Per-app virtual private network tunnel for multiple processes

    公开(公告)号:US11356295B2

    公开(公告)日:2022-06-07

    申请号:US17208202

    申请日:2021-03-22

    申请人: VMware, Inc.

    摘要: Examples described herein include systems and methods for creating a per-app virtual private network (“VPN”) using hooking, even though an isolated process is used for networking functions. The isolated process can include networking functions of the WebView class for ANDROID. The application can start an HTTP proxy server to receive local HTTP requests. Then, the application can trigger a broadcast to the isolated process, causing the isolated process to route its HTTP requests to the HTTP proxy of the application. The application can then hook HTTP requests and send them to a virtual private network (“VPN”) tunnel server. This can allow an application to securely connect to enterprise files or data even though the networking functions occur in the isolated process.

    Methods for dynamically optimizing a flying ad-hoc network

    公开(公告)号:US11089606B1

    公开(公告)日:2021-08-10

    申请号:US16907324

    申请日:2020-06-22

    申请人: VMWARE, INC.

    摘要: Described herein are methods and systems for dynamically optimizing a Flying Ad-Hoc Network (“FANET”). A server that manages the FANET can receive information relating to the network activity of user devices connected to the FANET. Examples of the type of information included can include the user devices' locations, network connection quality, and network traffic volume dedicated to a Unified Endpoint Management (“UEM”) system of an enterprise. The server can analyze the network activity information based on a set of rules to prioritize the user devices connected to the FANET. The server can instruct unmanned aerial vehicles (“UAVs”) in the FANET to reposition themselves to provide the best connection for higher priority user devices.

    Device scenario management
    3.
    发明授权

    公开(公告)号:US11070388B2

    公开(公告)日:2021-07-20

    申请号:US17027871

    申请日:2020-09-22

    申请人: VMware, Inc.

    IPC分类号: H04L12/28

    摘要: Disclosed are various examples for dynamically generating and implementing scenario profiles for a network of devices, including IoT devices. A managed device can receive a dynamically generated scenario profile that defines tasks to be performed by the device for a given scenario. The device can also receive a scenario message that is broadcasted to all managed devices in a network and identifies an occurrence of a given scenario. If the device determines that the device is an intended recipient of the scenario message, the device can identify the scenario profile associated with the given scenario and perform the tasks defined by the scenario profile. The scenario profile can be modified and/or updated based on event data associated with the device.

    DYNAMIC VARIANCE MECHANISM FOR SECURING ENTERPRISE RESOURCES USING A VIRTUAL PRIVATE NETWORK

    公开(公告)号:US20210185012A1

    公开(公告)日:2021-06-17

    申请号:US16788325

    申请日:2020-02-12

    申请人: VMWARE, INC.

    IPC分类号: H04L29/06 H04W12/00 G06N20/00

    摘要: Disclosed are various examples for securing enterprise resources using a virtual private network. A client device can send a first unique device identifier for the client device to a remote management service upon enrollment. When a virtual private network application is first executed, the client device can send a second unique device identifier to the remote management service, where the remote management service is configured to store the second unique device identifier in association with the first unique universal identifier. During subsequent executions of the virtual private network application, the virtual private network service can authenticate the client device by comparing the first unique device identifier and the second unique device identifier to a device identifier received from the remote management service. A machine learning routine can be employed to identify anomalies as the virtual private network application is executed.

    Dynamic variance mechanism for securing enterprise resources using a virtual private network

    公开(公告)号:US11418488B2

    公开(公告)日:2022-08-16

    申请号:US16788325

    申请日:2020-02-12

    申请人: VMWARE, INC.

    IPC分类号: H04L9/40 G06N20/00 H04W12/40

    摘要: Disclosed are various examples for securing enterprise resources using a virtual private network. A client device can send a first unique device identifier for the client device to a remote management service upon enrollment. When a virtual private network application is first executed, the client device can send a second unique device identifier to the remote management service, where the remote management service is configured to store the second unique device identifier in association with the first unique universal identifier. During subsequent executions of the virtual private network application, the virtual private network service can authenticate the client device by comparing the first unique device identifier and the second unique device identifier to a device identifier received from the remote management service. A machine learning routine can be employed to identify anomalies as the virtual private network application is executed.

    USER PROFILE DISTRIBUTION AND DEPLOYMENT SYSTEMS AND METHODS

    公开(公告)号:US20220150323A1

    公开(公告)日:2022-05-12

    申请号:US17581232

    申请日:2022-01-21

    申请人: VMware, Inc.

    IPC分类号: H04L67/306 H04L67/55 H04L9/40

    摘要: A first server can generate user profiles and receive requests from user devices for enrollment in a first server-managed system that includes user groups. The first server can provide a unique key to a user device during an enrolment process based on a user group the user device is assigned to. The first server can include an enrollment notification for the user device in a first notification transmitted to a messaging service. The messaging service can transmit a second notification to the user device, and the user device can request a user profile from a second server based on second server access information included in the second notification. The second server can use the unique key to access user profile information which it transmits to the user device based on the request. The user device can access the user profile from the profile information using the unique key.

    SINGLE SIGN ON (SSO) CAPABILITY FOR SERVICES ACCESSED THROUGH MESSAGES

    公开(公告)号:US20210203653A1

    公开(公告)日:2021-07-01

    申请号:US16790776

    申请日:2020-02-14

    申请人: VMWARE, INC.

    IPC分类号: H04L29/06 H04L12/24

    摘要: Disclosed are various approaches for facilitating single sign-on (SSO) for third-party services that are accessible through messages (e.g., email) received by a user. A user can receive a message that includes an embedded URL or link that opens in a third-party service that requires authentication. Instead of requiring the user to enter authentication credentials for accessing the third-party service, a tunnel service can be used to intercept requests for authentication and redirect the requests to an identity manager that can issue a SSO token following an authentication of the user and device. Upon supplying the third-party service with the SSO token, the user can access the content associated with the third-party service without entering authentication credentials.