IP Library Granted Patent US 12,481,774
Granted Patent B2
US 12,481,774 · App. 18/321,323 · Granted Nov 25, 2025

Secure cross-device direct transient data sharing

Inventors: Chaoting Xuan (Duluth, GA); Lin Lv (Beijing, CN); Suyu Pan (Atlanta, GA); Guoxin Liu (Beijing, CN); Qimin Yao (Atlanta, GA); Yue Zhao (Beijing, CN)
Assignee: Omnissa, LLC
G06F21/6218G06F16/2365G06F16/258G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,774
App. No.
18/321,323
Granted
Nov 25, 2025
Kind
B2
Abstract

Systems and methods can allow for secure cross-device sharing of transient data using direct transient data sharing (“DTDS”). A source destination can share data using local DTDS with an agent on a first device. The agent can send the data to a hub server that runs a security control process and data formatting process. The hub server can determine risk scores for the source and destination devices and allow the sharing to occur if a safety threshold is met. Then an agent on the destination device can receive the transient data and use local DTDS to send the data to a destination application.

Claims (40)

1 . A method for sharing between user devices using direct transient data sharing (“DTDS”), comprising:

receiving data at a server from a first device, wherein a source application on the first device shares the data with a first agent at the first device using DTDS, and wherein the first agent shares the data with the server;

identifying, at the server, a second device associated with a same user as the first device, the second device including a destination application to receive the data;

determining that security requirements are met based on the second device complying with a compliance policy provided from the server to the second device, wherein a second agent on the second device reports compliance status of the second device with the compliance policy to the server, and wherein the compliance status specifies a management status of the destination application, the management status indicating whether the destination application is managed by the server or not managed by the server; and

in an instance where the security requirements are met, sending the data to the destination application or the second agent of the second device, wherein the security requirements are met if the management status of the destination application indicates that the destination application is managed by the server, and wherein the security requirements are not met when the management status of the destination application indicates that the destination application is not managed by the server.

2 . The method of claim 1 , further comprising:

determining that the second device runs a different operating system (“OS”) compared to the first device; and

translating the data for use with the different OS.

3 . The method of claim 2 , wherein the translating includes the server converting an image to a different image format.

4 . The method of claim 2 , wherein the translating includes converting the data to a different size.

5 . The method of claim 1 , wherein determining the security requirements are met includes determining risk scores for the first device and second device based on the management status of the source application and destination application, wherein the risk scores are compared against a threshold to determine whether to send the data to the destination application.

6 . The method of claim 1 , wherein determining the security requirements are met includes determining that the first device is also compliant with the compliance policy.

7 . The method of claim 1 , wherein sending the data to the destination application includes sending the data from the server to the second agent on the second device, and wherein the second agent sends the data to the destination application using DTDS.

8 . A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, performs stages for sharing between user devices using direct transient data sharing (“DTDS”), the stages comprising:

receiving data at a server from a first device, wherein a source application on the first device shares the data with a first agent at the first device using DTDS, and wherein the first agent shares the data with the server;

identifying, at the server, a second device associated with a same user as the first device, the second device including a destination application to receive the data;

determining that security requirements are met by the second device, wherein the security requirements are met if a management status of the destination application indicates that the destination application is managed by the server, and wherein the security requirements are not met when the management status of the destination application indicates that the destination application is not managed by the server; and

in an instance where the security requirements are met:

converting the data to a different size based on the second device running a different operating system (“OS”) compared to the first device; and

sending the converted data to the second device.

9 . The non-transitory, computer-readable medium of claim 8 , wherein determining the security requirements are met includes verifying that both the first and second device meet compliance policies for the different respective operating systems.

10 . The non-transitory, computer-readable medium of claim 8 , wherein the converting includes the server converting an image to a different image format.

11 . The non-transitory, computer-readable medium of claim 8 , wherein the converting includes converting the data to a different size.

12 . The non-transitory, computer-readable medium of claim 8 , wherein determining the security requirements are met includes determining risk scores for the first device and second device based on the management status of the source application and destination application, wherein the risk scores are compared against a threshold to determine whether to send the data to the destination application.

