IP Library Granted Patent US 10,079,834
Granted Patent B2
US 10,079,834 · App. 15/006,917 · Granted Sep 18, 2018

Secure access to cloud-based services

Inventors: Kumara Das Karunakaran (San Jose, CA); Vijay Pawar (Palo Alto, CA); Ivan Golovenko (Mountain View, CA)
Assignee: MOBILE IRON, INC.
H04L63/102G06F21/33H04L63/0815H04L63/0884H04L63/10H04L63/0272H04L63/0281H04L63/0823H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,079,834
App. No.
15/006,917
Granted
Sep 18, 2018
Kind
B2
Abstract

Techniques to provide secure mobile access to a cloud-based service are disclosed. In various embodiments, a request to access the cloud-based service is received from a mobile device. A security certificate associated with the request is used to synthesize a basic authentication header associated with the request. The synthesized basic authentication header is sent to the cloud-based service on behalf of the mobile device.

Claims (36)

1. A method to provide secure mobile access to a cloud-based service, comprising:

receiving, at a security proxy, a request from a mobile device to access the cloud-based service, wherein the request includes a security certificate;

using the security certificate associated with the request to synthesize a basic authentication header associated with the request, wherein the basic authentication header includes a hash of information obtained from the security certificate;

sending the synthesized basic authentication header that includes the hash of information obtained from the security certificate to the cloud-based service on behalf of the mobile device, wherein the cloud-based service is configured to extract credential information from the synthesized basic authentication header and to send the extracted credential information to the security proxy;

using the extracted credential information to determine that access to the cloud based service is authorized; and

providing to the cloud based service a security token that indicates the mobile device is authorized to access the cloud-based service.

2. The method of claim 1 , wherein the request is associated with a mobile app on the mobile device.

3. The method of claim 2 , wherein the mobile app comprises a native email application.

4. The method of claim 1 , wherein the cloud-based service is configured to allow the mobile device to access the cloud-based service based on the security token.

5. The method of claim 4 , wherein the security proxy is remote from the cloud-based service and the synthesized basic authentication header is sent to the cloud-based service via a network.

6. The method of claim 1 , wherein the security certificate comprises a certificate provisioned to the mobile device.

7. The method of claim 1 , wherein using the security certificate to synthesize the basic authentication header includes using information comprising the security certificate to populate a data field of the basic authentication header.

8. The method of claim 1 , wherein using the security certificate to synthesize the basic authentication header includes using information comprising the security certificate to retrieve a data value to populate a data field of the basic authentication header.

9. The method of claim 8 , wherein the data value is retrieved via a call to a directory associated with the mobile device.

10. The method of claim 1 , wherein the basic authentication header is synthesized at least in part by computing the hash based on credential information associated with the request to access the cloud-based service.

11. The method of claim 10 , further comprising caching the credential information.

12. The method of claim 11 , further comprising receiving from the cloud-based service a request to authenticate the extracted credential information, wherein the request to authenticate the extracted credential information includes the extracted credential information.

13. The method of claim 12 , further comprising comparing the received extracted credential information with the cached credential information to authenticate the received extracted credential information.

14. The method of claim 13 , wherein the security token is provided to the cloud-based service based at least in part on said authentication of the received extracted credential information.

15. The method of claim 14 , wherein the security token comprises a Security Assertion Markup Language (SAML) assertion.

16. The method of claim 1 , wherein the security certificate associated with the request is used to synthesize a basic authentication header associated with the request based at least in part on a determination that access is authorized.

17. A system to provide secure mobile access to a cloud-based service, comprising:

a communication interface; and

a processor coupled to the communication interface and configured to:

receive, at a security proxy, a request from a mobile device to access the cloud-based service, wherein the request includes a security certificate;

use the security certificate associated with the request to synthesize a basic authentication header associated with the request, wherein the basic authentication header includes a hash of information obtained from the security certificate;

send the synthesized basic authentication header that includes the hash of information obtained from the security certificate to the cloud-based service on behalf of the mobile device, wherein the cloud-based service is configured to extract credential information from the synthesized basic authentication header and to send the extracted credential information to the security proxy;

use the extracted credential information to determine that access to the cloud-based service is authorized; and

provide to the cloud based service a security token that indicates the mobile device is authorized to access the cloud-based service.

18. The system of claim 17 , wherein the basic authentication header is synthesized at least in part by computing the hash based on credential information associated with the request to access the cloud-based service.

19. A computer program product to provide secure mobile access to a cloud-based service, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, at a security proxy, a request from a mobile device to access the cloud-based service, wherein the request includes a security certificate;

using the security certificate associated with the request to synthesize a basic authentication header associated with the request, wherein the basic authentication header includes a hash of information obtained from the security certificate;

sending the synthesized basic authentication header that includes the hash of information obtained from the security certificate to the cloud-based service on behalf of the mobile device, wherein the cloud-based service is configured to extract credential information from the synthesized basic authentication header and to send the extracted credential information to the security proxy;

using the extracted credential information to determine that access to the cloud-based service is authorized; and

providing to the cloud based service a security token that indicates the mobile device is authorized to access the cloud-based service.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DOCKET NUMBER PREVIOUSLY RECORDED AT REEL: 038184 FRAME: 0864. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 2, 2016
From: KARUNAKARAN, KUMARA DAS; PAWAR, VIJAY; GOLOVENKO, IVAN
To: MOBILE IRON, INC.
Reel/Frame 038593/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2016
From: KARUNAKARAN, KUMARA DAS; PAWAR, VIJAY; GOLOVENKO, IVAN
To: MOBILE IRON, INC.
Reel/Frame 038184/0864 →
Continuity (2)
Provisional Application 62107927 · Jan 26, 2015
Related Publication 20160219044A1 · Jul 28, 2016
Cited By (1)
US 12,556,536