IP Library Granted Patent US 10,965,658
Granted Patent B2
US 10,965,658 · App. 15/840,579 · Granted Mar 30, 2021

Application program as key for authorizing access to resources

Inventor: Erich Stuntebeck (Marietta, GA)
Assignee: AirWatch LLC
H04L63/08G06F21/10G06F21/335G06F21/6218H04L63/105H04L67/303
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,965,658
App. No.
15/840,579
Granted
Mar 30, 2021
Kind
B2
Abstract

In a networked environment, a client side application executed on a client device may transmit a request to an authorization service for access to a resource. The authorization service may authenticate the user of client device and/or the client device based on user credentials and/or a device identifier. In response to authenticating the user and/or the client device, the authorization service may send to the client side application a request for confirmation that the client device complies with a distribution rule associated with the resource, where the distribution rule requires a specific application or specific type of application to be installed, enabled and/or executing on the client device as a prerequisite to accessing the resource. If the client device complies with the distribution rule, the client side application accesses the resource. Accessing the resource may include receiving an authorization credential required for access to the resource.

Claims (38)

1. A method comprising:

obtaining, on a client device, a distribution rule requiring a key application configured to generate a credential for an application to access a resource on the client device;

determining, on the client device, a compliance with the distribution rule based on interrogating a listing of application programs on the client device to determine a presence of the key application;

initiating, on the client device, authentication of the client device with an authorization service, the authentication based upon at least one of a user credential or a device identifier;

in response to authenticating the client device with the authorization service, obtaining, from the key application, the credential associated with the resource; and

in response to a request from the application executed by the client device to access the resource, providing the credential to the application, wherein the credential enables the application to access the resource.

2. The method of claim 1 , wherein the resource is a file that is stored on the client device and the credential enables the application to access the resource.

3. The method of claim 1 , wherein the resource is a remote resource and the credential authenticates the application to the remote resource.

4. The method of claim 3 , wherein the credential comprises an authentication token that is different from the user credential.

5. The method of claim 1 , wherein providing the credential to the application comprises enabling a previously disabled function of the application for accessing the resource.

6. The method of claim 1 , wherein authentication of the client device is further based upon the compliance.

7. The method of claim 6 , wherein the distribution rule further requires that a particular application be installed on the client device as a prerequisite to accessing the resource.

8. A client device comprising:

a network connectivity interface for enabling communication between the client device and an authorization service via a network;

a memory for storing an application and at least one application comprising a key application;

a processor communicatively coupled to the memory for executing the at least one application, wherein the at least one application is configured to cause the client device to at least:

obtain a distribution rule requiring the key application configured to generate a credential for the application to access a resource on the client device;

determine a compliance with the distribution rule based on interrogating a listing of application programs on the client device to determine a presence of the key application;

initiate authentication of the client device with the authorization service, the authentication based upon at least one of a user credential or a device identifier;

in response to authenticating the client device with the authorization service, obtain, from the key application, the credential associated with the resource; and

in response to a request from the application executed by the client device to access the resource, provide the credential to the application, wherein the credential enables the application to access the resource.

9. The client device of claim 8 , wherein the resource is a file that is stored on the client device and the credential enables the application to access the resource.

10. The client device of claim 9 , wherein the credential comprises an authentication token that is different from the user credential.

11. The client device of claim 8 , wherein the resource is a remote resource and the credential authenticates the application to the remote resource.

12. The client device of claim 8 , wherein the credential is provided to the application by enabling a previously disabled function of the application for accessing the resource.

13. The client device of claim 8 , wherein authentication of the client device is further based upon the compliance.

14. The client device of claim 13 , wherein the distribution rule further requires that a particular application be installed on the client device as a prerequisite to accessing the resource.

15. A non-transitory computer-readable medium embodying a program executable in a client device, the program, when executed, causing the client device to at least:

obtain a distribution rule requiring a key application configured to generate a credential for an application to access a resource on the client device;

determine a compliance with the distribution rule based on interrogating a listing of application programs on the client device to determine a presence of the key application;

initiate authentication of the client device with an authorization service, the authentication based upon at least one of a user credential or a device identifier;

in response to authenticating the client device with the authorization service, obtain, from the key application, the credential associated with the resource; and

in response to a request from the application executed by the client device to access the resource, provide the credential to the application, wherein the credential enables the application to access the resource.

16. The non-transitory computer-readable medium of claim 15 , wherein the resource is a file that is stored on the client device and the credential enables the application to access the resource.

17. The non-transitory computer-readable medium of claim 15 , wherein the resource is a remote resource and the credential authenticates the application to the remote resource.

18. The non-transitory computer-readable medium of claim 17 , wherein the credential comprises an authentication token that is different from the user credential.

19. The non-transitory computer-readable medium of claim 15 , wherein the credential is provided to the application by enabling a previously disabled function of the application for accessing the resource.

20. The non-transitory computer-readable medium of claim 15 , wherein authentication of the client device is further based upon the compliance.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →