IP Library Granted Patent US 11,812,269
Granted Patent B2
US 11,812,269 · App. 17/528,091 · Granted Nov 7, 2023

Asserting user, app, and device binding in an unmanaged mobile device

Inventors: Renchi Raju (Belmont, CA); Vijay Pawar (Palo Alto, CA); Kumara Das Karunakaran (Milpitas, CA)
Assignee: Ivanti, Inc.
H04W12/108H04L12/4625H04L12/4641H04L63/0272H04L63/08H04L63/10H04L67/55H04W12/06H04W12/102H04W12/37H04L2463/082H04W12/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,812,269
App. No.
17/528,091
Granted
Nov 7, 2023
Kind
B2
Abstract

A request generated by an unmanaged app to access a resource is received from a mobile device. A notification is sent to the mobile device. A device level VPN connection to the mobile device is established. A unique identifier is associated with the device level VPN. App level traffic received via the device level VPN is tagged with the unique identifier. Access to the resource is allowed in response to the request based at least in part on a determination based on the tags that app level traffic from a trusted app and app level traffic from the unmanaged app are associated with the same mobile device.

Claims (53)

1. A system to manage access to a resource, comprising:

a communication interface configured to receive from a mobile device a request to access a resource at a cloud service; and

one or more processors coupled to the communication interface and configured to:

in response to receipt of the request being generated by an unmanaged application running on the mobile device, cause a device level virtual private network (VPN) connection to be established to the mobile device on which application-level traffic is received;

cause the application-level traffic received via the device level VPN to be tagged with a tag comprising a unique identifier associated with the device level VPN;

receive, via the communication interface, authentication traffic from a managed application mediating access to the cloud service;

determine whether the authentication traffic includes the tag;

based at least in part on a determination that the authentication traffic includes the tag, determine that the authentication traffic is received from the mobile device; and

in response to a determination that the authentication traffic is received from the mobile device, allow the mobile device access to the resource.

2. The system of claim 1 , wherein:

the causing the device level VPN connection to be established to the mobile device includes sending a notification to the mobile device in response to the receipt of the request; and

the notification is configured to cause the mobile device to invoke establishment of the device level VPN.

3. The system of claim 2 , wherein the notification comprises a push notification to a trusted application on the mobile device.

4. The system of claim 1 , wherein:

the causing the device level VPN connection to be established to the mobile device includes causing the managed application on the mobile device to receive traffic from multiple other applications on the mobile device; and

the managed application corresponds to the device level VPN.

5. The system of claim 1 , wherein the request is generated by the unmanaged app in response to an access redirection from a cloud service provider in connection with an authentication of the mobile device.

6. The system of claim 1 , wherein the device level VPN causes traffic from multiple applications on the mobile device to be routed via the device level VPN.

7. The system of claim 1 , wherein the device level VPN connection to the mobile device is established in response to determining that a security posture of the mobile device indicates that the mobile device is secure.

8. The system of claim 1 , wherein the device level VPN connection to the mobile device is established in response to determining that a trusted application on the mobile device indicates that the mobile device is secure.

9. The system of claim 8 , wherein the one or more processors are further configured to prevent establishment of the device level VPN connection in response to a determination that the trusted application indicates that the mobile device is not secure.

10. The system of claim 8 , wherein the trusted application comprises an authenticator application associated with a multi-factor authentication solution.

11. The system of claim 8 , wherein the trusted application has a secure connection on the mobile device to a mobile application management (MAM) application or agent.

12. The system of claim 11 , wherein the secure connection is provided via an application containerization solution.

13. The system of claim 1 , wherein the one or more processors are further configured to:

determine a security posture of the mobile device; and

deny access to the resource based at least in part on a determination that the mobile device is not in a secure state.

14. The system of claim 1 , wherein the authentication traffic is communicated in response to the mobile device attempting to access the cloud service.

15. The system of claim 1 , wherein the unmanaged application comprises an application associated with the service provider.

16. A method to manage access to a resource, comprising:

receiving, via a communication interface, from a mobile device a request to access a resource at a cloud service;

in response to receipt of the request being generated by an unmanaged application running on the mobile device, causing a device level virtual private network (VPN) connection to be established to the mobile device on which application-level traffic is received;

causing the application-level traffic received via the device level VPN to be tagged with a tag comprising a unique identifier associated with the device level VPN;

receiving, via the communication interface, authentication traffic from a managed application mediating access to the cloud service;

determining whether the authentication traffic includes the tag;

based at least in part on a determination that the authentication traffic includes the tag, further determining that the authentication traffic is received from the mobile device; and

in response to a determination that the authentication traffic is received from the mobile device, allowing the mobile device access to the resource.

17. A computer program product to manage access to a resource, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions that, when executed by one or more processors, cause the processors to:

receiving, via a communication interface, from a mobile device a request to access a resource at a cloud service;

in response to receipt of the request being generated by an unmanaged application running on the mobile device, causing a device level virtual private network (VPN) connection to be established to the mobile device on which application-level traffic is received;

causing the application-level traffic received via the device level VPN to be tagged with a tag comprising a unique identifier associated with the device level VPN;

receiving, via the communication interface, authentication traffic from a managed application mediating access to the cloud service;

determining whether the authentication traffic includes the tag;

based at least in part on a determination that the authentication traffic includes the tag, further determining that the authentication traffic is received from the mobile device; and

in response to a determination that the authentication traffic is received from the mobile device, allowing the mobile device access to the resource.

18. The system of claim 1 , wherein the unique identifier is specific to the mobile device.

19. The system of claim 1 , wherein the one or more processors are further configured to:

in response to receiving the request to access the resource from the mobile device, determine that the request is generated by the unmanaged application.

20. The system of claim 1 , wherein allowing the mobile device access to the resource includes:

allowing the unmanaged application to communicate with the cloud service in connection with accessing the resource.

21. The system of claim 1 , wherein the one or more processors are further configured to:

compare the tag associated with authentication traffic with the tag associated with application-level traffic;

in response to determining that the tag associated with authentication traffic matches the tag associated with application-level traffic, deeming the authentication traffic to be received from the mobile device.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 067457/0497 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071124/0331 →
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 067457/0472 →
SECOND LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 067457/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
Continuity (3)
Continuation 16246239 · Jan 11, 2019
Provisional Application 62617052 · Jan 12, 2018
Related Publication 20220150703A1 · May 12, 2022