IP Library Granted Patent US 11,620,372
Granted Patent B2
US 11,620,372 · App. 16/906,915 · Granted Apr 4, 2023

Application extension-based authentication on a device under third party management

Inventor: Suresh Kumar Batchu (Campbell, CA)
Assignee: Ivanti, Inc.
G06F21/41G06F21/305G06F21/44G06F21/45G06F21/604H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,620,372
App. No.
16/906,915
Granted
Apr 4, 2023
Kind
B2
Abstract

Techniques are disclosed to provide application extension-based authentication on a device under third party management. In various embodiments, a unique identifier associated with an authentication app is stored on the device. An app extension framework that enables a native app to request, via an app extension associated with the authentication app, access to a service with which the native app is associated is provided. The authentication app is configured to use the unique identifier to determine a security posture of the device and to grant or deny access to the service based at least in part on the security posture of the device.

Claims (32)

1. A device, comprising:

a memory configured to store a unique device identifier associated with an authentication app; and

a processor coupled to the memory and configured to provide an app extension framework that enables a native app to request, via an app extension associated with the authentication app, access to a service with which the native app is associated, the authentication app being configured to use the unique device identifier to determine a security posture of the device and to grant or deny access to the service based at least in part on the security posture of the device;

wherein the authentication app is configured to determine the security posture of the device at least in part by using the unique device identifier to query an access server with which the authentication app is associated; and

wherein the unique device identifier is different from a device vendor-assigned primary device identifier of the device and the access server is configured to map the unique device identifier to the device vendor-assigned primary device identifier of the device; and to use the device vendor-assigned primary device identifier of the device to obtain the security posture of the device from a third party device management server configured to manage the device.

2. The device of claim 1 , wherein the unique device identifier is different from a device vendor-assigned primary device identifier of the device.

3. The device of claim 1 , wherein the unique device identifier comprises a device vendor-assigned primary device identifier of the device.

4. The device of claim 1 , wherein the authentication app is installed on the device by the third party device management server configured to manage the device.

5. The device of claim 4 , wherein the third party device management server is further configured to provide the unique device identifier to the authentication app as installed on the device.

6. The device of claim 1 , wherein the app extension comprises a single sign-on extension.

7. The device of claim 1 , wherein the unique device identifier is different from a device vendor-assigned primary device identifier of the device and an operating system of the device prevents the authentication app from accessing a device vendor-assigned primary device identifier of the device.

8. The device of claim 1 , wherein the processor is further configured to route service access requests generated by the native app to the app extension associated with the authentication app.

9. The device of claim 1 , wherein the security posture is based at least in part on data indicating whether the device has been compromised.

10. The device of claim 1 , wherein the security posture is based at least in part on data indicating whether the service is permitted to be access via the device in a current context associated with the device.

11. The device of claim 1 , wherein the authentication app is configured to grant access at least in part by providing to the native app a token or other access data to access the service.

12. The device of claim 11 , wherein the authentication app receives token or other access data to access the service from an access server with which the authentication app is configured to communicate to determine the security posture of the device.

13. A method, comprising:

storing a unique device identifier associated with an authentication app on a device;

providing an app extension framework that enables a native app to request, via an app extension associated with the authentication app, access to a service with which the native app is associated, the authentication app being configured to use the unique device identifier to determine a security posture of the device and to grant or deny access to the service based at least in part on the security posture of the device;

wherein the authentication app is configured to determine the security posture of the device at least in part by using the unique device identifier to query an access server with which the authentication app is associated; and

wherein the unique device identifier is different from a device vendor-assigned primary device identifier of the device and the access server is configured to map the unique device identifier to the device vendor-assigned primary device identifier of the device; and to use the device vendor-assigned primary device identifier of the device to obtain the security posture of the device from a third party device management server configured to manage the device.

14. The method of claim 13 , wherein the authentication app is installed on the device by the third party device management server configured to manage the device.

15. The method of claim 14 , wherein the third party device management server is further configured to provide the unique device identifier to the authentication app as installed on the device.

16. The method of claim 13 , wherein the authentication app is configured to grant access at least in part by providing to the native app a token or other access data to access the service.

17. The method of claim 16 , wherein the authentication app receives token or other access data to access the service from an access server with which the authentication app is configured to communicate to determine the security posture of the device.

18. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

storing a unique device identifier associated with an authentication app on a device;

providing an app extension framework that enables a native app to request, via an app extension associated with the authentication app, access to a service with which the native app is associated, the authentication app being configured to use the unique device identifier to determine a security posture of the device and to grant or deny access to the service based at least in part on the security posture of the device;

wherein the authentication app is configured to determine the security posture of the device at least in part by using the unique device identifier to query an access server with which the authentication app is associated; and

wherein the unique device identifier is different from a device vendor-assigned primary device identifier of the device and the access server is configured to map the unique device identifier to the device vendor-assigned primary device identifier of the device; and to use the device vendor-assigned primary device identifier of the device to obtain the security posture of the device from a third party device management server configured to manage the device.

19. The computer program product of claim 18 , wherein the authentication app is installed on the device by the third party device management server configured to manage the device.

20. The computer program product of claim 19 , wherein the third party device management server is further configured to provide the unique device identifier to the authentication app as installed on the device.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 064932/0425 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071124/0228 →
SECURITY INTEREST Recorded Sep 18, 2023
From: IVANTI, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 064932/0425 →
SECURITY INTEREST Recorded Sep 18, 2023
From: IVANTI, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 064932/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2020
From: BATCHU, SURESH KUMAR
To: MOBILEIRON, INC.
Reel/Frame 053562/0042 →
Continuity (1)
Related Publication 20210397694A1 · Dec 23, 2021