IP Library › Granted Patent US 8,910,239
Granted Patent B2
US 8,910,239 · App. 14/029,088 · Granted Dec 9, 2014

Providing virtualized private network tunnels

Inventors: Gary Barton (Boca Raton, FL); Zhongmin Lang (Parkland, FL); Nitin Desai (Coral Springs, FL); James Robert Walker (Deerfield Beach, FL)
Assignee: Citrix Systems, Inc.
H04L63/0272H04L63/0815H04L63/20H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,910,239
App. No.
14/029,088
Granted
Dec 9, 2014
Kind
B2
Abstract

Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.

Claims (59)

1. A method, comprising:

detecting that an application is capable of running in both a first mode and a second mode on a mobile device, wherein the first mode is a managed mode operating under control of one or more policies separate from the application and usable to manage operations of multiple applications executing on the mobile device;

running, on the mobile device, the application in the first mode;

when the application is running in the first mode under the control of the one or more policies: transmitting, to an access gateway, a ticket configured to provide authentication in connection with establishing a per-application policy-controlled virtual private network (VPN) tunnel for the application to at least one resource, and providing the application with access to the at least one resource via the per-application policy-controlled VPN tunnel, wherein the ticket includes a validity duration;

transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time;

closing the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and

after closing the per-application policy-controlled VPN tunnel, transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

2. The method of claim 1 , wherein running the application in the first mode is responsive to comparing the application against policy information that defines the one or more policies.

3. The method of claim 2 , wherein the second mode is a second managed mode that operates under control of one or more additional policies different from the one or more policies.

4. The method of claim 3 , wherein the policy information defines that the application is to run in the second managed mode under the control of the one or more additional policies if the ticket is not valid or has expired, and wherein the method further comprises:

determining that the ticket is not valid or has expired;

responsive to determining that the ticket is not valid or has expired, switching from the first mode to the second managed mode; and

running the application in the second managed mode under the control of the one or more additional policies.

5. The method of claim 2 , wherein the policy information defines that the application is to run in the first mode if the ticket is valid or is stored in a secure container of the mobile device, and wherein the at least one resource is accessible only if the application is running in the first mode and only if the per-application policy-controlled VPN tunnel is established.

6. The method of claim 1 , further comprising:

monitoring the application;

determining a change in running the application in the first mode or the second mode based on the monitoring; and

switching between the first mode or the second mode.

7. The method of claim 6 , wherein switching between the first mode or the second mode includes switching from the first mode to the second mode, and

wherein determining the change in running the application in the first mode or the second mode based on the monitoring is conditioned upon a determination that the ticket is stored by the mobile device and is valid.

8. The method of claim 6 , wherein switching between the first mode or the second mode includes switching from the first mode to the second mode, wherein the second mode is an unmanaged mode, and wherein the method further comprises:

responsive to the switching from the first mode to the second mode, performing a selective wipe.

9. An apparatus, comprising:

at least one processor; and

memory storing executable instructions configured to, when executed by the at least one processor, cause the apparatus to:

detect that an application is capable of running in both a first mode and a second mode on the apparatus, wherein the first mode is a managed mode operating under control of one or more policies separate from the application and usable to manage operations of multiple applications executing on the apparatus,

run the application in the first mode,

when the application is running in the first mode under the control of the one or more policies: transmit, to an access gateway, a ticket configured to provide authentication in connection with establishing a per-application policy-controlled virtual private network (VPN) tunnel for the application to at least one resource, and provide the application with access to the at least one resource via the per-application policy-controlled VPN tunnel, wherein the ticket includes a validity duration;

transmit, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time,

close the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time, and

after closing the per-application policy-controlled VPN tunnel, transmit, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

10. The apparatus of claim 9 , wherein running the application in the first mode is responsive to comparing the application against policy information that defines the one or more policies.

11. The apparatus of claim 10 , wherein the second mode is a second managed mode that operates under control of one or more additional policies different from the one or more policies.

12. The apparatus of claim 11 , wherein the policy information defines that the application is to run in the second managed mode under the control of the one or more additional policies if the ticket is not valid or has expired, and wherein the executable instructions are configured to, when executed by the at least one processor, cause the apparatus to:

determine that the ticket is not valid or has expired;

responsive to determining that the ticket is not valid or has expired, switch from the first mode to the second managed mode; and

run the application in the second managed mode under the control of the one or more additional policies.

13. The apparatus of claim 10 , wherein the policy information defines that the application is to run in the first mode if the ticket is valid or is stored in a secure container of the apparatus, and wherein the at least one resource is accessible only if the application is running in the first mode and only if the per-application policy-controlled VPN tunnel is established.

14. The apparatus of claim 9 , wherein the executable instructions are configured to, when executed by the at least one processor, cause the apparatus to:

monitor the application;

determine a change in running the application in the first mode or the second mode based on the monitoring; and

switch between the first mode or the second mode.

15. The apparatus of claim 14 , wherein switching between the first mode or the second mode includes switching from the first mode to the second mode, and

wherein determining the change in running the application in the first mode or the second mode based on the monitoring is conditioned upon a determination that the ticket is stored by the apparatus and is valid.

16. One or more non-transitory computer-readable media storing instructions configured to, when executed, cause a computing device to:

detect that an application is capable of running in both a first mode and a second mode on the computing device, wherein the first mode is a managed mode operating under control of one or more policies separate from the application and usable to manage operations of multiple applications executing on the computing device;

run the application in the first mode; and

when the application is running in the first mode under the control of the one or more policies: transmit, to an access gateway, a ticket configured to provide authentication in connection with establishing a per-application policy-controlled virtual private network (VPN) tunnel for the application to at least one resource, and provide the application with access to the at least one resource via the per-application policy-controlled VPN tunnel, wherein the ticket includes a validity duration;

transmit, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time;

close the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and

after closing the per-application policy-controlled VPN tunnel, transmit, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

17. The one or more non-transitory computer-readable media of claim 16 , wherein running the application in the first mode is responsive to comparing the application against policy information that defines the one or more policies.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the policy information defines that the application is to run in the first mode if the ticket is valid or is stored in a secure container of the computing device, wherein the policy information defines that the application is to run in the second mode if the ticket is not valid or has expired,

wherein the at least one resource is accessible only if the application is run in the first mode and only if the VPN tunnel is established, and

wherein the second mode is a second managed mode that operates under control of one or more additional policies different from the one or more policies.

19. The one or more non-transitory computer-readable media of claim 16 , wherein the instructions are configured to, when executed, cause the computing device to:

monitor the application;

determine a change in running the application in the first mode or the second mode based on the monitoring, wherein determining the change in running the application in the first mode or the second mode based on the monitoring is conditioned upon a determination that the ticket is stored by the computing device and is valid; and

switch between the first mode or the second mode.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2013
From: BARTON, GARY; LANG, ZHONGMIN; DESAI, NITIN; WALKER, JAMES
To: CITRIX SYSTEMS INC.
Reel/Frame 031237/0116 →
Continuity (5)
Continuation 14027929 · Sep 16, 2013
Provisional Application 61861909 · Aug 2, 2013
Provisional Application 61713763 · Oct 15, 2012
Provisional Application 61806577 · Mar 29, 2013
Related Publication 20140109174A1 · Apr 17, 2014