IP Library Granted Patent US 12,218,974
Granted Patent B2
US 12,218,974 · App. 17/726,566 · Granted Feb 4, 2025

Securing web browsing on a managed user device

Inventors: Rohit Pradeep Shetty (Bangalore, IN); Ramanandan Nambannor Kunnath (Bangalore, IN); Kar-Fai Tse (Atlanta, GA)
Assignee: Omnissa, LLC
H04L63/166H04L9/3228H04L63/0807H04L67/02H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,974
App. No.
17/726,566
Granted
Feb 4, 2025
Kind
B2
Abstract

Systems and methods are described for increasing web browser security on a user device managed by a device management system. In an example, the user device can use an unmanaged web browser to access secure enterprise content using a browser extension provided by the enterprise. When a user attempts to access secure content from an unmanaged browser, the device management system can communicate with the extension and a management application on the user device to authenticate the user and verify that the user device complies with certain policies. In one example, the device management system can include an extension recommendation engine that analyzes user browsing data and recommends browser extensions for the user. Based on policies, the device management system can recommend the extension to the user or force installation of the extension on the user device.

Claims (53)

1. A method for accessing secure content from an unmanaged web browser on a managed user device, comprising:

sending, from the unmanaged browser to a server, a request for secure content, wherein the server is part of a unified endpoint management (UEM) system to which the managed user device is enrolled, and wherein a managed browser extension is installed on the unmanaged browser, the managed browser extension being managed by the UEM system;

prompting a user for authentication credentials in an instance where the request is redirected to an identity manager;

when the credentials are authenticated, receiving, by the managed browser extension installed on the unmanaged browser, a first session token and a temporary token from the server or the identity manager;

sending the first session token and the temporary token from the managed browser extension to a managed application on the managed user device;

validating, by the managed application at the managed user device, that the first session token was received from a trusted source;

sending the first session token, temporary token, and a second session token to the server, the second session token having been obtained by the managed application upon enrollment of the managed device with the UEM system; and

receiving authorization to access the secure content.

2. The method of claim 1 , wherein receiving the first session token and the temporary token includes decrypting, by the managed browser extension, the first session token and the temporary token.

3. The method of claim 1 , wherein the method further comprises, prior to sending the first session token, the temporary token, and the second session token to the server:

prompting the user to enter a passcode;

receiving the passcode from user input; and

verifying that the passcode matches a passcode previously provided by the user.

4. The method of claim 1 , wherein the temporary token expires after a predetermined amount of time.

5. The method of claim 1 , wherein the method further comprises, prior to receiving authorization to access the secure content:

verifying that the managed user device is compliant with a set of policies; and

sending, to the server, a notification that the managed user device is compliant, wherein receiving authorization to access the secure content is dependent on the managed user device being compliant.

6. A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, causes the processor to perform stages for accessing secure content from an unmanaged web browser on a managed user device, the stages comprising:

sending, from the unmanaged browser to a server, a request for secure content, wherein the server is part of a unified endpoint management (UEM) system to which the managed user device is enrolled, and wherein a managed browser extension is installed on the unmanaged browser, the managed browser extension being managed by the UEM system;

prompting a user for authentication credentials in an instance where the request is redirected to an identity manager;

when the credentials are authenticated, receiving, by the managed browser extension installed on the unmanaged browser, a first session token and a temporary token from the server or the identity manager;

sending the first session token and the temporary token from the managed browser extension to a managed application on the managed user device;

validating, by the managed application at the managed user device, that the first session token was received from a trusted source;

sending the first session token, temporary token, and a second session token to the server, the second session token having been obtained by the managed application upon enrollment of the managed device with the UEM system; and

receiving authorization to access the secure content.

7. The non-transitory, computer-readable medium of claim 6 , wherein receiving the first session token and the temporary token includes decrypting, by the managed browser extension, the first session token and the temporary token.

