IP Library Granted Patent US 12,438,847
Granted Patent B2
US 12,438,847 · App. 18/509,859 · Granted Oct 7, 2025

System and method for integrating systems to access websites by managed mobile devices

Inventors: Hafed A. Al Ghamdi (Dammam, SA); Mohammed M. Otaibi (Dammam, SA); Abdullah A. Almutlak (Khobar, SA); Ziyad A. Mubarak (Ras Tannurah, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/0272H04L63/0236H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,847
App. No.
18/509,859
Granted
Oct 7, 2025
Kind
B2
Abstract

Network systems integration and method inspect network traffic to enable secure access to internal and Internet websites from managed mobile devices. The integrated networks system implements a secure split tunneling to allow users of mobile devices managed by an organization Mobile Device Management system to securely browse only safe websites on the Internet or on an intranet resource of the organization. The system includes an internal firewall, a reception firewall, internal and external web application firewalls, a reverse proxy, an Internet proxy, and an enterprise mobility management system having a VPN-Tunnel system to implement the secure split tunneling method.

Claims (49)

1. An integrated networks system operatively connected to an internal web server configured as a private network device storing an internal website, operatively connected to an external web server configured as a public network device storing an external website, and operatively connected to a mobile device configured to execute a single browser, the integrated networks system configured to receive traffic from the mobile device sending a request to access to the internal and external websites, and the integrated networks system is configured to implement split tunneling to the internal and external web server, comprising:

a reception firewall operatively connected to the mobile device;

an external web application firewall (WAF) operatively connected to the reception firewall;

a reverse proxy operatively connected to the external WAF;

an enterprise mobility management (EMM) system operatively connected to the reverse proxy, wherein the EMM system includes:

a VPN-Tunnel system configured to validate the request; and

a proxy auto-config (PAC) system;

an Internet proxy operatively connected to the EMM system;

an external firewall operatively connected to the Internet proxy, and operatively connected to the external web server;

an internal WAF operatively connected to the EMM system; and

an internal firewall operatively connected to the internal WAF and to the internal web server,

wherein the PAC system is configured to choose one of the Internet proxy and the reverse proxy,

wherein the internal firewall, the reception firewall, the external and internal WAFs, the EMM system, the Internet proxy, and the reverse proxy are configured to implement a secure split tunneling of the mobile device to the internal and external web servers, and

wherein a single browser connection is established between the mobile device and one of the internal and external web servers, thereby permitting access by the mobile device to one of the internal and external websites using only the single browser by the secure split tunneling.

2. The integrated networks system of claim 1 , wherein the PAC system includes a PAC file storing at least one rule.

3. The integrated networks system of claim 2 , wherein the EMM system is configured to execute the PAC file to perform the at least one rule in the PAC file, and

wherein the EMM system, executing the PAC file, automatically chooses one of the reverse proxy and the Internet proxy to obtain a Uniform Resource Locator (URL) of the internal website or the external website, respectively.

4. The integrated networks system of claim 1 , wherein the internal web server is configured to be a network device of an intranet of an organization.

5. The integrated networks system of claim 1 , wherein the external web server is configured to be a network device of the Internet.

6. The integrated networks system of claim 1 , wherein the VPN-Tunnel system is configured to validate the case that the request is directed to the internal web server to access the internal website.

7. The integrated networks system of claim 1 , wherein the VPN-Tunnel system is configured to validate the case that the request is directed to the external web server to access the external website.

8. A method, comprising:

providing an integrated networks system operatively connected to an internal web server configured as a private network device storing an internal website, operatively connected to an external web server configured as a public network device storing an external website, and operatively connected to a mobile device configured to send a request to access to the internal and external websites, wherein the integrated networks system includes an internal firewall, a reception firewall, an external web application firewall (WAF), an internal WAF, an Internet proxy, a reverse proxy, and an enterprise mobility management (EMM) system including a VPN-Tunnel system and a proxy auto-config (PAC) system;

receiving the request at the integrated networks system;

passing the request through the reception firewall, the external WAF, and the reverse proxy;

validating the request, using the VPN-Tunnel system, for the case that the request is directed to the internal web server to access the internal website or directed to the external web server to access the external website;

implementing a secure split tunneling of the mobile device to the internal and external web servers; and

accessing the internal and external websites by the mobile device using only one browser.

9. The method of claim 8 , further comprising:

determining the case that the mobile device is compromised or not enrolled with the integrated networks system; and

rejecting the request.

10. The method of claim 9 , further comprising:

determining the case that the mobile device is not compromised and is enrolled with the integrated networks system; and

redirecting the request to a public domain name system (DNS) of the organization and to an Internet Protocol (IP) address.

11. The method of claim 10 , further comprising:

prior to validating the request, redirecting traffic between the mobile device and the internal and external servers to the VPN-Tunnel system.

12. The method of claim 11 , further comprising:

choosing one of the Internet proxy and the reverse proxy using the PAC system.

13. The method of claim 11 , further comprising:

storing a PAC file having at least one rule in the PAC system;

executing the PAC file by the EMM system to perform the at least one rule;

automatically choosing one of the reverse proxy and Internet proxy; and

obtaining a Uniform Resource Locator (URL) of the internal website or the external website, respectively.

14. The method of claim 13 , further comprising:

in the case that the Internet proxy is chosen, determining the case that an Internet-based website is not blocked; and

redirecting the requested website to the mobile device.

15. The method of claim 13 , further comprising:

in the case that the reverse proxy is chosen, determining the case that the traffic is safe; and

responding to the request with the requested website sent to the mobile device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2023
From: AL GHAMDI, HAFED A.; OTAIBI, MOHAMMED M.; ALMUTLAK, ABDULLAH A.; MUBARAK, ZIYAD A.
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 065590/0101 →
Continuity (1)
Related Publication 20250158964A1 · May 15, 2025
References Cited (8)
US 9270765B2 · Narayanaswamy · 2016 [cited by examiner]
US 10728246B2 · Bansal · 2020 [cited by examiner]
US 10986504B1 · Smith · 2021 [cited by examiner]
US 11700239B2 · Yin · 2023 [cited by examiner]
US 11968179B2 · Negrea · 2024 [cited by examiner]
US 12101247B2 · Vysotsky · 2024 [cited by examiner]
US 12284158B2 · Howe · 2025 [cited by examiner]
US 20230367833A1 · Kol · 2023 [cited by examiner]