IP Library › Granted Patent US 10,609,560
Granted Patent B2
US 10,609,560 · App. 16/378,147 · Granted Mar 31, 2020

Using derived credentials for enrollment with enterprise mobile device management services

Inventors: Shaunak Mistry (Scotts Valley, CA); Younus Aftab (Pleasanton, CA)
Assignee: Citrix Systems, Inc.
H04W12/06H04L63/083H04L63/0823H04L67/141H04W4/50H04W4/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,609,560
App. No.
16/378,147
Granted
Mar 31, 2020
Kind
B2
Abstract

Methods, systems, and computer-readable media for using derived credentials to enroll a mobile computing device with an enterprise mobile device management system are described herein. In various embodiments, a mobile computing device, responsive to a command to enroll with an enterprise mobile device management server, may launch an enrollment application; send an enrollment request message to the enterprise mobile device management server; switch to a certificate management system application on the mobile computing device; request one or more derived credentials from a certificate management system server; store the one or more derived credentials in a shared vault on the mobile computing device; switch to the enrollment application; retrieve a derived credential of the one or more derived credentials stored in the shared vault; and, provide the derived credential to the enterprise mobile device management server to enroll the mobile computing device with at least one mobile device management service.

Claims (68)

1. A method comprising:

receiving, by an automatic discovery server and from an enrollment application operating on a mobile computing device, a request for configuration information, wherein the configuration information is for a device management server;

sending, by the automatic discovery server and to the enrollment application operating on the mobile computing device, the configuration information;

receiving, by the device management server and from the enrollment application operating on the mobile computing device, an enrollment request message that comprises the configuration information;

receiving, by a certificate management system server and from a certification management system application operating on the mobile computing device, a request for a derived credential;

sending, by the certificate management system server and to the certification management system application operating on the mobile computing device, the derived credential, wherein the derived credential comprises a first derived credential relating to mobile device management enrollment and a second derived credential relating to mobile application management enrollment;

receiving, by the device management server and from the enrollment application operating on the mobile computing device, the derived credential; and

causing, based on the device management server receiving the derived credential, the mobile computing device to be enrolled with at least one mobile device management service provided by the device management server.

2. The method of claim 1 , further comprising:

sending, by the device management server and to the mobile computing device, a message identifying the certificate management system application.

3. The method of claim 1 , further comprising:

based on completion of an enrollment process, sending, by the device management server and to the mobile computing device, one or more policies and applications.

4. The method of claim 1 , further comprising:

authenticating, by the certificate management system server, the certificate management system application.

5. The method of claim 1 , further comprising:

obtain, by the certificate management system server and from a computing device configured with a biometric sensor, biometric information associated with authenticating that the mobile computing device is permitted to access the derived credential.

6. The method of claim 1 , further comprising:

validating, by the device management server and based on communication with the certificate management system server, the derived credential.

7. The method of claim 1 , wherein the at least one mobile device management service is associated with access to an enterprise resource.

8. A system comprising:

an automatic discovery server;

a device management server; and

a certificate management system server;

wherein the automatic discovery server comprises:

one or more first processors; and

first memory storing first executable instructions that, when executed by the one or more first processors, cause the automatic discovery server to:

receive, from an enrollment application operating on a mobile computing device, a request for configuration information, wherein the configuration information is for a device management server; and

send, to the enrollment application operating on the mobile computing device, the configuration information;

wherein the certificate management system server comprises:

one or more second processors; and

second memory storing second executable instructions that, when executed by the one or more second processors, cause the certificate management system server to:

receive, from a certification management system application operating on the mobile computing device, a request for a derived credential; and

send, to the certification management system application operating on the mobile computing device, the derived credential, wherein the derived credential comprises a first derived credential relating to mobile device management enrollment and a second derived credential relating to mobile application management enrollment; and

wherein the device management server comprises:

one or more third processors; and

third memory storing third executable instructions that, when executed by the one or more third processors, cause the device management server to:

receive, from the enrollment application operating on the mobile computing device, an enrollment request message that comprises the configuration information;

receive, from the enrollment application operating on the mobile computing device, the derived credential; and

cause, based on the device management server receiving the derived credential, the mobile computing device to be enrolled with at least one mobile device management service provided by the device management server.

9. The system of claim 8 , wherein the third executable instructions, when executed by the one or more third processors, cause the device management server to:

send, to the mobile computing device, a message identifying the certificate management system application.

10. The system of claim 8 , wherein the third executable instructions, when executed by the one or more third processors, cause the device management server to:

based on completion of an enrollment process, send, to the mobile computing device, one or more policies and applications.

11. The system of claim 8 , wherein the second executable instructions, when executed by the one or more second processors, cause the certificate management system server to:

authenticate the certificate management system application.

12. The system of claim 8 , wherein the second executable instructions, when executed by the one or more second processors, cause the certificate management system server to:

obtain, from a computing device configured with a biometric sensor, biometric information associated with authenticating that the mobile computing device is permitted to access the derived credential.

13. The system of claim 8 , wherein the third executable instructions, when executed by the one or more third processors, cause the device management server to:

validate, based on communication with the certificate management system server, the derived credential.

14. The system of claim 8 , wherein the at least one mobile device management service is associated with access to an enterprise resource.

15. One or more non-transitory computer readable media storing executable instructions that, when executed, cause one or more computing devices to:

receive, by an automatic discovery server and from an enrollment application operating on a mobile computing device, a request for configuration information, wherein the configuration information is for a device management server;

send, by the automatic discovery server and to the enrollment application operating on the mobile computing device, the configuration information;

receive, by the device management server and from the enrollment application operating on the mobile computing device, an enrollment request message that comprises the configuration information;

receive, by a certificate management system server and from a certification management system application operating on the mobile computing device, a request for a derived credential;

send, by the certificate management system server and to the certification management system application operating on the mobile computing device, the derived credential, wherein the derived credential comprises a first derived credential relating to mobile device management enrollment and a second derived credential relating to mobile application management enrollment;

receive, by the device management server and from the enrollment application operating on the mobile computing device, the derived credential; and

cause, based on the device management server receiving the derived credential, the mobile computing device to be enrolled with at least one mobile device management service provided by the device management server.

16. The one or more non-transitory computer readable media of claim 15 , wherein the executable instructions, when executed, cause the one or more computing devices to:

send, by the device management server and to the mobile computing device, a message identifying the certificate management system application.

17. The one or more non-transitory computer readable media of claim 15 , wherein the executable instructions, when executed, cause the one or more computing devices to:

based on completion of an enrollment process, send, by the device management server and to the mobile computing device, one or more policies and applications.

18. The one or more non-transitory computer readable media of claim 15 , wherein the executable instructions, when executed, cause the one or more computing devices to:

authenticate, by the certificate management system server, the certificate management system application.

19. The one or more non-transitory computer readable media of claim 15 , wherein the executable instructions, when executed, cause the one or more computing devices to:

obtain, by the certificate management system server and from a computing device configured with a biometric sensor, biometric information associated with authenticating that the mobile computing device is permitted to access the derived credential.

20. The one or more non-transitory computer readable media of claim 15 , wherein the executable instructions, when executed, cause the one or more computing devices to:

validate, by the device management server and based on communication with the certificate management system server, the derived credential.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2019
From: MISTRY, SHAUNAK; AFTAB, YOUNUS
To: CITRIX SYSTEMS, INC.
Reel/Frame 048823/0093 →
Continuity (3)
Continuation 15483076 · Apr 10, 2017
Continuation 14865376 · Sep 25, 2015
Related Publication 20190239073A1 · Aug 1, 2019