IP Library Granted Patent US 11,539,709
Granted Patent B2
US 11,539,709 · App. 16/725,295 · Granted Dec 27, 2022

Restricted access to sensitive content

Inventors: Hari Bhaskar S (Bangalore, IN); Deepak Sharma (Bengaluru, IN); Arvind SankaraSubramanian (Bangalore, IN); Madhura Keshava Ummettuguli (Bengaluru, IN)
Assignee: Citrix Systems, Inc.
H04L63/105G06F9/541G06F16/3347G06N5/04G06N20/00H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,709
App. No.
16/725,295
Granted
Dec 27, 2022
Kind
B2
Abstract

In one aspect, the present disclosure relates to a method including: receiving, by a client device, a request to access content stored on a remote server; determining, by the client device, that the requested content includes sensitive information based on a user profile associated with the client device; modifying, by the client device, the requested content in response to the determination that the content includes sensitive information; and providing, by client device, access to the modified content in place of the requested content that includes the sensitive information.

Claims (55)

1. A method comprising:

detecting, by a client device, a request to access content located on a remote server;

determining, by the client device, that the requested content includes sensitive information based on a profile associated with the client device and a context in which the content is being accessed, comprising:

extracting text from the requested content;

generating one or more feature vectors based on the extracted text; and

using the one or more feature vectors and one or more trained models to detect the sensitive information of the requested content, wherein a training of the one or more models comprise:

receiving a training dataset comprising one or more sensitive documents and one or more non-sensitive documents;

for individual documents in the training dataset, extracting tokens from text of the document, performing a Term Frequency-Inverse Document Frequency (TF-IDF) calculation using the tokens, and generating feature vectors based on the TF-IDF calculation; and

using the feature vectors generated for individual documents in the training dataset to generate the one or more trained models;

modifying, by the client device, the requested content in response to the determination that the content includes sensitive information; and

providing, by client device, access to the modified content in place of the requested content that includes the sensitive information.

2. The method of claim 1 , wherein the determination that the requested content includes sensitive information is further based on metadata associated with the content.

3. The method of claim 1 , wherein the determination that the requested content includes sensitive information further includes analysis of the requested content using the one or more trained models selected based on the user profile.

4. The method of claim 3 , further including selecting the one or more trained models based on attributes of an organization with which the requested content is associated.

5. The method of claim 1 , wherein the extraction of the text from the requested content includes using Optical Character Recognition (OCR) to extract the text.

6. The method of claim 1 , wherein the detection of the access to the requested content located on the remote server and the determination the requested content includes sensitive information is performed by a browser application of the client device.

7. The method of claim 6 , wherein the requested content is located within a Software-as-a-Service (SaaS) application.

8. The method of claim 1 , wherein the modification of the requested content includes a change to a document using an application programming interface (API), and the API being selected based on a file type of the content.

9. The method of claim 1 , wherein the request to access the content includes a request to upload, download, share, copy, or paste the content.

10. The method of claim 1 , wherein the performing of the TF-IDF calculation using the tokens comprises:

calculating a Document Frequency (DF) value for each of the tokens; and

determining which of the tokens to include in the feature vectors for the individual documents in the training dataset based on the calculated DF value for each of the tokens.

11. A device comprising:

a memory; and

a processor coupled to the memory and configured to:

access content of an application, the content including sensitive information, and the application being executable on a remote computing device;

detect the sensitive information of the content based on at least one of a user profile and a context in which the content is being accessed, comprising:

extract text from the requested content;

generate one or more feature vectors based on the extracted text; and

using the one or more feature vectors and one or more trained models to detect the sensitive information of the requested content, wherein a training of the one or more models comprise:

receive a training dataset comprising one or more sensitive documents and one or more non-sensitive documents;

for individual documents in the training dataset, extract tokens from text of the document, perform a Term Frequency-Inverse Document Frequency (TF-IDF) calculation using the tokens, and generate feature vectors based on the TF-IDF calculation; and

using the feature vectors generated for individual documents in the training dataset to generate the one or more trained models; and

modify the content in response to detection of the sensitive information, the modification enabling the computing device to replicate security controls applicable to local users of the application.

12. The device of claim 11 , wherein the processor is configured to detect the sensitive information of the content further based on metadata associated with the content.

13. The device of claim 11 , wherein the processor is configured to detect the sensitive information of the content by analyzing the content using the one or more trained models selected based on at least one of the user profile and the context in which the content is being accessed.

14. The device of claim 13 , wherein the processor is configured to select the one or more trained models based on attributes of an organization with which the content is associated.

15. The device of claim 11 , wherein the processor is configured to use Optical Character Recognition (OCR) to extract the text.

16. The device of claim 11 , further including a browser application that, when executed by the processor, is operable to detect the sensitive information of the content and to modify the content in response to detection of the sensitive information.

17. The device of claim 16 wherein the application is a Software-as-a-Service (SaaS) application.

18. The device of claim 11 , wherein the processor is configured to:

calculate a Document Frequency (DF) value for each of the tokens; and

determine which of the tokens to include in the feature vectors for the individual documents in the training dataset based on the calculated DF value for each of the tokens.

19. A method comprising:

detecting, by a gateway device, a request to access content stored on a remote server, the request being associated with a client device;

determining, by the gateway device, that the requested content includes sensitive information based on a user profile associated with the client device, comprising:

extracting text from the requested content;

generating one or more feature vectors based on the extracted text; and

using the one or more feature vectors and one or more trained models to detect the sensitive information of the requested content, wherein a training of the one or more models comprise:

receiving a training dataset comprising one or more sensitive documents and one or more non-sensitive documents;

for individual documents in the training dataset, extracting tokens from text of the document, performing a Term Frequency-Inverse Document Frequency (TF-IDF) calculation using the tokens, and generating feature vectors based on the TF-IDF calculation; and

using the feature vectors generated for individual documents in the training dataset to generate the one or more trained models;

modifying, by the gateway device, the requested content in response to the determination that the content includes sensitive information; and

providing, by gateway device, access to the modified content in place of the requested content that includes the sensitive information.

20. The method of claim 19 , wherein the determination that the requested content includes sensitive information further includes analysis of the requested content using the one or more trained models selected based on the user profile associated with the client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2019
From: BHASKAR S, HARI; SHARMA, DEEPAK; SANKARASUBRAMANIAN, ARVIND; UMMETTUGULI, MADHURA KESHAVA
To: CITRIX SYSTEMS, INC.
Reel/Frame 051385/0083 →
Continuity (1)
Related Publication 20210194888A1 · Jun 24, 2021
Cited By (1)
US 12,282,575