13 . The non-transitory, computer-readable medium of claim 8 , wherein determining the security requirements are met is based on compliance of the first and second devices with a compliance policy provided from the server to the first and second devices, wherein a first agent on the first and a second agent on the second device report compliance statuses to the server.

14 . The non-transitory, computer-readable medium of claim 8 , wherein sending the data to the destination application includes sending the data from the server to the second agent on the second device, and wherein the second agent sends the data to the destination application using DTDS.

15 . A system for secure cross-device transient data sharing using direct transient data sharing (“DTDS”), comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

a computing device including a hardware-based processor that executes the instructions to carry out stages comprising:

receiving data at a server from a first device, wherein a source application on the first device shares the data with a first agent at the first device using DTDS, and wherein the first agent shares the data with the server,

identifying, at the server, a second device associated with a same user as the first device, the second device including a destination application to receive the data;

determining that security requirements are met based on the second device complying with a compliance policy provided from the server to the second device, wherein a second agent on the second device reports compliance status of the second device with the compliance policy to the server, and wherein the compliance status specifies a management status of the destination application, the management status indicating whether the destination application is managed by the server or not managed by the server; and

in an instance where the security requirements are met, sending the data to the destination application or the second agent of the second device, wherein the security requirements are met if the management status of the destination application indicates that the destination application is managed by the server, and wherein the security requirements are not met when the management status of the destination application indicates that the destination application is not managed by the server.

16 . The system of claim 15 , the stages further comprising:

determining that the second device runs a different operating system (“OS”) compared to the first device; and

translating the data for use with the different OS.

17 . The system of claim 16 , wherein the translating includes the server converting an image to a different image format.

18 . The system of claim 16 , wherein the translating includes converting the data to a different size.

19 . The system of claim 15 , wherein determining the security requirements are met includes determining that the first device is also compliant with the compliance policy.

20 . The system of claim 15 , wherein determining the security requirements are met is based on compliance of the first and second devices with a compliance policy provided from the server to the first and second devices, wherein the first agent on the first device and the second agent on the second device report compliance statuses to the server.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
Priority Claims (1)
WO PCT/CN2020/072198 · Jan 15, 2020 · international
Continuity (2)
Continuation 15930284 · May 12, 2020
Related Publication 20230289463A1 · Sep 14, 2023
References Cited (15)
US 8473587B1 · Lappas · 2013 [cited by applicant]
US 11416342B2 · Zlotnick · 2022 [cited by applicant]
US 20080162586A1 · Vuori · 2008 [cited by examiner]
US 20150350268A1 · Chang · 2015 [cited by examiner]
US 20170371693A1 · Corrie · 2017 [cited by applicant]
EP 1158744A2 · 2001 [cited by examiner]
EP 1827033A2 · 2007 [cited by examiner]
TW 201305903 · 2013 [cited by examiner]
Hemmes (Hemmes, et al., On-Demand Transient Data Storage and Backup in Mobile Systems, Proceedings of the Military Communications Conference (MILCOM), Orlando, FL, Oct. 2007). [cited by examiner]
Michelle Laverick, “How to manage transiet data and replication”, ComputerWeekly.com, Nov. 2011. [cited by examiner]
Plu et al., “Transient data sharing among mobile programs” Report No. WUCS-95-01 (1995). All Computer Science and Engineering Research. https://openscholarship.wustl.edu/cse_research/361. [cited by examiner]
Al-Qudah et al., “Internet With Transient Destination-Controlled Addressing,” in IEEE/ACM Transactions on Networking, vol. 24, No. 2, pp. 731-744, Apr. 2016, doi: 10.1109/TNET.2014.2382110. (Year: 2016). [cited by examiner]
Boettcher , “Unleash the Power of Single Sign-On with Microsoft and SAP”, Collaboration Technology Support Center—Microsoft, Collaboration Brief, Sep. 2017, 2007. [cited by applicant]
Hadfield , “Server 4 Security Handbook”, ISBN 07897 1213x, 1997, 1997. [cited by applicant]
Liu, Zheng , “Microsoft NET Passport, a solution of single sign on”, Department of Computer Science University of Auckland, Feb. 2018, 2018. [cited by applicant]