IP Library Granted Patent US 8,775,944
Granted Patent B2
US 8,775,944 · App. 12/147,029 · Granted Jul 8, 2014

Methods and systems for interactive evaluation of policies

Inventor: Richard Hayton (Cambridge, GB)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,775,944
App. No.
12/147,029
Filed
Jun 26, 2008
Granted
Jul 8, 2014
Kind
B2
Art Unit
2179
USPC
715/744
Abstract

A system for interactive evaluation of policies includes a first graphical user interface element and a second graphical user interface element. The first graphical user interface element enumerates at least one resource. The second graphical user interface element receives an identification of a characteristic of at least one client and displays a result of an application of at least one policy associated with the at least one resource to the at least one client, the at least on policy applied responsive to the received identification of the characteristic.

Claims (91)

1. A method for interactive evaluation of policies using a graphical user interface to display the effect of alterable access policies on clients and resources, the method comprising the steps of:

(a) receiving, by a policy engine, a request to access at least one resource stored on a server from a client;

(b) transmitting, by the policy engine, a collection agent to the client in response to receiving the request;

(c) receiving, by the policy engine from the collection agent executing on the client, an identification of a characteristic of at least one client requesting access to the at least one resource;

(d) enumerating an identification of at least one resource;

(e) applying at least one policy including a first policy associated with the at least one resource to the at least one client requesting access to the at least one resource, responsive to the received identification of the characteristic of the at least one client;

(f) displaying data on the graphical user interface wherein the graphical user interface includes:

an interactive element that receives input from a user that alters settings in the first policy;

a description of the identified characteristic of at least one client received from the collection agent executing on the client; and

a description of the results of applying the first policy including whether the client may access the requested resource;

(g) receiving the input altering the settings of the first policy using the interactive element;

(h) simulating an application of the altered first policy producing an output comprising at least one description of a setting that resulted in denial of access to the requested resource in the case that the requested resource is denied, the description of the setting comprising a summary indicating how the altered first policy produced the result; and

(i) displaying the output of the simulation including the description of the summary indicating how the altered first policy produced the result in the graphical user interface.

2. The method of claim 1 further comprising the step of receiving an identification of a filter in the first policy, the filter satisfied by the at least one client.

3. The method of claim 1 further comprising the step of receiving an identification of a filter in the first policy, the filter not satisfied by the at least one client.

4. The method of claim 1 further comprising the step of identifying, by a policy simulation engine, a characteristic of the at least one client responsive to an evaluation of at least one filter in the first policy.

5. The method of claim 1 , wherein step (c) further comprises receiving an identification of a type of operating system executed on the at least one client.

6. The method of claim 1 , wherein step (c) further comprises receiving an identification of a type of application executed on the at least one client.

7. The method of claim 1 , wherein step (c) further comprises receiving an identification of a group in which the at least one client is a member.

8. The method of claim 1 , wherein step (c) further comprises receiving an identification of a range of internet protocol addresses associated with the at least client.

9. The method of claim 1 further comprising the step of determining whether first policy applies to the at least one client, responsive to the received identification of the characteristic.

10. The method of claim 9 , wherein step (e) further comprises displaying an indication that a second identification of a second characteristic is required to determine whether the first policy applies to the at least one client.

11. The method of claim 9 , further comprising the step of determining that at least one policy applies to the at least one client, responsive to the received identification of the characteristic.

12. The method of claim 1 , wherein step (e) further comprises displaying an identification of a requirement not satisfied by the at least one client.

13. The method of claim 1 , wherein step (e) further comprises displaying an identification of a requirement satisfied by the at least one client.

14. The method of claim 1 , wherein step (e) further comprises displaying, by the graphical user interface, an indication that the application of the first policy results in a request for additional information associated with the at least one client.

15. The method of claim 1 , wherein step (e) further comprises displaying, by the graphical user interface, a result of applying an auditing policy to the at least one client.

16. The method of claim 1 , wherein step (e) further comprises displaying, by the graphical user interface, a result of applying a caching policy to the at least one client.

17. The method of claim 1 , wherein step (e) further comprises displaying, by the graphical user interface, a result of applying a load balancing policy to the at least one client.

18. The method of claim 1 , wherein step (f) further comprises displaying one result of a type of access from a plurality of types of access to the resource.

19. The method of claim 18 , wherein the plurality of types of access includes at least one of: downloading, view remotely, and application streaming.

20. The method of claim 1 , wherein the request to access at least one resource stored on a server from a client is communicated using a remote display protocol.

21. A method for interactive evaluation of policies using a graphical user interface to display the effect of alterable access policies on clients and resources, the method comprising the steps of:

(a) displaying an identification of at least one resource;

(b) receiving an identification of a characteristic of at least one client requesting access to the at least one resource;

(c) displaying an indication that a second identification of a second characteristic is required to determine whether at least one policy including a first policy applies to the at least one client;

(d) displaying data on a graphical user interface wherein the graphical user interface includes:

an interactive element that receives input from a user that alters settings in the first policy;

a description of the identified characteristic of at least one client received from the collection agent executing on the client;

a description of the results of applying the first policy including whether the client may access the requested resource; and

a description of an access routing decision, identified responsive to an application of an access routing policy to a description of the client requesting access to the resource and a description of the resource, the description indicating at least one of a method of access and a type of access;

(e) receiving the input that alters the settings in the first policy using the interactive element;

(f) simulating an application of the altered first policy producing an output comprising at least one description of a setting that resulted in denial of access to the requested resource in the case that the requested resource is denied, the description of the setting comprising a summary indicating how the altered first policy produced the result; and

(g) displaying the output of the simulation including the description of the summary indicating how the altered first policy produced the result in the graphical user interface.

