IP Library Granted Patent US 11,087,008
Granted Patent B2
US 11,087,008 · App. 16/135,715 · Granted Aug 10, 2021

Systems and methods for integrating HTML based application with embedded browser

Inventors: Vipin Borkar (Bengaluru, IN); Santosh Sampath (Bengaluru, IN); Deepak Sharma (Bengaluru, IN); Arvind SankaraSubramanian (Bengaluru, IN)
Assignee: Citrix Systems, Inc.
G06F21/606G06F9/543G06F16/986G06F21/57G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,087,008
App. No.
16/135,715
Granted
Aug 10, 2021
Kind
B2
Abstract

Embodiments described include systems and methods for using an HTML-based application integrated with an embedded browser on a client device, for trusted data transfer for instance. An HTML-based application within an embedded browser of a client device can provide access to a network application and its resources. The HTML-based application can establish a secure session for the network application between a server and the HTML-based application. The embedded browser can determine that the HTML-based application is a trusted application via application of one or more policies. With the secure session established and responsive to determining that the HTML-based application is a trusted application, the embedded browser may establish at least one virtual channel between the embedded browser and the HTML-based application. Using the at least one virtual channels, the embedded browser can transfer data between the secure session of the network application and the operating system (OS) of the client device. The operating system of the client device may include a file system, a clip board, and/or input and output (I/O) devices.

Claims (30)

1. A method for trusted data transfer, the method comprising:

accessing, via an embedded browser executing on a client device, an HTML-based application of the client device, the HTML-based application configured to provide access to a network application via the embedded browser;

establishing, by the HTML-based application, a secure session for the network application between a server and the HTML-based application;

determining, by the embedded browser, that the HTML-based application is a trusted application;

establishing, by the embedded browser responsive to the determination that the HTML-based application is a trusted application, at least one virtual channel on the client device, between the embedded browser and the HTML-based application; and

transferring, by the embedded browser via the at least one virtual channel, data between the secure session and an operating system (OS) of the client device.

2. The method of claim 1 , wherein the server comprises a secure browser server configured to host a browser for accessing the network application, and to provide the HTML-based application with access to the network application.

3. The method of claim 2 , further comprising determining, by the embedded browser, that the HTML-based application is a trusted application by determining that the HTML-based application is provided or authorized by the secure browser server.

4. The method of claim 1 , further comprising determining, by the embedded browser, that the HTML-based application is a trusted application by at least one of: determining that the HTML-based application is from a trusted source, or applying at least one access control policy.

5. The method of claim 1 , further comprising establishing the at least one virtual channel responsive to determining that the network application is a permitted network application.

6. The method of claim 1 , wherein transferring the data comprises transferring the data, via a clipboard virtual channel of the at least one virtual channel, between a clipboard of the secure session and a clipboard of the OS of the client device.

7. The method of claim 1 , wherein transferring the data comprises performing, via the at least one virtual channel, a read or write access initiated through the OS of the client device to a file within the secure session.

8. The method of claim 1 , wherein transferring the data comprises performing, via the at least one virtual channel, a read or write access by the network application to a file or folder within a file system of the OS of the client device.

9. The method of claim 8 , further comprising determining, by the embedded browser via application of at least one access control policy, whether to allow the read or write access by the network application.

10. The method of claim 1 , wherein transferring the data comprises transferring the data between the secure session and an input or output (I/O) device of the client device.

11. A system for trusted data transfer, the system comprising:

an embedded browser executable on one or more processors of a client device, the embedded browser configured to:

access an HTML-based application of the client device, the HTML-based application configured to provide access to a network application via the embedded browser, the HTML-based application establishing a secure session for the network application between a server and the HTML-based application;

determine that the HTML-based application is a trusted application;

establish, responsive to the determination that the HTML-based application is a trusted application, at least one virtual channel on the client device, between the embedded browser and the HTML-based application; and

transfer, via the at least one virtual channel, data between the secure session and an operating system (OS) of the client device.

12. The system of claim 11 , wherein the server comprises a secure browser server configured to host a browser for accessing the network application, and to provide the HTML-based application with access to the network application.

13. The system of claim 12 , wherein the embedded browser is configured to determine that the HTML-based application is a trusted application by determining that the HTML-based application is provided or authorized by the secure browser server.

14. The system of claim 11 , wherein the embedded browser is configured to determine that the HTML-based application is a trusted application by at least one of: determining that the HTML-based application is from a trusted source, or applying at least one access control policy.

15. The system of claim 11 , wherein the embedded browser is configured to establish the at least one virtual channel responsive to determining that the network application is a permitted network application.

16. The system of claim 11 , wherein the embedded browser is configured to transfer the data via a clipboard virtual channel of the at least one virtual channel, between a clipboard of the secure session and a clipboard of the OS of the client device.

17. The system of claim 11 , wherein the embedded browser is configured to support, via the at least one virtual channel, a read or write access initiated through the OS of the client device to a file within the secure session.

18. The system of claim 11 , wherein the embedded browser is configured to support, via the at least one virtual channel, a read or write access by the network application to a file or folder within a file system of the OS of the client device.

19. The system of claim 18 , wherein the embedded browser is configured to determine, via application of at least one access control policy, whether to allow the read or write access by the network application.

20. The system of claim 11 , wherein the embedded browser is configured to transfer the data between the secure session and an input or output (I/O) device of the client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2018
From: BORKAR, VIPIN; SAMPATH, SANTOSH; SHARMA, DEEPAK; SANKARASUBRAMANIAN, ARVIND
To: CITRIX SYSTEMS, INC.
Reel/Frame 047383/0064 →
Continuity (1)
Related Publication 20200089898A1 · Mar 19, 2020
Cited By (5)
US 12,238,101 US 12,407,730 US 12,413,624 US 12,445,493 US 12,452,306