IP Library Granted Patent US 8,931,078
Granted Patent B2
US 8,931,078 · App. 14/029,096 · Granted Jan 6, 2015

Providing virtualized private network tunnels

Inventors: Gary Barton (Boca Raton, FL); Zhongmin Lang (Parkland, FL); Nitin Desai (Coral Springs, FL); James Robert Walker (Deerfield Beach, FL)
Assignee: Citrix Systems, Inc.
H04L63/0272H04W12/06H04L63/0807H04L63/20H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,931,078
App. No.
14/029,096
Granted
Jan 6, 2015
Kind
B2
Abstract

Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.

Claims (60)

1. A method, comprising:

receiving an authentication challenge at a mobile device in connection with an authentication process for a managed application establishing a per-application policy-controlled virtual private network (VPN) tunnel that is inaccessible to other applications of the mobile device;

analyzing policy information to determine that the policy information allows the mobile device to respond to the authentication challenge instead of a user or the managed application, wherein the policy information describes one or more policies for providing the managed application with access to at least one resource accessible through an access gateway;

responding, by the mobile device, to the authentication challenge instead of the user or the managed application;

providing the managed application with access to the at least one resource based at least on the per-application policy-controlled VPN tunnel, a ticket configured to provide authentication in connection with establishing the per-application policy-controlled VPN tunnel, and the policy information, wherein the ticket includes a validity duration;

transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time;

closing the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and

after closing the per-application policy-controlled VPN tunnel, transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

2. The method of claim 1 , wherein the policy information defines that the mobile device is allowed to send responses to authentication challenges based on a listing of allowed sources.

3. The method of claim 1 , wherein the policy information defines that the mobile device is allowed to send responses to authentication challenges based on the mobile device having the ticket.

4. The method of claim 1 , further comprising:

receiving another authentication challenge; and

after receiving said another authentication challenge:

determining that the mobile device is not allowed to respond to said another authentication challenge based on a determination that the ticket has expired, and

providing said another authentication challenge for further processing in accordance with a conventional method of responding to authentication challenges.

5. The method of claim 4 , wherein the conventional method of responding to authentication challenges includes providing a notification to the user that directs the user to select credentials to send as a response to said another authentication challenge.

6. The method of claim 1 , further comprising:

determining that the ticket has expired;

obtaining a new ticket;

determining that the new ticket is valid; and

transmitting the new ticket to the access gateway.

7. The method of claim 1 , further comprising:

providing the ticket to the access gateway as part of a process of establishing the per-application policy-controlled VPN tunnel.

8. The method of claim 1 , wherein responding to the authentication challenges is performed without requiring a user of the mobile device input or select a credential to send as a response to the authentication challenge.

9. The method of claim 1 , further comprising:

identifying receipt of the authentication challenge at least by monitoring network traffic flowing within the per-application policy-controlled VPN tunnel; and

intercepting the authentication challenge before it is received by the managed application.

10. A method, comprising:

providing a managed browser executing on a mobile device with access to at least one resource accessible through an access gateway based at least on a per-application policy-controlled virtual private network (VPN) tunnel that is inaccessible to applications of the mobile device different from the managed browser, a ticket configured to provide authentication in connection with creating the per-application policy-controlled VPN tunnel, and policy information that describes one or more policies for providing the managed browser with access to the at least one resource, wherein the ticket includes a validity duration;

receiving a message representing a demand for a certificate at a mobile device in connection with the managed browser;

analyzing policy information to determine that the policy information allows the mobile device to respond to the message instead of a user or the managed browser;

responding, by the mobile device, to the message instead of the user or the managed browser;

transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time;

closing the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and

after closing the per-application policy-controlled VPN tunnel, transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

11. The method of claim 10 , wherein the policy information defines that the mobile device is allowed to send responses to the message based on a listing of certificates or a listing of types of certificates.

12. The method of claim 10 , wherein the policy information defines that the mobile device is allowed to send responses to the message based on the mobile device having the ticket.

13. The method of claim 10 , further comprising:

receiving another message representing a demand for another certificate; and

after receiving said another message:

determining that the mobile device is not allowed to respond to said another message based on a determination that the ticket has expired, and

providing said another message for further processing in accordance with a conventional method of responding to certificate demands.

14. The method of claim 13 , wherein the conventional method of responding to certificate demands includes providing a notification to the user that directs the user to select credentials to send as a response to said another message.

15. The method of claim 10 , further comprising:

determining that the ticket has expired;

obtaining a new ticket;

determining that the new ticket is valid; and

transmitting the new ticket to the access gateway.

16. A method, comprising:

receiving, at an access gateway through which at least one resource is accessible, a message in connection with an initial authentication process that authenticates a user prior to allowing a managed application executing on a mobile device access to the at least one resource;

determining credential information associated with the user, wherein the credential information includes a ticket configured to provide authentication in connection with creating a per-application policy-controlled virtual private network (VPN) tunnel to access the at least one resource, wherein the ticket includes a validity duration;

transmitting the credential information to at least the mobile device;

opening the per-application policy-controlled VPN tunnel to provide the managed application with access to the at least one resource;

receiving, during the validity duration, the ticket at the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time;

closing the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and

after closing the per-application policy-controlled VPN tunnel, receiving, during the validity duration, the ticket at the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.

17. The method of claim 16 , wherein the credential information includes a listing of tickets that have been issued to a plurality of mobile devices associated with the user.

18. The method of claim 17 , further comprising:

transmitting the credential information to each of the plurality of mobile device.

19. The method of claim 16 , wherein the credential information includes a listing of one or more policies that are linked to the user, each policy of the listing of one or more policies being specific to a different application, and wherein one of the listing of one or more policies describes conditions related to when the mobile device is permitted access to the at least one resource.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2013
From: BARTON, GARY; LANG, ZHONGMIN; DESAI, NITIN; WALKER, JAMES
To: CITRIX SYSTEMS INC.
Reel/Frame 031237/0102 →
Continuity (5)
Continuation 14027929 · Sep 16, 2013
Provisional Application 61861909 · Aug 2, 2013
Provisional Application 61713763 · Oct 15, 2012
Provisional Application 61806557 · Mar 29, 2013
Related Publication 20140109175A1 · Apr 17, 2014