22. The method of claim 21 further comprising the step of receiving an identification of a filter in the first policy, the filter satisfied by the at least one client.

23. The method of claim 21 further comprising the step of receiving an identification of a filter in the first policy, the filter not satisfied by the at least one client.

24. The method of claim 21 further comprising the step of identifying, by a policy simulation engine, a characteristic of the at least one client responsive to an evaluation of at least one filter in the first policy.

25. The method of claim 21 , wherein step (b) further comprises receiving an identification of a type of operating system executed on the at least client.

26. The method of claim 21 , wherein step (b) further comprises receiving an identification of a type of application executed on the at least one client.

27. The method of claim 21 , wherein step (b) further comprises receiving an identification of a group in which the at least one client are members.

28. The method of claim 21 , wherein step (c) further comprises determining that first policy applies to the at least one client, responsive to the received identification of the characteristic.

29. The method of claim 21 , wherein step (c) further comprises determining that a second identification of a second characteristic is required to determine whether the first policy applies to the at least one client.

30. The method of claim 21 , wherein step (c) further comprises determining whether at least one auditing policy applies to the at least one client, responsive to the received identification of the characteristic.

31. The method of claim 21 , wherein step (c) further comprises determining whether at least one caching policy applies to the at least one client, responsive to the received identification of the characteristic.

32. The method of claim 21 , wherein step (c) further comprises determining whether at least one load-balancing policy applies to the at least one client, responsive to the received identification of the characteristic.

33. The method of claim 21 , wherein step (d) further comprises displaying, by the graphical user interface, an indication that the application of the first policy results in a request for additional information associated with the at least one client.

34. The method of claim 21 , wherein step (d) further comprises displaying an identification of a requirement satisfied by the at least one client.

35. The method of claim 21 , wherein step (d) further comprises displaying an identification of a requirement not satisfied by the at least one client.

36. The method of claim 21 , wherein step (d) further comprises displaying an indication that a second identification of a second characteristic is required to determine whether at least one auditing policy applies to the at least one client.

37. The method of claim 21 , wherein step (d) further comprises displaying an indication that a second identification of a second characteristic is required to determine whether at least one caching policy applies to the at least one client.

38. The method of claim 21 , wherein step (d) further comprises displaying an indication that a second identification of a second characteristic is required to determine whether at least one load-balancing policy applies to the at least one client.

39. The method of claim 21 further comprising the step of receiving, from a policy simulation engine, the indication that the second identification of the second characteristic is required to determine whether the first policy applies to the at least one client.

40. A system for interactive evaluation of policies using a graphical user interface to display the effect of alterable access policies on clients and resources, the system comprising:

a memory;

a processor configured to execute instructions stored in the memory to:

apply at least one policy including a first policy associated with at least one resource to at least one client requesting access to the at least one resource, responsive to the received identification of the characteristic of the at least one client;

displaying data on a graphical user interface wherein the graphical user interface includes:

a first graphical user interface element enumerating at least one resource; and

a second graphical user interface element that receives input from a user that alters a characteristic of the at least one client; and

receiving the input that alters the characteristic of the at least one client;

simulating an application of the altered characteristic to the at least one resource producing an output comprising at least one description of a setting that resulted in denial of access to the requested resource in the case that the requested resource is denied, the description of the setting comprising a summary indicating how the altered characteristic produced the result; and

displaying the output, including the description of the summary indicating how the altered characteristic produced the result, in the graphical user interface.

41. The system of claim 40 , wherein the first graphical user interface element further comprises a display of an identification of a type of anti-virus program executed by the at least one client.

42. The system of claim 40 , wherein the first graphical user interface element further comprises a display of an identification of a type of operating system executed by the at least one client.

43. The system of claim 40 , wherein the first graphical user interface element further comprises a display of an identification of a type of application executed by the at least one client.

44. The system of claim 40 , wherein the first graphical user interface element further comprises a display of an internet protocol (IP) address range, the at least one client assigned an IP address in the IP address range.

45. The system of claim 40 , wherein the first graphical user interface element further comprises an interface element for receiving an identification of at least one characteristic of the at least one client.

46. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying the first policy.

47. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a requirement of the first policy.

48. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a filter of the first policy.

49. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element indicating that an application of the first policy to the at least one client results in a denial of access to the at least one resource by the at least one client.

50. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element indicating that an application of the first policy to the at least one client results in an allowance of access to the at least one resource by the at least one client.

51. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element indicating that additional information associated with the at least one client is needed to identify a result of an application of the first policy to the at least one client.

52. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a result of applying an access control policy to the at least one client.

53. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a result of applying an auditing policy to the at least one client.

54. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a result of applying a caching policy to the at least one client.

55. The system of claim 40 , wherein the second graphical user interface element further comprises an interface element displaying a result of applying a load-balancing policy to the at least one client.

56. The system of claim 40 further comprising a policy simulation engine generating the result of the application of the first policy associated with the at least one resource to the at least one client.

57. The system of claim 40 further comprising a graphical user interface element receiving an identification of a filter in the first policy, the filter satisfied by the at least one client.

58. The system of claim 40 further comprising a graphical user interface element receiving an identification of a filter in the first policy, the filter not satisfied by the at least one client.

59. The system of claim 40 further comprising a graphical user interface element receiving, by a policy simulation engine, a characteristic of the at least one client responsive to an evaluation of at least one filter in the first policy.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2008
From: HAYTON, RICHARD
To: CITRIX SYSTEMS, INC
Reel/Frame 021402/0760 →
Continuity (1)
Related Publication 20090327909A1 · Dec 31, 2009