IP Library Granted Patent US 12,309,159
Granted Patent B2
US 12,309,159 · App. 18/464,106 · Granted May 20, 2025

TLS policy enforcement at a tunnel gateway

Inventors: Sanjay Patil (Atlanta, GA); Craig Farley Newell (Atlanta, GA); Leung Tao Kwok (Taipei, TW); Amit Kumar Yadav (Bangalore, IN)
Assignee: Omnissa, LLC
H04L63/102G06F21/31H04L63/0272H04L63/029H04L63/166H04L63/101H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,159
App. No.
18/464,106
Granted
May 20, 2025
Kind
B2
Abstract

Disclosed are various approaches for verifying the compliance of a TLS session with TLs policies. Traffic between an application and a destination server can be routed through a TLS gateway. The TLS gateway can inspect TLS handshake messages for compliance with TLS policies.

Claims (35)

1. A system for authenticating a user and determining a device posture during authentication, comprising:

at least one computing device comprising a processor and a memory; and

a tunnel gateway executed by the at least one computing device, the tunnel gateway causing the at least one computing device to at least:

obtain a transport layer security (TLS) message according to a TLS handshake over a virtual private network (VPN) tunnel established between a client device and the tunnel gateway, the TLS message comprising a connection attempt between a destination server and the client device, wherein the TLS message is received from the destination server and is intended for an application installed on the client device;

identify an aspect of the connection attempt based upon the TLS handshake;

identify the application based upon data embedded into the TLS message;

identify a TLS policy corresponding to the application, wherein the TLS policy is applied to network traffic for the application based on a Virtual Private Network (VPN) configuration for the application received by the client device from a management service, and wherein the tunnel gateway stores a pinned certificate in association with the destination server based on the TLS policy; and

terminate the connection attempt between the client device and the destination server in response to determining that the aspect of the connection attempt based upon the TLS handshake violates the TLS policy, wherein the TLS policy is violated if a certificate presented by the destination server in the TLS handshake with the client device does not match the pinned certificate stored on the tunnel gateway.

2. The system of claim 1 , wherein the connection attempt between the client device and the destination server is terminated by the tunnel gateway in response to a server name indication (SNI) or a TLS version specified by the TLS message comprising an unapproved value for the identified application.

3. The system of claim 1 , wherein the tunnel gateway causes the at least one computing device to at least terminate the connection attempt in response to a cipher suite specified by the TLS message comprising an unapproved cipher suite, wherein at least one approved cipher suite is associated with the application in the tunnel gateway.

4. The system of claim 1 , wherein the tunnel gateway causes the at least one computing device to at least terminate the connection attempt in response to the certificate provided by the destination server being signed by an unapproved certificate authority.

5. The system of claim 1 , wherein the tunnel gateway causes the at least one computing device to at least cause a push notification to be transmitted to the client device in response to terminating the connection attempt, the push notification comprising a message indicating that the connection attempt has been terminated.

6. The system of claim 1 , wherein the tunnel gateway further causes the at least one computing device to at least:

update the pinned certificate stored on the tunnel gateway to a new pinned certificate without updating the application on the client device or any certificates on the client device.

7. A method comprising:

obtaining a transport layer security (TLS) message according to a TLS handshake over a virtual private network (VPN) tunnel established between a client device and a tunnel gateway, the TLS message comprising a connection attempt between a destination server and the client device, wherein the TLS message is received from the destination server and is intended for an application installed on the client device;

identifying a property of the connection attempt based upon the TLS handshake;

identifying the application based upon data embedded into the TLS message;

identifying a TLS policy corresponding to the application, wherein the TLS policy is applied to network traffic for the application based on a Virtual Private Network (VPN) configuration for the application received by the client device from a management service, and wherein the tunnel gateway stores a pinned certificate in association with the destination server based on the TLS policy; and

terminating the connection attempt between the client device and the destination server in response to determining that the property of the connection attempt based upon the TLS handshake violates the TLS policy, wherein the TLS policy is violated if a certificate presented by the destination server in the TLS handshake with the client device does not match the pinned certificate stored on the tunnel gateway.

