IP Library › Granted Patent US 11,722,465
Granted Patent B2
US 11,722,465 · App. 16/519,243 · Granted Aug 8, 2023

Password encryption for hybrid cloud services

Inventors: Leo C. Singleton, IV (Fort Lauderdale, FL); Andy Cooper (Royston, GB)
H04L63/0435G06F21/554G06F21/6209H04L9/0827H04L63/062H04L63/08H04L63/083H04L63/0815G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,465
App. No.
16/519,243
Granted
Aug 8, 2023
Kind
B2
Abstract

Methods, systems, computer-readable media, and apparatuses may provide password encryption for hybrid cloud services. A workspace cloud connector internally residing with an entity may intercept user credentials associated with an internal application being transmitted to an external cloud service. The workspace cloud connector may generate an encryption key and encrypt the user credentials via a reversible encryption methodology. The workspace cloud connector may encrypt the encryption key using an irreversible encryption methodology (e.g., use a hashing function to produce a first hash). The workspace cloud connector may transmit the encrypted user credentials and the first hash to a virtual delivery agent via a first path (e.g., via the external cloud service). In response, the workspace cloud connector may receive an address of the virtual delivery agent and, using the address, may send the encryption key to the virtual delivery agent via a second path different from the first path.

Claims (38)

1. A method comprising:

receiving, by a computing device, from a client device, plaintext user identity credentials that authorize access to an application via a virtual delivery agent;

generating, by the computing device, a message to enable the access to the application via the virtual delivery agent, the message including a hash of an encryption key and encrypted user identity credentials generated by encrypting the plaintext user identity credentials using the encryption key; and

transmitting, by the computing device, the message to enable the client device to access the application via the virtual delivery agent.

2. The method of claim 1 , wherein the encryption key is a logon ticket.

3. The method of claim 1 , wherein receiving of the plaintext user identity credentials comprises:

receiving the plaintext user identity credentials within an unencrypted message being transmitted to the virtual delivery agent; and

intercepting the unencrypted message by preventing delivery of the unencrypted message to the virtual delivery agent.

4. The method of claim 3 , further comprising detecting that the unencrypted message contains plaintext user identity credentials, and wherein the interception of the unencrypted message is responsive to the detection.

5. The method of claim 1 , wherein the user identity credentials include one or more of a username, a password, or biometric data.

6. The method of claim 1 , wherein the computing device is a first computing device and the message is transmitted to a second computing device different from the first computing device, the second computing device configured to enable access to the application via the virtual delivery agent by a user of the client device.

7. The method of claim 1 , further comprising transmitting the encryption key to the client device to enable the client device to access the application via the virtual delivery agent.

8. An apparatus comprising:

one or more processors; and

memory storing instructions, wherein execution of the instructions by the one or more processors causes the apparatus to:

receive, from a client device, plaintext user identity credentials that authorize access to an application via a virtual delivery agent;

generate a message to enable the access to the application via the virtual delivery agent, the message including a hash of an encryption key and encrypted user identity credentials generated by encrypting the plaintext user identity credentials using the encryption key; and

transmit the message to enable the client device to access the application via the virtual delivery agent.

9. The apparatus of claim 8 , wherein the encryption key is a logon ticket.

10. The apparatus of claim 8 , wherein execution of the instructions by the one or more processors further causes the apparatus to:

receive the plaintext user identity credentials within an unencrypted message being transmitted to the virtual delivery agent; and

intercept the unencrypted message by preventing delivery of the unencrypted message to the virtual delivery agent.

11. The apparatus of claim 10 , wherein execution of the instructions by the one or more processors further causes the apparatus to detect that the unencrypted message contains plaintext user identity credentials, and wherein the interception of the unencrypted message is responsive to the detection.

12. The apparatus of claim 8 , wherein the user identity credentials include one or more of a username, a password, or biometric data.

13. The apparatus of claim 8 , wherein the apparatus is a first computing device and the message is transmitted to a second computing device different from the first computing device, the second computing device configured to enable access to the application via the virtual delivery agent by a user of the client device.

14. The apparatus of claim 8 , wherein execution of the instructions by the one or more processors further causes the apparatus to transmit the encryption key to the client device to enable the client device to access the application via the virtual delivery agent.

15. An apparatus comprising:

one or more processors; and

memory storing instructions wherein execution of the instructions by the one or more processors causes the apparatus to:

detect a message in transit to a computing device, the message being configured to provide remote access to an application and including an unencrypted credential associated with a user;

prevent delivery of the message including the unencrypted credential to the computing device;

encrypt the credential using a logon ticket as an encryption key after prevention of the delivery of the message to the computing device; and

transmit the encrypted credential to the computing device to enable the remote access to the application.

16. The apparatus of claim 15 , wherein the credential comprises one or more of a username, password, or biometric data.

17. The apparatus of claim 15 , wherein execution of the instructions, by the one or more processors, further causes the apparatus to transmit a hash of the logon ticket to the computing device.

18. The apparatus of claim 15 , wherein execution of the instructions, by the one or more processors, further causes the apparatus to transmit the logon ticket to a client device used by the user.

19. The apparatus of claim 18 , wherein the message is transmitted to the client device.

20. The apparatus of claim 15 , wherein execution of the instructions, by the one or more processors, further causes the apparatus to generate the logon ticket using one of a random or pseudo-random number generator.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2019
From: SINGLETON, LEO C., IV; COOPER, ANDY
To: CITRIX SYSTEMS, INC.
Reel/Frame 049833/0001 →
Continuity (3)
Continuation 15149707 · May 9, 2016
Provisional Application 62159320 · May 10, 2015
Related Publication 20190349341A1 · Nov 14, 2019