IP Library Patent Application 16940487
Patent Application
App. No. 16/940,487

SINGLE SIGN-ON USING A MOBILE DEVICE MANAGEMENT ENROLLED DEVICE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/940,487
Abstract

Systems and methods for providing a single sign-on for authenticating a user via multiple client devices in a distributed resource environment are provided. For example, the system includes a processor that receives a first connection request to a remote resource from an untrusted client device. The processor processes the first connection request to identify an enrolled client device that is configured to authenticate a user of the untrusted client device. The processor further verifies whether a user of the enrolled client device is the user of the untrusted client device and determine if the user of the untrusted client device is authorized to access the remote resource. If the processor determines that the user of the untrusted client device is authorized to access the remote resource, the processor provides the untrusted client device access to the remote resource.

Claims (83)

1 . A computer system for providing a single sign-on for authenticating a user via multiple client devices in a distributed resource environment, the system comprising:

a memory;

a network interface; and

at least one processor coupled to the memory and the network interface and being configured to

receive, via the network interface, a first request to connect to a remote resource from an untrusted client device,

process the first request to identify an enrolled client device that is configured to authenticate a user of the untrusted client device,

verify that a user of the enrolled client device is the user of the untrusted client device, and

provide the untrusted client device access to the remote resource.

2 . The computer system of claim 1 , wherein to verify whether the user of the enrolled client device is the user of the untrusted client device comprises the at least one processor being further configured to:

identify mobile device management (MDM) device identification information for the enrolled client device received in the first request;

transmit the MDM device identification information to an MDM processor for processing;

receive authentication information from the MDM processor, the authentication information comprising information about the user of the enrolled client device; and

verify whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information.

3 . The computer system of claim 2 , wherein to verify whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information comprises the at least one processor being further configured to:

extract user identification information for the user of the enrolled client device from the authentication information;

compare the user identification information for the user of the enrolled client device against user identification information for the user of the untrusted client device; and

determine if the user identification information for the user of the enrolled client device matches the user identification information for the user of the untrusted client device.

4 . The computer system of claim 2 , further comprising the MDM processor, the MDM processor being configured to:

receive the MDM device identification information from the at least one processor;

identify the enrolled client device based upon the MDM device identification information;

verify the user of the enrolled client device; and

transmit the authentication information to the at least one processor based upon verification of the user of the enrolled client device.

5 . The computer system of claim 4 , wherein to verify the user of the enrolled client device comprises the MDM processor being further configured to:

transmit an authentication request to the enrolled client device;

receive an authentication response from the enrolled client device; and

verify the user of the enrolled client based upon the authentication response.

6 . The computer system of claim 5 , wherein the authentication response is based upon a biometric authentication process of the user of the enrolled client device performed by the enrolled client device.

7 . The computer system of claim 1 , wherein the first request comprises single sign-on information including an identifier of the enrolled client device.

8 . A method of providing a single sign-on for authenticating a user via multiple client devices in a distributed resource environment, the method comprising:

receiving, by at least one processor, a first request to connect to a remote resource from an untrusted client device;

processing, by the at least one processor, the first request to identify an enrolled client device configured to authenticate a user of the untrusted client device;

verifying, by the at least one processor, that a user of the enrolled client device is the user of the untrusted client device; and

providing, by the at least one processor, the untrusted client device access to the remote resource.

9 . The method of claim 8 , wherein verifying whether the user of the enrolled client device is the user of the untrusted client device comprises:

identifying, by the at least one processor, mobile device management (MDM) device identification information for the enrolled client device received in the first request;

transmitting, by the at least one processor, the MDM device identification information to an MDM processor for processing;

receiving, by the at least one processor, authentication information from the MDM processor comprising information about the user of the enrolled client device; and

verifying, by the at least one processor, whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information.

10 . The method of claim 9 , wherein verifying whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information comprises:

extracting, by the at least one processor, user identification information for the user of the enrolled client device from the authentication information;

comparing, by the at least one processor, the user identification information for the user of the enrolled client device against user identification information for the user of the untrusted client device; and

determining, by the at least one processor, if the user identification information for the user of the enrolled client device matches the user identification information for the user of the untrusted client device.

11 . The method of claim 9 , further comprising:

receiving, by an MDM processor operably coupled to the at least one processor, the MDM device identification information from the at least one processor;

identifying, by the MDM processor, the enrolled client device based upon the MDM device identification information;

verifying, by the MDM processor, the user of the enrolled client device; and

transmitting, by the MDM processor, the authentication information to the at least one processor based upon verification of the user of the enrolled client device.

12 . The method of claim 11 , wherein verifying the user of the enrolled client device comprises:

transmitting, by the MDM processor, an authentication request to the enrolled client device;

receiving, by the MDM processor, an authentication response from the enrolled client device; and

verifying, by the MDM processor, the user of the enrolled client based upon the authentication response.

13 . The method of claim 12 , wherein the authentication response is based upon a biometric authentication process of the user of the enrolled client device performed by the enrolled client device.

14 . The method of claim 8 , wherein the first request comprises single sign-on information including an identifier of the enrolled client device.

15 . A computer system for providing a single sign-on for authenticating a user via multiple client devices in a distributed resource environment, the system comprising:

an untrusted client device configured to execute a first client agent for authenticating the user of the untrusted client device;

an enrolled client device configured to execute a second client agent for authenticating the user of the enrolled client device; and

a remote computing device comprising

a memory,

a network interface configured to communicate with the untrusted client device and the enrolled client device, and

at least one processor coupled to the memory and the network interface and configured to

receive a first request to a remote resource from the untrusted client device,

process the first request to identify the enrolled client device that is configured to authenticate a user of the untrusted client device,

query the enrolled client device to verify whether a user of the enrolled client device is the user of the untrusted client device, and

if the user of the untrusted client device is authorized to access the remote resource, provide the untrusted client device access to the remote resource.

16 . The computer system of claim 15 , wherein to query the enrolled client device to verify whether a user of the enrolled client device is the user of the untrusted client device comprises the at least one processor being further configured to:

identify mobile device management (MDM) device identification information for the enrolled client device received in the first request;

transmit the MDM device identification information to an MDM processor for processing;

receive authentication information from the MDM processor comprising information about the user of the enrolled client device; and

verify whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information.

17 . The computer system of claim 16 , wherein to verify whether a user of the enrolled client device is the user of the untrusted client device based upon the authentication information comprises the at least one processor being further configured to:

extract user identification information for the user of the enrolled client device from the authentication information;

compare the user identification information for the user of the enrolled client device against user identification information for the user of the untrusted client device; and

determine if the user identification information for the user of the enrolled client device matches the user identification information for the user of the untrusted client device.

18 . The computer system of claim 16 , further comprising the MDM processor, the MDM processor being configured to:

receive the MDM device identification information from the at least one processor;

identify the enrolled client device based upon the MDM device identification information;

verify the user of the enrolled client device; and

transmit the authentication information to the at least one processor based upon verification of the user of the enrolled client device.

19 . The computer system of claim 18 , wherein to verify the user of the enrolled client device comprises the MDM processor being further configured to:

transmit an authentication request to the enrolled client device;

receive an authentication response from the enrolled client device; and

verify the user of the enrolled client based upon the authentication response.

20 . The computer system of claim 19 , wherein the authentication response is based upon a biometric authentication process of the user of the enrolled client device performed by the enrolled client device.

Assignments (7)
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2020
From: DEFILIPPO, RICHARD; PLANAS, RAUL; MHATRE, PRACHEE; KRISHNAMURTHY, PADMASHRI NONABUR
To: CITRIX SYSTEMS, INC.
Reel/Frame 053526/0697 →