US2022086012A1PendingUtilityA1

Systems and methods providing connection lease anti-theft features for virtual computing sessions

Assignee: CITRIX SYSTEMS INCPriority: May 20, 2019Filed: Nov 30, 2021Published: Mar 17, 2022
Est. expiryMay 20, 2039(~12.8 yrs left)· nominal 20-yr term from priority
H04L 9/321H04L 9/30H04L 9/0819H04L 63/08H04L 9/3263G06F 9/452H04L 2463/082H04L 63/101H04L 63/0823H04L 67/14H04L 9/3247H04L 2463/121
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computing device may include a memory and a processor cooperating with the memory and configured to receive requests from a client device to connect with the computing device. The client device may be shared by multiple authenticated users and have a public/private encryption key pair associated therewith, and the requests may be based upon connection leases and the public key for the client device. The connection leases may also be generated for respective authenticated users and include an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users. The processor may also provide the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and prevent the use of the connection leases for authorizing connections for other authenticated users.

Claims

exact text as granted — not AI-modified
1 . A computing device comprising:
 a memory and a processor cooperating with the memory and configured to
 receive requests from a client device to connect with the computing device, the client device being shared by multiple authenticated users and having a public/private encryption key pair associated therewith, the requests based upon connection leases and the public key for the client device, and the connection leases being generated for respective authenticated users and including an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users; and 
 provide the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and prevents the use of the connection leases for authorizing connections for other authenticated users. 
   
     
     
         2 . The computing device of  claim 1  wherein the processor is further configured to, prior to authorizing connections with the client device:
 initiate a challenge to be signed by the client device with the private key associated with the client device; and 
 validate the signed response with the public key for the client device. 
 
     
     
         3 . The computing device of  claim 2  wherein the processor initiates the challenge and validates the signed response prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         4 . The computing device of  claim 2  wherein, prior to the challenge and response, the processor is further configured to validate a signature and date associated with the connection lease, and validate that the public key is valid. 
     
     
         5 . The computing device of  claim 2  wherein the processor initiates the challenge and validates the signed response after verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         6 . The computing device of  claim 1  wherein the connection lease includes a hash of the authenticated version of the public key for the client device. 
     
     
         7 . The computing device of  claim 1  wherein the public/private key pair is generated at the client device using a hardware-backed key store. 
     
     
         8 . The computing device of  claim 1  wherein the processor is further configured to drop the connection with the client device based on a failure to verify that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         9 . A method comprising:
 at a virtual delivery appliance,
 receiving requests from a client device to connect with the virtual delivery appliance, the client device being shared by multiple authenticated users, the client device having a public/private encryption key pair associated therewith, the requests based upon connection leases and the public key for the client device, and the connection leases being generated for respective authenticated users and including an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users; and 
 providing the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and preventing the use of the connection leases for authorizing connections for other authenticated users. 
   
     
     
         10 . The method of  claim 9  further comprising, prior to authorizing the connection with the client device:
 initiating a challenge from the virtual delivery appliance to be signed by the client device with the private key associated with the client device; and 
 validating at the virtual delivery appliance the signed response with the public key for the client device. 
 
     
     
         11 . The method of  claim 10  wherein initiating and validating comprise initiating the challenge and validating the signed response prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         12 . The method of  claim 10  wherein initiating and validating comprise initiating the challenge and validating the signed response after verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         13 . The method of  claim 9  wherein the public key for the client device is registered with a broker; and further comprising validating, at the virtual delivery appliance, that the public key for the client device is registered with the broker prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         14 . The method of  claim 9  wherein the connection lease includes a hash of the authenticated version of the public key for the client device. 
     
     
         15 . A method comprising:
 receiving a request at a computing device from a client device, the client device having a public/private encryption key pair associated therewith, the request being based upon a connection lease and the public key for the client device, and the connection lease including an authenticated version of the public key for the client device so that the connection lease is specific to the client device;   verifying at the computing device that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device; and   providing the client device with access to a computing session responsive to verification of the authenticated version of the public key.   
     
     
         16 . The method of  claim 15  further comprising, prior to providing the client device with access to the computing session:
 initiating a challenge from the computing device to be signed by the client device with the private key associated with the client device; and 
 validating at the computing device the signed response with the public key for the client device. 
 
     
     
         17 . The method of  claim 16  wherein initiating and validating comprise initiating the challenge and validating the signed response prior to verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         18 . The method of  claim 16  wherein initiating and validating comprise initiating the challenge and validating the signed response after verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         19 . The method of  claim 15  wherein the public key for the client device is registered with a broker; and further comprising validating, at the computing device, that the public key for the client device is registered with the broker prior to verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device. 
     
     
         20 . The method of  claim 15  wherein the connection lease includes a hash of the authenticated version of the public key for the client device.

Join the waitlist — get patent alerts

Track US2022086012A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.