IP Library › Granted Patent US 11,057,212
Granted Patent B2
US 11,057,212 · App. 16/439,781 · Granted Jul 6, 2021

Policy based authentication

Inventor: Pranav Kumar Konduru (Santa Clara, CA)
Assignee: Citrix Systems, Inc.
H04L9/3213G06F21/335G06F21/44H04L9/3268H04L63/0815H04L63/0853H04W12/06H04W12/63G06F21/34H04L63/0823H04W12/37H04W12/61
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,212
App. No.
16/439,781
Granted
Jul 6, 2021
Kind
B2
Abstract

Methods and systems for expedited authentication for mobile applications are described herein. A user of a mobile device may authenticate with an enterprise system, and thereby be granted access to enterprise applications and services on the mobile device. The user may then activate an application in a managed partition of the mobile device. The application may determine that the enterprise system supports expedited authentication. The application may request expedited authentication, and the request may be compared to policies for expedited authentication. If the request is permitted, the application may be granted access to an authorization code for expedited authentication. The application may then perform the expedited authentication, and the user may be granted access to the application when the expedited authentication has completed.

Claims (35)

1. A method comprising:

providing, by a client agent of a computing device, at least one application programming interface (API), the API configured to enable access to one or more applications without input of user authentication data;

determining, based on one or more rules received by the client agent, an availability of the API for the client agent of the computing device;

displaying, in response to determining that the API is available, a selectable element within a user interface, the selectable element configured to cause execution of the API; and

exchanging, by the client agent, an authorization code for an access token in response to a request for the API received via the selectable element, the access token being configured to provide the user with access to one of the one or more applications.

2. The method of claim 1 , wherein determining the availability of the API comprises comparing a current time to permitted times, in the one or more rules, for accessing the one of the one or more applications.

3. The method of claim 1 , wherein determining the availability of the API comprises comparing a current location of the user to permitted locations, in the one or more rules, for accessing the one of the one or more applications.

4. The method of claim 1 , wherein the one of the one or more applications is a secure application executing within a managed partition of a mobile device.

5. The method of claim 1 , wherein the one or more rules indicate one or more time periods in which the user is permitted to access the one of the one or more applications.

6. The method of claim 1 , wherein the one or more rules indicate one or more geographic areas in which the user is permitted to access the one of the one or more applications.

7. The method of claim 1 , further comprising downloading, via the client agent, the one of the one or more applications.

8. A method comprising:

receiving authentication credentials for a client agent, wherein the authentication credentials correspond to a user;

receiving, in response to an authentication request based on the received authentication credentials, one or more rules for expedited authentication;

receiving a request for expedited authentication, wherein the request corresponds to a secure application executing within a managed partition of a mobile device;

determining, based on the one or more rules, to provide expedited authentication to the secure application; and

providing, to the secure application, an access token authenticating the user with the secure application.

9. The method of claim 8 , further comprising:

transmitting, by the secure application an authorization cookie; and

receiving, by the secure application and in response to the authorization cookie, the access token.

10. The method of claim 8 , wherein the determining to provide expedited authentication to the secure application comprises comparing a current time to permitted times, in the one or more rules, for accessing the secure application.

11. The method of claim 8 , wherein the determining to provide expedited authentication to the secure application comprises comparing a current location of the user to permitted locations, in the one or more rules, for accessing the secure application.

12. The method of claim 8 , wherein the determining is performed based on one or more policy files received and stored independent of the secure application.

13. The method of claim 8 , wherein the client agent comprises an application programming interface (API) for expedited authentication.

14. The method of claim 13 , wherein the secure application communicates with the client agent via the API for expedited authentication.

15. A method comprising:

determining, by an application, that an expedited authentication application programming interface (API) is available at a client agent in response to receipt of a request to activate the application, the application configured to access data within a managed partition of a mobile device;

presenting, in response to determining that the expedited authentication API is available, a selectable element within a user interface of a computing device, the selectable element corresponding to expedited authentication;

in response to a selection received on the selectable element, exchanging, by the application, an authorization code with the client agent to receive an access token; and

authorizing, based on the received access token, access to the application.

16. The method of claim 15 , wherein the application is configured to interact with the expedited authentication API.

17. The method of claim 15 , wherein exchanging the authorization code comprises exchanging, via the expedited authentication API, the authorization code.

18. The method of claim 15 , wherein authorizing the user to access the application comprises implementing application settings corresponding to the user.

19. The method of claim 15 , wherein the determining is performed based on one or more policy files received and stored independent of the application.

20. The method of claim 15 , wherein the client agent provides the application access to the managed partition.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2021
From: KONDURU, PRANAV KUMAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 058433/0270 →
Continuity (2)
Continuation 15689568 · Aug 29, 2017
Related Publication 20190296912A1 · Sep 26, 2019