US 11,812,269 B2
Asserting user, app, and device binding in an unmanaged mobile device
Renchi Raju, Belmont, CA (US); Vijay Pawar, Palo Alto, CA (US); and Kumara Das Karunakaran, Milpitas, CA (US)
Assigned to Ivanti, Inc., South Jordan, UT (US)
Filed by Ivanti, Inc., South Jordan, UT (US)
Filed on Nov. 16, 2021, as Appl. No. 17/528,091.
Application 17/528,091 is a continuation of application No. 16/246,239, filed on Jan. 11, 2019, granted, now 11,206,540.
Claims priority of provisional application 62/617,052, filed on Jan. 12, 2018.
Prior Publication US 2022/0150703 A1, May 12, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04W 12/108 (2021.01); H04L 12/46 (2006.01); H04L 9/40 (2022.01); H04W 12/06 (2021.01); H04W 12/37 (2021.01); H04W 12/102 (2021.01); H04L 67/55 (2022.01); H04W 12/03 (2021.01)
CPC H04W 12/108 (2021.01) [H04L 12/4625 (2013.01); H04L 12/4641 (2013.01); H04L 63/0272 (2013.01); H04L 63/08 (2013.01); H04L 63/10 (2013.01); H04L 67/55 (2022.05); H04W 12/06 (2013.01); H04W 12/102 (2021.01); H04W 12/37 (2021.01); H04L 2463/082 (2013.01); H04W 12/03 (2021.01)] 21 Claims
OG exemplary drawing
 
1. A system to manage access to a resource, comprising:
a communication interface configured to receive from a mobile device a request to access a resource at a cloud service; and
one or more processors coupled to the communication interface and configured to:
in response to receipt of the request being generated by an unmanaged application running on the mobile device, cause a device level virtual private network (VPN) connection to be established to the mobile device on which application-level traffic is received;
cause the application-level traffic received via the device level VPN to be tagged with a tag comprising a unique identifier associated with the device level VPN;
receive, via the communication interface, authentication traffic from a managed application mediating access to the cloud service;
determine whether the authentication traffic includes the tag;
based at least in part on a determination that the authentication traffic includes the tag, determine that the authentication traffic is received from the mobile device; and
in response to a determination that the authentication traffic is received from the mobile device, allow the mobile device access to the resource.