IP Library Granted Patent US 11,283,785
Granted Patent B2
US 11,283,785 · App. 16/580,250 · Granted Mar 22, 2022

Systems and methods for credential control among a plurality of client devices

Inventors: Yedong Yu (Nanjing, CN); Hanyi Li (Nanjing, CN); Qiaofei Zhu (Nanjing, CN)
Assignee: Citrix Systems, Inc.
H04L63/08H04L41/046H04L67/24H04L67/306H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,785
App. No.
16/580,250
Granted
Mar 22, 2022
Kind
B2
Abstract

Disclosed herein includes a system, a method, and a device for credential control among a plurality of client devices. A server can receive a modification to a credential for an identifier associated with a user of an application accessed via a first client device. The credential can be used for authenticating to the application by the user. The server can store the modification to the credential to a login history for the user. The login history can identify client devices and one or more applications accessed via the client devices by the user using the credential. The server can identify, using the login history, client devices through which applications are accessed by the user using the credential. The server can communicate the modification to the credential to the client devices to indicate to the user to update the credential using the modified credential on each of the client devices.

Claims (59)

1. A method for credential control among a plurality of client devices, the method comprising:

receiving, by a server, a modification to a credential for an identifier associated with a user of an application accessed via a first client device, the credential modified by the user and used for authenticating the user to access the application of one or more applications accessed by the user across a plurality of client devices;

storing, by the server, the modification to the credential to a login history for the user, the login history identifying the plurality of client devices and one or more applications accessed via the plurality of client devices by the user using the credential;

identifying, by the server using the login history, one or more client devices of the plurality of client devices through which the application of the one or more applications is accessed by the user using the credential; and

communicating, by the server responsive to receiving the modification of the credential and identifying the one or more client devices using the login history, the modification to the credential to the one or more client devices to indicate to the user to update the credential using the modified credential on each of the one or more client devices to reduce or prevent occurrences of the user being locked out from accessing the application responsive to the user modifying the credential.

2. The method of claim 1 , comprising:

generating, by the server, a listing to map the one or more applications accessed by the user using the credential to respective ones of the plurality of client devices according to a login event at the respective ones of the plurality of client devices using the credential.

3. The method of claim 1 , comprising:

receiving, by the server via an agent executing on the first client device, a selection indicating at least one application of the one or more applications to communicate the modification to the credential for the at least one application via at least one client device of the plurality of client devices.

4. The method of claim 1 , comprising:

receiving, by the server via an agent executing on the first client device, an indication that the credential was updated for at least one application executing on the first client device.

5. The method of claim 1 , comprising:

updating, by the server, the login history for the user to indicate the credential was updated to include the modification for at least one application executing on the first client device.

6. The method of claim 1 , comprising:

determining, by the server, that the modification to the credential was unsuccessful at the first client device for at least one application of the one or more applications accessed by the user; and

providing, by the server to an agent executing on the first client device, an instruction to update the credential at the first client device for the at least one application of the one or more applications accessed by the user.

7. The method of claim 1 , comprising:

generating, by the server, a listing that includes a status for the plurality of client devices and the one or more applications accessed by the user across the plurality of client devices, the status indicative of the modification to the credential being received at respective ones of the plurality of client devices and the one or more applications.

8. The method of claim 1 , comprising:

updating, by the server, the credential to include the modification at the one or more client devices associated with the user and connected to the server.

9. The method of claim 1 , comprising:

detecting, by the server, a first group of client devices of the plurality of client devices associated with the user are offline; and

updating, by the server, the credential to include the modification at the first group of client devices of the one or more client devices responsive to a status of respective ones of the first group of client devices changing from offline to online.

