IP Library Granted Patent US 10,091,127
Granted Patent B2
US 10,091,127 · App. 15/815,434 · Granted Oct 2, 2018

Enrolling a mobile device with an enterprise mobile device management environment

Inventors: Tom Chang (Millbrae, CA); Mansu Kim (San Jose, CA)
Assignee: MOBILE IRON, INC.
H04L47/70H04L67/02H04L67/04H04L67/10H04L67/125H04L67/26H04L67/303H04W4/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,091,127
App. No.
15/815,434
Filed
Nov 16, 2017
Granted
Oct 2, 2018
Kind
B2
Examiner
LIM, KRISNA
Art Unit
2451
USPC
709/225
Abstract

Embodiments of the present application relate to a method, apparatus, and system for enrolling a mobile device with an enterprise network. The method includes receiving, from a mobile device, a request to access an enrollment address. In response to receiving the request to access the enrollment address, determining whether the mobile device is pre-enrolled with the enterprise network, and in the event that the mobile device from which the request to access the enrollment address is received corresponds to the mobile device that is pre-enrolled with the enterprise network, pushing user-specific settings to the mobile device.

Claims (39)

1. A computer program product for enrolling a mobile device with an enterprise network, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, from a mobile device, a request to enroll;

in response to receiving the request to enroll, determining, based on data received in connection with receipt of the request to enroll, that the mobile device is not pre-enrolled with the enterprise network at least in part by comparing device information stored in an enterprise database with device information included in the data; and

in response to determining that the device is not pre-enrolled with the enterprise network, determining whether anonymous device enrollment is permitted by the enterprise network.

2. A system, comprising:

a processor configured to:

receive, from a mobile device, a request to enroll;

in response to the receipt of the request to enroll, determine, based on data received in connection with receipt of the request to enroll, that the mobile device is not pre-enrolled with the enterprise network at least in part by comparing device information stored in an enterprise database with device information included in the data; and

in response to determining that the device is not pre-enrolled with the enterprise network, determining whether anonymous device enrollment is permitted by the enterprise network; and

a memory coupled to the processor and configured to provide the processor with instructions.

3. The system of claim 2 , wherein the processor is further configured to communicate an enrollment address to a user, wherein the enrollment address corresponds to an address through which the request to enroll can be sent, wherein the request to enroll received from the mobile device corresponds to a request to access the enrollment address that is communicated to the user.

4. The system of claim 3 , wherein the processor is further configured to generate an enrollment address.

5. The system of claim 3 , wherein an enrollment address is an address that is specific to the user.

6. The system of claim 3 , wherein an enrollment address is an address that is associated with an enterprise network but not associated with any specific user.

7. The system of claim 3 , wherein an enrollment address is one or more of a Uniform Resource Locator (URL) and a URL shortcut.

8. The system of claim 2 , wherein in response to determining that the mobile device from which the request to enroll is received is not pre-enrolled with the enterprise network, the processor is further configured to push default settings to the mobile device.

9. The system of claim 2 , wherein default settings are pushed to the mobile device in response to determining that anonymous device enrollment is permitted.

10. The system of claim 9 , wherein in response to determining that anonymous device enrollment is not permitted by the enterprise network, the processor is further configured to remove a setting associated with the enterprise network from the mobile device.

11. The system of claim 9 , wherein in response to determining that the mobile device is not pre-rolled with the enterprise network, the processor is further configured to:

receive authentication information for accessing the enterprise network from the mobile device;

validate a user based at least in part on the authentication information;

determine whether to enroll the mobile device with the enterprise network; and

in response to determining to enroll the mobile device with the enterprise network, enroll the mobile device with the enterprise network.

12. The system of claim 11 , wherein to determine whether to enroll the mobile device with the enterprise network, the processor is further configured to determine whether the user is a valid user of the enterprise network.

13. The system of claim 11 , wherein the processor is further configured to:

receive a request to access an enterprise network from the mobile device; and

prompt the mobile device for authentication information for accessing the enterprise network.

14. The system of claim 11 , wherein to enroll the mobile device with the enterprise network, the processor is further configured to communicate device information of the mobile device to a network server associated with management of the mobile devices enrolled with the enterprise network.

15. The system of claim 11 , wherein in response to validating the user, the processor is further configured to push user-specific settings to the mobile device.

16. The system of claim 2 , wherein the request to enroll corresponds to a request to access an enrollment address, and wherein in response to receiving the request to access the enrollment address, processing a mobile device enrollment request associated with the request to access the enrollment address.

17. The system of claim 2 , wherein the processor is further configured to:

in response to receiving the request to enroll, determine whether the mobile device has a mobile device management functionality, and

wherein the pushing of the user-specific settings to the mobile device comprises pushing the user-specific settings in the event that the mobile device has the mobile device management functionality.

18. The system of claim 17 , wherein in response to receiving the request to enroll, the processor is further configured to communicate a message to the mobile device so as to redirect the mobile device to an address for downloading a mobile device management application.

19. The system of claim 18 , wherein the message that redirects the mobile device to the address for downloading the mobile device management application is communicated in response to a determination that the mobile device does not have the mobile device management functionality.

20. A method of enrolling a mobile device with an enterprise network, comprising:

receiving, from a mobile device, a request to enroll;

in response to receiving the request to enroll, determining, based on data received in connection with receipt of the request to enroll, that the device is not pre-enrolled with the enterprise network at least in part by comparing device information stored in an enterprise database with device information included in the data; and

in response to determining that the device is not pre-enrolled with the enterprise network, determining whether anonymous device enrollment is permitted by the enterprise network.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (3)
Continuation 14633493 · Feb 27, 2015
Provisional Application 61946588 · Feb 28, 2014
Related Publication 20180145924A1 · May 24, 2018