IP Library Granted Patent US 49,585
Granted Patent E1
US 49,585 · App. 17/109,950 · Granted Jul 18, 2023

Certificate based profile confirmation

Inventors: Alan Dabbiere (McLean, VA); Erich Stuntebeck (Marietta, GA)
Assignee: AIRWATCH LLC
H04L63/10G06F21/30G06F21/33G06F21/335G06F21/44G06F21/50G06F21/51G06F21/54H04W12/08H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 49,585
App. No.
17/109,950
Granted
Jul 18, 2023
Kind
E1
Abstract

Disclosed are various embodiments for controlling access to resources in a network environment. Methods may include installing a profile on the device and installing a certificate included in or otherwise associated with the profile on the device. A request to execute an application, and/or access a resource using a particular application, is received and determination is made as to whether the certificate is installed on the device based on an identification of the certificate by the application. If the certificate is installed on the device, then execution of the application and/or access to the resource is allowed. If the certificate is not installed on the device, then the request for execution and/or access is refused.

Claims (49)

1. A method for managing a device, comprising:

sending, to the device from a remote server, a profile specifying that an application installed on the device is authorized to execute on the device and authorized to access a resource, wherein the profile comprises a certificate that uniquely identifies the profile from another profile;

receiving, at the remote server, a request from the application installed on the device to access the resource, the request including the certificate;

verifying that the certificate is valid;

identifying the resource based on a resource grouping identifier that is associated with a pairing of the profile and the certificate; and

if the certificate is valid, providing the application with access to the resource; and, wherein providing the application with access to the resource further comprises providing the application with access to a plurality of additional resources authorized by the certificate.

2. The method of claim 1 , further comprising: if the certificate is not valid, determining, in a subsequent verification, that the certificate is no longer valid, and denying access to the resource.

3. The method of claim 1 , further comprising: if the certificate is not valid, determining, in a subsequent verification, that the certificate is no longer valid, and initiating a remedial measure defined by the profile.

4. The method of claim 3 , wherein the remedial measure is one of at least:

causing the device to delete any resources originally accessed using the certificate;

disabling an enterprise application;

sending an alert to the device alerting a user of the device that access was denied;

sending an alert to an administrator; and

pursuing an alternate validation method.

5. The method of claim 1 , wherein the profile is uniquely associated with the application.

6. The method of claim 1 , wherein providing the application with access to the resource further comprises locating the resource and transmitting the resource to the device.

7. A non-transitory, computer-readable medium comprising instructions that, when executed by a processor of a remote server, performs stages for managing a device, the stages comprising:

sending, to the device from the remote server, a profile specifying that an application installed on the device is authorized to execute on the device and authorized to access a resource, wherein the profile comprises a certificate that uniquely identifies the profile from another profile;

receiving, at the remote server, a request from the application installed on the device to access the resource, the request including the certificate;

verifying that the certificate is valid;

identifying the resource based on a resource grouping identifier that is associated with a pairing of a user credential and a device identifier of the device; and

if the certificate is valid, providing the application with access to the resource; and, wherein providing the application with access to the resource further comprises providing the application with access to a plurality of additional resources authorized by the certificate.

8. The non-transitory, computer-readable medium of claim 7 , the stages further comprising: if the certificate is not valid, determining, in a subsequent verification, that the certificate is no longer valid, and denying access to the resource.

9. The non-transitory, computer-readable medium of claim 7 , the stages further comprising: if the certificate is not valid, determining, in a subsequent verification, that the certificate is no longer valid, and initiating a remedial measure defined by the profile.

10. The non-transitory, computer-readable medium of claim 9 , wherein the remedial measure is one of at least:

causing the device to delete any resources originally accessed using the certificate;

disabling an enterprise application;

sending an alert to the device alerting a user of the device that access was denied;

sending an alert to an administrator; and

pursuing an alternate validation method.

11. The non-transitory, computer-readable medium of claim 7 , wherein the profile is uniquely associated with the application.

12. The non-transitory, computer-readable medium of claim 7 , wherein providing the application with access to the resource further comprises locating the resource and transmitting the resource to the device.

13. A server, comprising:

a memory storage storing program code; and

a processor coupled to the memory storage, wherein, upon execution, the program code causes the processor to:

send, to a device from the server, a profile specifying that an application installed on the device is authorized to execute on the device and authorized to access a resource, wherein the profile comprises a certificate that uniquely identifies the profile from another profile;

receive a request, from the application installed on the device, to access the resource, the request including the certificate;

verify that the certificate is valid;

identify the resource based on a resource grouping identifier that is associated with a pairing of the profile and the certificate; and

if the certificate is valid, provide the application with access to the resource; and, wherein providing the application with access to the resource further comprises providing the application with access to a plurality of additional resources authorized by the certificate.

14. The server of claim 13 , wherein the program code causes the processor to, if the certificate is not valid, determine, in a subsequent verification, that the certificate is no longer valid, and deny access to the resource.

15. The server of claim 13 , wherein the program code causes the processor to, if the certificate is not valid, determine, in a subsequent verification, that the certificate is no longer valid, and initiate a remedial measure defined by the profile.

16. The server of claim 15 , wherein the remedial measure is one of at least:

causing the device to delete any resources originally accessed using the certificate;

disabling an enterprise application;

sending an alert to the device alerting a user of the device that access was denied;

sending an alert to an administrator; and

pursuing an alternate validation method.

17. The server of claim 13 , wherein the profile is uniquely associated with the application.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →