IP Library Patent Application 14027929
Patent Application
App. No. 14/027,929

Providing Virtualized Private Network tunnels

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/027,929
Abstract

Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.

Claims (46)

1 . A method, comprising:

storing, by a mobile device, a ticket in a secure container usable to store data related to a managed application being provided by the mobile device, wherein the ticket is configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the managed application to at least one resource accessible through an access gateway;

providing the managed application with access to the at least one resource based on the ticket, the VPN tunnel, and policy information that describes one or more policies for providing the managed application of the apparatus with access to the at least one resource;

determining to perform a selective wipe;

determining that the ticket is stored by the mobile device; and

deleting the ticket from the secure container.

2 . The method of claim 1 , further comprising:

storing, at the mobile device, the policy information in the secure container; and

deleting the policy information as part of a selective wipe process that deletes secured data associated with the managed application.

3 . The method of claim 2 , further comprising:

searching the secure container for the ticket based on information included in the policy information.

4 . The method of claim 1 , further comprising:

transmitting a selective wipe acknowledgement to the access gateway, wherein the acknowledgement includes a listing of tickets that were deleted during the selective wipe.

5 . The method of claim 1 , wherein determining that the ticket is stored by the mobile device includes analyzing the policy information for an identification of the ticket or a location where the ticket is stored.

6 . The method of claim 1 , wherein the VPN tunnel is a per-application policy-controlled VPN tunnel that provides only the application with access to the at least one resource.

7 . The method of claim 1 , wherein determining to perform the selective wipe is based on the managed application being switched from a managed mode of operation to an unmanaged mode of operation.

8 . The method of claim 1 , wherein determining to perform the selective wipe is based on one or more of the following: a determination that the mobile device is jailbroken or rooted, a determination that the mobile device is installed with a blacklisted application, or a determination that the mobile device is not configured with a lock screen.

9 . The method of claim 1 , wherein determining to perform the selective wipe is based on the managed application being uninstalled.

10 . An apparatus, comprising:

at least one processor; and

memory storing executable instructions configured to, when executed by the at least one processor, cause the apparatus to:

store a ticket in a secure container usable to store data related to a managed application being provided by the apparatus, wherein the ticket is configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the managed application to at least one resource accessible through an access gateway,

provide the managed application with access to the at least one resource based on the ticket, the VPN tunnel, and policy information that describes one or more policies for providing the managed application of the apparatus with access to the at least one resource,

determine to perform a selective wipe,

determine that the ticket is stored by the mobile device, and

delete the ticket from the secure container.

11 . The apparatus of claim 10 , wherein the executable instructions are configured to, when executed by the at least one processor, further cause the apparatus to:

store the policy information in the secure container; and

delete the policy information as part of a selective wipe process that deletes secured data associated with the managed application.

12 . The apparatus of claim 10 , wherein the executable instructions are configured to, when executed by the at least one processor, further cause the apparatus to search the secure container for the ticket based on information included in the policy information.

13 . The apparatus of claim 10 , wherein the executable instructions are configured to, when executed by the at least one processor, further cause the apparatus to transmit a selective wipe acknowledgement to the access gateway, wherein the acknowledgement includes a listing of tickets that were deleted during the selective wipe.

14 . The apparatus of claim 10 , wherein determining that the ticket is stored by the mobile device includes analyzing the policy information for an identification of the ticket or a location where the ticket is stored.

15 . The apparatus of claim 10 , wherein the VPN tunnel is a per-application policy-controlled VPN tunnel that provides only the application with access to the at least one enterprise resource.

16 . The method of claim 1 , wherein determining to perform the selective wipe is based on one or more of the following: the managed application being switched from a managed mode of operation to an unmanaged mode of operation, the managed application being uninstalled, a determination that the mobile device is jailbroken or rooted, a determination that the mobile device is installed with a blacklisted application, or a determination that the mobile device is not configured with a lock screen.

17 . One or more non-transitory computer-readable media storing instructions configured to, when executed, cause at least one computing device to:

store a ticket in a secure container usable to store data related to a managed application being provided by the apparatus, wherein the ticket is configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the managed application to at least one resource accessible through an access gateway;

provide the managed application with access to the at least one resource based on the ticket, the VPN tunnel, and policy information that describes one or more policies for providing the managed application of the apparatus with access to the at least one resource;

determine to perform a selective wipe;

determine that the ticket is stored by the mobile device; and

delete the ticket from the secure container.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein the instructions are configured to, when executed, further cause said at least one computing device to:

store the policy information in the secure container;

delete the policy information as part of a selective wipe process that deletes secured data associated with the managed application; and

search the secure container for the ticket based on information included in the policy information.

19 . The one or more non-transitory computer-readable media of claim 17 , wherein the instructions are configured to, when executed, further cause said at least one computing device to transmit a selective wipe acknowledgement to the access gateway, wherein the acknowledgement includes a listing of tickets that were deleted during the selective wipe.

20 . The one or more non-transitory computer-readable media of claim 17 , wherein determining that the ticket is stored by the mobile device includes analyzing the policy information for an identification of the ticket or a location where the ticket is stored.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2013
From: BARTON, GARY; LANG, ZHONGMIN; DESAI, NITIN; WALKER, JAMES
To: CITRIX SYSTEMS INC.
Reel/Frame 031217/0677 →