10. A method for credential control, the method comprising:

receiving, by an agent executing on a first client device, a modification of a first credential made by a user to change the first credential to a second credential for an identifier associated with the user of the first client device;

providing, by the agent to the user via the first client device, a listing identifying a plurality of applications accessed by the user using the first credential and accessible via the first client device;

receiving, by the agent, a selection of one or more applications of the plurality of applications from the listing; and

changing, by the agent responsive to receiving the modification of the first credential and the selection of one or more applications from the listing, the first credential to the second credential for the selected one or more applications of the plurality of applications at the first client device to reduce or prevent occurrences of the user being locked out from accessing the selected one or more applications responsive to the user modifying the first credential.

11. The method of claim 10 , comprising:

providing, by the agent to the user of the first client device, the listing identifying a plurality of client devices associated with the user and accessed using the first credential; and

providing, by the agent to a server, a selection of one or more client devices of the plurality of client devices to update the first credential to the second credential at the one or more client devices.

12. The method of claim 10 , comprising:

transmitting, by the agent to a server, a request for a login history for the user and associated with the first credential, the login history including the plurality of applications accessed by the user using the first credential within a determined time period and a plurality of client devices associated with the user and accessed using the first credential with the determined time period.

13. The method of claim 10 , comprising:

encrypting, by the agent, the second credential; and

transmitting, by the agent to a server, the encrypted second credential to be stored in a user profile for the user at a database of the server.

14. The method of claim 10 , comprising:

determining, by the agent, if the first credential was updated to the second credential at the selected one or more applications of the plurality of applications at the first client device; and

providing, by the agent to a server, an indication that the first credential was updated the second credential at respective ones of the selected one or more applications of the plurality of applications at the first client device.

15. The method of claim 10 , comprising:

determining, by the agent, that the first credential did not update to the second credential at the selected one or more applications of the plurality of applications at the first client device; and

receiving, by the agent from a server, an instruction to manually update the first credential to the second credential for respective ones of the selected one or more applications of the plurality of applications at the first client device.

16. A system for credential control, the system comprising:

a server having one or more processors coupled to a memory, the one or more processors configured to:

receive a modification to a credential for an identifier associated with a user of an application accessed via a first client device, the credential modified by the user and used for authenticating the user to access the application of one or more applications accessed by the user across a plurality of client devices;

store the modification to the credential to a login history for the user, the login history identifying the plurality of client devices and one or more applications accessed via the plurality of client devices by the user using the credential;

identify, using the login history, one or more client devices of the plurality of client devices through which the application of the one or more applications is accessed by the user using the credential; and

communicate, responsive to receipt of the modification of the credential and identification of the one or more client device using the login history, the modification to the credential to the one or more client devices to indicate to the user to update the credential using the modified credential on each of the one or more client devices to reduce or prevent occurrences of the user being locked out from accessing the application responsive to the user modifying the credential.

17. The system of claim 16 , wherein the one or more processors are configured to:

generate a listing to map the one or more applications accessed by the user using the credential to respective ones of the plurality of client devices according to a login event at the respective ones of the plurality of client devices using the credential.

18. The system of claim 16 , wherein the one or more processors are configured to:

receive, via an agent executing on the first client device, an indication that the credential was updated for at least one application executing on the first client device; and

update the login history for the user to indicate the credential was updated to include the modification for the at least one application executing on the first client device.

19. The system of claim 16 , wherein the one or more processors are configured to:

determine that the modification to the credential was unsuccessful at the first client device for at least one application of the one or more applications accessed by the user; and

provide, to an agent executing on the first client device, an instruction to update the credential at the first client device for the at least one application of the one or more applications accessed by the user.

20. The system of claim 16 , wherein the one or more processors are configured to:

detect a first group of client devices of the plurality of client devices associated with the user are offline; and

update the credential to include the modification at the first group of client devices of the one or more client devices responsive to a status of respective ones of the first group of client devices changing from offline to online.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2019
From: YU, YEDONG; LI, HANYI; ZHU, QIAOFEI
To: CITRIX SYSTEMS, INC.
Reel/Frame 050475/0304 →
Continuity (1)
Related Publication 20210092105A1 · Mar 25, 2021
Cited By (1)
US 12,495,026