发明名称 Providing virtualized private network tunnels
摘要 Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.
申请公布号 US8914845(B2) 申请公布日期 2014.12.16
申请号 US201314029068 申请日期 2013.09.17
申请人 Citrix Systems, Inc. 发明人 Barton Gary;Lang Zhongmin;Desai Nitin;Walker James Robert
分类号 G06F17/00;H04L29/06;H04W12/06 主分类号 G06F17/00
代理机构 Banner & Witcoff, Ltd. 代理人 Banner & Witcoff, Ltd.
主权项 1. A method, comprising: receiving, at a mobile device, policy information that describes one or more policies for providing an application of the mobile device with access to at least one resource accessible through an access gateway; determining that a ticket stored by the mobile device is valid, wherein the ticket is configured to provide authentication in connection with establishing a per-application policy-controlled virtual private network (VPN) tunnel for the application to the at least one resource, wherein the ticket includes a validity duration; analyzing policy information to determine that network access to the at least one resource is permitted; transmitting the ticket to the access gateway as part of a process of establishing the per-application policy-controlled VPN tunnel that is inaccessible to other applications of the mobile device; accessing the at least one resource via the per-application policy-controlled VPN tunnel; transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a first time; closing the per-application policy-controlled VPN tunnel after re-establishing the per-application policy-controlled VPN tunnel the first time; and after closing the per-application policy-controlled VPN tunnel, transmitting, during the validity duration, the ticket to the access gateway to cause the per-application policy-controlled VPN tunnel to be re-established a second time.
地址 Fort Lauderdale FL US
您可能感兴趣的专利