IP Library Patent Application 18874220
Patent Application
App. No. 18/874,220

ON-DEMAND VIRTUAL SECURE SESSION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/874,220
Abstract

Methods and systems for implementing on-demand virtual secure session are described herein. A computing device may monitor a virtual desktop accessible from an endpoint device. The computing device may detect a user selection of an application and generate a snapshot image indicating a state of the virtual desktop. The computing device may initiate an on-demand virtual secure session. The computing device may provide the endpoint device with access to a remote application. The computing device may detect a user indication to stop execution of the remote application. Accordingly, the computing device may terminate the on-demand virtual secure session and restore the virtual desktop.

Claims (74)

1 . A method comprising:

monitoring, by a computing device, a virtual desktop accessible from an endpoint device via a remote session associated with a user;

detecting, by the computing device, a user selection of an application displayed in the virtual desktop to be executed in a secure environment;

generating, by the computing device, a snapshot image indicating a state of the virtual desktop associated with the endpoint device;

initiating, by the computing device, an on-demand virtual secure session between the computing device and the endpoint device, wherein the on-demand virtual secure session is agnostic to an identity of the user;

providing, by the computing device and via the on-demand virtual secure session, the endpoint device with access to a remote application corresponding to the application displayed in the virtual desktop, the remote application being hosted on the computing device and displayable on the endpoint device in a form of a user interface;

detecting, by the computing device, a user indication to stop execution of the remote application in the user interface;

terminating, by the computing device, the on-demand virtual secure session; and

restoring, based on the snapshot image, the virtual desktop to a time prior to the initiation of the on-demand virtual secure session.

2 . The method of claim 1 , wherein the remote session associated with the user and the on-demand virtual secure session share no security context.

3 . The method of claim 1 , further comprising:

after providing the endpoint device with access to the remote application, receiving one or more user commands to execute the remote application;

executing, based on the one or more user commands, the remote application hosted on the computing device;

storing an execution result of the remote application in a secure storage in a cloud accessible by the computing device; and

causing to display the execution result of the remote application in the user interface.

4 . The method of claim 3 , further comprising:

after terminating the on-demand virtual secure session, deleting the execution result of the remote application from the secure storage.

5 . The method of claim 1 , further comprising:

after generating the snapshot image and prior to initiating the on-demand virtual secure session, terminating the remote session; and

after terminating the on-demand virtual secure session, initiating a new remote session associated with the user; and

wherein restoring the virtual desktop to the time prior to the initiation of the on-demand virtual secure session comprises:

providing, based on the snapshot image, the virtual desktop accessible from the endpoint device via the new remote session.

6 . The method of claim 1 , wherein the user selection of the application comprises:

opening a file in the secure environment;

opening a link to the file in the secure environment; and

installing a software in the secure environment.

7 . The method of claim 1 , wherein the application displayed in the virtual desktop corresponds to a first operating system format and the remote application displayed in the user interface corresponds to a second operating system format different from the first operating system format.

8 . The method of claim 7 , wherein the second operating system format comprises a Windows format, a Linux format and a Mac OS format.

9 . The method of claim 1 , further comprising:

after initiating the on-demand virtual secure session, assigning a temporary account to the user without a reference to the identity of the user.

10 . The method of claim 9 , further comprising:

after terminating the on-demand virtual secure session, deleting the temporary account and data associated with the temporary account from a secure storage associated with the on-demand virtual secure session.

11 . A computing device, comprising:

at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

determine a virtual desktop accessible from an endpoint device via a remote session associated with a user;

detect a user selection of an application displayed in the virtual desktop to be executed in a secure environment;

generate a snapshot image indicating a state of the virtual desktop associated with the endpoint device;

initiate an on-demand virtual secure session between the computing device and the endpoint device, wherein the on-demand virtual secure session is agnostic to an identity of the user;

provide, via the on-demand virtual secure session, the endpoint device with access to a remote application corresponding to the application displayed in the virtual desktop, the remote application being hosted on the computing device and displayable on the endpoint device in a form of a user interface;

detect a user indication to stop execution of the remote application in the user interface;

terminate the on-demand virtual secure session; and

restore, based on the snapshot image, the virtual desktop to a time prior to the initiation of the on-demand virtual secure session.

12 . The computing device of claim 11 , wherein the remote session associated with the user and the on-demand virtual secure session share no security context.

13 . The computing device of claim 11 , wherein the memory stores additional computer-readable instructions, that when executed by the at least one processor, cause the computing device to:

after providing the endpoint device with access to the remote application, receive one or more user commands to execute the remote application;

execute, based on the one or more user commands, the remote application hosted on the computing device;

store an execution result of the remote application in a secure storage in a cloud accessible by the computing device; and

cause to display the execution result of the remote application in the user interface.

14 . The computing device of claim 13 , wherein the memory stores additional computer-readable instructions, that when executed by the at least one processor, cause the computing device to:

after terminating the on-demand virtual secure session, delete the execution result of the remote application from the secure storage.

15 . The computing device of claim 11 , wherein the memory stores additional computer-readable instructions, that when executed by the at least one processor, cause the computing device to:

after generating the snapshot image and prior to initiating the on-demand virtual secure session, terminate the remote session; and

after terminating the on-demand virtual secure session, initiate a new remote session associated with the user; and

wherein restoring the virtual desktop to the time prior to the initiation of the on-demand virtual secure session comprises:

provide, based on the snapshot image, the virtual desktop accessible from the endpoint device via the new remote session.

16 . The computing device of claim 11 , wherein the user selection of the application comprises:

opening a file in the secure environment;

opening a link to the file in the secure environment; and

installing a software in the secure environment.

17 . The computing device of claim 11 , wherein the application displayed in the virtual desktop corresponds to a first operating system format and the remote application displayed in the user interface corresponds to a second operating system format different from the first operating system format.

18 . The computing device of claim 11 , wherein the memory stores additional computer-readable instructions, that when executed by the at least one processor, cause the computing device to:

after initiating the on-demand virtual secure session, assigning a temporary account to the user without a reference to the identity of the user.

19 . The computing device of claim 18 , wherein the memory stores additional computer-readable instructions, that when executed by the at least one processor, cause the computing device to:

after terminating the on-demand virtual secure session, delete the temporary account and data associated with the temporary account from a secure storage associated with the on-demand virtual secure session.

20 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing device comprising at least one processor and memory, cause the computing device to:

monitor a virtual desktop accessible from an endpoint device via a remote session associated with a user;

detect a user selection of an application displayed in the virtual desktop to be executed in a secure environment;

generate a snapshot image indicating a state of the virtual desktop associated with the endpoint device;

initiate an on-demand virtual secure session between the computing device and the endpoint device, wherein the on-demand virtual secure session is agnostic to an identity of the user;

provide, via the on-demand virtual secure session, the endpoint device with access to a remote application corresponding to the application displayed in the virtual desktop, the remote application being hosted on the computing device and displayable on the endpoint device in a form of a user interface;

detect a user indication to stop execution of the remote application in the user interface;

terminate the on-demand virtual secure session; and

restore, based on the snapshot image, the virtual desktop to a time prior to the initiation of the on-demand virtual secure session.

Assignments (1)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →