IP Library Granted Patent US 8,584,194
Granted Patent B1
US 8,584,194 · App. 11/214,467 · Granted Nov 12, 2013

Network access control using a quarantined server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,584,194
App. No.
11/214,467
Granted
Nov 12, 2013
Kind
B1
Abstract

Network address requests from candidate nodes are directed to a quarantined server rather than a network address server. The candidate node is admitted to a virtual network, enabling the candidate node to access only limited resources of the network and minimizing security risks to the network. The quarantined server determines whether the candidate node complies with a set of security criteria. If the candidate node conforms to the set of criteria, when a second request for a network address is sent by the candidate node, the second request is received by the quarantined server and relayed to the network address server. Thereafter, the network address server will issue a network address to the candidate node, enabling the candidate node to access at least a portion of the full resources of the network. If the candidate node does not comply with the security criteria and cannot be remediated, the network address server will not issue a network address to the candidate node.

Claims (46)

1. A method for minimizing security risks presented by adding a new node to a network, comprising:

capturing a first request to obtain a network address for a network from a candidate node at a validation module of a quarantined server;

transmitting a quarantined network address for a virtual network to the candidate node to enable the candidate node to communicate with only resources within the virtual network, wherein transmitting the quarantined network address to the candidate node occurs after the first request to obtain the network address has been captured;

admitting the candidate node to the virtual network, wherein the candidate node is admitted to the virtual network before any determination is made whether the candidate node satisfies a set of security criteria from a remediation module of the quarantined server;

determining whether the candidate node satisfies the set of security criteria from the remediation module of the quarantined server, wherein determining whether the candidate node satisfies the set of security criteria occurs after the quarantined network address has been transmitted to the candidate node and is based upon the first request, wherein determining comprises sending a script from the quarantined server to the quarantined network address after the quarantined network address has been sent to the candidate node, wherein the script scans the candidate node to determine whether the candidate node uses an updated version of anti-virus software and an updated version of an operating system;

receiving an authorization message at the validation module if the candidate node satisfies the set of security criteria;

transmitting a relayed request for a network address from the validation module to a network address server,

wherein a candidate node that does not satisfy the set of security criteria is prevented from transmitting a request for a network address, either directly or by a relayed request, to the network address server even if a conventional non-specialized router or switch is present in the network, wherein the validation module captures only network address requests and all other network traffic, either to or from the candidate node, is not required to pass through the validation module of the quarantined server; and

transmitting a network address from the network address server to the candidate node when the candidate node does satisfy the set of security criteria, wherein the transmitted network address is transmitted directly to the candidate node and does not pass through the validation module of the quarantined server.

2. The method of claim 1 , further comprising capturing a second request for a network address from the candidate node at the validation module, wherein the relayed request for a network address is transmitted to the network address server in response to capturing the second request.

3. The method of claim 2 , wherein the network is an Internet protocol (IP) network.

4. The method of claim 3 , wherein the network address server is a Dynamic Host Configuration Protocol (DHCP) server.

5. The method of claim 3 , wherein the second request for a network address is an IP renewal request.

6. The method of claim 1 , wherein the network is configured such that all network address requests are directed to the validation module of the quarantined server rather than the network address server.

7. The method of claim 1 , wherein the quarantined server comprises a plurality of servers.

8. The method of claim 1 , further comprising attempting to remediate the candidate node if the candidate node does not conform to the set of security criteria.

9. The method of claim 1 , wherein determining whether the candidate node satisfies the set of security criteria is implemented on the quarantined server.

