IP Library Granted Patent US 12,531,906
Granted Patent B2
US 12,531,906 · App. 17/726,592 · Granted Jan 20, 2026

Securing web browsing on a managed user device

Inventors: Rohit Pradeep Shetty (Bangalore, IN); Ramanandan Nambannor Kunnath (Bangalore, IN); Kar-Fai Tse (Atlanta, GA)
Assignee: Omnissa, LLC
H04L63/20H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,531,906
App. No.
17/726,592
Granted
Jan 20, 2026
Kind
B2
Abstract

Systems and methods are described for increasing web browser security on a user device managed by a device management system. In an example, the user device can use an unmanaged web browser to access secure enterprise content using a browser extension provided by the enterprise. When a user attempts to access secure content from an unmanaged browser, the device management system can communicate with the extension and a management application on the user device to authenticate the user and verify that the user device complies with certain policies. In one example, the device management system can include an extension recommendation engine that analyzes user browsing data and recommends browser extensions for the user. Based on policies, the device management system can recommend the extension to the user or force installation of the extension on the user device.

Claims (43)

1 . A method for browser agnostic policy enforcement, comprising:

receiving a request for secure content from a browser on a user device, wherein the user device is enrolled for management with a management server;

identifying, at the management server, a resource-specific policy for the secure content;

determining that the browser is not managed by the management server;

in response to determining that the browser is not managed by the management server, verifying that the browser includes a managed extension installed thereon that is managed by the management server;

sending, to the managed extension of the browser, a redirect Uniform Resource Locator (“URL”) and an access token for retrieving the resource-specific policy;

receiving a call back from the managed extension at the redirect URL; and

sending the secure content to the browser for display in accordance with the resource-specific policy, wherein the managed extension enforces the resource-specific policy on the secure content upon displaying the secure content on the browser.

2 . The method of claim 1 , wherein the request for secure content is redirected for purposes of user authentication at the management server prior to the management server identifying the resource-specific policy.

3 . The method of claim 1 , wherein enforcing the resource-specific policy includes intercepting the secure content and applying at least one modification prior to displaying the secure content on the browser.

4 . The method of claim 1 , wherein the call back is received in an instance where the managed extension enforces at least a portion of the resource-specific policy prior to calling back.

5 . The method of claim 1 , wherein the call back includes the access token.

6 . The method of claim 1 , further comprising sending the resource-specific policy to the managed extension of the browser in an instance where the access token is received by the management server from the managed extension.

7 . The method of claim 1 , further comprising sending a user-specific profile to the managed extension, wherein a policy from the user-specific profile is applied to the secure content in addition to the resource-specific policy.

8 . A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, cause the processor to perform stages for browser agnostic policy enforcement, the stages comprising:

receiving a request for secure content from a browser on a user device, wherein the user device is enrolled for management with a management server;

identifying, at the management server, a resource-specific policy for the secure content;

determining that the browser is not managed by the management server;

in response to determining that the browser is not managed by the management server, verifying that the browser includes a managed extension installed thereon that is managed by the management server;

sending, to the managed extension of the browser, a redirect Uniform Resource Locator (“URL”) and an access token for retrieving the resource-specific policy;

receiving a call back from the managed extension at the redirect URL; and

sending the secure content to the browser for display in accordance with the resource-specific policy, wherein the managed extension enforces the resource-specific policy on the secure content upon displaying the secure content on the browser.

9 . The non-transitory, computer-readable medium of claim 8 , wherein the request for secure content is redirected for purposes of user authentication at the management server prior to the management server identifying the resource-specific policy.

10 . The non-transitory, computer-readable medium of claim 8 , wherein enforcing the resource-specific policy includes intercepting the secure content and applying at least one modification prior to displaying the secure content on the browser.

11 . The non-transitory, computer-readable medium of claim 8 , wherein the call back is received in an instance where the managed extension enforces at least a portion of the resource-specific policy prior to calling back.

12 . The non-transitory, computer-readable medium of claim 8 , wherein the call back includes the access token.

13 . The non-transitory, computer-readable medium of claim 8 , the stages further comprising sending the resource-specific policy to the managed extension of the browser in an instance where the access token is received by the management server from the managed extension.

14 . The non-transitory, computer-readable medium of claim 8 , the stages further comprising sending a user-specific profile to the managed extension, wherein a policy from the user-specific profile is applied to the secure content in addition to the resource-specific policy.

15 . A system for browser agnostic policy enforcement, comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

at least one hardware-based processor that executes the instructions to carry out stages comprising:

receiving a request for secure content from a browser on a user device, wherein the user device is enrolled for management with a management server;

identifying, at a management server, a resource-specific policy for the secure content;

determining that the browser is not managed by the management server;

in response to determining that the browser is not managed by the management server, verifying that the browser includes a managed extension installed thereon that is managed by the management server;

sending, to the managed extension of the browser, a redirect Uniform Resource Locator (“URL”) and an access token for retrieving the resource-specific policy;

receiving a call back from the managed extension at the redirect URL; and

sending the secure content to the browser for display in accordance with the resource-specific policy, wherein the managed extension enforces the resource-specific policy on the secure content upon displaying the secure content on the browser.

16 . The system of claim 15 , wherein the request for secure content is redirected for purposes of user authentication at the management server prior to the management server identifying the resource-specific policy.

17 . The system of claim 15 , wherein enforcing the resource-specific policy includes intercepting the secure content and applying at least one modification prior to displaying the secure content on the browser.

18 . The system of claim 15 , wherein the call back is received in an instance where the managed extension enforces at least a portion of the resource-specific policy prior to calling back.

19 . The system of claim 15 , wherein the call back includes the access token.

20 . The system of claim 15 , the stages further comprising sending a user-specific profile to the managed extension, wherein a policy from the user-specific profile is applied to the secure content in addition to the resource-specific policy.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2022
From: SHETTY, ROHIT PRADEEP; NAMBANNOR KUNNATH, RAMANANDAN; TSE, KAR-FAI
To: VMWARE, INC.
Reel/Frame 059673/0368 →
Priority Claims (1)
IN 202241003570 · Jan 21, 2022 · national
Continuity (1)
Related Publication 20230275927A1 · Aug 31, 2023
References Cited (19)
US 7509679B2 · Alagna et al. · 2009 [cited by applicant]
US 9921976B2 · Linga · 2018 [cited by examiner]
US 10523660B1 · Volkov et al. · 2019 [cited by applicant]
US 11088993B2 · Wardell · 2021 [cited by examiner]
US 20140297861A1 · Qureshi · 2014 [cited by applicant]
US 20160094612A1 · Lockhart et al. · 2016 [cited by applicant]
US 20160241599A1 · Qureshi · 2016 [cited by applicant]
US 20180352002A1 · Ramachandran · 2018 [cited by examiner]
US 20200019414A1 · Byard et al. · 2020 [cited by applicant]
US 20200050431A1 · Zilouchian Moghaddam et al. · 2020 [cited by applicant]
US 20210081486A1 · Mattox, Jr. et al. · 2021 [cited by applicant]
US 20210126910A1 · Chauhan et al. · 2021 [cited by applicant]
US 20210135869A1 · Barhudarian · 2021 [cited by examiner]
US 20210266306A1 · Furman et al. · 2021 [cited by applicant]
US 20210336966A1 · Gujarathi et al. · 2021 [cited by applicant]
Non-Final Office Action mailed May 22, 2024 in U.S. Appl. No. 17/726,566, 9 pages. [cited by applicant]
Non-Final Office Action mailed Jun. 21, 2024 in U.S. Appl. No. 17/726,574, 14 pages. [cited by applicant]
Final Office Action mailed Jan. 13, 2025 in U.S. Appl. No. 17/726,574, 25 pages. [cited by applicant]
Notice of Allowance mailed Sep. 27, 2024 in U.S. Appl. No. 17/726,566, 10 pages. [cited by applicant]