IP Library Granted Patent US 11,336,645
Granted Patent B2
US 11,336,645 · App. 16/156,256 · Granted May 17, 2022

Computing system providing SaaS application access with different capabilities based upon user personas

Inventors: Jeroen Van Rotterdam (Fort Lauderdale, FL); Georgy Momchilov (Fort Lauderdale, FL)
Assignee: CITRIX SYSTEMS, INC.
H04L63/0876H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,645
App. No.
16/156,256
Granted
May 17, 2022
Kind
B2
Abstract

A computing system may include at least one client computing device and a server configured to authenticate the at least one client computing device based upon a user account, with the user account having an enterprise persona and a private persona associated therewith. The server may be further configured to determine whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device. When the enterprise persona is active, the server may provide access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and when the private persona is active, the server may provide access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities.

Claims (37)

1. A computing system comprising:

at least one client computing device; and

a server configured to

log the at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith, and

while the at least one client computing device is logged into the user account,

determine whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,

when the enterprise persona is active, provide the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and

when the private persona is active, provide the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;

wherein the first set of capabilities includes access to data from other user accounts, and the second set of capabilities includes access only to data from the user's respective account.

2. The computing system of claim 1 wherein the server determines whether the enterprise persona or the private persona is active based upon a location of the client computing device.

3. The computing system of claim 1 wherein the server determines whether the enterprise persona or the private persona is active based upon a type of data to be accessed by the at least one client computing device.

4. The computing system of claim 1 wherein the first and second sets of capabilities are associated with different respective data loss prevention (DLP) access levels.

5. The computing system of claim 1 wherein the server provides access to a first instance of the SaaS application with a first set of capabilities enabled for the enterprise persona, and provides access to a second instance of the SaaS application with the second set of capabilities enabled for the private persona.

6. The computing system of claim 5 wherein the server is further configured to migrate between the first and second instances of the SaaS application while the at least one client computing device remains authenticated based upon a change in the context.

7. The computing system of claim 1 wherein the first set of capabilities includes data recording, and the second set of capabilities does not include data recording.

8. A method for using a server comprising:

logging at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith; and

while the at least one client computing device is logged into the user account,

determining whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,

when the enterprise persona is active, providing the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and

when the private persona is active, providing the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;

wherein the first set of capabilities includes access to data from other user accounts, and the second set of capabilities includes access only to data from the user's respective account.

9. The method of claim 8 wherein the first and second sets of capabilities are associated with different respective data loss prevention (DLP) access levels.

10. The method of claim 8 wherein determining comprises determining whether the enterprise persona or the private persona is active based upon a location of the client computing device.

11. The method of claim 8 wherein determining comprises determining whether the enterprise persona or the private persona is active based upon a type of data to be accessed by the at least one client computing device.

12. The method of claim 8 wherein the first set of capabilities includes data recording, and the second set of capabilities does not include data recording.

13. The method of claim 8 wherein providing access to the SaaS application further comprises providing access to a first instance of the SaaS application with a first set of capabilities enabled for the enterprise persona, and providing access to a second instance of the SaaS application with the second set of capabilities enabled for the private persona.

14. The method of claim 13 further comprising migrating between the first and second instances of the SaaS application while the at least one client computing device remains authenticated based upon a change in the context.

15. A non-transitory computer-readable medium having computer-executable instructions for causing a server to perform steps comprising:

logging at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith; and

while the at least one client computing device is logged into the user account,

determining whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,

when the enterprise persona is active, providing the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and

when the private persona is active, providing the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;

wherein the first set of capabilities includes access to data from other user accounts, and the second set of capabilities includes access only to data from the user's respective account.

16. The non-transitory computer-readable medium of claim 15 wherein the first and second set of capabilities are associated with different respective data loss prevention (DLP) access levels.

17. The non-transitory computer-readable medium of claim 15 wherein determining comprises determining whether the enterprise persona or the private persona is active based upon a location of the client computing device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2018
From: VAN ROTTERDAM, JEROEN; MOMCHILOV, GEORGY
To: CITRIX SYSTEMS, INC.
Reel/Frame 047124/0170 →
Continuity (1)
Related Publication 20200120092A1 · Apr 16, 2020