IP Library Granted Patent US 8,225,091
Granted Patent B1
US 8,225,091 · App. 10/813,248 · Granted Jul 17, 2012

Systems and methods for protecting sensitive files from unauthorized access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,225,091
App. No.
10/813,248
Granted
Jul 17, 2012
Kind
B1
Abstract

Systems and methods for protecting sensitive files from unauthorized access are disclosed. An exemplary method involves detecting a connection of the computing device to an electronic device. An authorized connection list is accessed. It is then determined whether the connection is identified in the authorized connection list. If the connection is not identified in the authorized connection list, the method involves accessing sensitive file information which identifies at least one sensitive file stored on the computing device, and preventing access to the at least one sensitive file identified by the sensitive file information.

Claims (56)

1. In a computing device, a method for protecting sensitive files from unauthorized access, comprising:

detecting a connection of the computing device to an electronic device;

accessing an authorized connection list, wherein the authorized connection list comprises a list of at least one authorized network or a list of at least one authorized connection type;

determining whether the connection is identified in the authorized connection list; and

if the connection is not identified in the authorized connection list:

accessing sensitive file information which identifies multiple sensitive files stored on the computing device, wherein the sensitive files are not identified until after the connection has been identified as not being in the authorized connection list, wherein the sensitive file information is separate from the sensitive files; and

preventing access to all of the sensitive files identified by the sensitive file information by performing an access prevention task after the connection is not identified in the authorized connection list, wherein the sensitive files continue to be stored on the computing device but all of the sensitive files cannot be accessed when access is being prevented.

2. The method of claim 1 , wherein if the connection is not identified in the authorized connection list the method further comprises:

detecting termination of the connection; and

if the computing device does not have any other unauthorized connections, restoring access to the sensitive files identified by the sensitive file information.

3. The method of claim 1 , wherein the connection occurs via a computer network.

4. The method of claim 3 , wherein the network is a wireless network, and wherein the computing device is a mobile computing device.

5. The method of claim 1 , wherein the connection is a direct connection.

6. The method of claim 1 , wherein the access prevention task comprises locking the sensitive files.

7. The method of claim 1 , wherein the access prevention task comprises encrypting the sensitive files.

8. The method of claim 1 , wherein the computing device comprises a storage device, and wherein the access prevention task comprises moving the sensitive files to a host-protected area of the storage device.

9. The method of claim 1 , wherein the sensitive file information is a reference to a directory in which at least one of the sensitive files is stored.

10. The method of claim 1 , wherein the sensitive file information is a list of the sensitive files.

11. In an administrative system which distributes software to a plurality of computing devices on an enterprise network, a method comprising:

providing a security agent, wherein after installation on a computing device the security agent is configured to:

detect a connection of the computing device to an electronic device;

access an authorized connection list, wherein the authorized connection list comprises a list of at least one authorized network or a list of at least one authorized connection type;

determine whether the connection is identified in the authorized connection list; and

if the connection is not identified in the authorized connection list:

access sensitive file information which identifies multiple sensitive files stored on the computing device, wherein the sensitive files are not identified until after the connection has been identified as not being in the authorized connection list, wherein the sensitive file information is separate from the sensitive files; and

prevent access to all of the sensitive files identified by the sensitive file information by performing an access prevention task after the connection is not identified in the authorized connection list, wherein the sensitive files continue to be stored on the computing device but all of the sensitive files cannot be accessed when access is being prevented; and

transmitting the security agent to the plurality of computing devices via the enterprise network.

12. The method of claim 11 , further comprising:

providing the authorized connection list;

providing the sensitive file information; and

transmitting the authorized connection list and the sensitive file information to the plurality of computing devices via the enterprise network.

13. A computing device that is configured for protecting sensitive files from unauthorized access, comprising:

a processor;

memory in electronic communication with the processor; and

instructions stored in the memory, the instructions being executable to:

detect a connection of the computing device to an electronic device;

access an authorized connection list, wherein the authorized connection list comprises a list of at least one authorized network or a list of at least one authorized connection type;

determine whether the connection is identified in the authorized connection list; and

if the connection is not identified in the authorized connection list:

access sensitive file information which identifies multiple sensitive files stored on the computing device, wherein the sensitive files are not identified until after the connection has been identified as not being in the authorized connection list, wherein the sensitive file information is separate from the sensitive files; and

prevent access to all of the sensitive files identified by the sensitive file information by performing an access prevention task after the connection is not identified in the authorized connection list, wherein the sensitive files continue to be stored on the computing device but all of the sensitive files cannot be accessed when access is being prevented.

