Patents by Inventor David Halls

David Halls has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10798077
    Abstract: Approaches for securely authenticating untrusted operating environments. A software module intercepts a message which requires a first operating environment to authenticate itself to a service or resource provider. The software module executes outside of the first operating environment. The first operating environment lacks access to an authentication mechanism necessary to successfully authenticate to the service or resource provider. The software module notifies a second operating environment of the message. The second operating environment determines that the first operating environment should be permitted to authenticate to the service or resource provider. The second operating environment obtains authentication data generated using the authentication mechanism. The second operating environment provides the authentication data to the first operating environment to allow the first operating environment to authenticate itself to the service or resource provider.
    Type: Grant
    Filed: January 23, 2015
    Date of Patent: October 6, 2020
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Ian Pratt, David Halls
  • Patent number: 9804866
    Abstract: The methods and systems described herein provide for securing sensitive information using a hypervisor-trusted client, in a computing device executing a hypervisor hosting a control virtual machine and a non-trusted virtual machine. A user of a non-trusted virtual machine requests to establish a connection to a remote computing device. Responsive to the request, a control virtual machine launches a client agent. A graphics manager executed by the processor of the computing device assigns a secure section of a memory of a graphics processing unit of the computing device to the client agent. The graphics manager renders graphical data generated by the client agent to the secure section of the graphics processing unit memory.
    Type: Grant
    Filed: December 14, 2010
    Date of Patent: October 31, 2017
    Assignee: Citrix Systems, Inc.
    Inventors: David Halls, Rob Van Der Linden
  • Patent number: 9680873
    Abstract: Approaches for processing network requests based upon the perceived trustworthiness of the network. A software component renders a judgment, based on a policy that weighs one or more factors, about whether a network accessible to a device should be trusted. If the software component renders a judgment that the network should be trusted, then a network resource identified on a white list of trusted resources is allowed to be retrieved within a host operating system or in a first virtual machine. Conversely, if the software component renders a judgment that the network should not be trusted, then the network resource identified on the white list of trusted resources is prevented from be retrieved within the host operating system or the first virtual machine, and may instead be retrieved within a second virtual machine, which has a more restrictive set of access privileges than the first virtual machine.
    Type: Grant
    Filed: June 30, 2014
    Date of Patent: June 13, 2017
    Assignee: Bromium, Inc.
    Inventors: David Halls, Gaurav Banga, Ian Pratt, Vikram Kapoor, Xin Li
  • Patent number: 9210100
    Abstract: Methods and systems for establishing a cloud bridge between two virtual storage resources and for transmitting data from one first virtual storage resource to the other virtual storage resource. The system can include a first virtual storage resource or cloud, and a storage delivery management service that executes on a computer and within the first virtual storage resource. The storage delivery management service can receive user credentials of a user that identify a storage adapter. Upon receiving the user credentials, the storage delivery management service can invoke the storage adapter which executes an interface that identifies a second virtual storage resource and includes an interface translation file.
    Type: Grant
    Filed: October 21, 2013
    Date of Patent: December 8, 2015
    Assignee: Citrix Systems, Inc.
    Inventors: Rob Van Der Linden, David Halls, Simon Waterhouse, Peter Benoit
  • Publication number: 20140052864
    Abstract: Methods and systems for establishing a cloud bridge between two virtual storage resources and for transmitting data from one first virtual storage resource to the other virtual storage resource. The system can include a first virtual storage resource or cloud, and a storage delivery management service that executes on a computer and within the first virtual storage resource. The storage delivery management service can receive user credentials of a user that identify a storage adapter. Upon receiving the user credentials, the storage delivery management service can invoke the storage adapter which executes an interface that identifies a second virtual storage resource and includes an interface translation file.
    Type: Application
    Filed: October 21, 2013
    Publication date: February 20, 2014
    Applicant: Citrix Systems, Inc.
    Inventors: Rob Van Der Linden, David Halls, Simon Waterhouse, Peter Benoit
  • Patent number: 8621587
    Abstract: A method for facilitating distributed authentication includes the step of requesting, by a user of a client machine residing in a first domain, access to a resource residing in a second domain. The client machine authenticates the user to an intermediate machine. The intermediate machine impersonates the client machine. The intermediate machine impersonating the client machine requests access to the second domain from a domain controller residing in the second domain. The domain controller authorizes the requested access, responsive to a determination that the impersonated client machine is trusted for delegation. The domain controller transmits to an application server residing in the second domain, authentication data associated with the impersonated client machine. The application server transmits, to the intermediate machine, a launch ticket uniquely identifying a logon token. The client machine provides, to the application server, the launch ticket to access the resource residing in the second domain.
