IP Library Granted Patent US 11,134,104
Granted Patent B2
US 11,134,104 · App. 16/401,588 · Granted Sep 28, 2021

Secure execution of enterprise applications on mobile devices

Inventors: Waheed Qureshi (Pleasanton, CA); Thomas H. DeBenning (Mountain View, CA); Ahmed Datoo (Palo Alto, CA); Olivier Andre (Bry sur Marne, FR); Shafaq Abdullah (San Mateo, CA); John M. McGinty (Fremont, CA); Kelly Brian Roach (Palo Alto, CA)
Assignee: Citrix Systems, Inc.
H04L63/20G06F8/53G06F21/12G06F21/14G06F21/53G06F21/6209G06F21/6218H04L9/0822H04L9/0825H04L9/0891H04L63/0428H04L63/0471H04L63/105H04L67/10H04W4/029H04W12/086H04W12/37G06F21/62G06F2221/2113H04L2209/80H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,134,104
App. No.
16/401,588
Granted
Sep 28, 2021
Kind
B2
Abstract

A system is disclosed that includes components and features for enabling enterprise users to securely access enterprise resources (documents, data, application servers, etc.) using their mobile devices. An enterprise can use some or all components of the system to, for example, securely but flexibly implement a BYOD (bring your own device) policy in which users can run both personal applications and secure enterprise applications on their mobile devices. The system may, for example, implement policies for controlling mobile device accesses to enterprise resources based on device attributes (e.g., what mobile applications are installed), user attributes (e.g., the user's position or department), behavioral attributes, and other criteria. Client-side code installed on the mobile devices may further enhance security by, for example, creating a secure container for locally storing enterprise data, creating a secure execution environment for running enterprise applications, and/or creating secure application tunnels for communicating with the enterprise system.

Claims (50)

1. A method comprising:

determining, by an enterprise agent of a client device, that a user of the client device is a verified user associated with an enterprise based on one or more enterprise credentials associated with the user;

providing, by the enterprise agent, access for the verified user to an encrypted secure container in a first portion of a computer-readable storage of the client device;

establishing, by the enterprise agent, one or more secure connections to a server associated with the enterprise;

communicating over the one or more secure connections to maintain user authentication for access to the secure container;

communicating, by the enterprise agent via a secure tunnel, with the server associated with the enterprise;

receiving, by the enterprise agent via the secure tunnel, enterprise data from the server;

storing, by the enterprise agent, the enterprise data received from the server via the secure tunnel in the secure container in accordance with one or more policies associated with the enterprise; and

authorizing, by the enterprise agent, to one or more applications, access to the secure container in accordance with the one or more policies associated with the enterprise,

wherein the enterprise data received from the server via the secure tunnel and stored in the secure container is only accessible to the one or more applications authorized by the enterprise agent to access the secure container and to the verified user using the one or more applications authorized by the enterprise agent to access the secure container.

2. The method of claim 1 , wherein the first portion of the computer-readable storage is separate from a second portion of the computer-readable storage, and wherein access to the second portion of the computer-readable storage is provided to the one or more non-enterprise applications.

3. The method of claim 2 , comprising storing data not associated with the enterprise in the second portion of the computer-readable storage.

4. The method of claim 2 , comprising:

deleting, by the enterprise agent, the enterprise data stored in the secure container in accordance with the one or more policies associated with the enterprise, wherein, after the deleting, the second portion of the computer-readable storage is unmodified.

5. The method of claim 4 , wherein the deleting comprises deleting the enterprise data based on one or more of: an expiration of a period of time, a time at which access to the secure container is requested, a geographic location of the client device, an indication that the client device is compromised, a configuration setting of the client device, detected behavior of the user, an indication that the user no longer has valid enterprise credentials, a number of times the one or more enterprise credentials associated with the user cannot be verified, or receiving a command from the enterprise to wipe the secure container.

6. The method of claim 2 , comprising:

preventing, by the enterprise agent, enterprise data stored in the secure container from being copied and stored in the second portion of the computer-readable storage.

7. The method of claim 1 , wherein the enterprise data stored in the secure container comprises one or more of: one or more data files associated with the enterprise, one or more credentials associated with the user of the client device, one or more certificates associated with the enterprise, one or more applications downloaded to the client device from the server associated with the enterprise, or one or more encryption keys.

8. A client device comprising: at least one processor; and

a non-transitory computer-readable storage comprising instructions that, when executed by the at least one processor, cause an enterprise agent on the client device to:

access an encrypted secure container in a first portion of the computer-readable storage;

determine that a user of the client device is a verified user associated with an enterprise based on one or more enterprise credentials associated with the user;

establish one or more secure connections to a server associated with the enterprise;

communicate over one or more secure connections to maintain user authentication for access to the secure container;

communicate, via a secure tunnel, with the server associated with the enterprise;

receive, via the secure tunnel, enterprise data from the server; and

store the enterprise data received from the server via the secure tunnel in the secure container in accordance with one or more policies of the enterprise, wherein the enterprise data received from the server via the secure tunnel and stored in the secure container is only accessible to one or more applications permitted access to the secure container and to the verified user associated with the enterprise using the one or more applications permitted access to the secure container.