14. The computing device of claim 13 , wherein if the connection is not identified in the authorized connection list the instructions are further executable to:

detect termination of the connection; and

if the computing device does not have any other unauthorized connections, restore access to the sensitive files identified by the sensitive file information.

15. The computing device of claim 13 , wherein the access prevention task comprises at least one of locking the sensitive files, encrypting the sensitive files, and moving the sensitive files to a host-protected area of a storage device.

16. A non-transitory computer-readable medium for storing program data, wherein the program data comprises executable instructions, the executable instructions being executable to:

detect a connection of a computing device to an electronic device;

access an authorized connection list, wherein the authorized connection list comprises a list of at least one authorized network or a list of at least one authorized connection type;

determine whether the connection is identified in the authorized connection list; and

if the connection is not identified in the authorized connection list:

access sensitive file information which identifies multiple sensitive files stored on the computing device, wherein the sensitive files are not identified until after the connection has been identified as not being in the authorized connection list, wherein the sensitive file information is separate from the sensitive files; and

prevent access to all of the sensitive files identified by the sensitive file information by performing an access prevention task after the connection is not identified in the authorized connection list, wherein the sensitive files continue to be stored on the computing device but all of the sensitive files cannot be accessed when access is being prevented.

17. The non-transitory computer-readable medium of claim 16 , wherein if the connection is not identified in the authorized connection list the executable instructions are further executable to:

detect termination of the connection; and

if the computing device does not have any other unauthorized connections, restore access to the sensitive files identified by the sensitive file information.

18. The non-transitory computer-readable medium of claim 16 , wherein the access prevention task comprises at least one of locking the sensitive files, encrypting the sensitive files, and moving the sensitive files to a host-protected area of a storage device.

Assignments (31)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 29, 2012
From: D.E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C., AS AGENT
To: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
Reel/Frame 027783/0491 →
PATENT SECURITY AGREEMENT Recorded Sep 30, 2010
From: LAN DESK SOFTWARE, INC.; CRIMSON CORPORATION
To: D. E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C. AS AGENT
Reel/Frame 025095/0982 →
PATENT SECURITY AGREEMENT Recorded Sep 28, 2010
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 025056/0391 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNEE PREVIOUSLY RECORDED ON REEL 015171 FRAME 0237. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF PATENT SHOULD CORRECTL NAME LANDESK SOFTWARE LIMITED AS THE PROPER ASSIGNEE. Recorded Sep 3, 2010
From: PIMENTEL, PLINIO
To: LANDESK SOFTWARE LIMITED
Reel/Frame 024938/0475 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2010
From: CRIMSON HOLDING CORP.
To: LANDESK GROUP LIMITED
Reel/Frame 024823/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2010
From: LANDESK GROUP LIMITED
To: CRIMSON CORPORATION
Reel/Frame 024823/0656 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2010
From: LANDESK SOFTWARE LTD.
To: CRIMSON HOLDING CORP.
Reel/Frame 024823/0641 →
CHANGE OF NAME Recorded Mar 9, 2010
From: LANDESK IRELAND LIMITED
To: LANDESK SOFTWARE LIMITED
Reel/Frame 024045/0899 →
CORRECTIVE ASSIGMENT TO CORRECT THE ATTORNEY'S ADDRESS, ASSIGNOR'S NAME AND ASSIGNEE'S ADDRESS PREVIOUSLY RECORDED AT REEL 015171 FRAME 0237. Recorded Oct 5, 2004
From: PIMENTEL, PLINIO
To: LANDESK IRELAND LIMITED
Reel/Frame 015854/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2004
From: PEMENTEL, PLINIO
To: LANDESK IRELAND LIMITED
Reel/Frame 015171/0237 →