IP Library › Granted Patent US 11,297,058
Granted Patent B2
US 11,297,058 · App. 16/809,093 · Granted Apr 5, 2022

Systems and methods using a cloud proxy for mobile device management and policy

Inventors: Ajit Singh (Freemont, CA); Vivek Raman (San Jose, CA); Tejus Gangadharappa (Freemont, CA)
Assignee: Zscaler, Inc.
H04L63/0884H04L61/1511H04L63/0272H04L63/0281H04L67/02H04L67/10H04L67/1002H04L67/125H04L67/16H04L67/28H04L67/2814H04L67/2819H04L69/162H04L61/6063
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,297,058
App. No.
16/809,093
Granted
Apr 5, 2022
Kind
B2
Abstract

Systems and methods include, in a cloud node, receiving Mobile Device Management (MDM) data from a central authority, wherein the MDM data includes policy metadata specifying MDM functions for mobile devices associated with users of an enterprise; communicating to an application on a mobile device associated with a user, via a tunnel, wherein the application is configured for service discovery and connectivity; and providing the MDM data to the mobile device associated with the user via the tunnel.

Claims (43)

1. A non-transitory computer readable medium storing computer executable instructions, and in response to execution by the processor in a cloud node, the computer-executable instructions cause a processor to perform the steps of:

providing an application to a mobile device for installation and operation thereon, wherein the application is configured for service discovery and connectivity of one or more cloud services, for the mobile device;

creating a tunnel to the mobile device via the application for the one or more cloud services;

receiving Mobile Device Management (MDM) data from a central authority, wherein the MDM data includes policy metadata specifying MDM functions for mobile devices associated with users of an enterprise;

communicating to the application on the mobile device associated with a user, via a tunnel; and

providing a 200 OK with a custom HTTP header with the MDM data to the mobile device associated with the user via the tunnel and the application in response to a CONNECT request,

wherein the application is configured to implement MDM functions on the mobile device in addition to the service discovery and connectivity of the one or more cloud services, and wherein the application does not call home or subscribe to notification services for scalability and efficiency.

2. The non-transitory computer readable medium of claim 1 , wherein the steps further include:

receiving an update to the MDM data from the central authority; and

one of instantly communicating the update to the mobile device and communicating the update to the mobile device based on a schedule.

3. The non-transitory computer readable medium of claim 1 , wherein the providing is via an encrypted control channel.

4. The non-transitory computer readable medium of claim 1 , wherein the MDM data specifies any of password configuration, screen lock, remote wipe, enable/disable features, allowed/disallowed applications, deletion of applications, and installation of applications.

5. The non-transitory computer readable medium of claim 1 , wherein the steps further include:

authenticating the user into the one or more cloud services via the tunnel.

6. The non-transitory computer readable medium of claim 1 , wherein the application on the mobile device is configured to forward traffic via the tunnel, through the cloud node.

7. A cloud node comprising:

a processor and memory storing instructions that, when executed, cause the processor to

providing an application to a mobile device for installation and operation thereon, wherein the application is configured for service discovery and connectivity of one or more cloud services, for the mobile device;

creating a tunnel to the mobile device via the application for the one or more cloud services;

receive Mobile Device Management (MDM) data from a central authority, wherein the MDM data includes policy metadata specifying MDM functions for mobile devices associated with users of an enterprise;

communicate to the application on the mobile device associated with a user, via a tunnel; and

provide a custom Hypertext Transfer Protocol (HTTP) header with encrypted payload a 200 OK with a custom HTTP header with the MDM data to the mobile device associated with the user via the tunnel and the application, wherein the application is configured to implement MDM functions on the mobile device in addition to the service discovery and connectivity of the one or more cloud services, and wherein the application does not call home or subscribe to notification services for scalability and efficiency.

8. The cloud node of claim 7 , wherein the instructions that, when executed, further cause the processor to

receive an update to the MDM data from the central authority; and

one of instantly communicate the update to the mobile device and communicate the update to the mobile device based on a schedule.

9. The cloud node of claim 7 , wherein the MDM data is provided via an encrypted control channel.

10. The cloud node of claim 7 , wherein the MDM data specifies any of password configuration, screen lock, remote wipe, enable/disable features, allowed/disallowed applications, deletion of applications, and installation of applications.

11. The cloud node of claim 7 , wherein the instructions that, when executed, further cause the processor to

authenticating the user into the one or more cloud services via the tunnel.

12. The cloud node of claim 7 , wherein the application on the mobile device is configured to forward traffic via the tunnel, through the cloud node.

13. A method implemented in a cloud node comprising:

providing an application to a mobile device for installation and operation thereon, wherein the application is configured for service discovery and connectivity of one or more cloud services, for the mobile device;

creating a tunnel to the mobile device via the application for the one or more cloud services;

receiving Mobile Device Management (MDM) data from a central authority, wherein the MDM data includes policy metadata specifying MDM functions for mobile devices associated with users of an enterprise;

communicating to application on the mobile device associated with a user, via a tunnel, wherein the application is configured for service discovery and connectivity of one or more cloud services; and

providing via a custom Hypertext Transfer Protocol (HTTP) header with encrypted payload a 200 OK with a custom HTTP header with the MDM data to the mobile device associated with the user via the tunnel and the application, wherein the application is configured to implement MDM functions on the mobile device in addition to the service discovery and connectivity of the one or more cloud services, and wherein the application does not call home or subscribe to notification services for scalability and efficiency.

14. The method of claim 13 , further comprising

receiving an update to the MDM data from the central authority; and

one of instantly communicating the update to the mobile device and communicating the update to the mobile device based on a schedule.

15. The method of claim 13 , wherein the providing is via an encrypted control channel.

16. The method of claim 13 , wherein the MDM data specifies any of password configuration, screen lock, remote wipe, enable/disable features, allowed/disallowed applications, deletion of applications, and installation of applications.

17. The method of claim 13 , further comprising:

authenticating the user into the one or more cloud services via the tunnel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2020
From: SINGH, AJIT; RAMAN, VIVEK; GANGADHARAPPA, TEJUS
To: ZSCALER, INC.
Reel/Frame 052015/0221 →
Priority Claims (1)
IN 201611010521 · Mar 28, 2016 · national
Continuity (3)
Continuation In Part 15900951 · Feb 21, 2018
Continuation 15153108 · May 12, 2016
Related Publication 20200204551A1 · Jun 25, 2020
Cited By (1)
US 12,639,132