IP Library Granted Patent US 11,824,859
Granted Patent B2
US 11,824,859 · App. 17/206,269 · Granted Nov 21, 2023

Certificate based profile confirmation

Inventors: Alan Dabbiere (McLean, VA); Erich Stuntebeck (Marietta, GA)
Assignee: AirWatch LLC
H04L63/10G06F21/30G06F21/33G06F21/335G06F21/44G06F21/50G06F21/51G06F21/54H04W12/08H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,824,859
App. No.
17/206,269
Granted
Nov 21, 2023
Kind
B2
Abstract

Disclosed are various embodiments for controlling access to resources in a network environment. Methods may include installing a profile on the device and installing a certificate included in or otherwise associated with the profile on the device. A request to execute an application, and/or access a resource using a particular application, is received and determination is made as to whether the certificate is installed on the device based on an identification of the certificate by the application. If the certificate is installed on the device, then execution of the application and/or access to the resource is allowed. If the certificate is not installed on the device, then the request for execution and/or access is refused.

Claims (37)

1. A method comprising:

receiving, at a device from a remote server, a profile and a certificate that is unique to the profile, the profile specifying mandatory settings for the device, wherein installation of the profile by the device causes the certificate to be accessible by the device;

sending, by the device, a request to perform at least one of utilizing a resource and executing an application; and

receiving, at the device, authorization to perform the at least one of utilizing a resource and executing an application, wherein the authorization is based on:

a determination that the certificate is accessible by the device; and

a determination that the device is compliant with the specified mandatory settings.

2. The method of claim 1 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored on the device.

3. The method of claim 1 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored remotely from the device and associated with the device.

4. The method of claim 1 , wherein one of the mandatory settings includes the device having an embedded certificate installed, the embedded certificate being included in the in the profile.

5. The method of claim 1 , wherein the authorization is further based on verifying that the certificate is valid.

6. The method of claim 1 , wherein the request includes a request by the device to execute the application to utilize the resource.

7. The method of claim 1 , wherein the request further includes a request to provide the application with access to a plurality of additional resources authorized by the certificate in order to provide the application with access to the resource.

8. A non-transitory, computer-readable medium comprising instructions that, when executed by a processor of a device, performs stages comprising:

receiving, at a device from a remote server, a profile and a certificate that is unique to the profile, the profile specifying mandatory settings for the device, wherein installation of the profile by the device causes the certificate to be accessible by the device;

sending, by the device, a request to perform at least one of utilizing a resource and executing an application; and

receiving, at the device, authorization to perform the at least one of utilizing a resource and executing an application, wherein the authorization is based on:

a determination that the certificate is accessible by the device; and

a determination that the device is compliant with the specified mandatory settings.

9. The non-transitory, computer-readable medium of claim 8 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored on the device.

10. The non-transitory, computer-readable medium of claim 8 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored remotely from the device and associated with the device.

11. The non-transitory, computer-readable medium of claim 8 , wherein one of the mandatory settings includes the device having an embedded certificate installed, the embedded certificate being included in the in the profile.

12. The non-transitory, computer-readable medium of claim 8 , wherein the authorization is further based on verifying that the certificate is valid.

13. The non-transitory, computer-readable medium of claim 8 , wherein the request includes a request by the device to execute the application to utilize the resource.

14. The non-transitory, computer-readable medium of claim 8 , wherein the request further includes a request to provide the application with access to a plurality of additional resources authorized by the certificate in order to provide the application with access to the resource.

15. A device, comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

at least one processor that executes the instructions to carry out stages comprising:

receiving, at a device from a remote server, a profile and a certificate that is unique to the profile, the profile specifying mandatory settings for the device, wherein installation of the profile by the device causes the certificate to be accessible by the device;

sending, by the device, a request to perform at least one of utilizing a resource and executing an application; and

receiving, at the device, authorization to perform the at least one of utilizing a resource and executing an application, wherein the authorization is based on:

a determination that the certificate is accessible by the device; and

a determination that the device is compliant with the specified mandatory settings.

16. The device of claim 15 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored on the device.

17. The device of claim 15 , wherein the determination that the certificate is accessible by the device includes determining whether the certificate is stored remotely from the device and associated with the device.

18. The device of claim 15 , wherein one of the mandatory settings includes the device having an embedded certificate installed, the embedded certificate being included in the in the profile.

19. The device of claim 15 , wherein the authorization is further based on verifying that the certificate is valid.

20. The device of claim 15 , wherein the request includes a request by the device to execute the application to utilize the resource.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (4)
Continuation 16749937 · Jan 22, 2020
Continuation 15800224 · Nov 1, 2017
Continuation 13835542 · Mar 15, 2013
Related Publication 20210211429A1 · Jul 8, 2021