IP Library Granted Patent US 8,667,555
Granted Patent B1
US 8,667,555 · App. 11/678,432 · Granted Mar 4, 2014

Integrity plug-in-proxy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,667,555
App. No.
11/678,432
Granted
Mar 4, 2014
Kind
B1
Abstract

A system receives user data associated with a user device and integrity policies associated with the user data, and distributes the user data and the integrity policies to one or more remote integrity servers. The system further receives integrity results from the one or more remote integrity servers based on the user data and the integrity policies, and collates the integrity results to formulate an access recommendation or a single integrity result for the user device.

Claims (113)

1. A method comprising:

receiving, by a device, user data associated with a user device,

the user data including integrity information, associated with the user device, that is received from one or more integrity plug-ins associated with the user device,

the device being different than the user device;

generating, by the device and based on the received user data, a plurality of integrity policies,

each of the plurality of integrity policies being associated with a respective rule for accessing, by the user device, a resource,

each respective rule, associated with each of the plurality of integrity policies, being different;

parsing, by the device, each of the plurality of integrity policies to determine a type of the respective rule associated with each of the plurality of integrity policies;

determining, by the device and based on each determined type of respective rule, a remote integrity server, of a plurality of remote integrity servers, associated with processing each determined type of respective rule;

distributing, by the device, information identifying at least one respective rule and a portion of the user data corresponding to the at least one respective rule to at least one of the plurality of remote integrity servers based on at least one function performed by each of the plurality of remote integrity servers,

the portion of the user data being a subset of the user data and including a portion of the integrity information;

receiving, by the device, one or more integrity results from the at least one of the plurality of remote integrity servers based on the portion of the user data and the at least one respective rule,

at least one of the one or more integrity results indicating whether to grant or deny access, to the resource, by the user device; and

formulating, by the device and based on the one or more integrity results, at least one of an access recommendation or an overall integrity result for the user device.

2. The method of claim 1 , further comprising:

determining whether to grant or deny access to the user device based on the at least one of the access recommendation or the overall integrity result.

3. The method of claim 1 , where generating the plurality of integrity policies comprises:

receiving one or more integrity policies for analyzing the integrity information.

4. The method of claim 1 , where generating the plurality of integrity policies comprises:

receiving one or more integrity policies that include a condition for the user device to access a protected resource.

5. The method of claim 1 , where distributing the information identifying the at least one respective rule and the portion of the user data corresponding to the at least one respective rule comprises:

distributing the information identifying the at least one respective rule and the portion of the user data based on a portion of the plurality of integrity policies.

6. The method of claim 1 , where receiving the one or more integrity results comprises:

receiving the one or more integrity results from one or more remote integrity plug-ins associated with a respective one of the plurality of remote integrity servers.

7. The method of claim 1 , where formulating the at least one of the access recommendation or the overall integrity result further comprises:

formulating the at least one of the access recommendation or the overall integrity result to facilitate determination of whether to grant or deny access to the user device.

8. The method of claim 1 , where the device comprises a network access authority device.

9. The method of claim 1 , further comprising:

granting or denying access, by the user device, to the resource based on the at least one of the access recommendation or the overall integrity result.

10. The method of claim 1 , where formulating the at least one of the access recommendation or the overall integrity result further comprises:

formulating the at least one of the access recommendation or the overall integrity result for a single integrity policy of the plurality of integrity policies.

11. A method comprising:

receiving, by a device, user data associated with a user device requesting access to a resource,

the user data including integrity information, associated with the user device, that is received from one or more integrity plug-ins associated with the user device,

the device being different than the user device;

generating, by the device, a plurality of integrity policies based on the received user data,

each of the plurality of integrity policies being associated with a respective rule for accessing the resource,

each respective rule being different;

providing, by the device, the user data and the plurality of integrity policies to an integrity plug-in proxy of the device;

parsing, by the integrity plug-in proxy, each of the plurality of integrity policies to determine a type of the respective rule associated with each of the plurality of integrity policies;

determining, by the integrity plug-in proxy and based on each determined type of respective rule, a remote integrity server, of a plurality of remote integrity servers, associated with processing each determined type of respective rule;

distributing, by the integrity plug-in proxy, information identifying at least one respective rule and a portion of the user data corresponding to the at least one respective rule to at least one of the plurality of remote integrity servers based on at least one function performed by each of the plurality of remote integrity servers,

the portion of the user data being a subset of the user data and including a portion of the integrity information,

receiving, by the integrity plug-in proxy, one or more integrity results from the at least one of the plurality of remote integrity servers based on the portion of the user data and the at least one respective rule,

at least one of the one or more integrity results indicating whether to grant or deny access, to the resource, by the user device;

receiving, by the device, an access recommendation or an overall integrity result from the integrity plug-in proxy based on the received one or more integrity results; and

granting or denying, by the device, access to the user device based on the access recommendation or the overall integrity result.

12. The method of claim 11 , where generating the plurality of integrity policies comprises:

generating one or more integrity policies, of the plurality of integrity policies, that include a condition for the user device to access the resource.

13. The method of claim 11 , where each of the respective rules comprises:

at least one rule to examine the user device and prohibit the user device from accessing the resource when the user device is unsafe or non-compliant.

