IP Library Granted Patent US 9,565,176
Granted Patent B2
US 9,565,176 · App. 14/643,049 · Granted Feb 7, 2017

Multiscreen secure content access

Inventor: Ashish Goyal (Sunnyvale, CA)
Assignee: Citrix Systems, Inc.
H04L63/08H04L63/04H04L63/0492H04L63/12H04W4/02H04W4/023H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,565,176
App. No.
14/643,049
Granted
Feb 7, 2017
Kind
B2
Abstract

Methods and systems for securely accessing content irrespective of the security of the environment in which the content is being accessed are described herein. In some embodiments, a mobile computing device may determine whether secure enterprise content is being accessed on a mobile computing device. In response to determining that a private user device (e.g., virtual reality or augmented reality headwear/eyewear), is communicatively coupled to the mobile computing device, the mobile computing device may prevent the secure content from display on the mobile computing device and instead generate the secure enterprise content for presentation in an unencrypted form on the private user device.

Claims (85)

1. A method comprising:

receiving, at a mobile computing device, secure enterprise content;

determining, by the mobile computing device, whether the secure enterprise content is being accessed on the mobile computing device;

responsive to determining that the secure enterprise content is being accessed on the mobile computing device:

preventing, by the mobile computing device, the secure enterprise content from being presented in an unencrypted form on the mobile computing device;

encrypting, by the mobile computing device, the secure enterprise content for presentation in an encrypted form on the mobile computing device by:

determining that content is to be presented on the mobile computing device,

determining a portion of the content to be presented on the mobile computing device that comprises the secure enterprise content, and

encrypting the portion of the content to be presented that comprises the secure enterprise content,

wherein the secure enterprise content is encrypted for presentation in the encrypted form in response to:

determining that the mobile computing device is in a public environment, and

determining that a secure mode to encrypt secure enterprise content on the mobile computing device has been enabled;

determining, by the mobile computing device, whether a private user device is communicatively coupled to the mobile computing device; and

responsive to determining that the private user device is communicatively coupled to the mobile computing device, transmitting, by the mobile computing device, the secure enterprise content to the private user device via the network to generate the secure enterprise content for presentation in an unencrypted form on the private user device.

2. The method of claim 1 , wherein the private user device comprises a head-mounted display device configured to place a display screen in physical proximity to a wearer's eye and visible only to the wearer.

3. The method of claim 1 , further comprising generating non-secure content for presentation in an unencrypted form on the mobile computing device.

4. The method of claim 1 , further comprising:

instructing the private user device to collect authentication information from a wearer of the private user device;

receiving the authentication information from the private user device; and

using the authentication information received from the private user device to authenticate the wearer of the private user device.

5. The method of claim 1 , wherein instructing the private user device to generate the secure enterprise content for presentation in an unencrypted form comprises:

determining that a wearer of the private user device has been authenticated;

generating the secure enterprise content into an unencrypted presentable form; and

transmitting the secure enterprise content to the private user device.

6. The method of claim 1 , further comprising:

determining whether any additional content is to be generated for presentation based on a received user input;

responsive to determining that additional content is to be generated based on the received user input, determining which portion of the additional content generated for presentation comprises additional secure enterprise content;

encrypting the portion of the additional content to be presented that comprises the additional secure enterprise content; and

generating the additional secure enterprise content for presentation in an encrypted form on the mobile computing device.

7. The method of claim 6 , further comprising:

determining that a wearer of the private user device has been authenticated;

generating the additional secure enterprise content into an unencrypted presentable form; and

transmitting the additional secure enterprise content to the private user device for presentation in an unencrypted form.

8. The method of claim 1 , wherein the encrypting the secure enterprise content for presentation in an encrypted form on the mobile computing device further comprises:

generating a blank area on a display screen of the mobile device, wherein the blank area is generated on an area of the display screen of the mobile device corresponding to the secure enterprise content.

