IP Library Granted Patent US 10,523,636
Granted Patent B2
US 10,523,636 · App. 15/015,686 · Granted Dec 31, 2019

Enterprise mobility management and network micro-segmentation

Inventors: Craig Farley Newell (Atlanta, GA); Sulay Shah (Atlanta, GA); Adam Rykowski (Alpharetta, GA); Leung Tao Kwok (Cumming, GA)
Assignee: AIRWATCH LLC
H04L63/0272H04W12/001H04W12/0027H04L63/029H04L63/0236H04L63/0245H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,636
App. No.
15/015,686
Granted
Dec 31, 2019
Kind
B2
Abstract

Disclosed are various examples for the use of network micro-segmentation in enterprise mobility management. In one example, a gateway receives network traffic from a client device through a virtual private network (VPN) tunnel. The gateway determines one or more device management attributes associated with the client device in response to receiving the network traffic. The gateway then determines a particular network virtual segment based at least in part on the device management attribute(s). The gateway forwards the network traffic to the particular virtual network segment.

Claims (44)

1. A non-transitory computer-readable medium embodying at least one program executable in at least one gateway computing device, the at least one program, when executed by the at least one gateway computing device, being configured to cause the at least one gateway computing device to at least:

divide an internal network into a plurality of virtual network segments, wherein the plurality of virtual network segments comprise different configurations of network resources;

receive network traffic from a client device through a virtual private network (VPN) tunnel of an external network, wherein the at least one gateway computing device is coupled to the external network and the internal network;

determine at least one device management attribute associated with the client device, wherein the at least one device management attribute is provided to the gateway computing device by a management application executed by the client device;

embed, by the at least one gateway computing device, the at least one device management attribute in a header of a packet comprising the network traffic;

determine a particular virtual network segment of the plurality of virtual network segments based at least in part on the at least one device management attribute; and

forward the packet comprising the network traffic to the particular virtual network segment, wherein a network device in the internal network receives the packet and evaluates the at least one device management attribute in the header of the packet in order to forward the packet within the internal network.

2. The non-transitory computer-readable medium of claim 1 , wherein when executed to determine the particular virtual network segment of the plurality of virtual network segments based at least in part on the at least one device management attribute further comprises evaluating a compliance status of the client device by applying at least one compliance rule to the at least one device management attribute.

3. The non-transitory computer-readable medium of claim 1 , wherein the VPN tunnel is associated with a single client application executed by the client device.

4. The non-transitory computer-readable medium of claim 1 , wherein the at least one device management attribute includes a jailbreak status of the client device.

5. The non-transitory computer-readable medium of claim 1 , wherein the at least one device management attribute includes a location of the client device.

6. The non-transitory computer-readable medium of claim 1 , wherein the at least one device management attribute includes an identifier of a client application executed by the client device.

7. The non-transitory computer-readable medium of claim 1 , wherein when executed the at least one program further causes the at least one gateway computing device to at least:

receive additional network traffic from the client device through the VPN tunnel;

determine at least one updated device management attribute associated with the client device in response to receiving the additional network traffic;

determine a different virtual network segment of the plurality of virtual network segments based at least in part on the at least one updated device management attribute; and

forward the network traffic to the different virtual network segment.

8. A system, comprising:

at least one gateway computing device; and

a gateway executable by the at least one gateway computing device, the gateway configured to cause the at least one gateway computing device to at least:

divide an internal network into a plurality of virtual network segments, wherein the plurality of virtual network segments comprise different configurations of network resources;

receive network traffic from a client device through a virtual private network (VPN) tunnel of an external network, wherein the at least one gateway computing device is coupled to the external network and the internal network;

determine at least one device management attribute associated with the client device, wherein the at least one device management attribute is provided to the gateway computing device by a management application executed by the client device;

embed, by the at least one gateway computing device, the at least one device management attribute in a header of a packet comprising the network traffic;

determine a particular virtual network segment of the plurality of virtual network segments based at least in part on the at least one device management attribute; and

forward the packet comprising the network traffic to the particular virtual network segment, wherein a network device in the internal network receives the packet and evaluates the at least one device management attribute in the header of the packet in order to forward the packet within the internal network.

9. The system of claim 8 , wherein the network traffic is associated with a destination network resource that is unreachable through the particular virtual network segment.

10. The system of claim 8 , wherein the at least one device management attribute includes a jailbreak status of the client device.

11. The system of claim 8 , wherein the at least one device management attribute includes at least one of: a user identifier or an identifier of the client device.

12. The system of claim 8 , wherein the at least one device management attribute includes a location of the client device.

13. The system of claim 8 , wherein when executed the gateway is further configured to cause the at least one gateway computing device to at least determine a port address associated with the particular virtual network segment, wherein the network traffic is forwarded to the particular virtual network segment using the port address as a source port address.

14. The system of claim 8 , wherein when executed the gateway is further configured to cause the at least one gateway computing device to at least determine an internet protocol (IP) address associated with the particular virtual network segment, wherein the network traffic is forwarded to the particular virtual network segment using the IP address as a source IP address.

15. A method for forwarding network traffic using a gateway device, the method comprising:

dividing an internal network into a plurality of virtual network segments, wherein the plurality of virtual network segments comprise different configurations of network resources;

receiving network traffic from a client device through a virtual private network (VPN) tunnel of an external network, wherein the gateway computing device is coupled to the external network and the internal network;

determining at least one device management attribute associated with the client device, wherein the at least one device management attribute is provided to the gateway computing device by a management application executed by the client device;

embedding, by the gateway computing device, the at least one device management attribute in a header of a packet comprising the network traffic;

determining a particular virtual network segment of the plurality of virtual network segments based at least in part on the at least one device management attribute; and

forwarding the packet comprising the network traffic to the particular virtual network segment, wherein a network device in the internal network receives the packet and evaluates the at least one device management attribute in the header of the packet in order to forward the packet within the internal network.

16. The method of claim 15 , wherein the at least one device management attribute includes a user identifier associated with the client device.

17. The method of claim 15 , wherein the at least one device management attribute includes an identifier of an operating system of the client device.

18. The method of claim 15 , wherein the at least one device management attribute includes a jailbreak status of the client device.

19. The method of claim 15 , further comprising determining a port address associated with the particular virtual network segment, wherein the network traffic is forwarded to the particular virtual network segment using the port address as a source port address.

20. The method of claim 15 , further comprising determining an internet protocol (IP) address associated with the particular virtual network segment, wherein the network traffic is forwarded to the particular virtual network segment using the IP address as a source IP address.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2016
From: NEWELL, CRAIG FARLEY; RYKOWSKI, ADAM; SHAH, SULAY; KWOK, LEUNG TAO
To: AIRWATCH LLC
Reel/Frame 038452/0180 →