IP Library Granted Patent US 11,570,160
Granted Patent B2
US 11,570,160 · App. 17/036,297 · Granted Jan 31, 2023

Securely authorizing access to remote resources

Inventor: Jonathan Blake Brannon (Mableton, GA)
Assignee: AirWatch, LLC
H04L63/062H04L63/08H04L63/0823H04L63/10H04L63/102H04W12/088H04L63/0892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,160
App. No.
17/036,297
Granted
Jan 31, 2023
Kind
B2
Abstract

Methods and an apparatus are provided for securely authorizing access to remote resources. For example, a method is provided that includes receiving a request to determine whether a user device communicatively coupled to a resource server is authorized to access at least one resource hosted by the resource server and determining whether the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server based at least in part on whether the user device communicatively coupled to the resource server has been issued a management identifier. The method further includes providing a response indicating that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server. The method yet further includes providing a response indicating that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server.

Claims (36)

1. A method for repository access authorization, comprising:

receiving, from a user device, a request to access a content repository;

determining, by a management server, that the user device is managed by associating the user device with a management record;

determining, by the management server, whether the mobile device is in compliance with a configuration profile received by the user device from the management server, wherein the compliance is checked in association with receiving the access request; and

granting access to the content repository based on a determination that the user device is compliant with the configuration profile.

2. The method of claim 1 , wherein the management server determines that the user device is managed based on a certificate received with the request to access the content repository.

3. The method of claim 1 , wherein the request further comprises a management identifier for determining the user device is managed and authentication credentials for accessing the content repository.

4. The method of claim 1 , further comprising:

determining a subset of content for which access should be granted based on the management record and compliance with the configuration profile.

5. The method of claim 1 , wherein the access request further comprises an address of the management server.

6. The method of claim 5 , wherein the content repository uses the address to send a management identifier to the management server, wherein the management server uses the management identifier to associate the user device with a management record.

7. The method of claim 1 , wherein granting access to the content repository is preconditioned on bringing the mobile device into compliance with an encryption policy.

8. A non-transitory, computer-readable medium comprising instructions which, when executed by a processor, perform stages for authorizing access, the stages comprising:

receiving, from a user device, a request to access a content repository;

determining, by a management server, the user device is managed by associating the user device with a management record;

determining, by the management server, whether the mobile device is in compliance with a configuration profile received from the management service, wherein the compliance is checked in association with receiving the access request; and

granting access to the content repository based on a determination that the user device is compliant with the configuration profile.

9. The non-transitory, computer-readable medium of claim 8 , wherein the management server determines the user device is managed based on a certificate received with the request to access content.

10. The non-transitory, computer-readable medium of claim 8 , wherein the request further comprises a management identifier for determining the user device is managed and authentication credentials for accessing the content repository.

11. The non-transitory, computer-readable medium of claim 8 , the stages further comprising:

determining a subset of content for which access should be granted based on the management record and compliance with the configuration profile.

12. The non-transitory, computer-readable medium of claim 8 , wherein the access request further comprises an address of the management server.

13. The non-transitory, computer-readable medium of claim 12 , wherein the content repository uses the address to send a management identifier to the management server, wherein the management server uses the management identifier to associate the user device with a management record.

14. The non-transitory, computer-readable medium of claim 8 , wherein granting access to the content repository is preconditioned on bringing the mobile device into compliance with an encryption policy.

15. A system for authorizing access, comprising:

a content repository; and

a management server, the management server performing stages comprising:

receiving, from a user device, a request to access the content repository;

determining the user device is managed by associating the user device with a management record;

determining whether the mobile device is in compliance with a configuration profile received from the management service, wherein the compliance is checked in association with receiving the access request; and

granting access to the content repository based on a determination that the user device is compliant with the configuration profile.

16. The system of claim 15 , wherein the management server determines the user device is managed based on a certificate received with the request to access content.

17. The system of claim 15 , wherein the request further comprises a management identifier for determining the user device is managed and authentication credentials for accessing the content repository.

18. The system of claim 15 , wherein the access request further comprises an address of the management server.

19. The system of claim 18 , wherein the content repository uses the address to send a management identifier to the management server, wherein the management server uses the management identifier to associate the user device with a management record.

20. The system of claim 15 , wherein granting access to the content repository is preconditioned on bringing the mobile device into compliance with an encryption policy.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (5)
Continuation 16377290 · Apr 8, 2019
Continuation 15708136 · Sep 19, 2017
Continuation 14927504 · Oct 30, 2015
Continuation 14033682 · Sep 23, 2013
Related Publication 20210014208A1 · Jan 14, 2021