IP Library Granted Patent US 9,843,572
Granted Patent B2
US 9,843,572 · App. 14/753,889 · Granted Dec 12, 2017

Distributing an authentication key to an application installation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,843,572
App. No.
14/753,889
Granted
Dec 12, 2017
Kind
B2
Abstract

Disclosed are various examples for facilitating distribution of an authentication code to installation of managed applications. An identity certificate is sent to a device by installing a configuration profile on the client device. The configuration profile includes the identity certificate. A management service can also initiate installation of a managed application. The identity certificate can be used to authenticate the client device so that an authentication key can be provided to the managed application.

Claims (52)

1. A non-transitory computer-readable medium embodying a program executable in a computing device, the program, when executed by the computing device, being configured to cause the computing device to at least:

transmit an identity certificate to a client device, the identity certificate uniquely associated with a user account and specifying which applications installed on the client device have permission to access the identity certificate, the identity certificate further being installed as a certificate profile by an operating system executed by the client device;

initiate an installation of an instance of an application on the client device;

receive a request to access content from the instance of the application;

transmit a request for the identity certificate to the client device, wherein the request is intercepted by the operating system executed by the client device;

receive the identity certificate from the client device;

validate an identity of the user account based upon whether the identity certificate received from the client device matches the identity certificate transmitted to the client device without first requiring comparison of a username or a password corresponding to a user;

generate an authentication key in response to validation of the identity of the user account, the authentication key being associated with the instance of the application; and

transmit the authentication key to the client device to be stored in access-restricted storage such that access by other applications on the client device is prohibited by the operating system, wherein the instance of the application provides the authentication key to authenticate the application for access to a network resource without first requiring comparison of the username or the password corresponding to the user.

2. The non-transitory computer-readable medium of claim 1 , wherein the authentication key comprises at least one of a keyed-hash message authentication code (HMAC) or a session token that is associated with the instance of the application.

3. The non-transitory computer-readable medium of claim 1 , wherein the authentication key is transmitted to the instance of the application executed by the client device.

4. The non-transitory computer-readable medium of claim 1 , wherein the request for the identity certificate comprises a hypertext transfer protocol (HTTP) response with status code 401 .

5. The non-transitory computer-readable medium of claim 1 , wherein the request for the identity certificate is generated in response to a determination that the instance of the application is not associated with the authentication key, wherein the authentication key is associated with the user account in a data store accessible to the computing device.

6. The non-transitory computer-readable medium of claim 1 , the program further being configured to cause the computing device to at least:

receive a request for access to content from the client device; and

authenticate the client device based upon whether the request for access to content from the client device contains the authentication key.

7. The non-transitory computer-readable medium of claim 1 , the program further being configured to cause the computing device to at least revoke the authentication key by disassociating the instance of the application from the authentication key in a data store accessible to the computing device.

8. A system, comprising:

at least one computing device comprising one or more processors and memory; and

a management service executable by the at least one computing device, the management service configured to cause the at least one computing device to at least:

transmit an identity certificate to a client device, the identity certificate uniquely associated with a user account and specifying which applications installed on the client device have permission to access the identity certificate, the identity certificate further being installed as a certificate profile by an operating system executed by the client device;

initiate an installation of an instance of an application on the client device;

receive a request to access content from the instance of the application;

transmit a request for the identity certificate to the client device, wherein the request is intercepted by the operating system executed by the client device;

receive the identity certificate from the client device;

validate an identity of the user account based upon whether the identity certificate received from the client device matches the identity certificate transmitted to the client device without first requiring comparison of a username or a password corresponding to a user;

generate an authentication key in response to validation of the identity of the user account, the authentication key being associated with the instance of the application; and

transmit the authentication key to the client device to be stored in access-restricted storage such that access by other applications on the client device is prohibited by the operating system, wherein the instance of the application provides the authentication key to authenticate the application for access to a network resource without first requiring comparison of the username or the password corresponding to the user.

9. The system of claim 8 , wherein the authentication key comprises at least one of a keyed-hash message authentication code (HMAC) or a session token that is associated with the instance of the application.

10. The system of claim 8 , wherein the authentication key is transmitted to the instance of the application executed by the client device.

11. The system of claim 8 , wherein the request for the identity certificate comprises a hypertext transfer protocol (HTTP) response with status code 401 .

12. The system of claim 8 , wherein the request for the identity certificate is generated in response to a determination that the instance of the application is not associated with the authentication key, wherein the authentication key is associated with the user account in a data store accessible to the at least one computing device.

13. The system of claim 8 , wherein the management service is further configured to:

receive a request for access to content from the client device; and

authenticate the client device based upon whether the request for access to content from the client device contains the authentication key.

14. The system of claim 8 , wherein the management service is further configured to cause the at least one computing device to at least revoke the authentication key by disassociating the instance of the application from the authentication key in a data store accessible to the at least one computing device.

15. A method, comprising:

transmitting an identity certificate to a client device, the identity certificate uniquely associated with a user account and specifying which applications installed on the client device have permission to access the identity certificate, the identity certificate further being installed as a certificate profile by an operating system executed by the client device;

initiating an installation of an instance of an application on the client device;

receiving a request to access content from the instance of the application;

transmitting a request for the identity certificate to the client device, wherein the request is intercepted by the operating system executed by the client device;

receiving the identity certificate from the client device;

validating an identity of the user account based upon whether the identity certificate received from the client device matches the identity certificate transmitted to the client device without first requiring comparison of a username or a password corresponding to a user;

generating an authentication key in response to validation of the identity of the user account, the authentication key being associated with the instance of the application; and

transmitting the authentication key to the client device to be stored in access-restricted storage such that access by other applications on the client device is prohibited by the operating system, wherein the instance of the application provides the authentication key to authenticate the application for access to a network resource without first requiring comparison of the username or the password corresponding to the user.

16. The method of claim 15 , wherein the authentication key comprises at least one of a keyed-hash message authentication (HMAC) code or a session token that is associated with the instance of the application.

17. The method of claim 15 , wherein the authentication key is transmitted to the instance of the application executed by the client device.

18. The method of claim 15 , wherein the request for the identity certificate is generated in response to a determination that the instance of the application is not associated with the authentication key, wherein the authentication key is associated with the user account.

19. The method of claim 15 , further comprising:

receiving a request for access to content from the client device; and

authenticating the client device based upon whether the request for access to content from the client device contains the authentication key.

20. The method of claim 15 , further comprising revoking the authentication key by disassociating the instance of the application from the authentication key in a data store.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2016
From: RYKOWSKI, ADAM STEPHEN
To: AIRWATCH LLC
Reel/Frame 039018/0081 →