IP Library Granted Patent US 11,294,865
Granted Patent B2
US 11,294,865 · App. 16/101,841 · Granted Apr 5, 2022

Using a scan data ledger for distributed security analysis of shared content

Inventors: Ramanjaneya Reddy Kamalapuram (Bangalore, IN); Praveen Raja Dhanabalan (Bangalore, IN)
Assignee: Citrix Systems, Inc.
G06F16/176G06F16/122G06F16/182G06F21/44G06F21/6218H04L9/0637H04L67/1097G06F2221/2141H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,294,865
App. No.
16/101,841
Granted
Apr 5, 2022
Kind
B2
Abstract

Methods and systems for providing a cost effective and robust security solution for shared files stored by file sharing software solutions are described herein. The methods and systems for generating a ledger associated with shared files, which may include scanning data received from applications associated with a number of client devices and from a cloud based scanner. An access manager may control file permissions granted to users based on requests for scan data from each user device requesting access to a shared file. A plurality of different scanning applications may provide data that is collected for each shared file to provide a diverse analysis of a shared file to increase user confidence in a file security status.

Claims (72)

1. A method comprising:

storing, in a network storage system, a shared file received from a first user device;

receiving, by the network storage system and from the first user device, scan data associated with the shared file, wherein the scan data indicates results of a security scan of the shared file;

generating, by the network storage system, a ledger associated with the shared file, wherein the ledger comprises the scan data associated with the shared file on the network storage system;

receiving, at the network storage system, scan data from one or more additional user devices;

determining, by the network storage system, that the shared file is a valid file to share with users of the network storage system based on the scan data from one or more of the first user device and the one or more additional user devices, wherein determining that the shared file is a valid file comprises determining that there are no pre-identified issues associated with the shared file;

updating, by the network storage system and in response to the receipt of scan data from the one or more additional user devices, the ledger of the shared file in the network storage system;

weighting, by the network storage system, the scan data based on a type of scanner;

determining, based on the weighted scan data, a confidence value of the shared file;

determining that the confidence value exceeds a confidence threshold; and

providing, by the network storage system, based on the determining that the shared file is a valid file to share with the users of the network storage system, and based on the determination that the confidence value exceeds the confidence threshold, permission to access the shared file to the one or more additional user devices.

2. The method of claim 1 , further comprising:

sending, from the network storage system and to the one or more additional user devices, a request for a scanner credential from the one or more additional user devices;

receiving, at the network storage system, the scanner credential from the one or more additional user devices; and

authenticating, by the network storage system, an additional user device scanner based on the scanner credential received from the one or more additional user devices.

3. The method of claim 1 , wherein the determining that the shared file is a valid file to share with users of the network storage system based on the scan data from one or more of the first user device and the one or more additional user devices comprises:

receiving, from one or more of the first user device and the one or more additional user devices, scan data;

analyzing the scan data for an indicator that the shared file includes one or more of signatures of known exploits, malware, or viruses; and

determining that shared file is valid based on the indicator of the scan data.

4. The method of claim 1 , further comprising:

obtaining, by the network storage system, policy information associated with the shared file; and

preventing, based on the policy information associated with the shared file, write access to the shared file until policy conditions have been met.

5. The method of claim 1 , wherein the generating the ledger associated with the shared file comprises generating a blockchain associated with the shared file.

6. The method of claim 5 , wherein updating the ledger of the shared file comprises adding to the blockchain based on scan data of the one or more additional user devices and a hash related to scan data of at least one of the first user device or the network storage system.

7. The method of claim 1 , wherein the network storage system comprises a cloud network storage system, and wherein the ledger is stored in the same cloud network storage system as the shared file.

8. The method of claim 1 , further comprising:

scanning, by the network storage system, the shared file with a security application to generate the scan data; and

associating, by the network storage system, the scan data with the ledger of the shared file.

9. The method of claim 1 , wherein the scan data comprises scanner type data indicating the type of scanner and scanner update data indicating any updates the scanner has applied.

10. An apparatus, comprising:

at least one processor; and

memory storing executable instructions configured to, when executed by the at least one processor, cause the apparatus to:

store a shared file in a network storage system;

request, from a first user device, scan data associated with the shared file, wherein the scan data indicates results of a security scan of the shared file;

generate a ledger associated with the shared file, wherein the ledger comprises the scan data associated with the shared file;

receive a request from a second user device to access the shared file stored on the network storage system;

in response to receiving the request to access the shared file, request scan data from the second user device;

update, based on a response to the request for scan data from the second user device, the ledger of the shared file in the network storage system;

weight the scan data based on a type of scanner;

determine, based on the weighted scan data, a confidence value of the shared file;

determine that the confidence value exceeds a confidence threshold; and

transmit, based on a determination that the confidence value exceeds the confidence threshold, write permission for the shared file to the second user device.

11. The apparatus of claim 10 , wherein the apparatus is further configured to:

receive, from a third user device, a second request to access the shared file stored on the network storage system;

in response to receiving the second request to access the shared file, request scan data from the third user device; and

update, based on a response to the requesting scan data from the third user device, the ledger of the shared file in the network storage system.

12. The apparatus of claim 10 , wherein the apparatus is further configured to: obtain policy information associated with the shared file; and

prevent, based on the policy information associated with the shared file, write access to the shared file until policy conditions have been met.

13. The apparatus of claim 10 , wherein the apparatus is further configured to:

scan the shared file with a security application of a cloud storage system to generate the scan data; and

associate the scan data with the ledger of the shared file.

14. The apparatus of claim 10 , wherein the confidence value indicates a likelihood that the shared file is corrupted.

15. The apparatus of claim 10 , wherein the scan data comprises scanner type data indicating the type of scanner and scanner update data indicating any updates the scanner has applied.

16. One or more non-transitory computer-readable media storing instructions configured to, when executed, cause a computing device to:

store a shared file in a network storage system;

request, from a first user device, scan data associated with the shared file, wherein the scan data indicates results of a security scan of the shared file;

generate a ledger associated with the shared file, wherein the ledger comprises the scan data associated with the shared file;

receive a request from a second user device to access the shared file stored on the network storage system;

in response to receiving the request to access the shared file, request scan data from the second user device;

update, based on a response to the request for scan data from the second user device, the ledger of the shared file in the network storage system;

weight the scan data based on a type of scanner;

determine, based on the weighted scan data, a confidence value of the shared file;

determine that the confidence value exceeds a confidence threshold; and

transmit, based on the determination that the confidence value exceeds the confidence threshold, write permission for the shared file to the second user device.

17. The one or more non-transitory computer-readable media of claim 16 , wherein the instructions are configured to, when executed, cause the computing device to:

receive, at the network storage system and from a third user device, a second request to access the shared file stored on the network storage system;

in response to receiving the second request to access the shared file, request scan data from the third user device; and

update, based on a response to the requesting scan data from the third user device, the ledger of the shared file in the network storage system.

18. The one or more non-transitory computer-readable media of claim 16 , wherein the instructions are configured to, when executed, cause the computing device to:

obtain policy information associated with the shared file; and

prevent, based on the policy information associated with the shared file, write access to the shared file until policy conditions have been met.

19. The one or more non-transitory computer-readable media of claim 16 , wherein the scan data comprises scanner type data indicating the type of scanner and scanner update data indicating any updates the scanner has applied.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2018
From: KAMALAPURAM, RAMANJANEYA REDDY; DHANABALAN, PRAVEEN RAJA
To: CITRIX SYSTEMS, INC.
Reel/Frame 047336/0202 →
Continuity (1)
Related Publication 20200050686A1 · Feb 13, 2020