IP Library Granted Patent US 10,681,028
Granted Patent B2
US 10,681,028 · App. 15/713,750 · Granted Jun 9, 2020

Controlling access to resources on a network

Inventors: John Marshall (Atlanta, GA); Erich Stuntebeck (Marietta, GA)
Assignee: VMWare, Inc.
H04L63/08G06F21/335H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,681,028
App. No.
15/713,750
Granted
Jun 9, 2020
Kind
B2
Abstract

Disclosed are various embodiments for controlling access to data on a network. Upon receiving a request comprising a device identifier and at least one user credential to access a remote resource, the request may be authenticated according to at least one compliance policy. If the request is authenticated, a resource credential associated with the remote resource may be provided.

Claims (59)

1. A method for authenticating a client device and providing access to a remote resource hosted by a remote device, comprising:

receiving, in a proxy server, a re-routed request, the re-routed request originating from a request by a client device to the remote device and being re-routed to the proxy server;

requesting, using the proxy server, user credentials of a user from the client device in response to receiving the re-routed request;

obtaining, in the proxy server, the requested user credentials from the client device;

determining, using the proxy server, that the client device is authorized to access the remote resource based at least in part upon the user credentials obtained from the client device;

generating, in the proxy server, an access credential associated with the remote resource; and

transmitting, from the proxy server, the access credential to the client device, wherein the access credential permits the client device to access the remote resource from the remote device.

2. The method of claim 1 , wherein the user credentials are obtained from a prompt to authenticate the user generated by the client device.

3. The method of claim 1 , wherein determining that the client device is authorized to access the remote resource further comprises:

extracting, in the proxy server, a device identifier from the re-routed request received from the client device; and

determining, in the proxy server, that the device identifier corresponds to one of a plurality of approved device identifiers accessible to the proxy server.

4. The method of claim 3 , wherein determining that the client device is authorized to access the remote resource further comprises:

transmitting, from the proxy server, a request to authorize the client device or the user associated with the client device to another server; and

obtaining, in the proxy server, an indication from the other server that the client device or the user associated with the client device are authorized.

5. The method of claim 1 , wherein determining that the client device is authorized to access the remote resource further comprises:

extracting, in the proxy server, a device identifier from the re-routed request received from the client device; and

determining, in the proxy server, that the device identifier corresponds to a client device that is in compliance with at least one compliance rule.

6. The method of claim 5 , wherein determining that the device identifier corresponds to a client device that is in compliance with at least one compliance rule further comprises:

transmitting, from the proxy server, a request to obtain a compliance status of the client device to another server; and

obtaining, in the proxy server, an indication from the other server that the client device is in compliance with the at least one compliance rule.

7. A system for authenticating a client device and providing access to a remote resource hosted by a remote device, comprising:

a proxy server; and

an application executed by the proxy server, the application, when executed, causing the proxy server to at least:

receive a re-routed request, the re-routed request originating from a request by a client device to the remote device and being re-routed to the proxy server;

request user credentials of a user from the client device in response to receiving the re-routed request;

obtain the requested user credentials from the client device;

determine that the client device is authorized to access the remote resource based at least in part upon the user credentials obtained from the client device;

generate an access credential associated with the remote resource; and

transmit the access credential to the client device, wherein the access credential permits the client device to access the remote resource from the remote device.

8. The system of claim 7 , wherein the user credentials are obtained from a prompt to authenticate the user generated by the client device.

9. The system of claim 7 , wherein the application determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

extract a device identifier from the re-routed request received from the client device; and

determine that the device identifier corresponds to one of a plurality of approved device identifiers accessible to the proxy server.

10. The system of claim 9 , wherein the application determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

transmit a request to authorize the client device or the user associated with the client device to another server; and

obtain an indication from the other server that the client device or the user associated with the client device are authorized.

11. The system of claim 7 , wherein the application determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

extract a device identifier from the re-routed request received from the client device; and

determine that the device identifier corresponds to a client device that is in compliance with at least one compliance rule.

12. The system of claim 11 , wherein the application determines that the device identifier corresponds to a client device that is in compliance with at least one compliance rule by causing the proxy server to at least:

transmit a request to obtain a compliance status of the client device to another server; and

obtain an indication from the other server that the client device is in compliance with the at least one compliance rule.

13. A non-transitory computer readable medium embodying a program executable by a proxy server for authenticating a client device and providing access to a remote resource hosted by a remote device, the program, when executed, causing the proxy server to at least:

receive a re-routed request, the re-routed request originating from a request by a client device to the remote device and being re-routed to the proxy server;

request user credentials of a user from the client device in response to receiving the re-routed request;

obtain the requested user credentials from the client device;

determine that the client device is authorized to access the remote resource based at least in part upon the user credentials obtained from the client device;

generate an access credential associated with the remote resource; and

transmit the access credential to the client device, wherein the access credential permits the client device to access the remote resource from the remote device.

14. The non-transitory computer readable medium of claim 13 , wherein the user credentials are obtained from a prompt to authenticate the user generated by the client device.

15. The non-transitory computer readable medium of claim 13 , wherein the program determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

extract a device identifier from the re-routed request received from the client device; and

determine that the device identifier corresponds to one of a plurality of approved device identifiers accessible to the proxy server.

16. The non-transitory computer readable medium of claim 15 , wherein the program, when executed, determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

transmit a request to authorize the client device or the user associated with the client device to another server; and

obtain an indication from the other server that the client device or the user associated with the client device are authorized.

17. The non-transitory computer readable medium of claim 13 , wherein the program, when executed, determines that the client device is authorized to access the remote resource by causing the proxy server to at least:

extract a device identifier from the re-routed request received from the client device; and

determine that the device identifier corresponds to a client device that is in compliance with at least one compliance rule.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (3)
Continuation 13891612 · May 10, 2013
Continuation In Part 13316073 · Dec 9, 2011
Related Publication 20180013747A1 · Jan 11, 2018