    Type: Grant
    Filed: January 12, 2012
    Date of Patent: December 31, 2013
    Assignee: Citrix Systems, Inc.
    Inventors: David Halls, Chris Mayers
  • Patent number: 8578076
    Abstract: Methods and systems for establishing a cloud bridge between two virtual storage resources and for transmitting data from one first virtual storage resource to the other virtual storage resource. The system can include a first virtual storage resource or cloud, and a storage delivery management service that executes on a computer and within the first virtual storage resource. The storage delivery management service can receive user credentials of a user that identify a storage adapter. Upon receiving the user credentials, the storage delivery management service can invoke the storage adapter which executes an interface that identifies a second virtual storage resource and includes an interface translation file.
    Type: Grant
    Filed: May 3, 2010
    Date of Patent: November 5, 2013
    Assignee: Citrix Systems, Inc.
    Inventors: Rob van der Linden, David Halls, Simon Waterhouse, Peter Benoit
  • Publication number: 20120117634
    Abstract: A method for facilitating distributed authentication includes the step of requesting, by a user of a client machine residing in a first domain, access to a resource residing in a second domain. The client machine authenticates the user to an intermediate machine. The intermediate machine impersonates the client machine. The intermediate machine impersonating the client machine requests access to the second domain from a domain controller residing in the second domain. The domain controller authorizes the requested access, responsive to a determination that the impersonated client machine is trusted for delegation. The domain controller transmits to an application server residing in the second domain, authentication data associated with the impersonated client machine. The application server transmits, to the intermediate machine, a launch ticket uniquely identifying a logon token. The client machine provides, to the application server, the launch ticket to access the resource residing in the second domain.
    Type: Application
    Filed: January 12, 2012
    Publication date: May 10, 2012
    Inventors: DAVID HALLS, Chris Mayers
  • Patent number: 8161472
    Abstract: The invention relates to a method and apparatus for regenerating portions of the page that have changed and transmitting only those portions to the client for display. Executing only the necessary parts of the page generation code and transmitting only changes to the client improves the efficiency of using the resources of the network communication channel, the client node and the server node. Performing these operations only when required, when the data has changed, improves the efficiency of use even further. The invention also takes advantage of any portions of the page that are already on the client by reusing them and thus eliminates the need to regenerate or transmit those reusable portions. In one aspect, the invention relates to a method for incorporating a partial page into a transmitted page displayed on a client.
    Type: Grant
    Filed: February 27, 2008
    Date of Patent: April 17, 2012
    Assignee: Citrix Systems, Inc.
    Inventors: Richard Hayton, David Halls
  • Patent number: 8112789
    Abstract: A method for facilitating distributed authentication includes the step of requesting, by a user of a client machine residing in a first domain, access to a resource residing in a second domain. The client machine authenticates the user to an intermediate machine. The intermediate machine impersonates the client machine. The intermediate machine impersonating the client machine requests access to the second domain from a domain controller residing in the second domain. The domain controller authorizes the requested access, responsive to a determination that the impersonated client machine is trusted for delegation. The domain controller transmits to an application server residing in the second domain, authentication data associated with the impersonated client machine. The application server transmits, to the intermediate machine, a launch ticket uniquely identifying a logon token. The client machine provides, to the application server, the launch ticket to access the resource residing in the second domain.
    Type: Grant
    Filed: October 6, 2006
    Date of Patent: February 7, 2012
    Assignee: Citrix Systems, Inc.
    Inventors: David Halls, Chris Mayers
  • Publication number: 20110141124
    Abstract: The methods and systems described herein provide for securing sensitive information using a hypervisor-trusted client, in a computing device executing a hypervisor hosting a control virtual machine and a non-trusted virtual machine. A user of a non-trusted virtual machine requests to establish a connection to a remote computing device. Responsive to the request, a control virtual machine launches a client agent. A graphics manager executed by the processor of the computing device assigns a secure section of a memory of a graphics processing unit of the computing device to the client agent. The graphics manager renders graphical data generated by the client agent to the secure section of the graphics processing unit memory.
    Type: Application
    Filed: December 14, 2010
    Publication date: June 16, 2011
    Inventors: David Halls, Rob Van Der Linden
  • Publication number: 20110022812
    Abstract: Methods and systems for establishing a cloud bridge between two virtual storage resources and for transmitting data from one first virtual storage resource to the other virtual storage resource. The system can include a first virtual storage resource or cloud, and a storage delivery management service that executes on a computer and within the first virtual storage resource. The storage delivery management service can receive user credentials of a user that identify a storage adapter. Upon receiving the user credentials, the storage delivery management service can invoke the storage adapter which executes an interface that identifies a second virtual storage resource and includes an interface translation file.
    Type: Application
    Filed: May 3, 2010
    Publication date: January 27, 2011
    Inventors: Rob van der Linden, David Halls, Simon Waterhouse, Peter Benoit
  • Publication number: 20080163193
    Abstract: The invention relates to a method and apparatus for regenerating portions of the page that have changed and transmitting only those portions to the client for display. Executing only the necessary parts of the page generation code and transmitting only changes to the client improves the efficiency of using the resources of the network communication channel, the client node and the server node. Performing these operations only when required, when the data has changed, improves the efficiency of use even further. The invention also takes advantage of any portions of the page that are already on the client by reusing them and thus eliminates the need to regenerate or transmit those reusable portions. In one aspect, the invention relates to a method for incorporating a partial page into a transmitted page displayed on a client.
    Type: Application
    Filed: February 27, 2008
    Publication date: July 3, 2008
    Inventors: Richard Hayton, David Halls
  • Patent number: 7346842
    Abstract: The invention relates to a method and apparatus for regenerating portions of the page that have changed and transmitting only those portions to the client for display. Executing only the necessary parts of the page generation code and transmitting only changes to the client improves the efficiency of using the resources of the network communication channel, the client node and the server node. Performing these operations only when required, when the data has changed, improves the efficiency of use even further. The invention also takes advantage of any portions of the page that are already on the client by reusing them and thus eliminates the need to regenerate or transmit those reusable portions. In one aspect, the invention relates to a method for incorporating a partial page into a transmitted page displayed on a client.
    Type: Grant
    Filed: November 2, 2000
    Date of Patent: March 18, 2008
    Assignee: Citrix Systems, Inc.
    Inventors: Richard Hayton, David Halls
  • Publication number: 20070107048
    Abstract: A method for facilitating distributed authentication includes the step of requesting, by a user of a client machine residing in a first domain, access to a resource residing in a second domain. The client machine authenticates the user to an intermediate machine. The intermediate machine impersonates the client machine. The intermediate machine impersonating the client machine requests access to the second domain from a domain controller residing in the second domain. The domain controller authorizes the requested access, responsive to a determination that the impersonated client machine is trusted for delegation. The domain controller transmits to an application server residing in the second domain, authentication data associated with the impersonated client machine. The application server transmits, to the intermediate machine, a launch ticket uniquely identifying a logon token. The client machine provides, to the application server, the launch ticket to access the resource residing in the second domain.
    Type: Application
    Filed: October 6, 2006
    Publication date: May 10, 2007
    Inventors: David Halls, Chris Mayers
  • Patent number: 7051084
    Abstract: The invention relates to a method and apparatus for regenerating portions of the page that have changed and transmitting only those portions to the client for display. In one aspect, the invention relates to a method for partial page regeneration of a transmitted page by a server. The method includes receiving page generation code that generates a page, transmitting the page to a client for display, associating a portion of the transmitted page with a fragment of the page generation code, and executing the associated fragment of the code to regenerate the portion of the transmitted page. In one embodiment, the method includes transmitting the regenerated page portion to the client for incorporation into the transmitted page.
    Type: Grant
    Filed: November 2, 2000
    Date of Patent: May 23, 2006
    Assignee: Citrix Systems, Inc.
    Inventors: Richard Hayton, David Halls
  • Patent number: 6766333
    Abstract: A system and method for synchronizing a user interface element displayed on a client and a software application component executing on a web server are described. The synchronizing of a user interface element and a software application component includes representing a user interface element as a user interface element component having a characteristic and providing a wiring descriptor relating the characteristic of the user interface element component with a characteristic of a software application component. The wiring descriptor associates the user interface element component with the software application component and synchronizes the characteristic of the user interface element component with the characteristic of the software application component.
    Type: Grant
    Filed: November 8, 2000
    Date of Patent: July 20, 2004
    Assignee: Citrix Systems, Inc.
    Inventors: Zhixue Wu, David Halls, Rob van der Linden