IP Library Granted Patent US 7,664,822
Granted Patent B2
US 7,664,822 · App. 10/459,421 · Granted Feb 16, 2010

Systems and methods for authentication of target protocol screen names

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,664,822
App. No.
10/459,421
Granted
Feb 16, 2010
Kind
B2
Abstract

A protocol management system is capable of detecting certain message protocols and applying policy rules to the detected message protocols that prevent intrusion, or abuse, of a network's resources. In one aspect, a protocol message gateway is configured to apply policy rules to high level message protocols, such as those that reside at layer 7 of the ISO protocol stack.

Claims (44)

1. A method for managing communication policy in a network, the method comprising:

receiving a first message from a client device over a network, the client device associated with a user having at least two different screen names, each of the screen names being an alias of the user, the first message being generated according to a first instant messaging protocol, the first message being associated with a first one of the at least two screen names;

determining a unique name of the user in response to receiving the first message, said determining comprising interrogating a registry of the client device;

selecting a policy rule for controlling the user's usage of instant messaging within an enterprise network based at least partly on the user's unique name, wherein the policy rule comprises a rule for restricting the user from sending or receiving a predefined number of messages within a given time period;

applying the policy rule to the first message;

receiving a second message from the client device, the second message being generated according to a second instant messaging protocol different than the first instant messaging protocol, the second message being associated with a second one of the at least two screen names, the second screen name being different than the first screen name;

determining the user's unique name in response to receiving the second message; and

applying the policy rule to the second message, such that the same policy rule is applied to instant message communications by the user whether the user uses the first or second screen name.

2. The method of claim 1 , wherein the policy rule comprises a policy for resetting a communication connection associated with the first or second message.

3. The method of claim 1 , wherein the policy rule is based on information included in the first or second message.

4. The method of claim 1 , wherein the policy rule is based on when the first or second message is sent or intended to be received.

5. The method of claim 1 , wherein the policy rule is based on the size of the first or second message.

6. The method of claim 1 , wherein the policy rule is based on whether the first or second message includes an attachment.

7. The method of claim 1 , wherein the policy rule is based on whether the first or second message includes a virus.

8. The method of claim 1 , further comprising determining if a session associated with the first or second message is still in progress before applying the policy rule.

9. The method of claim 1 , further comprising recording information associated with the first or second message.

10. The method of claim 1 , further comprising creating a log comprising information associated with the first or second message and any related messages.

11. The method of claim 1 , wherein the first message is associated with a network address, and wherein determining the unique user name further comprises identifying the client device using the network address.

12. The method of claim 11 , wherein interrogating the registry of the client device further comprises determining a global user identification associated with the client device.

13. The method of claim 12 , further comprising associating the first screen name with the unique user name and storing the association between the first screen name and the unique user name in a database.

14. A user authentication module, comprising:

a network interface configured to receive first and second messages from a client device associated with a user over a network, the first and second messages generated according to different instant messaging protocols, the first message being associated with a first screen name of the user, the second message being associated with a second screen name of the user, the second screen name being different than the first screen name; and

the user authentication module configured to:

access a user database stored in a computer memory to determine whether the first screen name is associated with a unique name of the user,

in response to a determination that the first screen name is associated with the unique user name, forward the unique user name to a policy enforcement module operative to process the message according to a policy rule for restricting the user from sending or receiving a predefined number of messages within a given time period,

determine whether the second screen name is stored in the user database,

in response to a determination that the second screen name is not stored in the user database, interrogate a registry at the client device to obtain a user identifier,

use the user identifier to obtain the unique user name,

associate the second screen name with the unique user name,

store the association between the second screen name and the unique user name in the user database, and

forward the unique user name to the policy enforcement module, the policy enforcement module being operative to process the second message according to the same policy rule, such that the same policy rule is applied to instant message communications by the user whether the user uses the first or second screen name.

15. The user authentication module of claim 14 , wherein the policy rule comprises a policy for resetting a communication connection associated with the first or second message.

16. The user authentication module of claim 14 , wherein the policy rule is based on the intended destination of the first or second message.

17. The user authentication module of claim 14 , wherein the policy rule is based on information included in the first or second message.

18. The user authentication module of claim 14 , wherein the policy rule is based on when the first or second message is sent or intended to be received.

19. The user authentication module of claim 14 , wherein the policy rule is based on the size of the first or second message.

20. The user authentication module of claim 14 , wherein the policy rule is based on whether the first or second message includes an attachment.

21. The user authentication module of claim 14 , wherein the policy rule is based on whether the first or second message includes a virus.

22. The user authentication module of claim 14 , further configured to determine if a session associated with the first or second message is still in progress before applying the policy rule.

23. The user authentication module of claim 14 , further configured to record information associated with the first or second message.

24. The user authentication module of claim 14 , further configured to create a log comprising information associated with the first or second message and any related messages.

25. The user authentication module of claim 14 , wherein the first or second message is associated with a network address, and wherein determining a unique user name comprises identifying the source using the network address.

26. The user authentication module of claim 25 , wherein determining a unique user name further comprises determining a global user identification associated with the client device.

27. The user authentication module of claim 26 , further configured to use the global user identification to request the unique user name from a domain controller.

Assignments (24)
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
RELEASE OF SECURITY INTEREST Recorded Sep 20, 2013
From: MENLO VENTURES IX, L.P.; MENLO ENTREPRENEURS FUND IX, L.P.; MENLO ENTREPRENEURS FUND IX(A), L.P.; MMEF IX, L.P.; PALOMAR VENTURES II, L.P.; WINDWARD VENTURES 2000, L.P.; WINDWARD VENTURES 2000-A, L.P.; MISSION VENTURES II, L.P.; MISSION VENTURES AFFILIATES II, L.P.; GC&H INVESTMENTS, LLC; PERFORMANCE DIRECT INVESTMENTS I, L.P.; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-127; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-128; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-129; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-130
To: AKONIX SYSTEMS, INC.
Reel/Frame 031247/0495 →
CHANGE OF NAME Recorded Aug 20, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031043/0281 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Sep 28, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC (FORMERLY KNOWN AS WELLS FARGO FOOTHILL, LLC)
To: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
Reel/Frame 029050/0679 →