9. An apparatus comprising:

at least one processor;

at least one display screen; and

at least one memory storing computer-readable instructions that, when executed by the at least one processor, cause the apparatus to:

receive secure enterprise content; determine whether the secure enterprise content is being accessed on the apparatus;

responsive to determining that the secure enterprise content is being accessed on the apparatus:

prevent the secure enterprise content from being presented in an unencrypted form on the apparatus;

encrypt the secure enterprise content for presentation in an encrypted form on the apparatus by:

determining that content is to be presented on the mobile computing device,

determining a portion of the content to be presented on the mobile computing device that comprises the secure enterprise content, and

encrypting the portion of the content to be presented that comprises the secure enterprise content,

wherein the secure enterprise content is encrypted for presentation in the encrypted form in response to:

determining that the mobile computing device is in a public environment, and

determining that a secure mode to encrypt secure enterprise content on the mobile computing device has been enabled;

determine whether a private user device is communicatively coupled to the apparatus; and

responsive to determining that the private user device is communicatively coupled to the apparatus, transmit the secure enterprise content to the private user device via the network to generate the secure enterprise content for presentation in an unencrypted form on the private user device.

10. The apparatus of claim 9 , wherein the instructions, when executed by the at least one processor, further cause the apparatus to generate non-secure content for presentation in an unencrypted form on the apparatus.

11. The apparatus of claim 9 , wherein the instructions, when executed by the at least one processor, further cause the apparatus to:

instruct the private user device to collect authentication information from a wearer of the private user device;

receive the authentication information from the private user device; and

use the authentication information received from the private user device to authenticate the wearer of the private user device.

12. The apparatus of claim 9 , wherein the instructions, when executed by the at least one processor, cause the apparatus to generate the secure enterprise content for presentation in an unencrypted form on the private user device by further causing the apparatus to:

determine that a wearer of the private user device has been authenticated;

generate the secure enterprise content into an unencrypted presentable form; and

transmit the secure enterprise content to the private user device.

13. The apparatus of claim 9 , wherein the instructions, when executed by the at least one processor, further cause the apparatus to:

determine whether any additional content is to be generated for presentation based on a received user input;

responsive to determining that additional content is to be generated based on the received user input, determine which portion of the additional content generated for presentation comprises additional secure enterprise content;

encrypt the portion of the additional content to be presented that comprises the additional secure enterprise content; and

generate the additional secure enterprise content for presentation in an encrypted form on the apparatus.

14. The apparatus of claim 13 , wherein the instructions, when executed by the at least one processor, further cause the apparatus to:

determine that a wearer of the private user device has been authenticated;

generate the additional secure enterprise content into an unencrypted presentable form; and

transmit the additional secure enterprise content to the private user device for presentation in an unencrypted form.

15. The apparatus of claim 9 , wherein the instructions, when executed by the at least one processor, cause the apparatus to encrypt the secure enterprise content for presentation in an encrypted form on the apparatus by further causing the apparatus to:

generate a blank area on the at least one display screen of the apparatus, wherein the blank area is generated on an area of the at least one display screen of the apparatus corresponding to the secure enterprise content.

16. One or more non-transitory computer readable media storing executable instructions that, when executed, cause a computing device to:

receive secure enterprise content;

determine whether the secure enterprise content is being accessed on the computing device;

responsive to determining that the secure enterprise content is being accessed on the computing device:

prevent the secure enterprise content from being presented in an unencrypted form on the computing device;

encrypt the secure enterprise content for presentation in an encrypted form on the computing device by:

determining that content is to be presented on the mobile computing device,

determining a portion of the content to be presented on the mobile computing device that comprises the secure enterprise content, and

encrypting the portion of the content to be presented that comprises the secure enterprise content,

wherein the secure enterprise content is encrypted for presentation in the encrypted form in response to:

determining that the mobile computing device is in a public environment, and

determining that a secure mode to encrypt secure enterprise content on the mobile computing device has been enabled;

determine whether a private user device is communicatively coupled to the apparatus; and

responsive to determining that the private user device is communicatively coupled to the apparatus, transmit the secure enterprise content to the private user device via the network to generate the secure enterprise content for presentation in an unencrypted form on the private user device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2015
From: GOYAL, ASHISH
To: CITRIX SYSTEMS, INC.
Reel/Frame 035126/0040 →
Continuity (1)
Related Publication 20160269376A1 · Sep 15, 2016