IP Library Granted Patent US 10,003,600
Granted Patent B2
US 10,003,600 · App. 15/006,906 · Granted Jun 19, 2018

Identity proxy to provide access control and single sign on

Inventors: Kumara Das Karunakaran (San Jose, CA); Vijay Pawar (Palo Alto, CA); Jian Liu (Fremont, CA)
Assignee: MOBILE IRON, INC.
H04L63/102H04L63/10H04L63/0272H04L63/0281H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,003,600
App. No.
15/006,906
Granted
Jun 19, 2018
Kind
B2
Abstract

Techniques to provide secure access to a cloud-based service are disclosed. In various embodiments, a request is received from a client app on a device to connect to a security proxy associated with the cloud-based service. A secure tunnel connection between the device and a node with which the security proxy is associated is used to establish the requested connection to the security proxy. Information associated with the secure tunnel is used to determine that the requesting client app is authorized to access the cloud-based service from the device and to obtain from an identity provider associated with the cloud-based service a security token to be used by the client app to authenticate to the cloud-based service.

Claims (40)

1. A method of providing secure access to a cloud-based service, comprising:

receiving a request associated with a client app on a device to connect to a security proxy associated with the cloud-based service, wherein the security proxy is remote from the cloud-based service; and

determining whether a security posture associated with the device is compliant;

establishing, by a tunnel server associated with the security proxy, a secure tunnel between the device and the security proxy in response to determining that the security posture associated with the device is compliant;

determining by the security proxy that the requesting client app is authorized to access the cloud-based service from the device based on information associated with the device;

obtaining, by the security proxy from an identity provider associated with the cloud-based service, a security token signed by the identity provider;

providing, by the tunnel server, the security token to the client app, wherein the security token is to be used by the client app to authenticate to the cloud-based service; and

monitoring, by the tunnel server, a compliance posture of the device and blocking access to the cloud-based service based at least in part on an indication that the compliance posture of the device has changed.

2. The method of claim 1 , wherein the request is sent by the client app in response to a redirect message received from the cloud-based service.

3. The method of claim 2 , wherein the redirect message includes a URL or other locator associated with the security proxy.

4. The method of claim 1 , wherein the security proxy is associated with a security proxy server system and the secure tunnel is established between the device and a tunnel server running on the security proxy server system.

5. The method of claim 1 , wherein establishing the secure tunnel includes receiving from the device a security certificate.

6. The method of claim 5 , further comprising using information comprising the security certificate to determine one or more of device, app, user, and certificate information.

7. The method of claim 5 , further comprising using information associated with the security certificate to determine that the requesting client app is authorized to access the cloud-based service.

8. The method of claim 1 , wherein the security proxy is configured to use the information associated with the device to determine that the requesting client app is authorized to access the cloud-based service from the device at least in part by performing a compliance check with respect to the device.

9. The method of claim 1 , wherein the secure proxy comprises an identity provider proxy configured to have a chained identity provider or other trust-based relationship to the identity provider associated with the cloud-based service.

10. The method of claim 9 , further comprising determining that the secure tunnel has already been established and establishing the requested connection to the identity provider proxy on behalf of the requesting client app without requiring any further credential to be provided.

11. The method of claim 1 , wherein the security token comprises a Security Assertion Markup Language (SAML) assertion.

12. The method of claim 1 , wherein the security proxy comprises a delegated identity provider.

13. The method of claim 1 , wherein the security proxy comprises a service provider proxy.

14. The method of claim 13 , wherein the service provider proxy is configured to sign the security token as and on behalf of an identity provider proxy associated with the cloud-based service.

15. A system to provide secure access to a cloud-based service, comprising:

a communication interface; and

a hardware processor coupled to the communication interface and configured to:

receive via the communication interface a request associated with a client app on a device to connect to a security proxy associated with the cloud-based service, wherein the security proxy is remote from the cloud-based service; and

determine whether a security posture associated with the device is compliant;

establish, by a tunnel server associated with the security proxy, a secure tunnel between the device and the security proxy in response to determining that the security posture associated with the device is compliant;

determine, by the security proxy, that the requesting client app is authorized to access the cloud-based service from the device based on information associated with the device;

obtain, by the security proxy from an identity provider associated with the cloud-based service, a security token signed by the identity provider;

provide, by the tunnel server, the security token to the client app, wherein the security token is to be used by the client app to authenticate to the cloud-based service; and

monitor, by the tunnel server, a compliance posture of the device and blocking access to the cloud-based service based at least in part on an indication that the compliance posture of the device has changed.

16. The system of claim 15 , wherein the security proxy comprises an identity provider proxy.

17. The system of claim 15 , wherein the security proxy comprises a service provider proxy.

18. A computer program product to provide secure access to a cloud-based service, the computer program product being embodied in a non-transitory computer readable storage device and comprising computer instructions for:

determining whether a security posture associated with the device is compliant;

establishing, by a tunnel server associated with the security proxy, a secure tunnel between the device and the security proxy in response to determining that the security posture associated with the device is compliant;

determining, by the security proxy, that the requesting client app is authorized to access the cloud-based service from the device based on information associated with the device;

obtaining, by the security proxy from an identity provider associated with the cloud-based service, a security token signed by the identity provider;

providing, by the tunnel sever, the security token to the client app, wherein the security token is to be used by the client app to authenticate to the cloud-based service; and

monitoring, by the tunnel server, a compliance posture of the device and blocking access to the cloud-based service based at least in part on an indication that the compliance posture of the device has changed.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2016
From: KARUNAKARAN, KUMARA DAS; PAWAR, VIJAY; LIU, JIAN
To: MOBILE IRON, INC.
Reel/Frame 038103/0720 →
Continuity (2)
Provisional Application 62107927 · Jan 26, 2015
Related Publication 20160219060A1 · Jul 28, 2016
Cited By (1)
US 12,368,712