8. The method of claim 7 , wherein the connection attempt between the client device and the destination server is terminated by the tunnel gateway in response to a server name indication (SNI) or a TLS version specified by the TLS message comprising an unapproved value for the identified application.

9. The method of claim 7 , wherein the connection attempt is terminated in response to a cipher suite specified by the TLS message comprising an unapproved cipher suite, wherein at least one approved cipher suite is associated with the application in the tunnel gateway.

10. The method of claim 7 , wherein the connection attempt is terminated in response to the certificate provided by the destination server being signed by an unapproved certificate authority.

11. The method of claim 7 , further comprising causing a push notification to be transmitted to the client device in response to terminating the connection attempt, the push notification comprising a message indicating that the connection attempt has been terminated.

12. The method of claim 7 , further comprising:

updating the pinned certificate stored on the tunnel gateway to a new pinned certificate without updating the application on the client device or any certificates on the client device.

13. A non-transitory computer-readable medium comprising executable instructions implementing a tunnel gateway, the instructions, when executed, causing at least one computing device to at least:

obtain a transport layer security (TLS) message according to a TLS handshake over a virtual private network (VPN) tunnel established between a client device and the tunnel gateway, the TLS message comprising a connection attempt between a destination server and the client device, wherein the TLS message is received from the destination server and is intended for an application installed on the client device;

identify an aspect of the connection attempt based upon the TLS handshake;

identify the application based upon data embedded into the TLS message;

identify a TLS policy corresponding to the application, wherein the TLS policy is applied to network traffic for the application based on a Virtual Private Network (VPN) configuration for the application received by the client device from a management service, and wherein the tunnel gateway stores a pinned certificate in association with the destination server based on the TLS policy; and

terminating the connection attempt between the client device and the destination server in response to determining that the aspect of the connection attempt based upon the TLS handshake violates the TLS policy, wherein the TLS policy is violated if a certificate presented by the destination server in the TLS handshake with the client device does not match the pinned certificate stored on the tunnel gateway.

14. The non-transitory computer-readable medium of claim 13 , wherein the connection attempt between the client device and the destination server is terminated by the tunnel gateway in response to a server name indication (SNI) or a TLS version specified by the TLS message comprising an unapproved value for the identified application.

15. The non-transitory computer-readable medium of claim 13 , wherein the tunnel gateway causes the at least one computing device to at least cause a push notification to be transmitted to the client device in response to terminating the connection attempt, the push notification comprising a message indicating that the connection attempt has been terminated.

