Providing Virtualized Private Network Tunnels
First Claim
1. A method, comprising:
- receiving, at a mobile device, policy information that describes one or more policies for providing an application of the mobile device with access to at least one resource accessible through an access gateway;
determining that the mobile device has a ticket that is valid, said ticket being configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the application to said at least one resource;
analyzing policy information to determine that network access to the at least one resource is permitted;
transmitting the ticket to the access gateway; and
creating the VPN tunnel for the application to access said at least one resource.
7 Assignments
0 Petitions
Accused Products
Abstract
Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.
23 Citations
20 Claims
-
1. A method, comprising:
-
receiving, at a mobile device, policy information that describes one or more policies for providing an application of the mobile device with access to at least one resource accessible through an access gateway; determining that the mobile device has a ticket that is valid, said ticket being configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the application to said at least one resource; analyzing policy information to determine that network access to the at least one resource is permitted; transmitting the ticket to the access gateway; and creating the VPN tunnel for the application to access said at least one resource. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. An apparatus, comprising:
-
at least one processor; and memory storing executable instructions configured to, when executed by the at least one processor, cause the apparatus to; receive policy information that describes one or more policies for providing an application of the mobile device with access to at least one resource that is accessible through an access gateway, determine that the mobile device has a ticket that is valid, said ticket being configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the application to said at least one resource, analyze policy information to determine that network access to the at least one resource is permitted, transmit the ticket to the access gateway, and create the VPN tunnel for the application to access said at least one resource. - View Dependent Claims (11, 12, 13, 14, 15, 16)
-
-
17. One or more non-transitory computer-readable media storing instructions configured to, when executed, cause at least one computing device to:
-
receive policy information that describes one or more policies for providing an application of the mobile device with access to at least one resource accessible through an access gateway; determine that the mobile device has a ticket that is valid, said ticket being configured to provide authentication in connection with creating a virtual private network (VPN) tunnel for the application to said at least one resource; analyze policy information to determine that network access to the at least one resource is permitted; transmit the ticket to the access gateway; and create the VPN tunnel for the application to access said at least one resource. - View Dependent Claims (18, 19, 20)
-
Specification