IP Library Granted Patent US 9,785,794
Granted Patent B2
US 9,785,794 · App. 14/104,457 · Granted Oct 10, 2017

Securing sensitive data on a mobile device

Inventor: Nitin Desai (Coral Springs, FL)
Assignee: Citrix Systems, Inc.
G06F21/6227G06F21/554H04L51/18H04W12/08G06F2221/2137G06F2221/2143H04L63/108H04W4/001
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,785,794
App. No.
14/104,457
Granted
Oct 10, 2017
Kind
B2
Abstract

Illustrative aspects described herein relate to data security and automatic deletion of data when specific criteria are met. Sensitive data may be protected when sent over unsecured networks or to unsecured or BYOD devices while preventing data leakage by specifying conditions under which the data is to be automatically deleted. This prevention may involve using a managed application to receive a data message from an application on a sending mobile device, such that the managed application is configure to delete the data message when the specified criteria are met. In one embodiment, the data message may include the criteria which, when met, results in the destruction of the data message, thereby allowing a sender to define the criteria. Once the data message is stored on the second mobile device, the receiving application determines whether the destruction criteria have been met. If so, the receiving application deletes the data message.

Claims (33)

1. A method comprising:

executing a managed application on a mobile device, wherein the managed application is configured to operate in accordance with a set of one or more policy files defined independent of the managed application, wherein the one or more policy files restrict the managed application to accept messages only from other instances of the managed application executing on other devices, and wherein the one or more policy files configure the managed application to delete at least a payload of a data message when one or more of a plurality of destruction criteria are met, and wherein the data message is addressed from a first user to a second user;

receiving, by the mobile device as sent from a second mobile device, a request for a response indicating whether the mobile device includes at least one managed application capable of accepting the data message;

sending, by the mobile device, a response to the request that indicates whether the mobile device includes at least one managed application capable of accepting the data message;

receiving, when the response to request indicates that the mobile device includes at least one managed application capable of accepting the data message, the data message from an application on the second mobile device, wherein the data message specifies the plurality of destruction criteria; and

automatically deleting the payload when one or more of the plurality of destruction criteria are met by analyzing the payload for whether or not the payload meets any one of the plurality of destruction criteria in a predetermined order, starting with detection of a known security threat on the mobile device,

wherein the plurality of destruction criteria comprise: a) a length of time the payload has been viewed, b) a number of times the payload has been viewed, c) a length of time the payload has been stored on the mobile device since receipt of the payload by the mobile device, 4) a length of time the data message has been stored unopened on the mobile device, and 5) detection of a known security threat on the mobile device.

2. A method comprising:

executing a managed application on a mobile device, wherein the managed application is configured to operate in accordance with a set of one or more policy files defined independently of and received independently from the managed application, wherein the one or more policy files restrict the managed application to accept messages only from other instances of the managed application executing on other devices;

receiving, by the mobile device as sent from a second mobile device, a request for a response indicating whether the mobile device includes at least one managed application capable of accepting a message;

sending, by the mobile device, a response to the request that indicates whether the mobile device includes at least one managed application capable of accepting the message;

receiving, when the response to request indicates that the mobile device includes at least one managed application capable of accepting the message, a message from the second mobile device, said message comprising a data payload and a plurality of destruction criteria, wherein the plurality of destruction criteria are usable by the managed application to delete the data payload when one or more of the plurality of destruction criteria are met;

determining that one or more of the plurality of destruction criteria are met; and

deleting the data payload from the mobile device responsive to determining that one or more of the plurality of destruction criteria are met by analyzing the data payload for whether or not the data payload meets any one of the plurality of destruction criteria in a predetermined order, starting with detection of a known security threat on the mobile device,

wherein the plurality of destruction criteria comprise: a) a length of time the data payload has been viewed, b) a number of times the data payload has been viewed, c) a length of time the data payload has been stored on the mobile device since receipt of the data payload by the mobile device, 4) a length of time the message has been stored unopened on the mobile device, and 5) detection of a known security threat on the mobile device.

3. The method of claim 2 , wherein the known security threat comprises predetermined executable code detected on the mobile device, and wherein the predetermined executable code comprises one of malware and a virus.

4. A computing device, comprising:

a processor;

a memory, storing computer readable instructions that, when executed by the processor, configure the computing device to:

execute a managed application, wherein the managed application is configured to operate in accordance with a set of one or more policy files defined independent of and received independent from the managed application, wherein the one or more policy files restrict the managed application to accept messages only from other instances of the managed application executing on other devices, and;

receiving, by the computing device as sent from a second computing device, a request for a response indicating whether the computing device includes at least one managed application capable of accepting a data message;

sending, by the computing device, a response to the request that indicates whether the computing device includes at least one managed application capable of accepting the data message;

receive a data message from the second computing device, wherein the data message comprises a data payload and a plurality of destruction criteria;

determine when one or more of the plurality of destruction criteria are met by analyzing the data payload for whether or not the data payload meets any one of the plurality of destruction criteria in a predetermined order, starting with detection of a known security threat on the computing device; and

responsive to determining that one or more of the plurality of destruction criteria are met, automatically delete at least the data payload,

wherein the plurality of destruction criteria comprise: a) a length of time the data payload has been viewed, b) a number of times the data payload has been viewed, c) a length of time the data payload has been stored on the computing device since receipt of the data payload by the computing device, 4) a length of time the message has been stored unopened on the computing device, and 5) detection of a known security threat on the computing device.

5. The computing device of claim 4 , wherein responsive to the determining, the computing device automatically deletes all of the data message.

6. The method of claim 2 , further comprising:

receiving a second message from the second mobile device, the second message comprising a second data payload and one or more of a plurality of second destruction criteria, wherein the plurality of second destruction criteria are usable by the managed application to delete the second data payload when one or more of the plurality of second destruction criteria are met;

determining that one or more of the plurality of second destruction criteria are met; and

deleting the second data payload from the mobile device responsive to determining that one or more of the plurality of second destruction criteria are met.

7. The method of claim 1 , wherein the plurality of destruction criteria further comprises a type of mobile device that sent the payload to the mobile device.

8. The method of claim 7 , wherein the mobile device only deletes the payload when the type of the mobile device that sent the payload to the mobile device is a same as the type of the mobile device that received the payload.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2014
From: DESAI, NITIN
To: CITRIX SYSTEMS, INC.
Reel/Frame 032885/0158 →
Continuity (1)
Related Publication 20150169893A1 · Jun 18, 2015