8. The non-transitory, computer-readable medium of claim 6 , wherein the stages further comprise, prior to sending the first session token, the temporary token, and the second session token to the server:

prompting the user to enter a passcode;

receiving the passcode from user input; and

verifying that the passcode matches a passcode previously provided by the user.

9. The non-transitory, computer-readable medium of claim 6 , wherein the temporary token expires after a predetermined amount of time.

10. The non-transitory, computer-readable medium of claim 6 , wherein the stages further comprise, prior to receiving authorization to access the secure content:

verifying that the managed user device is compliant with a set of policies; and

sending, to the server, a notification that the managed user device is compliant, wherein receiving authorization to access the secure content is dependent on the managed user device being compliant.

11. A system for accessing secure content from an unmanaged web browser on a managed user device, comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

a hardware-based processor that executes the instructions to carry out stages comprising:

sending, from the unmanaged browser to a server, a request for secure content, wherein the server is part of a unified endpoint management (UEM) system to which the managed user device is enrolled, and wherein a managed browser extension is installed on the unmanaged browser, the managed browser extension being managed by the UEM system;

prompting a user for authentication credentials in an instance where the request is redirected to an identity manager;

when the credentials are authenticated, receiving, by the managed browser extension installed on the unmanaged browser, a first session token and a temporary token from the server or the identity manager;

sending the first session token and the temporary token from the managed browser extension to a managed application on the managed user device;

validating, by the managed application at the managed user device, that the first session token was received from a trusted source;

sending the first session token, temporary token, and a second session token to the server, the second session token having been obtained by the managed application upon enrollment of the managed device with the UEM system; and

receiving authorization to access the secure content.

12. The system of claim 11 , wherein receiving the first session token and the temporary token includes decrypting, by the managed browser extension, the first session token and the temporary token.

13. The system of claim 11 , wherein the stages further comprise, prior to sending the first session token, the temporary token, and the second session token to the server:

prompting the user to enter a passcode;

receiving the passcode from user input; and

verifying that the passcode matches a passcode previously provided by the user.

14. The system of claim 11 , wherein the temporary token expires after a predetermined amount of time.

15. The method of claim 1 , wherein the managed browser extension is downloaded from the UEM management system by the managed application and installed in the unmanaged web browser on the managed user device in response to instructions received by the managed application from the UEM system.

16. The non-transitory, computer-readable medium of claim 6 , wherein the managed browser extension is downloaded from the UEM management system by the managed application and installed in the unmanaged web browser on the managed user device in response to instructions received by the managed application from the UEM system.

17. The system of claim 11 , wherein the managed browser extension is downloaded from the UEM management system by the managed application and installed in the unmanaged web browser on the managed user device in response to instructions received by the managed application from the UEM system.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2022
From: SHETTY, ROHIT PRADEEP; NAMBANNOR KUNNATH, RAMANANDAN; TSE, KAR-FAI
To: VMWARE, INC.
Reel/Frame 059673/0040 →
Priority Claims (1)
IN 202241003563 · Jan 21, 2022 · national
Continuity (1)
Related Publication 20230239324A1 · Jul 27, 2023
References Cited (11)
US 7509679B2 · Alagna et al. · 2009 [cited by applicant]
US 10523660B1 · Volkov · 2019 [cited by examiner]
US 20140297861A1 · Qureshi · 2014 [cited by examiner]
US 20160094612A1 · Lockhart et al. · 2016 [cited by applicant]
US 20160241599A1 · Qureshi · 2016 [cited by examiner]
US 20200019414A1 · Byard et al. · 2020 [cited by applicant]
US 20200050431A1 · Zilouchian Moghaddam et al. · 2020 [cited by applicant]
US 20210126910A1 · Chauhan · 2021 [cited by examiner]
US 20210266306A1 · Furman · 2021 [cited by examiner]
US 20210336966A1 · Gujarathi · 2021 [cited by examiner]
Non-Final Office Action mailed Jun. 21, 2024 in U.S. Appl. No. 17/726,574, 14 pages. [cited by applicant]