10. A computer system that is configured for minimizing security risks to a network while adding a node to the network, the computer system comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

capture a first request to obtain a network address for a network from a candidate node at a validation module of a quarantined server;

transmit a quarantined network address for a virtual network to the candidate node to enable the candidate node to communicate with only resources within the virtual network, wherein the quarantined network address is transmitted to the candidate node after the first request to obtain the network address has been captured;

admit the candidate node to the virtual network, wherein the candidate node is admitted to the virtual network before any determination is made whether the candidate node satisfies a set of security criteria from a remediation module of the quarantined server;

determine whether the candidate node satisfies the set of security criteria from the remediation module, wherein a determination whether the candidate node satisfies the set of security criteria occurs after the quarantined network address has been transmitted to the candidate node and is based upon the first request, wherein determining comprises sending a script from the quarantined server to the quarantined network address after the quarantined network address has been sent to the candidate node, wherein the script scans the candidate node to determine whether the candidate node uses an updated version of anti-virus software and an updated version of an operating system;

receive an authorization message at the validation module if the candidate node satisfies the set of security criteria;

transmit a relayed request for a network address from the validation module to a network address server,

wherein a candidate node that does not satisfy the set of security criteria is prevented from transmitting a request for a network address, either directly or by a relayed request, to the network address server even if a conventional non-specialized router or switch is present in the network, wherein the validation module captures only network address requests and all other network traffic, either to or from the candidate node, is not required to pass through the validation module of the quarantined server; and

transmit a network address from the network address server to the candidate node when the candidate node does satisfy the set of security criteria, wherein the transmitted network address is transmitted directly to the candidate node and does not pass through the validation module of the quarantined server.

11. The system of claim 10 , wherein the instructions are further executable to capture a second request for a network address from the candidate node at the validation module, wherein the relayed request for a network address is transmitted to the network address server in response to capturing the second request.

12. The system of claim 10 , wherein the network is configured such that all network address requests are directed to the validation module of the quarantined server rather than the network address server.

13. The system of claim 10 , wherein the instructions are further executable to attempt to remediate the candidate node if it does not conform to the set of security criteria.

14. The system of claim 10 , wherein determining whether the candidate node satisfies the set of security criteria is implemented on the quarantined server.

15. A non-transitory computer-readable medium comprising executable instructions for minimizing security risks to a network while adding a node to the network, the instructions being executable to:

capture a first request to obtain a network address for a network from a candidate node at a validation module of a quarantined server;

transmit a quarantined network address for a virtual network to the candidate node to enable the candidate node to communicate with only resources within the virtual network, wherein the quarantined network address is transmitted to the candidate node after the first request to obtain the network address has been captured;

admit the candidate node to the virtual network, wherein the candidate node is admitted to the virtual network before any determination is made whether the candidate node satisfies a set of security criteria from a remediation module of the quarantined server;

determine whether the candidate node satisfies the set of security criteria from the remediation module of the quarantined server, wherein a determination whether the candidate node satisfies the set of security criteria occurs after the quarantined network address has been transmitted to the candidate node and is based upon the first request, wherein determining comprises sending a script from the quarantined server to the quarantined network address after the quarantined network address has been sent to the candidate node, wherein the script scans the candidate node to determine whether the candidate node uses an updated version of anti-virus software and an updated version of an operating system;

receive an authorization message at the validation module if the candidate node satisfies the set of security criteria;

transmit a relayed request for a network address from the validation module to a network address server,

wherein a candidate node that does not satisfy the set of security criteria is prevented from transmitting a request for a network address, either directly or by a relayed request, to the network address server even if a conventional non-specialized router or switch is present in the network, wherein the validation module captures only network address requests and all other network traffic, either to or from the candidate node, is not required to pass through the validation module of the quarantined server; and

transmit a network address from the network address server to the candidate node when the candidate node does satisfy the set of security criteria, wherein the transmitted network address is transmitted directly to the candidate node and does not pass through the validation module of the quarantined server.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions are further executable to capture a second request for a network address from the candidate node at the validation module, wherein the relayed request for a network address is transmitted to the network address server in response to capturing the second request.

17. The non-transitory computer-readable medium of claim 16 , wherein the network is an Internet protocol (IP) network.

18. The non-transitory computer-readable medium of claim 17 , wherein the second request for a network address is an IP renewal request.

19. The non-transitory computer-readable medium of claim 15 , wherein determining whether the candidate node satisfies the set of security criteria is implemented on the quarantined server.

Assignments (22)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →