IP Library Granted Patent US 7,954,150
Granted Patent B2
US 7,954,150 · App. 11/624,396 · Granted May 31, 2011

Methods and systems for assigning access control levels in providing access to resources via virtual machines

Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,954,150
App. No.
11/624,396
Granted
May 31, 2011
Kind
B2
Abstract

A system for granting access to resources includes a client machine, a collection agent, a policy engine, and a broker server. The client machine requests access to a resource. The collection agent gathers information about the client machine. The policy engine receives the gathered information and assigns one of a plurality of levels of access responsive to application of a policy to the received information. The broker server establishes, responsive to the assigned level of access, a connection between the client machine and a computing environment providing the requested resource, the computing environment provided by a virtual machine.

Claims (73)

1. A system for granting levels of access to a resource according to information gathered about client machines comprising:

a policy engine that

i) receives a first request for access to a resource from a user at a first client machine,

ii) directs a first collection agent to gather information about the first client machine,

iii) grants the first client machine a first level of access to the resource responsive to application of a policy to the information about the first client machine, the first level chosen from a plurality of levels of access; and

a broker machine that

i) selects a first virtual machine that can provide

a) a first desktop computing environment with the resource according to the first granted level of access, and

b) a first operating system in which to execute the first desktop computing environment,

ii) selects a first execution machine executing a first hypervisor providing access to hardware resources required by the first virtual machine,

iii) launches the first virtual machine into the first execution machine, the first virtual machine executing the first operating system,

iv) launches the first desktop computing environment with the resource according to the first granted level of access into the first executing operating system on the first execution machine;

v) establishes a first connection between the client machine and the first desktop computing environment with the resource according to the first granted level of access; wherein

the policy engine

i) receives a second request for access to the resource from the user at a second client machine,

ii) directs a second collection agent to gather information about the second client machine, and

iii) grants the second client machine a second level of access to the resource responsive to application of the policy to the information about the second client machine, the second level chosen from the plurality of levels of access; and

the broker machine

i) selects a second virtual machine that can provide

a) a second desktop computing environment with the resource according to the second granted level of access, and

b) a second operating system in which to execute the second desktop computing environment,

ii) selects a second execution machine executing a second hypervisor providing access to hardware resources required by the second virtual machine,

iii) launches the second virtual machine into the second execution machine, the second virtual machine executing the second operating system,

iv) launches the second desktop computing environment with the resource according to the second granted level of access into the second executing operating system on the second execution machine;

v) establishes a second connection between the client machine and the second desktop computing environment with the resource according to the second granted level of access.

2. The system of claim 1 wherein the policy engine comprises a database storing configurable policies.

3. The system of claim 2 wherein the policies in the policy engine can be configured by a system administrator.

4. The system of claim 1 wherein the policy engine directs the first or second collection agent to gather a type of information.

5. The system of claim 1 wherein the policy engine comprises a logon agent.

6. The system of claim 5 wherein the logon agent receives the information from the first or second collection agent.

7. The system of claim 5 wherein the logon agent identifies for the policy engine authentication information received from the first or second collection agent.

8. The system of claim 1 wherein the policy engine comprises a plurality of logon agents.

9. The system of claim 8 wherein each network domain from which the first or second client machine may transmit the first or second request includes at least one of the plurality of logon agents.

10. The system of claim 9 wherein the first or second client machine transmits the first or second request to a logon agent of the plurality of logon agents.

11. The system of claim 10 where the logon agent identifies for the policy engine the network domain from which the first or second client machine transmits the request.

12. The system of claim 1 wherein the first collection agent executes on the first client machine.

13. The system of claim 1 wherein the policy engine transmits the first collection agent to the first client machine.

14. The system of claim 1 wherein the first collection agent comprises at least one script.

15. The system of claim 1 wherein the first collection agent comprises bytecode.

16. The system of claim 1 wherein the first collection agent gathers the information about the first client machine by running at least one script on the first client machine.

17. The system of claim 1 wherein the information includes a network zone of the first client machine.

18. The system of claim 1 wherein the information includes a method of authentication used by the first client machine.

19. The system of claim 1 wherein the information includes a machine ID of the first client machine.

20. The system of claim 1 wherein the information includes a type of operating system on the first client machine.

21. The system of claim 1 wherein the information includes an existence of a patch to an operating system.

22. The system of claim 1 wherein the information includes MAC addresses of installed network cards.

23. The system of claim 1 wherein the information includes a watermark on the first client machine.

24. The system of claim 1 wherein the information includes membership in an Active Directory.

25. The system of claim 1 wherein the information includes an existence of a virus scanner.

26. The system of claim 1 wherein the information includes an existence of a firewall.

27. The system of claim 1 wherein the information includes an HTTP header.

28. A method for granting levels of access to a resource according to information gathered about client machines, the method comprising:

receiving, by a policy engine, a first request for access to a resource from a user at a first client machine;

directing, by the policy engine, a first collection agent to gather information about the first client machine;

granting, by the policy engine, the first client machine a first level of access to the resource responsive to application of a policy to the information about the first client machine, the first level chosen from a plurality of levels of access;

selecting, by a broker machine, a first virtual machine that can provide a first desktop computing environment with the resource according to the first granted level of access and a first operating system in which to execute the first desktop computing environment;

selecting, by the broker machine, a first execution machine executing a first hypervisor providing access to hardware resources required by the first virtual machine;

launching, by the broker machine, the first virtual machine into the first execution machine, the first virtual machine executing the first operating system;

launching, by the broker machine, the first desktop computing environment with the resource according to the first granted level of access into the first executing operating system on the first execution machine;

establishing, by the broker machine, a first connection between the client machine and the first desktop computing environment with the resource according to the first granted level of access;

receiving, by the policy engine, a second request for access to the resource from the user at a second client machine;

directing, by the policy engine, a second collection agent to gather information about the second client machine;

granting, by the policy engine, the second client machine a second level of access to the resource responsive to application of the policy to the information about the second client machine, the second level chosen from the plurality of levels of access

selecting, by the broker machine, a second virtual machine that can provide a second desktop computing environment with the resource according to the second granted level of access and a second operating system in which to execute the second desktop computing environment;

selecting, by the broker machine, a second execution machine executing a second hypervisor providing access to hardware resources required by the second virtual machine;

launching, by the broker machine, the second virtual machine into the second execution machine, the second virtual machine executing the second operating system;

launching, by the broker machine, the second desktop computing environment with the resource according to the second granted level of access into the second executing operating system on the second execution machine; and

establishing, by the broker machine, a second connection between the client machine and the second desktop computing environment with the resource according to the second granted level of access.

29. The method of claim 28 wherein receiving the first or second request further comprises receiving the first or second request over a network connection.

30. The method of claim 28 further comprising receiving, by the policy engine, the information about the first or second client machine over a network connection.

31. The method of claim 28 wherein granting the first or second level of access further comprises determining if the information about the first or second client machine satisfies a condition.

32. The method of claim 31 wherein granting the first or second level of access further comprises granting the first or second level of access responsive to application of the policy to the condition.

33. The method of claim 28 , wherein selecting the first or second virtual machine further comprises selecting the first or second virtual machine responsive to the grant of the first or second level of access.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2007
From: CROFT, RICHARD JASON; LOW, ANTHONY EDWARD; MAZZAFERRI, RICHARD JAMES; ROBINSON, DAVID NEIL; PEDERSEN, BRADLEY J.
To: CITRIX SYSTEMS, INC.
Reel/Frame 019138/0980 →
Continuity (2)
Provisional Application 60761674 · Jan 24, 2006
Related Publication 20070180493A1 · Aug 2, 2007