IP Library Granted Patent US 11,019,066
Granted Patent B2
US 11,019,066 · App. 16/193,802 · Granted May 25, 2021

Systems and methods for securely managing browser plugins via embedded browser

Inventors: Vipin Borkar (Bengaluru, IN); Santosh Sampath (Bengaluru, IN); Deepak Sharma (Bengaluru, IN); Arvind SankaraSubramanian (Bengaluru, IN)
Assignee: Citrix Systems, Inc.
H04L63/102G06F8/61G06F9/44526H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,019,066
App. No.
16/193,802
Granted
May 25, 2021
Kind
B2
Abstract

Embodiments described include systems and methods for securely managing browser plugins via embedded browser. The solution enables a client application or embedded browser to dynamically load the browser components into the embedded browser based on a risk or security profile and one or more policies. The policies can be centrally managed to enable only allowed browser components to be loaded within the embedded browser for a given risk profile. Based on the risk profile, a session established by the embedded browser can be transferred from the client application to a hosted browser at a secure sever. When the session is transferred to the hosted browser, the present system can also redirect the browser component configurations to the hosted browser such that the same browser components are enabled, disabled, or modified at the hosted browser.

Claims (24)

1. A method of including one or more components in an embedded browser for a network application, the method comprising:

establishing, by an embedded browser within a client application on a client device of a first entity, a session with a network application provided by one or more servers of a second entity;

identifying, by the client application of the first entity, a policy for the network application of the second entity, the policy specifying one or more components to change one or more functions of the embedded browser in accessing the network application via the session, the one or more components comprising one of a plug-in, an add-on, or an extension; and

including, by the client application responsive to the policy, the one or more components in the embedded browser.

2. The method of claim 1 , further comprising removing, by the client application, a component from the embedded browser that is not allowed by the policy for the network application.

3. The method of claim 1 , further comprising executing, by the embedded browser, the one or more components only for the network application.

4. The method of claim 1 , wherein identifying the policy further comprises receiving, by the client application, the policy from a server of one of the first entity or a third entity.

5. The method of claim 1 , wherein the policy identifies a list of one of blacklisted or whitelisted one or more components.

6. The method of claim 1 , wherein including the one or more component further comprises installing, by one of the client application or the embedded browser, a component of the one or more components in the embedded browser.

7. The method of claim 1 , wherein including the one or more component further comprises configuring, by one of the client application or the embedded browser responsive to the policy, a component of the one or more components in the embedded browser.

8. The method of claim 1 , further comprising switching the session of the network application from the embedded browser on the client device to a secure browser session hosted on one or more servers, the secure browser session providing a second embedded browser to resume the session of the network application.

9. The method of claim 8 , further comprising redirecting the one or more components from the embedded browser of the client application to the second embedded browser of the secure browser session.

10. A system for including one or more components in an embedded browser for a network application, the system comprising:

a client application comprising an embedded browser executable on one or more processors, coupled to memory, on a client device of a first entity, the embedded browser configured to establish a session with a network application provided by one or more servers of a second entity;

wherein the client application of the first entity is configured to identify a policy for the network application of the second entity, the policy specifying one or more components to change one or more functions of the embedded browser in accessing the network application via the session, the one or more components comprising one of a plug-in, an add-on, or an extension; and

wherein the client application is configured to include, responsive to the policy, the one or more components in the embedded browser.

11. The system of claim 10 , wherein the client application is further configured to remove a component from the embedded browser that is not allowed by the policy for the network application.

12. The system of claim 10 , wherein the client application is configured to execute the one or more components only for the network application.

13. The system of claim 10 , wherein the client application is configured to receive the policy from a server of one of the first entity or a third entity.

14. The system of claim 10 , wherein the policy identifies a list of one of blacklisted or whitelisted one or more components.

15. The system of claim 10 , wherein one of the client application or the embedded browser is further configured to install a component of the one or more components in the embedded browser.

16. The system of claim 10 , wherein the client application or the embedded browser is further configured to configure responsive to the policy a component of the one or more components in the embedded browser.

17. The system of claim 10 , wherein the session of the network application is switched from the embedded browser on the client device to a secure browser session hosted on one or more servers, the secure browser session providing a second embedded browser to resume the session of the network application.

18. The system of claim 17 , wherein the one or more components from the embedded browser of the client application are redirected to the second embedded browser of the secure browser session.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2018
From: BORKAR, VIPIN; SAMPATH, SANTOSH; SHARMA, DEEPAK; SANKARASUBRAMANIAN, ARVIND
To: CITRIX SYSTEMS, INC.
Reel/Frame 047592/0030 →
Continuity (1)
Related Publication 20200162471A1 · May 21, 2020
Cited By (5)
US 12,238,101 US 12,407,730 US 12,413,624 US 12,445,493 US 12,452,306