IP Library Granted Patent US 8,533,309
Granted Patent B1
US 8,533,309 · App. 11/257,246 · Granted Sep 10, 2013

Systems and methods for distributed node detection and management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,533,309
App. No.
11/257,246
Granted
Sep 10, 2013
Kind
B1
Abstract

A discovery agent is running on a node within the network group. The network group is shielded from an administrative system by a communication limiting device. The communication limiting device prevents the administrative system from detecting nodes within the network group. The communication limiting device, however, does not prevent the node running the discovery agent from identifying other nodes within the network group. The discovery agent detects one or more nodes within the network group and transmits data identifying these nodes to the administrative system. Accordingly, the administrative system may identify and manage the newly detected nodes using a management agent installed on the nodes.

Claims (53)

1. A method of detecting and managing nodes within a network group, comprising:

providing an administrative computer system, a network group, and a communication pathway for electronic communication between the administrative computer system and the network group, wherein a communication limiting device in the communication pathway prevents the administrative computer system from detecting a first node within the network group;

managing a second node within the network group using a management agent to enable the administrative computer system to communicate with and manage the second node through the communication limiting device;

from the second node within the network group, detecting, by a discovery agent installed on the second node, the first node within the network group, wherein the discovery agent is separate and distinct from the management agent;

obtaining, at the second node, identifying data to identify the first node, wherein the identifying data comprises an address of the first node;

transferring the address of the first node to the administrative computer system;

transferring an installable management agent from the second node to the first node;

transferring the discovery agent to the first node, wherein the discovery agent is transferred after the transfer of the installable management agent to the first node, and wherein the discovery agent on the first node is executable to detect additional nodes, wherein the identifying data is obtained at the second node before the installable management agent and the discovery agent are transferred to the first node, wherein the address of the first node is obtained by the second node and transferred from the second node to the administrative computer system before the discovery agent is transferred to the first node;

installing and maintaining the installable management agent on the first node to enable the administrative computer system to communicate with and manage the first node through the communication limiting device; and

maintaining the discovery agent on the first node to detect additional nodes.

2. The method of claim 1 , further comprising:

compiling a list of nodes within the network group that are managed by the administrative computer system; and

based on the identifying data, determining whether the first node is included in the list of nodes, wherein transferring the installable management agent to the first node is based on whether the first node is included in the list of nodes.

3. The method of claim 1 , wherein transferring the installable management agent to the first node comprises transferring the installable management agent from the second node to the first node.

4. The method of claim 3 , wherein a domain login script on the second node is configured to transfer the installable management agent to the first node.

5. The method of claim 1 , further comprising transferring credential data to the administrative system to enable the administrative system to communicate with the first node.

6. The method of claim 5 , wherein transferring the installable management agent to the first node comprises transferring the installable management agent from the administrative system to the first node.

7. The method of claim 6 , wherein the credential data allows the administrative system to establish a virtual private network connection with the first node.

8. The method of claim 1 , wherein at least one of the first and second nodes are end-user nodes.

9. The method of claim 1 , wherein the administrative computer system sends a command to the second node to transfer the installable management agent to the first node, wherein the installable management agent is not transferred to the first node until the command from the administrative computer system is received.

10. The method of claim 1 , wherein obtaining identifying data to identify the first node comprises querying, by the discovery agent, at least one of User Datagram Protocol (UDP) packets, directory services, a Domain Name System (DNS) table, a Dynamic Host Configuration Protocol (DHCP) table, and a router table.

11. A system for detecting and managing nodes within a network group, comprising:

a first and a second node within a network group, the first and second nodes being in electronic communication with each other;

an administrative computer system;

a communication pathway for electronic communication between the network group and the administrative computer system;

a communication limiting device in the communication pathway that prevents the administrative computer system from detecting the first node within the network group, wherein the second node and administrative system include a computer-readable storage medium comprising instructions for detecting and managing nodes within the network group, the instructions being executable to:

manage the second node within the network group using a management agent to enable the administrative system to communicate with and manage the second node through the communication limiting device;

from the second node within the network group, detect, by a discovery agent installed on the second node, the first node within the network group, wherein the discovery agent is separate and distinct from the management agent;

obtain, at the second node, identifying data to identify the first node, wherein the identifying data comprises an address of the first node;

transfer the address of the first node to the administrative computer system;

transfer an installable management agent from the second node to the first node;

transfer the discovery agent to the first node, wherein the discovery agent is transferred after the transfer of the management agent to the first node, and wherein the discovery agent on the first node is executable to detect additional nodes, wherein the identifying data is obtained at the second node before the management agent and the discovery agent are transferred to the first node, wherein the address of the first node is obtained by the second node and transferred from the second node to the administrative computer system before the discovery agent is transferred to the first node;

install and maintain the installable management agent on the first node to enable the administrative computer system to communicate with and manage the first node through the communication limiting device; and

maintain the discovery agent on the first node to detect additional nodes.

12. The system of claim 11 , wherein the instructions are further executable to:

compile a list of nodes within the network group that are managed by the administrative computer system; and

based on the identifying data, determine whether the first node is included in the list of nodes, wherein transferring the installable management agent to the first node is based on whether the first node is included in the list of nodes.

13. The system of claim 11 , wherein the instructions to transfer the installable management agent to the first node comprise instructions to transfer the installable management agent from the second node to the first node.

14. The system of claim 11 , wherein at least one of the first and second nodes are end-user nodes.

15. A non-transitory computer-readable storage medium comprising executable instructions for detecting and managing nodes within a network group, the instructions being executable to:

provide an administrative computer system, a network group, and a communication pathway for electronic communication between the administrative computer system and the network group, wherein a communication limiting device in the communication pathway prevents the administrative computer system from detecting a first node within the network group;

manage a second node within the network group using a management agent to enable the administrative system to communicate with and manage the second node through the communication limiting device;

from the second node within the network group, detect, by a discovery agent installed on the second node, the first node within the network group, wherein the discovery agent is separate and distinct from the management agent;

obtain, at the second node, identifying data to identify the first node, wherein the identifying data comprises an address of the first node;

transfer the address of the first node to the administrative computer system;

transfer an installable management agent from the second node to the first node;

transfer the discovery agent to the first node, wherein the discovery agent is transferred after the transfer of the installable management agent to the first node, and wherein the discovery agent on the first node is executable to detect additional nodes, wherein the identifying data is obtained at the second node before the management agent and the discovery agent are transferred to the first node, wherein the address of the first node is obtained by the second node and transferred from the second node to the administrative computer system before the discovery agent is transferred to the first node;

install and maintain the installable management agent on the first node to enable the administrative computer system to communicate with and manage the first node through the communication limiting device; and

maintain the discovery agent on the first node to detect additional nodes.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions are further executable to:

compile a list of nodes within the network group that are managed by the administrative computer system; and

based on the identifying data, determine whether the first node is included in the list of nodes, wherein transferring the installable management agent to the first node is based on whether the first node is included in the list of nodes.

17. The non-transitory computer-readable storage medium of claim 15 , wherein at least one of the first and second nodes are end-user nodes.

Assignments (22)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →