IP Library Granted Patent US 10,673,861
Granted Patent B2
US 10,673,861 · App. 16/396,354 · Granted Jun 2, 2020

Identity proxy to provide access control and single sign on

Inventors: Kumara Das Karunakaran (Milpitas, CA); Vijay Pawar (Palo Alto, CA); Jian Liu (Fremont, CA)
Assignee: MOBILE IRON, INC.
H04L63/102G06F21/33H04L63/0815H04L63/0884H04L63/10H04W12/0027H04W12/06H04L63/0272H04L63/0281H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,861
App. No.
16/396,354
Filed
Apr 26, 2019
Granted
Jun 2, 2020
Kind
B2
Art Unit
2439
USPC
726/4
Abstract

Techniques to provide secure access to a cloud-based service are disclosed. In various embodiments, a request is received from a client app on a device to connect to a security proxy associated with the cloud-based service. A secure tunnel connection between the device and a node with which the security proxy is associated is used to establish the requested connection to the security proxy. Information associated with the secure tunnel is used to determine that the requesting client app is authorized to access the cloud-based service from the device and to obtain from an identity provider associated with the cloud-based service a security token to be used by the client app to authenticate to the cloud-based service.

Claims (37)

1. A system, comprising:

a processor configured to:

receive a request associated with a first client app on a device to connect to a security proxy, wherein the first client app is associated with a first cloud-based service;

determine that a secure tunnel exists between the device and a second cloud-based service, wherein a second client app is associated with the second cloud-based service, wherein the secure tunnel was used to authenticate the second client app to the second cloud-based service;

use the existing secure tunnel to establish a connection to the security proxy and to authenticate the first client app to the first cloud-based service, wherein to authenticate the first client app to the first cloud-based service, cached user or device information associated with the second client app is used to obtain a first security token for the first cloud-based service, wherein the cached user or device information associated with the second client app was cached in connection with authenticating the second client app to access the second cloud-based service;

provide the first security token to the first client app, wherein the first client app is configured to use the first security token to gain access to the first cloud-based service;

grant access to the first cloud-based service based at least in part on an indication that a compliance posture of the device is in compliance; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the request is sent by the first client app in response to a redirect message received from the first cloud-based service.

3. The system of claim 2 , wherein the redirect message includes a URL or other locator associated with the security proxy.

4. The system of claim 1 , wherein the secure tunnel is established between the device and a tunnel server associated with the security proxy.

5. The system of claim 1 , wherein to establish the secure tunnel, the processor is configured to receive from the device a security certificate.

6. The system of claim 5 , wherein the processor is further configured to use information comprising the security certificate to determine one or more of device, app, user, and certificate information.

7. The system of claim 5 , wherein the processor is further configured to use information associated with the security certificate to determine that the first client app is authorized to access the first cloud-based service.

8. The system of claim 1 , wherein the secure proxy comprises an identity provider proxy configured to have a chained identity provider or other trust-based relationship to the identity provider associated with the second cloud-based service.

9. The system of claim 8 , wherein the processor is further configured to determine that the secure tunnel has already been established and to establish the requested connection to the identity provider proxy on behalf of the first client app without requiring any further credential to be provided.

10. The system of claim 1 , wherein the processor is further configured to provide the first security token to the first client app, wherein the security token comprises a Security Assertion Markup Language (SAML) assertion.

11. The system of claim 8 , wherein the security proxy comprises a delegated identity provider.

12. The system of claim 9 , wherein the security proxy comprises a service provider proxy.

13. The system of claim 12 , wherein the processor is configured to provide and sign the first security token as and on behalf of an identity provider proxy associated with the first cloud-based service.

14. A method, comprising:

receiving a request associated with a first client app on a device to connect to a security proxy, wherein the first client app is associated with a first cloud-based service;

determining that a secure tunnel exists between the device and a second cloud-based service, wherein a second client app is associated with the second cloud-based service, wherein the secure tunnel was used to authenticate the second client app to the second cloud-based service;

using the existing secure tunnel to establish a connection to the security proxy and to authenticate the first client app to the first cloud-based service, wherein to authenticate the first client app to the first cloud-based service, cached user or device information associated with the second client app is used to obtain a first security token for the first cloud-based service, wherein the cached user or device information associated with the second client app was cached in connection with authenticating the second client app to access the second cloud-based service;

providing the first security token to the first client app, wherein the first client app is configured to use the first security token to gain access to the first cloud-based service; and

granting access to the first cloud-based service based at least in part on an indication that a compliance posture of the device is in compliance.

15. The method of claim 14 , wherein the request is sent by the first client app in response to a redirect message received from the first cloud-based service.

16. The method of claim 15 , wherein the redirect message includes a URL or other locator associated with a security proxy.

17. The method of claim 14 , wherein a security proxy is associated with a system and the secure tunnel is established between the device and a tunnel server running on the system.

18. The method of claim 15 , wherein establishing the secure tunnel includes receiving from the device a security certificate.

19. A computer program product to provide secure access to a cloud-based service, the computer program product being embodied in a non-transitory computer readable storage device and comprising computer instructions for:

receiving a request associated with a first client app on a device to connect to a security proxy, wherein the first client app is associated with a first cloud-based service;

determining that a secure tunnel exists between the device and a second cloud-based service, wherein a second client app is associated with the second cloud-based service, wherein the secure tunnel was used to authenticate the second client app to the second cloud-based service;

using the existing secure tunnel to establish a connection to the security proxy and to authenticate the first client app to the first cloud-based service, wherein to authenticate the first client app to the first cloud-based service, cached user or device information associated with the second client app is used to obtain a first security token for the first cloud-based service, wherein the cached user or device information associated with the second client app was cached in connection with authenticating the second client app to access the second cloud-based service;

providing the first security token to the first client app, wherein the first client app is configured to use the first security token to gain access to the first cloud-based service; and

granting access to the first cloud-based service based at least in part on an indication that a compliance posture of the device is in compliance.

20. The computer program product of claim 19 , wherein the request is sent by the first client app in response to a redirect message received from the first cloud-based service.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (5)
Continuation 16141716 · Sep 25, 2018
Continuation 15962291 · Apr 25, 2018
Continuation 15006906 · Jan 26, 2016
Provisional Application 62107927 · Jan 26, 2015
Related Publication 20190319962A1 · Oct 17, 2019
Cited By (3)
US 12,393,675 US 12,413,629 US 12,445,442