IP Library Granted Patent US 11,792,203
Granted Patent B2
US 11,792,203 · App. 17/509,405 · Granted Oct 17, 2023

Systems and methods for controlling email access

Inventors: Saravanan Pitchaimani (Atlanta, GA); Vijay Pitchumani Kodaganallur (Atlanta, GA); Craig Newell (Atlanta, GA)
Assignee: VMware, Inc.
H04L63/102H04L63/083H04L63/0807H04L63/0884H04L63/18H04L67/10H04L67/125H04L67/146H04L67/53H04W12/084H04W12/37H04L12/66H04L51/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,203
App. No.
17/509,405
Granted
Oct 17, 2023
Kind
B2
Abstract

Examples described herein include systems and methods for controlling access to a server, such as an email server or a gateway, in situations where the identity of the requesting device is unknown or where the user device accesses the server using an unknown or unmanaged application. In one example, the system can utilize a user authentication credential included in the request to identify other devices belonging to the user that happen to be enrolled with the system. An out-of-band message can be sent to those enrolled devices, requesting confirmation from the user and, in conjunction with an authentication token, allowing the system to trust the previously unknown device. In the example of an unmanaged application attempting to access an email server, the system can confirm compliance of the requesting device and issue an authentication token that, along with an appropriate command sent to the email server, provides access.

Claims (35)

1. A method for obtaining access to an email server using first and second user devices of a user, comprising:

sending, from the first user device to a gateway server, a request for access to an email server, wherein the gateway server has privileged access to the email server and routes emails to and from the email server, and wherein the request includes a user authentication credential associated with the user, a device identifier associated with the user device, and an application identifier associated with an email application being used to request access;

receiving, at the second user device from an out-of-band communication module separate from the gateway server, a message requesting confirmation from the user regarding the request for access sent by the first user device;

providing, from the second user device to the out-of-band communication module, a confirmation in response to the message;

receiving, at the first user device, an authentication token, wherein the authentication token is specific to the first user device, the user, and the email application; and

accessing the email server with the first user device using the authentication token.

2. The method of claim 1 , wherein the authentication token is received from the out-of-band communication module.

3. The method of claim 1 , wherein the authentication token is received from the gateway server.

4. The method of claim 1 , wherein providing the confirmation by the second user device causes a database to be updated with information regarding the authentication token and the associated user device, user, and application.

5. The method of claim 1 , wherein the request for access is sent in response to the user operating the email application on the first user device.

6. The method of claim 1 , wherein the message requesting confirmation is sent by the out-of-band communication module in an instance where the device identifier associated with the first user device is not present on a list of device identifiers approved for access to the email server.

7. The method of claim 1 , wherein the out-of-band communication module executes on the gateway server.

8. A non-transitory, computer-readable medium comprising instructions that, when executed by processors associated with a first user device and a second user device, cause the processors to perform stages for obtaining access to an email server using the first and second user devices of a user, the stages comprising:

sending, from the first user device to a gateway server, a request for access to an email server, wherein the gateway server has privileged access to the email server and routes emails to and from the email server, and wherein the request includes a user authentication credential associated with the user, a device identifier associated with the user device, and an application identifier associated with an email application being used to request access;

receiving, at the second user device from an out-of-band communication module separate from the gateway server, a message requesting confirmation from the user regarding the request for access sent by the first user device;

providing, from the second user device to the out-of-band communication module, a confirmation in response to the message;

receiving, at the first user device, an authentication token, wherein the authentication token is specific to the first user device, the user, and the email application; and

accessing the email server with the first user device using the authentication token.

9. The non-transitory, computer-readable medium of claim 8 , wherein the authentication token is received from the out-of-band communication module.

10. The non-transitory, computer-readable medium of claim 8 , wherein the authentication token is received from the gateway server.

11. The non-transitory, computer-readable medium of claim 8 , wherein providing the confirmation by the second user device causes a database to be updated with information regarding the authentication token and the associated user device, user, and application.

12. The non-transitory, computer-readable medium of claim 8 , wherein the request for access is sent in response to the user operating the email application on the first user device.

13. The non-transitory, computer-readable medium of claim 8 , wherein the message requesting confirmation is sent by the out-of-band communication module in an instance where the device identifier associated with the first user device is not present on a list of device identifiers approved for access to the email server.

14. The non-transitory, computer-readable medium of claim 8 , wherein the out-of-band communication module executes on the gateway server.

15. A system for obtaining access to an email server, the system comprising a first user device and a second user device of a user, wherein the system performs stages comprising:

sending, from the first user device to a gateway server, a request for access to an email server, wherein the gateway server has privileged access to the email server and routes emails to and from the email server, and wherein the request includes a user authentication credential associated with the user, a device identifier associated with the user device, and an application identifier associated with an email application being used to request access;

receiving, at the second user device from an out-of-band communication module separate from the gateway server, a message requesting confirmation from the user regarding the request for access sent by the first user device;

providing, from the second user device to the out-of-band communication module, a confirmation in response to the message;

receiving, at the first user device, an authentication token, wherein the authentication token is specific to the first user device, the user, and the email application; and

accessing the email server with the first user device using the authentication token.

16. The system of claim 15 , wherein the authentication token is received from the out-of-band communication module.

17. The system of claim 15 , wherein the authentication token is received from the gateway server.

18. The system of claim 15 , wherein providing the confirmation by the second user device causes a database to be updated with information regarding the authentication token and the associated user device, user, and application.

19. The system of claim 15 , wherein the request for access is sent in response to the user operating the email application on the first user device.

20. The system of claim 15 , wherein the message requesting confirmation is sent by the out-of-band communication module in an instance in which the device identifier associated with the first user device is not present on a list of device identifiers approved for access to the email server.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (3)
Continuation 16591242 · Oct 2, 2019
Continuation 15664729 · Jul 31, 2017
Related Publication 20220046025A1 · Feb 10, 2022