IP Library › Granted Patent US 11,165,575
Granted Patent B2
US 11,165,575 · App. 16/238,202 · Granted Nov 2, 2021

Tracking tainted connection agents

Inventor: Leo C. Singleton, IV (Fort Lauderdale, FL)
Assignee: Citrix Systems, Inc.
H04L9/30H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,575
App. No.
16/238,202
Filed
Jan 2, 2019
Granted
Nov 2, 2021
Kind
B2
Art Unit
2493
USPC
713/171
Abstract

Methods and systems for tracking tainted connection agents, such as without a trusted central authority, are described herein. During a server outage, a client device may verify that a connection agent is untainted based on a public-key encryption or certificate-based system. If the connection agent is untainted, a server may sign a public key or certificate associated with the connection agent. The server may provide, to the client device, a lease, a public key associated with the server. The connection agent may sign data generated by the client device. The client device may verify a signature of the signed public key, such as based on the public key associated with the server. The client device may verify a signature of the signed data, such as based on the verified public key associated with the connection agent.

Claims (33)

1. A method comprising:

registering, to one or more servers, a connection agent on a computing device and a public key associated with the connection agent;

signing, by the one or more servers and based on a determination that the connection agent is not tainted by one or more previously logged in users, the public key associated with the connection agent;

receiving, by the connection agent and from the one or more servers, the signed public key associated with the connection agent;

storing, by the connection agent, the signed public key associated with the connection agent;

signing, by the connection agent, data received from a client device; and

sending, by the connection agent and to the client device, the signed public key associated with the connection agent and the signed data.

2. The method of claim 1 , wherein the determination that the connection agent is not tainted by one or more previously logged in users comprises a determination that an unauthorized software application is not installed at the connection agent.

3. The method of claim 1 , further comprising:

before the registering the connection agent and the public key associated with the connection agent, reimaging, by the one or more servers and based on a determination that the connection agent is tainted, the connection agent.

4. The method of claim 1 , further comprising:

generating, by the one or more servers, a public key and a private key that are associated with the one or more servers; and

storing, in a database associated with the one or more servers, the public key and the private key that are associated with the one or more servers.

5. The method of claim 1 , further comprising:

removing, from the connection agent, a private key associated with the connection agent after the signing the data received from the client device.

6. The method of claim 5 , further comprising:

removing, from the connection agent, the signed public key associated with the connection agent and the public key associated with the connection agent after the sending the signed public key associated with the connection agent.

7. The method of claim 1 , further comprising:

after the sending the signed public key associated with the connection agent and the signed data, connecting the client device to one or more of a virtual desktop or virtual application associated with the connection agent.

8. One or more non-transitory computer readable media storing computer readable instructions that, when executed, cause a connection agent on a computing device to:

register, to one or more servers, the connection agent and a public key associated with the connection agent;

receive, from the one or more servers and based on a determination that the connection agent is not tainted by one or more previously logged in users, the public key associated with the connection agent and signed by the one or more servers;

store the signed public key associated with the connection agent;

sign data received from a client device; and

send, to the client device, the signed public key associated with the connection agent and the signed data.

9. The one or more non-transitory computer readable media of claim 8 , wherein the computer readable instructions, when executed, further cause the connection agent on the computing device to:

remove, from the connection agent, a private key associated with the connection agent after the connection agent signs the data received from the client device.

10. The one or more non-transitory computer readable media of claim 9 , wherein the computer readable instructions, when executed, further cause the connection agent on the computing device to:

remove, from the connection agent, the signed public key associated with the connection agent and the public key associated with the connection agent after the connection agent sends, to the client device, the signed public key associated with the connection agent.

11. The one or more non-transitory computer readable media of claim 8 , wherein the computer readable instructions, when executed, further cause the connection agent on the computing device to:

receive, from the client device and based on a determination that a signature of the signed public key associated with the connection agent is verified, a request to connect to the connection agent; and

connect to the client device.

12. The one or more non-transitory computer readable media of claim 11 , wherein the determination that the signature of the signed public key associated with the connection agent is verified comprises a determination that a signature of the signed data is verified.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2019
From: SINGLETON, LEO C., IV
To: CITRIX SYSTEMS, INC.
Reel/Frame 049356/0309 →
Continuity (1)
Related Publication 20200213112A1 · Jul 2, 2020