to the portion of the network application, and

generate a second network application consisting essentially of the extracted portion of the DOM tree.

20. The system of claim 11 , wherein the application server is further configured to:

receive authentication credentials of the second client device, and

access data of the network application associated with the first client device, responsive to a determination that a security policy applied to the authentication credentials of the second client device does not prevent the second client device from accessing the data.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2019
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 048189/0162 →
Continuity (1)
Related Publication 20200153862A1 · May 14, 2020
Cited By (1)
US 12,238,101