14. The method of claim 11 , where the device comprises a network access authority device.

15. The method of claim 11 , where granting or denying access to the user device comprises:

granting access to the user device when the user device is determined to be trustworthy based on the access recommendation or the overall integrity result.

16. The method of claim 11 , where granting or denying access to the user device comprises:

denying access to the user device when the user device is determined to be untrustworthy based on the access recommendation or the overall integrity result.

17. A device comprising:

a memory to store a plurality of instructions; and

a processor to execute the plurality of instructions in the memory to:

receive user data associated with a user device requesting access to a resource,

the user data including integrity information, associated with the user device, that is received from one or more integrity plug-ins associated with the user device;

generate a plurality of integrity policies based on the user data,

each of the plurality of integrity policies being associated with a respective rule for accessing the resource,

each respective rule, associated with each of the plurality of integrity policies, being different;

parse each of the plurality of integrity policies to determine a type of the respective rule associated with each of the plurality of integrity policies;

determine, based on each determined type of respective rule, a remote integrity server, of a plurality of remote integrity servers, associated with processing each determined type of respective rule;

distribute information identifying at least one respective rule and a portion of the user data corresponding to the at least one respective rule to at least one of the plurality of remote integrity servers based on at least one function performed by each of the plurality of remote integrity servers,

the portion of the user data being a subset of the user data and including a portion of the integrity information;

receive integrity results from the at least one of the plurality of remote integrity servers based on the portion of the user data and the at least one respective rule,

at least one of the integrity results indicating whether to grant or deny access, to the resource, by the user device;

collate the integrity results; and

formulate an access recommendation or an overall integrity result for the user device based on the collated integrity results.

18. The device of claim 17 , where the processor is further to:

receive one or more integrity policies for analyzing the integrity information.

19. The device of claim 17 , where the processor is further to:

receive one or more integrity policies that include a condition for the user device to access the resource.

20. The device of claim 17 , where the processor is further to:

receive the integrity results from one or more remote integrity plug-ins associated with each of the plurality of remote integrity servers.

21. The device of claim 17 , where the processor, when formulating the access recommendation or the overall integrity result, is further to:

formulate the access recommendation or the overall integrity result for multiple, different integrity policies.

22. The device of claim 17 , where the processor, when formulating the access recommendation or the overall integrity result, is further to:

formulate the access recommendation or the overall integrity result to facilitate determination of whether to grant or deny the user device access to the resource.

23. The device of claim 17 , where the processor, when formulating the access recommendation or the overall integrity result, is further to:

formulate the access recommendation or the overall integrity result for a single integrity policy.

24. The device of claim 17 , where the processor is further to:

grant or deny access, by the user device, to the resource based on formulating the access recommendation or the overall integrity result.

25. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions which, when executed by a device, cause the device to:

receive user information associated with a user device requesting access to a protected resource,

the user information including integrity information, associated with the user device, that is received from one or more integrity plug-ins associated with the user device;

generate a plurality of integrity policies based on the user information,

each of the plurality of integrity policies being associated with a respective rule for accessing, by the user device, the protected resource,

each respective rule, associated with each of the plurality of integrity policies, being different;

parse each of the plurality of integrity policies to determine a type of the respective rule associated with each of the plurality of integrity policies;

determine, based on each determined type of respective rule, a remote integrity server, of a plurality of remote integrity servers, associated with processing each determined type of respective rule;

distribute information identifying at least one respective rule and a portion of the user information corresponding to the at least one respective rule to at least one of the plurality of remote integrity servers based on at least one function performed by each of the plurality of remote integrity servers,

the portion of the user information being a subset of the user information and including a portion of the integrity information;

receive integrity results from the at least one of the plurality of remote integrity servers based on the portion of the user information and the at least one respective rule,

at least one of the integrity results indicating whether to grant or deny access, to the protected resource, by the user device;

collate the integrity results to determine an access recommendation or an overall integrity result; and

grant or deny the user device access to the protected resource based on the access recommendation or the overall integrity result.

26. The medium of claim 25 , where the one or more instructions to generate the plurality of integrity policies further comprise:

one or more instructions to generate integrity policies, of the plurality of integrity policies, that include a condition for the user device to access the protected resource.

27. The medium of claim 25 , where each of the respective rules comprises:

at least one rule to examine the user device and prohibit the user device from accessing the protected resource when the user device is unsafe or non-compliant.

28. The medium of claim 25 , further comprising:

one or more instructions to receive the access recommendation or the overall integrity result for a single integrity policy.

29. The medium of claim 25 , where the one or more instructions to grant or deny the user device access to the protected resource further comprise:

one or more instructions to grant the user device access to the protected resource when the user device is determined to be trustworthy based on the access recommendation or the overall integrity result.

30. The medium of claim 25 , where the one or more instructions to grant or deny the user device access to the protected resource further comprise:

one or more instructions to deny the user device access to the protected resource when the user device is determined to be untrustworthy based on the access recommendation or the overall integrity result.

31. The medium of claim 25 , where the one or more instructions to collate the integrity results to determine an access recommendation or an overall integrity result further comprise:

one or more instructions to collate the access recommendation or the overall integrity result for multiple, different integrity policies of the plurality of integrity policies.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
SECURITY INTEREST Recorded Dec 30, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034713/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034045/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2007
From: ERICKSON, STEVEN
To: JUNIPER NETWORKS, INC.
Reel/Frame 018928/0449 →