IP Library › Granted Patent US 12,443,744
Granted Patent B2
US 12,443,744 · App. 17/501,500 · Granted Oct 14, 2025

Systems and methods to secure authentication data for accessing resources in a distributed manner

Inventors: Chris Pavlou (Boca Raton, FL); Daniel G. Wing (Truckee, CA)
G06F21/6245G06F21/35G06F21/45G06K19/0723H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,744
App. No.
17/501,500
Granted
Oct 14, 2025
Kind
B2
Abstract

Described embodiments provide systems and methods for securely storing private information of a user on a device of the user. A server may register a mobile device to store credentials of a user thereon, based on authentication of the user of the mobile device. The server may encrypt credentials of the user using a key of the server. The server may send the encrypted credentials to the registered mobile device for storage thereon without the key. The server may send a code to an endpoint device to initiate authentication of the user with use of the mobile device. The server may receive the encrypted credentials from the mobile device in response to the authentication. The server may decrypt the encrypted credentials using an encryption key of the server. The server may send the decrypted credentials to the endpoint device to authenticate the user at the endpoint device.

Claims (50)

1. A method comprising:

registering, by a server, a mobile device to store credentials of a user thereon, based on authentication of the user of the mobile device;

encrypting, by the server, credentials of the user using a key of the server;

sending, by the server, the encrypted credentials to the registered mobile device for storage thereon without the key;

sending, by the server responsive to a request for the credentials from an endpoint device different than the mobile device, a code to the endpoint device to initiate authentication of the user with use of the mobile device, to initiate a transfer of the encrypted credentials from the mobile device to the server;

receiving, by the server, the encrypted credentials from the mobile device in response to the authentication of the user;

decrypting, by the server, the encrypted credentials using an encryption key of the server; and

sending, by the server, the decrypted credentials to the endpoint device to authenticate the user at the endpoint device, to enable access to a remote application via the endpoint device;

wherein sending the credentials to the endpoint device comprises encrypting, by the server, the credentials using a key of the endpoint device.

2. The method of claim 1 , comprising:

receiving, by the server, a request from a computing device to register the mobile device; and

sending, by the server, a code to the computing device for registering the mobile device with the server.

3. The method of claim 2 , comprising:

causing the computing device to render the code as a quick response (QR) or scannable code, for the mobile device to scan.

4. The method of claim 1 , comprising:

sending, by the server, a prompt to the user to provide the credentials, responsive to the authentication of the user on the mobile device.

5. The method of claim 4 , comprising:

receiving, by the server, the credentials of the user from a computing device.

6. The method of claim 1 , comprising:

sending, by the server to the endpoint device, the credentials encrypted using the key of the endpoint device.

7. A method comprising:

registering, by a server, a mobile device to store credentials of a user, based on authentication of the user on the mobile device;

receiving, by the server, credentials of the user;

encrypting, by the server, the credentials using a key of the server;

sending, by the server, the encrypted credentials to the registered mobile device for storage thereon without the key;

receiving, by the server, the encrypted credentials responsive to the authentication of the user;

decrypting, by the server, the encrypted credentials to obtain the credentials, using the key of the server;

encrypting, by the server, the credentials using a key of an endpoint device; and

sending, by the server to the endpoint device, the credentials encrypted using the key of the endpoint device.

8. The method of claim 7 , comprising:

receiving, by the server, a request from a computing device to register the mobile device; and

sending, by the server, a code to the computing device for registering the mobile device with the server.

9. The method of claim 8 , comprising:

causing the computing device to render the code as a quick response (QR) or scannable code, for the mobile device to scan.

10. The method of claim 7 , comprising:

sending, by the server, a prompt to the user to provide the credentials, responsive to the authentication of the user on the mobile device.

11. The method of claim 10 , comprising:

receiving, by the server, the credentials of the user from a computing device.

12. The method of claim 7 , comprising:

receiving, by the server, a request from the endpoint device for the credentials; and

sending, by the server, a code to the endpoint device to initiate authentication of the user at the mobile device.

13. A method, comprising:

receiving, by a server, a request from an endpoint device for credentials of a user;

determining, by the server, a mobile device registered with the server for storing an encrypted version of the credentials;

sending, by the server, a code to the endpoint device to initiate authentication of the user at the mobile device, to initiate a transfer of the encrypted credentials from the mobile device to the server;

receiving, by the server from the mobile device, the encrypted version responsive to the authentication of the user;

obtaining, by the server, the credentials from the encrypted version, using an encryption key of the server; and

encrypting, by the server, the credentials using a key of the endpoint device.

14. The method of claim 13 , comprising:

sending, by the server to the endpoint device, the credentials encrypted using the key of the endpoint device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2021
From: PAVLOU, CHRIS; WING, DANIEL G.
To: CITRIX SYSTEMS, INC.
Reel/Frame 057797/0395 →
Continuity (1)
Related Publication 20230122215A1 · Apr 20, 2023
References Cited (6)
US 20150332262A1 · Lingappa · 2015 [cited by examiner]
US 20160036809A1 · Bhimanaik · 2016 [cited by examiner]
US 20170094509A1 · Mistry · 2017 [cited by examiner]
US 20220086134A1 · Xie · 2022 [cited by examiner]
US 20220408261A1 · Everson · 2022 [cited by examiner]
US 20230122215A1 · Pavlou · 2023 [cited by examiner]