IP Library Granted Patent US 12,580,776
Granted Patent B2
US 12,580,776 · App. 18/376,444 · Granted Mar 17, 2026

Application integrity verification for enterprise resource access

Inventors: Amit Kumar Yadav (Marietta, GA); Utkarsh Singh (Bangalore, IN); Nikhil Jere (Kalaburagi, IN); Martin Kniffin (Roswell, GA); Rabish Kumar (Bangalore, IN)
Assignee: Omnissa, LLC
H04L9/3263H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,776
App. No.
18/376,444
Granted
Mar 17, 2026
Kind
B2
Abstract

Disclosed are various approaches for ensuring application integrity for enterprise resource access. In some examples, a client device extracts installed application data from a local instance of an application that is installed on the client device. The installed application data includes actual certificate-based signature information for the local instance of the application. An application verification status is generated using the actual certificate-based signature information and the expected certificate-based signature information; and network access to a protected set of enterprise resources is permitted or denied using the application verification status.

Claims (37)

1 . A system comprising:

one or more processors; and

a computer readable storage medium storing a set of instructions executed by the one or more processors to cause the one or more processors to:

receive, by a client device from a management service, application verification data comprising expected certificate-based signature information for an application;

receive a request to establish a per-application virtual private network (VPN) tunnel for a local instance of the application installed on the client device, wherein the per-application VPN tunnel is restricted to the local instance of the application;

in response to the request to establish the per-application VPN tunnel, extract, by the client device, installed application data from the local instance of the application, the installed application data comprising actual certificate-based signature information for the local instance of the application;

generate, by at least one of the client device or the management service, an application verification status using the actual certificate-based signature information and the expected certificate-based signature information; and

provide or deny network access to a protected set of enterprise resources for the local instance of the application using the per-application VPN tunnel based at least in part on the application verification status.

2 . The system of claim 1 , wherein the computer readable storage medium further comprises instructions to:

transmit a request for the application verification data, wherein the request comprises an application identifier of the application.

3 . The system of claim 1 , wherein the application verification status comprises an indication of a success or a failure, wherein the success is indicated in an instance in which the installed application data matches the application verification data, and the failure is indicated in an instance in which the installed application data fails to match the application verification data.

4 . The system of claim 1 , wherein the computer readable storage medium further comprises instructions to:

provide access to a default gateway comprising unprotected enterprise resources, in an instance in which the network access to the protected set of enterprise resources is denied.

5 . The system of claim 1 , wherein the computer readable storage medium further comprises instructions to:

transmit a notification to an administrator or a user of the client device.

6 . A non-transitory computer-readable medium comprising machine-readable instructions, wherein the instructions, when executed by at least one processor, cause at least one computing device to at least:

receive a request to establish a per-application virtual private network (VPN) tunnel for a local instance of an application installed on a client device, wherein the per-application VPN tunnel is restricted to the local instance of the application;

in response to the request to establish the per-application VPN tunnel, extract, by the client device, actual certificate-based signature information from the local instance of the application installed on the client device;

generate, by at least one of the client device or a management service, an application verification status using the actual certificate-based signature information and expected certificate-based signature information received from the management service; and

provide or deny network access to a protected set of enterprise resources for the local instance of the application using the per-application VPN tunnel based at least in part on the application verification status.

7 . The non-transitory computer-readable medium of claim 6 , wherein the instructions cause the at least one computing device to at least:

transmit a request for the application verification data, wherein the request comprises an application identifier of the application.

8 . The non-transitory computer-readable medium of claim 6 , wherein the application verification status comprises an indication of a success or a failure, wherein the success is indicated in an instance in which the actual certificate-based signature information matches the expected certificate-based signature information, and the failure is indicated in an instance in which the actual certificate-based signature information fails to match the expected certificate-based signature information.

9 . The non-transitory computer-readable medium of claim 6 , wherein the instructions cause the at least one computing device to at least:

provide access to a default gateway comprising unprotected enterprise resources, in an instance in which the network access to the protected set of enterprise resources is denied.

10 . The non-transitory computer-readable medium of claim 6 , wherein the instructions cause the at least one computing device to at least:

transmit a notification to an administrator or a user of the client device.

11 . A method performed using instructions executed by at least one computing device, the method comprising:

receiving a request to establish a per-application virtual private network (VPN) tunnel for a local instance of an application installed on a client device, wherein the per-application VPN tunnel is restricted to the local instance of the application;

in response to the request to establish the per-application VPN tunnel, extracting, by the client device, actual certificate-based signature information from the local instance of the application installed on the client device;

generating, by at least one of the client device or a management service, an application verification status using the actual certificate-based signature information and expected certificate-based signature information received from the management service; and

providing or denying network access to a protected set of enterprise resources for the local instance of the application using the per-application VPN tunnel based at least in part on the application verification status.

12 . The method of claim 11 , further comprising:

transmitting a request for the application verification data, wherein the request comprises an application identifier of the application.

13 . The method of claim 11 , wherein the application verification status comprises an indication of a success or a failure, wherein the success is indicated in an instance in which the actual certificate-based signature information matches the expected certificate-based signature information, and the failure is indicated in an instance in which the actual certificate-based signature information fails to match the expected certificate-based signature information.

14 . The method of claim 11 , further comprising:

performing a remedial action comprising providing access to a default gateway comprising unprotected enterprise resources, in an instance in which the network access to the protected set of enterprise resources is denied.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 25, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067239/0402 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2023
From: YADAV, AMIT KUMAR; SINGH, UTKARSH; JERE, NIKHIL; KNIFFIN, MARTIN; KUMAR, RABISH
To: VMWARE, INC.
Reel/Frame 065113/0108 →
Priority Claims (1)
IN 202341048790 · Jul 20, 2023 · national
Continuity (1)
Related Publication 20250030558A1 · Jan 23, 2025
References Cited (3)
US 8843741B2 · Koster · 2014 [cited by examiner]
US 9507920B2 · Yach · 2016 [cited by examiner]
US 11729147B2 · Pabijanskas · 2023 [cited by examiner]