IP Library Granted Patent US 7,360,242
Granted Patent B2
US 7,360,242 · App. 09/988,355 · Granted Apr 15, 2008

Personal firewall with location detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,360,242
App. No.
09/988,355
Granted
Apr 15, 2008
Kind
B2
Abstract

A computer device which can be connected to a home network and to a foreign network is provided with a local security mechanism, called a personal firewall, for protecting the computer device from attacks from the foreign network, in addition to or instead of a firewall in the internal network which protects the computer when connected to the internal network. The personal firewall is arranged to detect its current location, i.e. to determine the network to which it is connected at each particular moment, and to control its operation accordingly. The current location of the computer device is first determined on the basis of a currently used IP address of the computer device. Then this location determined on the basis of the current IP address of the computer device is verified by carrying out an additional location verification procedure with a predetermined network element.

Claims (35)

1. A method of detecting location for a personal firewall of a client computer, said method comprising

determining the current location of said personal firewall based on an Internet Protocol (IP) address currently used by said client computer,

verifying the current location determined on the basis of the current IP address of said client computer by carrying out a location verification procedure with a predetermined network element,

sending log files to a centralized log server from said personal firewall when the current location of said client computer is in said home network, said log files containing information on communication transactions in said client computer,

collecting log files locally at said personal firewall when the current location of said client computer is not in said home network,

transferring said locally collected log files from said personal firewall to said centralized log server when said client computer is connected to said home network.

2. A method according to claim 1 , wherein said step of determining comprises

storing in said personal firewall a list of IP addresses of a home network,

comparing the current IP address of said client computer with said list of IP addresses, and

if the current IP address of said client computer matches one of said addresses on said list, determining said personal firewall to be located in said home network.

3. A method according to claim 1 , wherein said step of determining comprises

storing in said client computer an IP address space of a home network,

comparing the current IP address of said client computer with said IP address space, and

if the current IP address of said client computer matches said IP address space, determining said personal firewall to be located in said home network.

4. A method according to claim 1 , 2 or 3 , wherein said step of verifying comprises

checking availability of said predetermined network element related to the current IP address, said predetermined network element responding only if said personal firewall is located in the network in which it is assumed to be on the basis of the current IP address,

verifying the current location determined based on said current IP address if said predetermined network element responds with a specific identity data.

5. A method according to claim 4 , wherein said specific identity data is a Media Access Control (MAC) address of said predetermined network element.

6. A method according to claim 4 , wherein said predetermined network clement is a firewall in said home network.

7. A method according to claim 1 , comprising

using said determined and verified location for selecting security rules for controlling said personal firewall in a location-dependent way.

8. A method according to claim 1 , comprising

using said determined and verified location for enabling a periodical security rule update enquiry from said personal firewall to the central management, when said personal firewall is in said home network, and for disabling said periodical enquiry, when said personal firewall is outside said home network.

9. A computer terminal, comprising

a personal firewall having a mechanism monitoring the current location of said personal firewall based on a Internet Protocol (IP) address currently used by said computer terminal,

said personal firewall having a mechanism verifying the current location determined on the basis of the current IP address of said client computer by carrying out a location verification procedure with a predetermined network element,

said personal firewall having a mechanism sending log files to a centralized log server from said personal firewall when the current location of said client computer is in said home network, said log files containing information on communication transactions in said client computer,

said personal firewall having a mechanism collecting log files locally at said personal firewall when the current location of said client computer is not in said home network, and

said personal firewall having a mechanism transferring said locally collected log files from said personal firewall to said centralized log server when said client computer is connected to said home network.

10. A computer-readable medium, containing a computer software which, when executed in a computer device, causes the computer device to provide a personal firewall routine comprising

determining the current location of said personal firewall based on an Internet Protocol (IP) address currently used by said client computer,

verifying the current location determined on the basis of the current IP address of said client computer by carrying out a location verification procedure with a predetermined network element,

sending log files to a centralized log server from said personal firewall when the current location of said client computer is in said home network, said log files containing information on communication transactions in said client computer,

collecting log files locally at said personal firewall when the current location of said client computer is not in said home network, and

transferring said locally collected log files from said personal firewall to said centralized log server when said client computer is connected to said home network.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FINLAND OY
To: FORCEPOINT LLC
Reel/Frame 043156/0547 →
CHANGE OF NAME Recorded Apr 15, 2016
From: WEBSENSE FINLAND OY
To: FORCEPOINT FINLAND OY
Reel/Frame 038447/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: STONESOFT OY DBA STONESOFT CORPORATION
To: WEBSENSE FINLAND OY
Reel/Frame 037828/0385 →