IP Library Granted Patent US 11,895,096
Granted Patent B2
US 11,895,096 · App. 17/503,955 · Granted Feb 6, 2024

Systems and methods for transparent SaaS data encryption and tokenization

Inventor: Abhishek Chauhan (Santa Clara, CA)
H04L63/0428G06F16/95G06F21/602H04L9/0861H04L63/20H04L67/14H04L67/565H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,895,096
App. No.
17/503,955
Granted
Feb 6, 2024
Kind
B2
Abstract

Embodiments described include systems and methods for encoding and decoding data for a network application. A client application may include an embedded browser. The embedded browser may establish a session with a network application. The client application may identify a policy specifying a type of data to encode upon input. The embedded browser may detect the type of data of an input field of the network application being displayed in the embedded browser. The embedded browser may, responsive to the detection and the policy, encode the data inputted into the input field or decode encoded data displayed in the input field.

Claims (33)

1. A method comprising:

identifying, by a client device, a type of data to encode into a format recognizable to the client device as being an input to an application;

determining, by the client device, that data of the type is provided as input to the application;

encoding, by the client device, the data into the format recognizable to the client device;

providing, by the client device, the encoded data as input to the application; and

encoding, by the client device based at least on the type of data, the data using one of reverse encryption or tokenization.

2. The method of claim 1 , further comprising identifying, by the client device, the type of data based on at least one of the client device, a user of the client device or a location of the client device.

3. The method of claim 1 , further comprising identifying, by the client device, the type of data based at least on a mode in which to authenticate a user to the client device or the application.

4. The method of claim 1 , further comprising encoding, by the client device, the data by encrypting at least a portion of the data or replacing at least a portion of the data with a token.

5. The method of claim 1 , further comprising determining, by the client device, that data of the type of data as being input based on the data being inputted into an input field of the application.

6. The method of claim 1 , further comprising encoding, by the client device, the data as the data is being inputted into an input field of the application.

7. A device comprising:

one or more processors, coupled to memory and configured to:

identify a type of data to encode into a format recognizable to the client device as being an input to an application;

determine that data of the type is provided as input to the application; encode the data into the format recognizable to the client device;

provide the encoded data as input to the application; and

encode, based at least on the type of data, the data using one of reverse encryption or tokenization.

8. The device of claim 7 , wherein the one or more processors are further configured to identify the type of data based at least on one of the device, a user of the device or a location of the device.

9. The device of claim 7 , wherein the one or more processors are further configured to identify the type of data based at least on a mode in which to authenticate a user to the device or the application.

10. The device of claim 7 , wherein the one or more processors are further configured to encode the data by encrypting at least a portion of the data or replacing at least a portion of the data with a token.

11. The device of claim 7 , wherein the one or more processors are further configured to determine that data of the type of data is provided as input upon the data being inputted into an input field of the application.

12. The device of claim 7 , wherein the one or more processors are further configured to encode the data as the data is being inputted into an input field of the application.

13. A system comprising:

one or more processors, coupled to memory and configured to:

identify a type of data for an application to decode as input;

determine that encoded data of the identified type is being displayed as input to the application, the encoded data having a format recognizable by the one or more processors;

decode, responsive to the determination, the encoded data; and display the decoded data as the input to the application; and

encode, by the client device based at least on the type of data, the data using one of reverse encryption or tokenization.

14. The system of claim 13 , wherein the one or more processors are further configured to identify the type of data based a user of a device comprising the one or more processors or a location of the device comprising the one or more processors.

15. The system of claim 13 , wherein the one or more processors are further configured to identify the type of data based at least on a mode in which to authenticate a user to the device or the application.

16. The system of claim 13 , wherein the one or more processors are further configured to determine that the encoded data has one of a format or a tag recognizable by the one or more processors.

17. The system of claim 13 , wherein the one or more processors are further configured to decode the encoded data using decryption.

18. The system of claim 13 , wherein the one or more processors are further configured to decode the encoded data by replacing a token of the encoded data with data retrieved by the one or more processors.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: CHAUHAN, ABHISHEK
To: CITRIX SYSTEMS, INC.
Reel/Frame 057822/0539 →
Continuity (2)
Continuation 16183226 · Nov 7, 2018
Related Publication 20220038441A1 · Feb 3, 2022