IP Library Granted Patent US 12,218,952
Granted Patent B2
US 12,218,952 · App. 18/108,566 · Granted Feb 4, 2025

Peer-to-peer offline access mode

Inventors: Ramanandan Nambannor Kunnath (Bangalore, IN); Rohit Pradeep Shetty (Bangalore, IN)
Assignee: Omnissa, LLC
H04L63/108H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,952
App. No.
18/108,566
Granted
Feb 4, 2025
Kind
B2
Abstract

Disclosed are various embodiments for enabling an enrolled client device of a user to access an enterprise resource via a second enrolled client device of the user. One such method comprises launching, by the first client device, a peer-to-peer communication channel between the first client device and a second client device of the user that is online with the management server; transmitting, by the first client device, a peer-to-peer offline access mode request over the peer-to-peer communication channel for the first client device to be given access to an enterprise resource that is being managed by the management server, wherein the request includes instructions for the second client device to forward the request to the management server, wherein the request further includes enterprise resource identification and verification data showing that the first client device is in compliance with a compliancy policy of the management service.

Claims (38)

1. A system comprising:

a first client device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the first client device to at least:

detect that the first client device of a user is in an offline state, wherein the first client device is not currently communicatively coupled to a management server, wherein the first client device is enrolled with a management service hosted by the management server;

detect that a second client device of the user is in an online state, wherein the second client device is currently communicatively coupled to the management server, wherein the second client device is enrolled with the management service hosted by the management server;

launch a peer-to-peer communication channel between the first client device and the second client device of the user;

transmit a peer-to-peer offline access mode request over the peer-to-peer communication channel for the first client device to be given access to an enterprise resource that is being managed by the management server, wherein the request includes instructions for the second client device to forward the request to the management server, wherein the request further includes enterprise resource identification and verification data showing that the first client device is in compliance with a compliance policy of the management service; and

receive a special access token over the peer-to-peer communication channel, wherein the special access token is provided by the management server and enables the first client device access to the enterprise resource.

2. The system of claim 1 , wherein the verification data comprises heartbeat information for the first client device and interrogation information.

3. The method of claim 2 , wherein the verification data includes a time-based session token.

4. The system of claim 1 , wherein the compliance policy comprises a rule requiring that the first client device needs to be communicatively coupled to the management service before access can be granted to the enterprise resource.

5. The system of claim 1 , wherein the machine-readable instructions further cause the first client device to encrypt a payload of the peer-to-peer offline access mode request with a private key of the first client device.

6. The system of claim 1 , wherein the special access token is time-limited and is set to expire after a defined time period.

7. The system of claim 1 , wherein the enterprise resource comprises a data file stored in a data store remote from the first client application, a client application of the first client device, or a client application of the second client device.

8. A method, comprising:

detecting, by a first client device, that the first client device of a user is in an offline state, wherein the first client device is not currently communicatively coupled to a management server, wherein the first client device is enrolled with a management service hosted by the management server;

detecting, by the first client device, that a second client device of the user is in an online state, wherein the second client device is currently communicatively coupled to the management server, wherein the second client device is enrolled with the management service hosted by the management server;

launching, by the first client device, a peer-to-peer communication channel between the first client device and the second client device of the user;

transmitting, by the first client device, a peer-to-peer offline access mode request over the peer-to-peer communication channel for the first client device to be given access to an enterprise resource that is being managed by the management server, wherein the request includes instructions for the second client device to forward the request to the management server, wherein the request further includes enterprise resource identification and verification data showing that the first client device is in compliance with a compliance policy of the management service; and

receiving, by the first client device, a special access token over the peer-to-peer communication channel, wherein the special access token is provided by the management server and enables the first client device access to the enterprise resource; and

accessing, by the first client device, the enterprise resource using the special access token.

9. The method of claim 8 , wherein the verification data comprises heartbeat information for the first client device, and interrogation information.

10. The method of claim 9 , wherein the verification data includes a time-based session token.

11. The method of claim 8 , wherein the compliance policy comprises a rule requiring that the first client device needs to be communicatively coupled to the management service before access can be granted to the enterprise resource.

12. The method of claim 8 , further comprising encrypting a payload of the peer-to-peer offline access mode request with a private key of the first client device.

13. The method of claim 8 , wherein the special access token is time-limited and is set to expire after a defined time period.

14. The method of claim 8 , wherein the enterprise resource comprises a data file stored in a data store remote from the first client application, a client application of the first client device, or a client application of the second client device.

15. A non-transitory, computer-readable medium, comprising machine-readable instructions that, when executed by a processor of a first client device, cause the first client device to at least:

detect that the first client device of a user is in an offline state, wherein the first client device is not currently communicatively coupled to a management server, wherein the first client device is enrolled with a management service hosted by the management server;

detect that a second client device of the user is in an online state, wherein the second client device is currently communicatively coupled to the management server, wherein the second client device is enrolled with the management service hosted by the management server;

launch a peer-to-peer communication channel between the first client device and the second client device of the user;

transmit a peer-to-peer offline access mode request over the peer-to-peer communication channel for the first client device to be given access to an enterprise resource that is being managed by the management server, wherein the request includes instructions for the second client device to forward the request to the management server, wherein the request further includes enterprise resource identification and verification data showing that the first client device is in compliance with a compliance policy of the management service; and

receive a special access token over the peer-to-peer communication channel, wherein the special access token is provided by the management server and enables the first client device access to the enterprise resource.

16. The non-transitory, computer-readable medium of claim 15 , wherein the verification data comprises heartbeat information for the first client device, and interrogation information.

17. The non-transitory, computer-readable medium of claim 16 , wherein the verification data includes a time-based session token.

18. The non-transitory, computer-readable medium of claim 15 , wherein the compliance policy comprises a rule requiring that the first client device needs to be communicatively coupled to the management service before access can be granted to the enterprise resource.

19. The non-transitory, computer-readable medium of claim 15 , wherein the machine-readable instructions further cause the first client device to encrypt a payload of the peer-to-peer offline access mode request with a private key of the first client device.

20. The non-transitory, computer-readable medium of claim 15 , wherein the special access token is time-limited and is set to expire after a defined time period.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 25, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067239/0402 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: NAMBANNOR KUNNATH, RAMANANDAN; SHETTY, ROHIT PRADEEP
To: VMWARE, INC.
Reel/Frame 062663/0784 →
Priority Claims (1)
IN 202241074214 · Dec 21, 2022 · national
Continuity (1)
Related Publication 20240214388A1 · Jun 27, 2024
References Cited (9)
US 11582201B1 · Moon · 2023 [cited by examiner]
US 20150089571A1 · Srinivasan · 2015 [cited by examiner]
US 20150256545A1 · Dotterer, III · 2015 [cited by examiner]
US 20180336334A1 · Yadav · 2018 [cited by examiner]
US 20180351938A1 · Vongsouvanh · 2018 [cited by examiner]
US 20230231909A1 · Moon · 2023 [cited by examiner]
US 20240137358A1 · Nambannor Kunnath · 2024 [cited by examiner]
US 20240214221A1 · Nambannor Kunnath · 2024 [cited by examiner]
US 20240214388A1 · Nambannor Kunnath · 2024 [cited by examiner]