IP Library › Granted Patent US 12,039,054
Granted Patent B2
US 12,039,054 · App. 17/358,765 · Granted Jul 16, 2024

Systems and methods for dynamic detection of vulnerable credentials

Inventor: Rama Rao Katta (Fremont, CA)
Assignee: Citrix Systems, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,039,054
App. No.
17/358,765
Granted
Jul 16, 2024
Kind
B2
Abstract

A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to detect a request for a sign-up form from a client device to a remote server. The at least one processor is further configured to generate a code module based on the detection. The code module is configured to request a credential vulnerability check from an application management server. The at least one processor is further configured to provide the code module to the client device for execution on the client device in response to an attempted submission of the sign-up form. The at least one processor is further configured to receive a result of the credential vulnerability check from the client device and perform a security action in response to the credential vulnerability check indicating vulnerable credentials.

Claims (43)

1. A computer system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

detect a request for a sign-up form from a client device to a remote server;

generate code based on the detection, the code configured to request a credential vulnerability check from an application management server, wherein the vulnerability check comprises checking against a database of passwords that are known to be vulnerable;

generate, based on the request for the sign up form, a unique client session identifier and unique token corresponding to a Uniform Resource Locator (URL) of the request for the sign up form;

provide the unique client session identifier, the unique token, and the URL to the application management server;

provide the code and a cookie containing the client session identifier to the client device for execution on the client device;

receive a result of the credential vulnerability check from the client device; and

perform a security action in response to the credential vulnerability check indicating vulnerable credentials, wherein the security action includes one or more of requiring that the vulnerable credentials be updated, blocking submission of the sign-up form to the remote server, providing a warning to the client device, logging the vulnerability, and generating an alert to an administrator.

2. The computer system of claim 1 , wherein the code is JavaScript.

3. The computer system of claim 1 , wherein the code includes an on-submit event handler configured to trigger execution of the code in response to a submission of the sign-up form.

4. The computer system of claim 1 , wherein the code is configured to generate a hash of credentials included in the sign-up form and to include the hash in the request for the credential vulnerability check.

5. The computer system of claim 1 , wherein the code is configured to maintain consistent password-setting rules across a plurality of applications.

6. The computer system of claim 1 , wherein the computer system parses the sign up form to identify the mechanism for form submission.

7. The computer system of claim 1 , wherein the credential vulnerability check is initiated at the application management server and is triggered by the client device.

8. A method for detection of vulnerable credentials comprising:

detecting, by a computer system, a request for a sign-up form from a client device to a remote server;

generating, by the computer system, code based on the detection, the code configured to request a credential vulnerability check from an application management server, wherein the vulnerability check comprises checking against a database of passwords that are known to be vulnerable;

generating, based on the request for the sign up form, a unique client session identifier and unique token corresponding to a uniform resource locator (URL) of the request for the sign up form;

providing the unique client session identifier, the unique token, and the URL to the application management server;

providing the code and a cookie containing the client session identifier to the client device for execution on the client device;

receiving, by the computer system, a result of the credential vulnerability check from the client device; and

performing, by the computer system, a security action in response to the credential vulnerability check indicating vulnerable credentials, wherein the security action includes one or more of requiring that the vulnerable credentials be updated, blocking submission of the sign-up form to the remote server, providing a warning to the client device, logging the vulnerability, and generating an alert to an administrator.

9. The method of claim 8 , wherein generating the code includes generating JavaScript.

10. The method of claim 8 , wherein generating the code includes generating an on-submit event handler configured to trigger execution of the code in response to a submission of the sign-up form.

11. The method of claim 8 , wherein generating the code includes generating code configured to generate a hash of credentials included in the sign-up form and to include the hash in the request for the credential vulnerability check.

12. The method of claim 8 , wherein the code is configured to maintain consistent password-setting rules across a plurality of applications.

13. The method of claim 8 , wherein the computer system parses the sign up form to identify the mechanism for form submission.

14. The method of claim 8 , wherein the credential vulnerability check is initiated at the application management server and is triggered by the client device.

15. A non-transitory computer readable medium storing executable sequences of instructions to provide detection of vulnerable credentials, the sequences of instructions comprising instructions to:

detect a request for a sign-up form from a client device to a remote server;

generate code based on the detection, the code configured to request a credential vulnerability check from an application management server, wherein the vulnerability check comprises checking against a database of passwords that are known to be vulnerable;

generate, based on the request for the sign up form, a unique client session identifier and unique token corresponding to a uniform resource locator (URL) of the request for the sign up form;

provide the unique client session identifier, the unique token, and the URL to the application management server;

provide the code and a cookie containing the client session identifier to the client device for execution on the client devicei receive a result of the credential vulnerability check from the client device; and

perform a security action in response to the credential vulnerability check indicating vulnerable credentials, wherein the security action includes one or more of requiring that the vulnerable credentials be updated, blocking submission of the sign-up form to the remote server, providing a warning to the client device, logging the vulnerability, and generating an alert to an administrator.

16. The computer readable medium of claim 15 , wherein the code is JavaScript.

17. The computer readable medium of claim 15 , wherein the code includes an on-submit event handler configured to trigger execution of the code in response to a submission of the sign-up form.

18. The computer readable medium of claim 15 , wherein the code is further configured to generate a hash of credentials included in the sign-up form and to include the hash in the request for the credential vulnerability check.

19. The computer readable medium of claim 15 , wherein the code is configured to maintain consistent password-setting rules across a plurality of applications.

20. The computer readable medium of claim 15 , wherein the computer system parses the sign up form to identify the mechanism for form submission.

21. The computer readable medium of claim 15 , wherein the credential vulnerability check is initiated at the application management server and is triggered by the client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2021
From: KATTA, RAMA RAO
To: CITRIX SYSTEMS, INC.
Reel/Frame 056679/0047 →
Continuity (1)
Related Publication 20220414226A1 · Dec 29, 2022
Cited By (1)
US 12,432,197