IP Library › Granted Patent US 12,670,290
Granted Patent B2
US 12,670,290 · App. 17/878,284 · Granted Jun 30, 2026

Secure storage and maintenance of potentially sensitive file downloads

Inventors: Zongpeng Qiao (Nanjing, CN); Jia Yin (Nanjing, CN); Li Qiming (Nanjing, CN); Jinming Zhao (Nanjing, CN)
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,670,290
App. No.
17/878,284
Filed
Aug 1, 2022
Granted
Jun 30, 2026
Kind
B2
Examiner
JOO, JOSHUA
Art Unit
2445
USPC
726/26
Abstract

One disclosed method involves detecting a request to download a file, via a network, to a first storage medium associated with a client device, and determining that the file is potentially sensitive. The method further involves initiating a process to download the file to a second storage medium rather than the first storage medium based at least in part on the file being potentially sensitive.

Claims (54)

1 . A method, comprising:

detecting, by a client device, a first request to download a first file, via a network, to a first storage medium associated with the client device;

determining, by the client device, that the first file is potentially sensitive, based at least in part on sensitivity criteria applied to the first request and the first file; and

based at least in part on the first file being potentially sensitive, initiating, by the client device, a process to download the first file to a second storage medium rather than the first storage medium.

2 . The method of claim 1 , wherein initiating the process to download the first file to the second storage medium comprises:

causing the client device to present a prompt requesting authorization to download the first file to the second storage medium, and the method further comprises:

determining that a user input authorizing downloading of the first file to the second storage medium has been received; and

causing, based at least in part on the receipt of the user input, the first file to be downloaded to the second storage medium rather than the first storage medium.

3 . The method of claim 1 , wherein the first file is determined to be potentially sensitive based at least in part on a web domain from which the first file is to be downloaded.

4 . The method of claim 1 , wherein the first file is determined to be potentially sensitive based at least in part on metadata associated with the first file.

5 . The method of claim 1 , wherein the first file is determined to be potentially sensitive based at least in part on content of the first file.

6 . The method of claim 1 , further comprising:

detecting a second request to download a second file, via the network, to the first storage medium associated with the client device;

determining that the second file is unlikely to be sensitive; and

based at least in part on the second file being unlikely to be sensitive, initiating a process to download the second file to the first storage medium.

7 . The method of claim 6 , further comprising:

downloading the second file to the first storage medium;

determining that an amount of time that has elapsed since the second file on the first storage medium has been accessed exceeds a threshold; and

based at least in part on the amount of time exceeding the threshold, causing the client device to present a first prompt.

8 . The method of claim 1 , wherein initiating the process to download the first file to the second storage medium further comprises:

sending a hyperlink to a remote application that is configured to use the hyperlink to download the first file to the second storage medium.

9 . The method of claim 8 , wherein the remote application is further configured to use access credentials associated with a user of the client device to authenticate to the second storage medium to enable secure storage of the first file in the second storage medium.

10 . A computing system of a client device, the computing system comprising:

at least one processor; and

at least one computer-readable medium encoded with instructions which, when executed by the at least one processor, cause the computing system to:

detect a first request to download a first file, via a network, to a first storage medium associated with the client device;

determine that the first file is potentially sensitive, based at least in part on sensitivity criteria applied to the first request and the first file; and

based at least in part on the first file being potentially sensitive, initiate a process to download the first file to a second storage medium rather than the first storage medium.

11 . The computing system of claim 10 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the computing system to cause the computing system to initiate the process to download the first file to the second storage medium at least in part by:

causing the client device to present a prompt requesting authorization to download the first file to the second storage medium;

determining that a user input authorizing downloading of the first file to the second storage medium has been received; and

causing, based at least in part on the receipt of the user input, the first file to be downloaded to the second storage medium rather than the first storage medium.

12 . The computing system of claim 10 , wherein the first file is determined to be potentially sensitive based at least in part on a web domain from which the first file is to be downloaded.

13 . The computing system of claim 10 , wherein the first file is determined to be potentially sensitive based at least in part on metadata associated with the first file.

14 . The computing system of claim 10 , wherein the first file is determined to be potentially sensitive based at least in part on content of the first file.

15 . The computing system of claim 10 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the computing system to:

detect a second request to download a second file, via the network, to the first storage medium associated with the client device;

determine that the second file is unlikely to be sensitive; and

based at least in part on the second file being unlikely to be sensitive, initiate a process to download the second file to the first storage medium.

16 . The computing system of claim 15 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the computing system to:

download the second file to the first storage medium;

determine that an amount of time that has elapsed since the second file on the first storage medium has been accessed exceeds a threshold; and

based at least in part on the amount of time exceeding the threshold, cause the client device to present a first prompt.

17 . The computing system of claim 10 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the computing system to initiate the process to download the first file to the second storage medium at least in part by:

sending a hyperlink to a remote application that is configured to use the hyperlink to download the first file to the second storage medium.

18 . The computing system of claim 17 , wherein the remote application is further configured to use access credentials associated with a user of the client device to authenticate to the second storage medium to enable secure storage of the first file in the second storage medium.

19 . At least one non-transitory computer-readable medium encoded with instructions which, when executed by at least one processor of a client device, cause the client device to:

detect a first request to download a first file, via a network, to a first storage medium associated with the client device;

determine that the first file is potentially sensitive, based at least in part on sensitivity criteria applied to the first request and the first file; and

based at least in part on the first file being potentially sensitive, initiate a process to download the first file to a second storage medium rather than the first storage medium.

20 . The at least one non-transitory computer-readable medium of claim 19 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the client device to initiate the process to download the first file to the second storage medium at least in part by:

causing the client device to present a prompt requesting authorization to download the first file to the second storage medium;

determining that a user input authorizing downloading of the first file to the second storage medium has been received; and

causing, based at least in part on the receipt of the user input, the first file to be downloaded to the second storage medium rather than the first storage medium.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2022
From: QIAO, ZONGPENG; YIN, JIA; QIMING, LI; ZHAO, JINMING
To: CITRIX SYSTEMS, INC.
Reel/Frame 060685/0225 →
Continuity (2)
Continuation PCTCN2022104856 · Jul 11, 2022
Related Publication 20240012932A1 · Jan 11, 2024
References Cited (17)
US 20100174804A1 · Sonoyama · 2010 [cited by examiner]
US 20130145085A1 · Yu · 2013 [cited by examiner]
US 20150106946A1 · Soman · 2015 [cited by examiner]
US 20150332051A1 · Ech-Chergui et al. · 2015 [cited by applicant]
US 20160357978A1 · Lin · 2016 [cited by examiner]
US 20180114033A1 · Mathur · 2018 [cited by examiner]
US 20190087596A1 · Lin · 2019 [cited by examiner]
US 20200004839A1 · Naravenekar · 2020 [cited by applicant]
US 20200145515A1 · Fleck · 2020 [cited by examiner]
US 20210194888A1 · Bhaskar S · 2021 [cited by examiner]
US 20220012070A1 · Azulay · 2022 [cited by examiner]
US 20220141281A1 · Ramamoorthy · 2022 [cited by examiner]
US 20220294831A1 · Narayanaswamy · 2022 [cited by examiner]
US 20230016018A1 · Agarwal · 2023 [cited by examiner]
CN 111241565A · 2020 [cited by applicant]
CN 111404706A · 2020 [cited by applicant]
International Search Report and Written Opinion issued Dec. 26, 2022 for International Patent Application No. PCT/CN2022/104856. [cited by applicant]