9. The client device of claim 8 , wherein the first portion of the computer-readable storage is separate from a second portion of the computer-readable storage, and wherein access to the second portion of the computer-readable storage is provided to one or more non-enterprise applications.

10. The client device of claim 9 , wherein data not associated with the enterprise is stored in the second portion of the computer-readable storage.

11. The client device of claim 9 , wherein the enterprise agent is configured to delete the enterprise data in the secure container in accordance with the one or more policies of the enterprise, and wherein, after the deleting, the second portion of the computer-readable storage is unmodified.

12. The client device of claim 11 , wherein the enterprise agent is configured to delete the enterprise data based on one or more of: an expiration of a period of time, a time at which access to the secure container is requested, a geographic location of the client device, an indication that the client device is compromised, a configuration setting of the client device, detected behavior of the user, an indication that the user no longer has valid enterprise credentials, a number of times the one or more enterprise credentials associated with the user cannot be verified, or receiving a command from the enterprise to wipe the secure container.

13. The client device of claim 9 , wherein the enterprise agent is configured to prevent enterprise data stored in the secure container from being copied and stored in the second portion of the computer-readable storage.

14. The client device of claim 8 , wherein the enterprise data stored in the secure container comprises one or more of: one or more data files associated with the enterprise, one or more credentials associated with the user of the client device, one or more certificates associated with the enterprise, one or more applications downloaded to the client device from the server associated with the enterprise, or one or more encryption keys.

15. The client device of claim 8 , wherein the enterprise agent is configured to make the secure container inaccessible to one or more applications not associated with the enterprise.

16. A method comprising:

determining, utilizing an enterprise agent of a client device, that a user of the client device is a verified user associated with an enterprise based upon one or more enterprise credentials associated with the user;

providing, utilizing the enterprise agent, access to an encrypted secure container in a first portion of a computer-readable storage of the client device to the verified user;

establishing, utilizing the enterprise agent, one or more secure connections to a server associated with the enterprise;

communicating over the one or more secure connections to maintain user authentication for access to the secure container;

communicating, utilizing the enterprise agent and via a secure tunnel, with the server associated with the enterprise;

receiving, utilizing the enterprise agent and via the secure tunnel, enterprise data from the server;

storing, utilizing the enterprise agent, the enterprise data in the secure container in accordance with one or more policies associated with the enterprise; and

authorizing, utilizing the enterprise agent, access to the secure container by one or more applications based on the one or more policies associated with the enterprise,

wherein, among a plurality of users of the client device and a plurality of applications, the enterprise data received from the server via the secure tunnel and stored in the secure container is only accessible to one or more applications authorized access to the secure container and to one or more verified users associated with the enterprise using the one or more applications authorized access to the secure container.

17. The method of claim 16 , wherein the first portion of the computer-readable storage is separate from a second portion of the computer-readable storage, and wherein access to the second portion of the computer-readable storage is provided to the one or more non-enterprise applications.

18. The method of claim 17 , comprising storing data not associated with the enterprise in the second portion of the computer-readable storage.

19. The method of claim 17 , comprising:

deleting, by the enterprise agent, the enterprise data stored in the secure container in accordance with the one or more policies associated with the enterprise, wherein, after the deleting, the second portion of the computer-readable storage is unmodified.

20. The method of 17 , comprising:

preventing, by the enterprise agent, enterprise data stored in the secure container from being copied and stored in the second portion of the computer-readable storage.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2019
From: MCGINTY, JOHN M.; ROACH, KELLY BRIAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 049925/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2019
From: ZENPRISE, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 049922/0765 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2019
From: QURESHI, WAHEED; DEBENNING, THOMAS H.; DATOO, AHMED; ANDRE, OLIVIER; ABDULLAH, SHAFAQ
To: ZENPRISE, INC.
Reel/Frame 049922/0754 →
Continuity (9)
Continuation 16267357 · Feb 4, 2019
Continuation 15946692 · Apr 5, 2018
Continuation 14875450 · Oct 5, 2015
Continuation 13649024 · Oct 10, 2012
Provisional Application 61702671 · Sep 18, 2012
Provisional Application 61649134 · May 18, 2012
Provisional Application 61546922 · Oct 13, 2011
Provisional Application 61546021 · Oct 11, 2011
Related Publication 20190258781A1 · Aug 22, 2019
Cited By (9)
US 12,199,950 US 12,231,433 US 12,244,564 US 12,250,221 US 12,289,313 US 12,294,615 US 12,481,759 US 12,537,852 US 12,615,235