IP Library Granted Patent US 10,523,660
Granted Patent B1
US 10,523,660 · App. 16/257,654 · Granted Dec 31, 2019

Asserting a mobile identity to users and devices in an enterprise authentication system

Inventors: Alexei Volkov (Mountain View, CA); Kumara Das Karunakaran (Milpitas, CA); Vijay Pawar (Palo Alto, CA)
Assignee: MOBILEIRON, INC.
H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,660
App. No.
16/257,654
Granted
Dec 31, 2019
Kind
B1
Abstract

In an embodiment, a system for asserting a mobile identity to users and devices in an enterprise authentication system includes a communication interface and a processor coupled to the interface. The processor is configured to receive, via the communication interface and from a first device, a request to authenticate a user to a service using a unique identity associated with a second device. The processor is configured to determine, based at least in part on the unique identity, an identity certificate associated with the request, generate an identity assertion based at least in part on the identity certificate, and provide the identity assertion via the communication interface to a requesting node with which the request to authenticate is associated.

Claims (51)

1. A system comprising:

a communication interface;

a processor coupled to the communication interface and configured to:

receive, via the communication interface and from a first device, a request to authenticate a user to a service using a unique identity associated with a second device;

determine, based at least in part on the unique identity, an identity certificate associated with the request including by:

presenting an interaction page on an unmanaged device to receive the unique identity,

mapping the unique identity to a managed device that established the unique identity, and

in response to receiving approval from the managed device,

matching an identity certificate to the unique identity;

generate an identity assertion based at least in part on the identity certificate; and

provide the identity assertion via the communication interface to a requesting node with which the request to authenticate is associated;

wherein the first device is not managed by an enterprise mobile management server and the second device is managed by the enterprise mobile management server, and

the determination of the identity certificate includes, prior to mapping the unique identity to the managed device: at least one of: sending a verification code to the managed device and generating a verification code at the managed device, and receiving a verification code from the unmanaged device matching the verification code sent to the managed device.

2. The system of claim 1 , wherein the requesting node is a cloud service provider.

3. The system of claim 1 , wherein the unique identity identifies an associated managed device.

4. The system of claim 1 , wherein the identity certificate is associated with a device managed by an enterprise mobile management server.

5. The system of claim 1 , wherein the unique identity is unaccompanied by a credential.

6. The system of claim 1 , wherein the unique identity identifies a user authenticated to the unique identity.

7. The system of claim 1 , wherein the determination of the identity certificate includes:

sending a push notification to the managed device, and

the approval is received in response to the push notification.

8. The system of claim 1 , wherein the interaction page includes a visual reminder of a process for authenticating a unique identity.

9. The system of claim 1 , where the unique identity is hashed upon entry by a user.

10. The system of claim 1 , wherein the identity assertion is generated based at least in part on attributes in the identity certificate.

11. The system of claim 1 , wherein the processor is further configured to perform a one-time authentication.

12. The system of claim 1 , wherein the processor is further configured to authenticate the unique identity using a biometric identifier, and the identity certificate is determined in response to authenticating the unique identity.

13. The system of claim 1 , wherein the processor is further configured to, prior to receiving the request to authenticate the user:

associate the unique identity with managed devices; and

associate the unique identity with the identity certificate.

14. The system of claim 1 , wherein the processor is further configured to create the unique identity.

15. The system of claim 1 , wherein the processor is further configured to associate a login session identified by a received scannable code with the identity certificate.

16. A method comprising:

receiving from a first device a request to authenticate a user to a service using a unique identity associated with a second device;

determining, based at least in part on the unique identity, an identity certificate associated with the request including by:

presenting an interaction page on an unmanaged device to receive the unique identity,

mapping the unique identity to a managed device that established the unique identity, and

in response to receiving approval from the managed device, matching an identity certificate to the unique identity;

generating an identity assertion based at least in part on the identity certificate; and

providing the identity assertion to a requesting node with which the request to authenticate is associated;

wherein the first device is not managed by an enterprise mobile management server and the second device is managed by the enterprise mobile management server, and

the determination of the identity certificate includes, prior to mapping the unique identity to the managed device: at least one of: sending a verification code to the managed device and generating a verification code at the managed device, and receiving a verification code from the unmanaged device matching the verification code sent to the managed device.

17. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving from a first device a request to authenticate a user to a service using a unique identity associated with a second device;

determining, based at least in part on the unique identity, an identity certificate associated with the request including by:

presenting an interaction page on an unmanaged device to receive the unique identity,

mapping the unique identity to a managed device that established the unique identity, and

in response to receiving approval from the managed device, matching an identity certificate to the unique identity;

generating an identity assertion based at least in part on the identity certificate; and

providing the identity assertion to a requesting node with which the request to authenticate is associated;

wherein the first device is not managed by an enterprise mobile management server and the second device is managed by the enterprise mobile management server, and

the determination of the identity certificate includes, prior to mapping the unique identity to the managed device: at least one of: sending a verification code to the managed device and generating a verification code at the managed device, and receiving a verification code from the unmanaged device matching the verification code sent to the managed device.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2019
From: VOLKOV, ALEXEI; KARUNAKARAN, KUMARA DAS; PAWAR, VIJAY
To: MOBILEIRON, INC.
Reel/Frame 048784/0976 →
Continuity (3)
Continuation In Part 15595648 · May 15, 2017
Provisional Application 62622715 · Jan 26, 2018
Provisional Application 62336451 · May 13, 2016
Cited By (4)
US 12,218,974 US 12,335,239 US 12,488,121 US 12,531,906