IP Library Granted Patent US 9,948,610
Granted Patent B2
US 9,948,610 · App. 14/839,748 · Granted Apr 17, 2018

Method and apparatus for accessing third-party resources

Inventors: Robert Emer Broadbent (Spring, TX); Tyrone F. Pike (Woodside, CA)
Assignee: Citrix Systems, Inc.
H04L63/0281H04L63/0807H04L63/0884H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,948,610
App. No.
14/839,748
Granted
Apr 17, 2018
Kind
B2
Abstract

A method, system, and apparatus for providing a client access to third-party resources by utilizing third-party access tokens via a network gateway. The method can prevent the third-party access tokens from being exposed directly to the client environment. The client receives a gateway security credential, which encapsulates the third-party access token in an encrypted form. The client provides the gateway access token to the network gateway where the third-party access token is decrypted and then used to access the third-party resource. Client requests to the network gateway are executed using a custom API. The gateway relays the client requests to the appropriate third-party resources using the third-party-specific API with the decrypted third-party access token. Gateway access tokens are short-lived and can be renewed according to the client-environment life cycle.

Claims (46)

1. A device comprising:

one or more processors;

memory; and

a network gateway configured to:

acquire a first token from a client, the first token encrypting a second token, wherein the first token is used to access the network gateway and the second token is used to access a third-party resource provider, the network gateway granting access to the client based on at least the first token;

provide the first token to a token management service, wherein the token management service is inaccessible to the client;

decrypt the second token from the first token;

request one of a refresh or replacement of the second token from the token management service, wherein the token management service is inaccessible to the client;

receive the second token from the token management service;

access the third-party resource provider using the second token; and

grant the client access to the third-party resource provider.

2. The device of claim 1 , wherein the second token includes information associated with the client.

3. The device of claim 1 , wherein the client is included in a stateless device.

4. The device of claim 1 , wherein the client requests a particular second token based on user input.

5. The device of claim 1 , wherein the network gateway is further configured to:

relay client requests to the third-party resource provider.

6. The device of claim 1 , wherein the network gateway is further configured to:

replace the first token with the second token to provide the client with access to the third-party resource provider.

7. A method for accessing a resource provider, the method being performed by one or more processors and comprising:

acquiring a first token from a client the first token encrypting a second token, wherein the first token is used to access a network gateway and the second token is used to access a third-party resource provider, the network gateway granting access to the client based on at least the first token;

providing the first token to a token management service, wherein the token management service is inaccessible to the client;

decrypting the second token from the first token;

requesting one of a refresh or replacement of the second token from the token management service, wherein the token management service is inaccessible to the client;

receiving the second token from the token management service;

accessing the third-party resource provider using the second token; and

granting the client access to the third-party resource provider.

8. The method of claim 7 , wherein the second token includes information associated with the client.

9. The method of claim 7 , wherein the client is included in a stateless device.

10. The method of claim 7 , wherein the client requests a particular second token based on user input.

11. The method of claim 7 , further comprising: relaying client requests to the third-party resource provider.

12. The method of claim 7 , further comprising:

replacing the first token with the second token to provide the client with access to the third-party resource provider.

13. A non-transitory computer readable storage medium storing a set of instructions that are executable by at least one processor of a computer, to cause the computer to perform a method for accessing a resource provider, the method comprising:

acquiring a first token from a client, the first token encrypting a second token, wherein the first token is used to access a network gateway and the second token is used to access a third-party resource provider, the network gateway granting access to the client based on at least the first token;

providing the first token to a token management service, wherein the token management service is inaccessible to the client;

encrypting the second token from the first token;

requesting one of a refresh or replacement of the second token from the token management service, wherein the token management service is inaccessible to the client;

receiving the second token from the token management service;

accessing the third-party resource provider using the second token; and

granting the client access to the third-party resource provider.

14. The non-transitory computer readable storage medium of claim 13 , wherein the client is included in a stateless device.

15. The non-transitory computer readable storage medium of claim 13 , wherein the client requests a particular second token based on user input.

16. The non-transitory computer readable storage medium of claim 13 , wherein the method further comprises:

relaying client requests to the third-party resource provider.

17. The non-transitory computer readable storage medium of claim 13 , wherein the method further comprises:

replacing the first token with the second token to provide the client with access to the third-party resource provider.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: BROADBENT, ROBERT EMER; PIKE, TYRONE F.
To: CITRIX SYSTEMS, INC.
Reel/Frame 036487/0542 →
Continuity (2)
Provisional Application 62044043 · Aug 29, 2014
Related Publication 20160065563A1 · Mar 3, 2016