IP Library Granted Patent US 10,375,052
Granted Patent B2
US 10,375,052 · App. 15/451,586 · Granted Aug 6, 2019

Device verification of an installation of an email client

Inventors: Adarsh Kesari (Atlanta, GA); Martin Kniffin (Atlanta, GA)
Assignee: Airwatch LLC
H04L63/0807H04L51/22H04L63/0272H04L63/0853H04W12/06H04L63/068H04L63/0823H04W12/00512
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,375,052
App. No.
15/451,586
Granted
Aug 6, 2019
Kind
B2
Abstract

Disclosed are various examples for single-sign on by way of managed mobile devices. For example, an identity provider service can receive a request for an identity assertion from an email client executed in a client device. The identity provider service can then detect a platform associated with the client device. The device and the user's identity can be authenticated so that an IT administrator can specify that only authorized devices can access email using the email client.

Claims (43)

1. A non-transitory computer-readable medium embodying a program executable in at least one computing device, the program, when executed by the at least one computing device, being configured to cause the at least one computing device to at least:

receive a request for an identity assertion from an email client executed in a mobile device, the request being generated in response to a redirection received in the email client from an authentication server associated with an email service of a user;

detect an operating system associated with the mobile device based upon the request for the identity assertion;

in response to determining that the operating system is iOS and the mobile device is unauthenticated, send a Kerberos challenge to the mobile device;

extract a device-specific credential from a response to the Kerberos challenge, the device-specific credential comprising a device identifier embedded within a certificate used to encrypt the response, the device-specific credential being associated with a previous user authentication of the user, wherein the certificate is provided to the client device upon enrollment of the client device with a device management service;

determine that the user is authorized to access the email service based upon the response by determining that the device-specific credential is unexpired and unrevoked;

determine that the mobile device is authorized to access the email service of the user based upon the device identifier by querying the device management service with the device identifier; and

in response to determining that the device-specific credential is unexpired and unrevoked and that the mobile device is authorized to access the email service, send the identity assertion to the email client.

2. The non-transitory computer-readable medium of claim 1 , wherein the certificate is installed on the mobile device by the device management service upon enrollment of the mobile device with the device management service as a managed device.

3. The non-transitory computer-readable medium of claim 2 , wherein the certificate is installed as a portion of a single sign-on profile installed by the device management service on the mobile device.

4. The non-transitory computer-readable medium of claim 2 , wherein the certificate is installed with a virtual private network (VPN) client installed by the device management service on the mobile device.

5. The non-transitory computer-readable medium of claim 1 , wherein the program causes the at least one computing device to determine that the mobile device is authorized to access the email service by determining that the mobile device complies with at least one compliance rule or that the mobile device is enrolled as a managed device with the device management service.

6. The non-transitory computer-readable medium of claim 1 , wherein the redirection received in the email client comprises a Security Assertion Markup Language (SAML) redirect sent from the email service to the email client.

7. The non-transitory computer-readable medium of claim 1 , wherein the device-specific credential further comprises an authentication token provided to the client device upon enrollment of the client device with the device management service.

8. A system, comprising:

at least one computing device; and

an identity provider service executable by the at least one computing device, the identity provider service configured to cause the at least one computing device to at least:

receive a request for an identity assertion from an email client executed in a mobile device, the request being generated in response to a redirection received in the email client from an authentication server associated with an email service of a user;

detect an operating system associated with the mobile device based upon the request for the identity assertion;

in response to determining that the operating system is iOS and the mobile device is unauthenticated, send a Kerberos challenge to the mobile device;

extract a device-specific credential from a response to the Kerberos challenge, the device-specific credential comprising a device identifier embedded within a certificate used to encrypt the response, the device-specific credential being associated with a previous user authentication of the user, wherein the certificate is provided to the client device upon enrollment of the client device with a device management service;

determine that the user is authorized to access the email service based upon the response by determining that the device-specific credential is unexpired and unrevoked;

determine that the mobile device is authorized to access the email service based upon the device identifier by querying the device management service with the device identifier; and

in response to determining that the user is authorized to access the email service and that the mobile device is authorized to access the email service, send the identity assertion to the email client.

9. The system of claim 8 , wherein the certificate is installed on the mobile device by the device management service upon enrollment of the mobile device with the device management service as a managed device.

10. The system of claim 9 , wherein the certificate is installed as a portion of a single sign-on profile installed by the device management service on the mobile device.

11. The system of claim 9 , wherein the certificate is installed with a virtual private network (VPN) client installed by the device management service on the mobile device.

12. The system of claim 8 , wherein the identity provider determines that the mobile device is authorized to access the email service by determining that the mobile device complies with at least one compliance rule or that the mobile device is enrolled as a managed device with the device management service.

13. The system of claim 8 , wherein the redirection received in the email client comprises a Security Assertion Markup Language (SAML) redirect sent from the email service to the email client.

14. The system of claim 8 , wherein the device-specific credential further comprises an authentication token provided to the client device upon enrollment of the client device with the device management service.

15. A method, comprising:

receiving a request for an identity assertion from an email client executed in a mobile device, the request being generated in response to a redirection received in the email client from an authentication server associated with an email service of a user;

detecting an operating system associated with the mobile device based upon the request for the identity assertion;

in response to determining that the operating system is iOS and the mobile device is unauthenticated, sending a Kerberos challenge to the mobile device;

extracting a device-specific credential from a response to the Kerberos challenge, the device-specific credential comprising a device identifier embedded within a certificate used to encrypt the response, the device-specific credential being associated with a previous user authentication of the user, wherein the certificate is provided to the client device upon enrollment of the client device with a device management service;

determining that the user is authorized to access the email service based upon the response by determining that the device-specific credential is unexpired and unrevoked;

determining that the mobile device is authorized to access the email service of the user based upon the device identifier by querying the device management service with the device identifier; and

in response to determining that the user is authorized to access the email service and that the mobile device is authorized to access the email service, sending the identity assertion to the email client.

16. The method of claim 15 , wherein the certificate is installed on the mobile device by the device management service upon enrollment of the mobile device with the device management service as a managed device.

17. The method of claim 16 , wherein the certificate is installed as a portion of a single sign-on profile installed by the device management service on the mobile device.

18. The method of claim 16 , wherein the certificate is installed with a virtual private network (VPN) client installed by the device management service on the mobile device.

19. The method of claim 15 , wherein the redirection received in the email client comprises a Security Assertion Markup Language (SAML) redirect sent from the email service to the email client.

20. The method of claim 15 , wherein the device-specific credential further comprises an authentication token provided to the client device upon enrollment of the client device with the device management service.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2017
From: KESARI, ADARSH; KNIFFIN, MARTIN
To: AIRWATCH LLC
Reel/Frame 041528/0115 →
Continuity (1)
Related Publication 20180262484A1 · Sep 13, 2018