IP Library Granted Patent US 12,418,794
Granted Patent B2
US 12,418,794 · App. 15/175,927 · Granted Sep 16, 2025

Mobile device authentication

Inventors: Daniel James Beveridge (Apollo Beach, FL); Blake Watts (St. George, UT); Jian Mu (BeiJing, CN)
Assignee: Omnissa, LLC
H04W12/06G06F9/452G06F21/34G06F21/35H04L63/0853H04L67/08H04L67/75G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,794
App. No.
15/175,927
Granted
Sep 16, 2025
Kind
B2
Abstract

A desktop is unlocked or locked using a mobile client device, such as a smart phone, tablet, smart watch, etc. The authentication mechanism of the mobile client device, such as fingerprint, facial recognition, voice recognition, username and password, is leveraged for faster, less-cumbersome user authentication on the desktop. In this vein, a client device is added to an authentication agent on the desktop, and the desktop recognizes successful attempts to access the mobile client device as a method of unlocking or locking the desktop.

Claims (45)

1. A method, comprising:

prior to authorizing a client device to access a desktop:

registering the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device to unlock the desktop, the desktop hosted by a hypervisor running on the client device;

receiving an indication on the client device corresponding to the authentication mechanism;

determining that the indication is an authorized unlocking indication;

upon determining that the indication is an authorized unlocking indication, transmitting client device credentials to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and

upon the client device being determined to satisfy the enterprise administrative policy, transmitting the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop, the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop.

2. The method of claim 1 , wherein the client device is provided with a token to access the desktop management server.

3. The method of claim 1 , wherein the indication comprises sequentially touching specifically displayed elements on the client device.

4. The method of claim 1 , wherein the enterprise administrative policy includes rules associated with one or more of an access level and an access frequency.

5. The method of claim 1 , wherein the authentication mechanism includes one or more of a thermogram and gait recognition.

6. The method of claim 1 , wherein the indication includes a sequence of a plurality of related events that satisfies the enterprise administrative policy.

7. The method of claim 1 , further comprising:

receiving the indication on a smart watch; and

transmitting the indication from a smart phone to the desktop to unlock the desktop.

8. The method of claim 1 , wherein authenticating the user on the client device includes receiving authentication data comprising one or more of voice recognition information and facial recognition information.

9. A system, comprising:

one or more memories storing computer-executable instructions; and

one or more processors operationally coupled to the one or more memories and configured to execute the computer-executable instructions to:

prior to authorizing a client device to access a desktop:

register the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device unlock the desktop, the desktop hosted by a hypervisor running on the client device;

receive an indication, on the client device, corresponding to the authentication mechanism;

determine that the indication is an authorized unlocking indication;

upon determining that the indication is an authorized unlocking indication, transmit client device credentials of the client device to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and

upon the client device being determined to satisfy the enterprise administrative policy, transmit the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop, the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop.

10. The system of claim 9 , wherein the client device is provided with a token to access the desktop management server.

11. The system of claim 9 , wherein the indication comprises sequentially touching specifically displayed elements on the client device.

12. The system of claim 9 , wherein the indication includes a sequence of a plurality of related events that satisfies the enterprise administrative policy.

13. The system of claim 9 , wherein the authentication mechanism includes one or more of: a thermogram and gait recognition.

14. The system of claim 9 , wherein authenticating a user on a client device includes receiving authentication data comprising one or more of voice recognition information and facial recognition information.

15. A non-transitory computer-storage memory embodied with instructions executable by one or more processors to enable remote authentication of a desktop by a client device, the instructions comprising:

prior to authorizing the client device to access a desktop:

registering the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device to unlock the desktop, the desktop hosted by a hypervisor running on the client device;

receiving an indication on the client device corresponding to the authentication mechanism;

determine whether the indication is an authorized unlocking indication;

upon determining that the indication is an authorized unlocking indication, transmitting client device credentials to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine, whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and

upon the client device being determined to satisfy the enterprise administrative policy, transmitting the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop. the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop.

16. The non-transitory computer-storage memory of claim 15 , wherein the client device is provided with a token to access the desktop management server.

17. The non-transitory computer-storage memory of claim 15 , wherein the instructions further cause disabling of the client device from locking or unlocking the desktop on condition that the client device credentials are determined to be unauthorized.

18. The non-transitory computer-storage memory of claim 15 , wherein the enterprise administrative policy includes rules associated with one or more of an access level and an access frequency.

19. The non-transitory computer-storage memory of claim 15 , wherein the authentication mechanism includes one or more of: a thermogram, and gait recognition.

20. The non-transitory computer-storage memory of claim 19 , wherein authenticating a user on a client device includes receiving authentication data comprising one or more of voice recognition information and facial recognition information.

21. The method of claim 1 , wherein the hypervisor is a Type 2 hypervisor.

22. The method of claim 1 , further comprising:

receiving, at the desktop agent, a results set from the desktop in the side channel, where the results set includes a result of authenticating the user to unlock the desktop.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067103/0030 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2016
From: BEVERIDGE, DANIEL JAMES; WATTS, BLAKE; MU, JIAN
To: VMWARE, INC.
Reel/Frame 038901/0045 →
Continuity (6)
Continuation In Part 14686769 · Apr 14, 2015
Continuation 13217484 · Aug 25, 2011
Provisional Application 62211850 · Aug 30, 2015
Provisional Application 62211736 · Aug 29, 2015
Provisional Application 61508404 · Jul 15, 2011
Related Publication 20160342784A1 · Nov 24, 2016
References Cited (91)
US 4467421A · White · 1984 [cited by applicant]
US 7117243B2 · Peart · 2006 [cited by applicant]
US 7181578B1 · Guha et al. · 2007 [cited by applicant]
US 7184764B2 · Raviv et al. · 2007 [cited by applicant]
US 7325040B2 · Truong · 2008 [cited by applicant]
US 7606868B1 · Le et al. · 2009 [cited by applicant]
US 7669020B1 · Shah et al. · 2010 [cited by applicant]
US 7941470B2 · Le et al. · 2011 [cited by applicant]
US 8027354B1 · Portolani · 2011 [cited by applicant]
US 8112748B2 · Pomerantz · 2012 [cited by applicant]
US 8234236B2 · Beaty · 2012 [cited by applicant]
US 8261268B1 · Forgette · 2012 [cited by applicant]
US 8266311B2 · Virdi et al. · 2012 [cited by applicant]
US 8271528B1 · Wilkinson et al. · 2012 [cited by applicant]
US 8356084B2 · Yamamoto · 2013 [cited by applicant]
US 8396452B1 · Matsuoka · 2013 [cited by examiner]
US 8433802B2 · Head et al. · 2013 [cited by applicant]
US 8494576B1 · Bye · 2013 [cited by examiner]
US 8555274B1 · Chawla et al. · 2013 [cited by applicant]
US 9009219B2 · Chawla et al. · 2015 [cited by applicant]
US 9075979B1 · Queru · 2015 [cited by examiner]
US 9509676B1 · Johnson · 2016 [cited by examiner]
US 20030195950A1 · Huang et al. · 2003 [cited by applicant]
US 20060080397A1 · Chene et al. · 2006 [cited by applicant]
US 20060128305A1 · Delalat · 2006 [cited by examiner]
US 20070174410A1 · Croft et al. · 2007 [cited by applicant]
US 20070180493A1 · Croft et al. · 2007 [cited by applicant]
US 20070186212A1 · Mazzaferri et al. · 2007 [cited by applicant]
US 20070192329A1 · Croft et al. · 2007 [cited by applicant]
US 20070198656A1 · Mazzaferri et al. · 2007 [cited by applicant]
US 20070204011A1 · Shaver et al. · 2007 [cited by applicant]
US 20070260702A1 · Richardson et al. · 2007 [cited by applicant]
US 20080034071A1 · Wilkinson et al. · 2008 [cited by applicant]
US 20080250424A1 · Brugiolo et al. · 2008 [cited by applicant]
US 20080281798A1 · Chatterjee et al. · 2008 [cited by applicant]
US 20080320583A1 · Sharma et al. · 2008 [cited by applicant]
US 20090006537A1 · Palekar et al. · 2009 [cited by applicant]
US 20090094523A1 · Treder et al. · 2009 [cited by applicant]
US 20090216975A1 · Halperin et al. · 2009 [cited by applicant]
US 20090235358A1 · Tolba · 2009 [cited by applicant]
US 20090240904A1 · Austruy et al. · 2009 [cited by applicant]
US 20090276475A1 · Ramsey · 2009 [cited by examiner]
US 20100070870A1 · Halperin et al. · 2010 [cited by applicant]
US 20100070978A1 · Chawla et al. · 2010 [cited by applicant]
US 20100114867A1 · Olston · 2010 [cited by applicant]
US 20100131654A1 · Malakapalli et al. · 2010 [cited by applicant]
US 20100131949A1 · Ferris · 2010 [cited by applicant]
US 20100191783A1 · Mason · 2010 [cited by applicant]
US 20100199276A1 · Umbehocker · 2010 [cited by applicant]
US 20100211944A1 · Kaneda · 2010 [cited by applicant]
US 20100268813A1 · Pahlavan et al. · 2010 [cited by applicant]
US 20100269152A1 · Pahlavan et al. · 2010 [cited by applicant]
US 20100274784A1 · Acharya · 2010 [cited by applicant]
US 20110004680A1 · Ryman · 2011 [cited by applicant]
US 20110066668A1 · Guarraci · 2011 [cited by applicant]
US 20110099297A1 · Hayton · 2011 [cited by applicant]
US 20110119668A1 · Calder et al. · 2011 [cited by applicant]
US 20110153716A1 · Malakapalli et al. · 2011 [cited by applicant]
US 20110184993A1 · Chawla · 2011 [cited by applicant]
US 20110185292A1 · Chawla et al. · 2011 [cited by applicant]
US 20110185355A1 · Chawla et al. · 2011 [cited by applicant]
US 20110209064A1 · Jorgensen et al. · 2011 [cited by applicant]
US 20110225426A1 · Agarwal · 2011 [cited by examiner]
US 20120023558A1 · Rafiq · 2012 [cited by examiner]
US 20120216260A1 · Crawford · 2012 [cited by examiner]
US 20130018939A1 · Chawla et al. · 2013 [cited by applicant]
US 20130191902A1 · Friedl · 2013 [cited by examiner]
US 20140189808A1 · Mahaffey · 2014 [cited by examiner]
US 20140270127A1 · Becker · 2014 [cited by examiner]
US 20140308930A1 · Tran · 2014 [cited by examiner]
US 20140372762A1 · Flautner · 2014 [cited by examiner]
US 20150028996A1 · Agrafioti · 2015 [cited by examiner]
US 20150186636A1 · Tharappel · 2015 [cited by examiner]
US 20150257004A1 · Shanmugam · 2015 [cited by examiner]
US 20150295901A1 · Woodward · 2015 [cited by examiner]
US 20150326578A1 · Hsu · 2015 [cited by examiner]
US 20150347738A1 · Ulrich · 2015 [cited by examiner]
US 20160048705A1 · Yang · 2016 [cited by examiner]
US 20160224779A1 · Kitane · 2016 [cited by examiner]
US 20160246341A1 · Burrell · 2016 [cited by examiner]
JP 08212187 · 1996 [cited by applicant]
JP 2006081159 · 2006 [cited by applicant]
JP 2008511931 · 2008 [cited by applicant]
JP 2009230253 · 2009 [cited by applicant]
Clover, Juli, “Apple Working on OS X 10.12 Feature Allowing Macs to Be Unlocked via iPhone's Touch ID”, MacRumors, May 19, 2016, 5 pages. [cited by applicant]
European Patent Office, International Search Report and Written Opinion for PCT/US2010/046377, transmitted on Jan. 30, 2013, 11 pages. [cited by applicant]
Quickoffice, Inc., QuickOffice Pro for iPhone and iPod Touch, Version 4.0.0, User Help Guide; Jan. 1, 2010, 42 pages. [cited by applicant]
Tedd Fox, Citrix Received >> XenApp—Citrix Community, http://community.citrix.com/display/xa/Citrix+Receiver, Aug. 13, 2010. [cited by applicant]
John McBride et al., Project GoldenGate >> XenApp—Citrix Community, http:/community.citrix.com/display/xa/Project+GoldenGate, Jul. 1, 2011. [cited by applicant]
Office Action received in copending Australian Patent Application No. 2012284345, Received Feb. 18, 2015, 3 pages. [cited by applicant]
Japanese Office Action received in Japanese Patent Application No. 2014-520299. Received Dec. 1, 2015. 6 Pages. [cited by applicant]