16. The non-transitory computer-readable medium of claim 13 , further comprising instructions, which when executed, cause at least one computing device to at least: update the pinned certificate stored on the tunnel gateway to a new pinned certificate without updating the application on the client device or any certificates on the client device.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Priority Claims (1)
IN 201941002281 · Jan 18, 2019 · national
Continuity (3)
Continuation 17452854 · Oct 29, 2021
Continuation 16384968 · Apr 16, 2019
Related Publication 20230421565A1 · Dec 28, 2023
References Cited (68)
US 8281371B1 · Chickering et al. · 2012 [cited by applicant]
US 8341702B2 · Graziani et al. · 2012 [cited by applicant]
US 8875223B1 · Chen · 2014 [cited by examiner]
US 9148408B1 · Glazemakers et al. · 2015 [cited by applicant]
US 9306913B1 · Volkov · 2016 [cited by applicant]
US 9419942B1 · Buruganahalli · 2016 [cited by examiner]
US 9509662B2 · Mudigonda et al. · 2016 [cited by applicant]
US 9571465B1 · Sharifi Mehr · 2017 [cited by examiner]
US 9736120B2 · Glazemakers et al. · 2017 [cited by applicant]
US 9769131B1 · Hartley · 2017 [cited by examiner]
US 9998425B2 · Raman et al. · 2018 [cited by applicant]
US 10122577B1 · Rykowski · 2018 [cited by examiner]
US 10135789B2 · Mayya et al. · 2018 [cited by applicant]
US 10171452B2 · Pendarakis et al. · 2019 [cited by applicant]
US 10382401B1 · Lee et al. · 2019 [cited by applicant]
US 10439990B2 · Shi et al. · 2019 [cited by applicant]
US 10440053B2 · Wyatt et al. · 2019 [cited by applicant]
US 10505985B1 · Walter · 2019 [cited by examiner]
US 10523636B2 · Newell et al. · 2019 [cited by applicant]
US 10778642B2 · Kenyan et al. · 2020 [cited by applicant]
US 10791118B2 · Konda et al. · 2020 [cited by applicant]
US 10958664B2 · Jeon et al. · 2021 [cited by applicant]
US 11019100B2 · Penner et al. · 2021 [cited by applicant]
US 11082403B2 · McGinnity · 2021 [cited by examiner]
US 11089058B2 · Lee et al. · 2021 [cited by applicant]
US 11165604B2 · Yang et al. · 2021 [cited by applicant]
US 11190521B2 · Patil · 2021 [cited by examiner]
US 11233801B1 · Robinson · 2022 [cited by applicant]
US 11277399B2 · Milton et al. · 2022 [cited by applicant]
US 11792202B2 · Patil · 2023 [cited by examiner]
US 11924195B2 · Milton · 2024 [cited by examiner]
US 20060294366A1 · Nadalin · 2006 [cited by examiner]
US 20160014154A1 · Huang · 2016 [cited by examiner]
US 20160119330A1 · L'Heureux · 2016 [cited by examiner]
US 20160219018A1 · Raman · 2016 [cited by examiner]
US 20160315912A1 · Mayya · 2016 [cited by examiner]
US 20170078328A1 · McGinnity et al. · 2017 [cited by examiner]
US 20170207921A1 · Rantapuska · 2017 [cited by examiner]
US 20170230334A1 · Newell · 2017 [cited by examiner]
US 20170289137A1 · Pendarakis · 2017 [cited by examiner]
US 20170346853A1 · Wyatt · 2017 [cited by examiner]
US 20180332003A1 · Deriso · 2018 [cited by examiner]
US 20190052482A1 · Yang · 2019 [cited by examiner]
US 20190098016A1 · Jeon · 2019 [cited by examiner]
US 20190215308A1 · Feyzibehnagh · 2019 [cited by examiner]
US 20190230125A1 · Lee · 2019 [cited by examiner]
US 20190306166A1 · Konda · 2019 [cited by examiner]
US 20200169584A1 · Penner · 2020 [cited by examiner]
US 20200169875A1 · Sundar · 2020 [cited by examiner]
US 20200177630A1 · Penner · 2020 [cited by examiner]
US 20200213206A1 · Bracken · 2020 [cited by examiner]
US 20200236114A1 · Patil · 2020 [cited by examiner]
US 20200280584A1 · Zhao · 2020 [cited by examiner]
US 20200322332A1 · Haque · 2020 [cited by examiner]
US 20220116381A1 · Bosch · 2022 [cited by examiner]
US 20220303244A1 · Wondra · 2022 [cited by examiner]
US 20240291806A1 · Sethi · 2024 [cited by examiner]
CN 102333306A · 2012 [cited by applicant]
CN 101199183B · 2015 [cited by examiner]
CN 105794171A · 2016 [cited by examiner]
CN 109558721A · 2019 [cited by applicant]
CN 111726366A · 2020 [cited by applicant]
CN 114629678A · 2022 [cited by examiner]
CN 113810369B · 2023 [cited by examiner]
WO WO2012087435A1 · 2012 [cited by examiner]
WO 2014062337A1 · 2014 [cited by applicant]
WO WO2020033493A1 · 2020 [cited by examiner]
WO WO2023059696A1 · 2023 [cited by examiner]