IP Library Granted Patent US 8,601,102
Granted Patent B1
US 8,601,102 · App. 11/421,294 · Granted Dec 3, 2013

Dynamic access management for network security

Inventors: Chi-Cheng Lee (Cupertino, CA); Arvind Gopalan (Hacienda Heights, CA)
Assignee: Juniper Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,601,102
App. No.
11/421,294
Granted
Dec 3, 2013
Kind
B1
Abstract

A method for managing access to network resources by a first network device may include establishing a communication session with the first network device. The method may also include receiving information from the first network device during the communication session, the information indicating that the first network device is not in compliance with at least one security-related rule. The method may further include determining whether to modify access by the first network device to at least one of the network resources based on the received information.

Claims (68)

1. A method for managing access to network resources by a first network device, comprising:

establishing, by a processor, a communication session with the first network device, the communication session providing the first network device with access to the network resources;

receiving, by the processor, information from the first network device during the communication session, the information indicating that the first network device is not in compliance with at least one security-related rule; and

determining, by the processor, whether to modify access by the first network device to at least one of the network resources based on the received information.

2. The method of claim 1 , further comprising:

sending a message to the first network device when the determining determines that access to a first one of the at least one network resources is to be modified, the message indicating that access by the first network device to the first network resource is prohibited.

3. The method of claim 2 , where the method further comprises:

continuing to allow the first network device to access at least one other network resource of the network resources while access to the first network resource is prohibited.

4. The method of claim 1 , further comprising:

receiving information from the first network device at periodic intervals during the communication session, the information indicating a status of at least one of software or hardware included on the first network device; and

determining, at the periodic intervals, whether to modify access by the first network device to at least one of the network resources in response to the received information.

5. The method of claim 1 , where the receiving information is triggered by a change in configuration of the first network device.

6. The method of claim 1 , where the receiving information is triggered in response to a timer at the first network device reaching a predetermined value.

7. The method of claim 1 , further comprising:

initiating a re-evaluation of access to network resources by a plurality of network devices in response to the received information.

8. The method of claim 1 , further comprising:

storing information associated with a plurality of network devices, the information identifying a plurality of security rules associated with managing access to network resources by the plurality of network devices.

9. The method of claim 8 , where the determining comprises:

determining whether the first network device complies with the at least one security-related rule based on the stored information.

10. A system, comprising:

a memory to store security-related rules; and

a processor coupled to the memory, the processor to:

establish a client session with a first client device, the client session providing the first client device with access to at least one resource,

receive information from the first client device during the client session, the information indicating that the first client device is not in compliance with at client device has changed, and

determine whether to modify access by the first client device to the at least one resource based on the received information and the information stored in the memory.

11. The system of claim 10 , where the at least one security-related rule comprises information identifying at least one of anti-virus software or anti-spyware software associated with accessing the at least one resource.

12. The system of claim 10 , where when receiving information, the processor is to receive information indicating that the configuration of at least one of hardware or software associated with the first client device has changed.

13. The system of claim 10 , where the memory is further to:

store information associated with a plurality of client devices, the information identifying a plurality of security-related rules associated with managing access to resources by the plurality of client devices.

14. The system of claim 10 , where the at least one resource comprises a plurality of resources, and the processor is further to:

generate a message to the first client device when the processor determines that access to a first one of the plurality of resources is to be modified, the message indicating that access by the first client device to the first resource is prohibited, and

terminate access by the first client device to the first resource,

the system further comprising:

a transmit device to transmit the message to the first client device.

15. The system of claim 14 , where the message does not affect access by the first client device to resources other than the first resource.

16. The system of claim 14 , where the message indicates why access to the first resource is prohibited.

17. The system of claim 10 , where the processor is further to:

receive information from the first client device at periodic intervals during the client session, the information indicating a status of at least one of software or hardware included on the first client device, and

determine, at the periodic intervals, whether to modify access by the first client device to at least one of the network resources in response to the received information.

18. The system of claim 10 , where the processor is further to:

generate a message to re-evaluate access by a plurality of client devices to network resources in response to the received information,

the system further including:

a transmit device configured to transmit the message to the plurality of client devices.

19. The system of claim 18 , where the message includes an identifier identifying the plurality of client devices.

20. The system of claim 18 , where the message identifies a function or role performed by at least some of the plurality of client devices.

21. The system of claim 10 , where the processor is to receive the information from the first client device in response to a triggering event at the first client device.

22. A system, comprising:

a memory to store instructions; and

a processor to execute the instructions to implement:

means for establishing a client-sever session with a first client device, the client-server session providing the first client device with access to at least one network service or resource;

means for receiving information from the first client device during the client-server session, the information indicating that the first client device is not in compliance with at least one security-related rule or that a configuration of the first client device has changed; and

means for determining whether to modify access by the first client device to the at least one network service or resource based on the received information.

23. The system of claim 22 , further comprising:

means for initiating re-evaluation of access associated with a plurality of client devices based on the received information.

24. A network device, comprising:

a processor to:

establish a client-server session with a server, the client-server session providing the network device with access to one or more network resources,

periodically scan the network device during the client-server session to identify a status associated with at least one of hardware or software included on the network device, the periodic scanning being triggered by the network device, and

report the status associated with the network device to the server.

25. The network device of claim 24 , where the processor is further to:

identify a change in configuration of the network device, and

when reporting the status, the processor is to:

report the status associated with the network device in response to the identified change in configuration of the network device.

26. A computer-readable memory device having stored thereon sequences of instructions which, when executed by a processor of a network device, cause the processor to:

establish a communication session with a server controlling access to a plurality of resources, the communication session providing the network device with access to the plurality of resources;

periodically scan the network device during the communication session to identify a status associated with at least one of hardware or software included on the network device, the periodic scanning being triggered by the network device and not by a command from the server; and

report the status associated with the network device to the server.

27. The computer-readable memory device of claim 26 , where the instructions cause the processor to report the status associated with the network device in response to at least one of a hardware or software change associated with the network device.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
SECURITY INTEREST Recorded Dec 30, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034713/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034045/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2006
From: LEE, CHI-CHENG; GOPALAN, ARVIND
To: JUNIPER NETWORKS, INC.
Reel/Frame 017704/0799 →