IP Library Granted Patent US 11,704,427
Granted Patent B2
US 11,704,427 · App. 17/728,404 · Granted Jul 18, 2023

Systems and methods for providing data loss prevention via an embedded browser

Inventors: Christopher Fleck (Fort Lauderdale, FL); Juan Rivera (Fort Lauderdale, FL)
G06F21/6218G06F9/547G06F13/20G06F16/27G06F21/602H04L67/5683H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,704,427
App. No.
17/728,404
Granted
Jul 18, 2023
Kind
B2
Abstract

Described embodiments provide systems and methods for providing data loss prevention via an embedded browser. An interprocess communication (IPC) manager may interface with an embedded browser to control the transfer of data from a first application to a second application in accordance with a policy. The IPC manager may detect a command to store data accessed on the first application via the embedded browser and store the data onto a secure container. The secure container may be dedicated to the embedded browser. The IPC manager may subsequently detect a command to retrieve data from the secure container and to replicate the data onto the second application. The IPC manager may determine a policy to apply to the data. The policy may specify whether the data from the first application is permitted to be replicated onto the second application. The IPC manager may subsequently replicate the data on the second application.

Claims (30)

1. A method comprising:

accessing, by a client device, a first application of a plurality of applications hosted on one or more remote computing devices that are accessible to the client device;

storing, by the client device in response to detecting a command from the first application to store data, the data in a container accessible by the client device;

determining, by the client device using one or more rules, access to the data stored in the container by a second application of the plurality of applications; and

determining, by the client device using the one or more rules, to modify at least a portion of the data stored in the container prior to being provided to the second application.

2. The method of claim 1 , wherein a client application of the client device accesses the first application using an embedded browser.

3. The method of claim 1 , wherein the container is a secure container that stores the data.

4. The method of claim 1 , further comprising receiving, by the client device, a request by the second application to access the data.

5. The method of claim 1 , further comprising determining, by the client device using the one or more rules, to restrict from the second application replication of the data stored in the container.

6. The method of claim 1 , further comprising determining, by the client device using the one or more rules, to permit a copy and paste operation of the data in the container to the second application.

7. A system comprising:

a client device in communication with a plurality of applications hosted on one or more remote computing devices, the client device configured to:

access a first application of the plurality of applications;

store, response to detecting a command from the first application to store data, the data in a container accessible by the client device; and

determine, using one or more rules, access to the data stored in the container by a second application of the plurality of applications;

wherein the client device is further configured to determine, using the one or more rules, to modify at least a portion of the data stored in the container prior to being provided to the second application.

8. The system of claim 7 , wherein a client application of the client device accesses the first application using an embedded browser.

9. The system of claim 7 , wherein the container is a secure container that stores the data encrypted.

10. The system of claim 7 , wherein the client device is further configured to receive a request by the second application to access the data.

11. The system of claim 7 , wherein the client device is further configured, using the one or more rules, to restrict from the second application replication of the data stored in the container.

12. The system of claim 7 , wherein the client device is further configured to determine, using the one or more rules, to permit a copy and paste operation of the data in the container to the second application.

13. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

access a first application of a plurality of applications hosted on one or more remote computing devices that are accessible to the one or more processors;

store, in response to detecting a command from the first application to store data, the data in a container accessible by the one or more processors; and

determine, using one or more rules, access to the data stored in the container by a second application of the plurality of applications.

14. The non-transitory computer-readable medium of claim 13 , wherein a client application of the one or more processors accesses the first application using an embedded browser.

15. The non-transitory computer-readable medium of claim 13 , wherein the container is a secure container that stores the data encrypted.

16. The non-transitory computer-readable medium of claim 13 , wherein the one or more processors are further configured to determine, using the one or more rules, to restrict from the second application replication of the data stored in the container.

17. The non-transitory computer-readable medium of claim 13 , wherein the one or more processors are further configured to determine, using the one or more rules, to modify at least a portion of the data stored in the container prior to being provided to the second application.

18. The non-transitory computer-readable medium of claim 13 , wherein the one or more processors are further configured to determine, using the one or more rules, to permit a copy and paste operation of the data in the container to the second application.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: FLECK, CHRISTOPHER; RIVERA, JUAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 059700/0127 →
Continuity (3)
Continuation 16402899 · May 3, 2019
Provisional Application 62667199 · May 4, 2018
Related Publication 20220245272A1 · Aug 4, 2022