IP Library Granted Patent US 8,850,547
Granted Patent B1
US 8,850,547 · App. 11/686,113 · Granted Sep 30, 2014

Remote access service inspector

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,850,547
App. No.
11/686,113
Granted
Sep 30, 2014
Kind
B1
Abstract

A method, system, and computer program product for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections. A remote access configuration file is created for the remote access client. A digital hash of the configuration file is then generated. The digital hash is compared with a configuration file stored at a predefined web location. If the comparison results in a match between the digital hash and the stored configuration file, a digital hash comparison is performed between an encrypted remote access configuration file and an encrypted configuration file stored at the predefined web location. If the plurality of inspections are passed, the remote access client is released from a quarantine state and a virtual private network (VPN) connection to the remote access server is established.

Claims (42)

1. A method for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections, comprising:

creating a remote access configuration file for the remote access client operating on a user workstation device;

generating a digital hash of the remote access configuration file;

comparing the digital hash with a configuration file stored at a predefined web location;

if the comparison results in a match between the digital hash and the stored configuration file,

comparing a digital hash of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location wherein the comparing of the digital hash of the configuration file and the comparing of the digital hash of the encrypted configuration file are performed by an executable file that provides a key and hashing algorithm used for generating the digital hash of the configuration file, and wherein the executable file is stored at the user workstation device location that is remote from the predefined web location;

if the plurality of inspections are passed, releasing the remote access client from a quarantine state and establishing a virtual private network (VPN) connection between the remote access client and the remote access server; and

downloading a new executable configuration file and launching the new executable configuration file from a dynamic link library component, if the comparison between the digital hash and stored configuration file stored at the predefined web location does not result in a match.

2. The method for providing protected remote access of claim 1 further comprising updating of virus definitions.

3. The method for providing protected remote access of claim 2 further comprising validating that the virus definitions exist and are currently in effect.

4. The method for providing protected remote access of claim 1 further comprising determining if an installed antivirus program is active and running on the remote access client.

5. The method for providing protected remote access of claim 1 further comprising inspecting at least one operating system patch for a current version and timestamp.

6. The method for providing protected remote access of claim 1 further comprising downloading and replacing the encrypted remote access configuration file, if the digital hash comparison of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location does not result in a match.

7. The method for providing protected remote access of claim 1 further comprising forcing a failure to prevent access to the remote access server if the plurality of inspections does not pass.

8. A computer program product for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections, comprising a non-transitory computer readable storage medium having computer readable code embedded therein, the computer readable medium comprising:

program instructions that create a remote access configuration file for the remote access client operating on a user workstation device;

program instructions that generate a digital hash of the remote access configuration file;

program instructions that compare the digital hash with a configuration file stored at a predefined web location;

program instructions that perform a digital hash comparison of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location if the comparison results in a match between the digital hash and the stored configuration file, wherein the comparison of the digital hash of the configuration file and the comparison of the digital hash of the encrypted configuration file are performed by an executable file that provides a key and hashing algorithm used to generate the digital hash of the configuration file, and wherein the executable file is stored at the user workstation device location that is remote from the predefined web location;

program instructions that release the remote access client from a quarantine state and establish a virtual private network (VPN) connection between the remote access client and the remote access server if the plurality of inspections are passed; and

further comprising program instructions that download a new executable configuration file and launch the new executable configuration file from a dynamic link library component, if the comparison between the digital hash and stored configuration file stored at the predefined web location does not result in a match.

9. The non-transitory computer readable storage medium of claim 8 further comprising program instructions that update a plurality of virus definitions.

10. The non-transitory computer readable storage medium of claim 9 further comprising program instructions that validate that the virus definitions exist and are currently in effect.

11. The non-transitory computer readable storage medium of claim 8 further comprising program instructions that determine if an installed antivirus program is active and running on the remote access client.

12. The non-transitory computer readable storage medium of claim 8 further comprising program instructions that inspect at least one operating system patch for a current version and timestamp.

13. The non-transitory computer readable storage medium of claim 8 further comprising program instructions that download and replace the encrypted remote access configuration file, if the digital hash comparison of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location does not result in a match.

14. The non-transitory computer readable storage medium of claim 8 further comprising program instructions that force a failure to prevent access to the remote access server if the plurality of inspections does not pass.

15. A system for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections, comprising:

a local data store;

a processor for executing a plurality of components including:

a component for creating a remote access configuration file for the remote access client operating on a user workstation device and storing the remote access configuration file in the local data store;

a component for generating a digital hash of the remote access configuration file;

a component for comparing the digital hash with a configuration file stored at a predefined web location;

a component for performing a digital hash comparison of an encrypted remote access configuration file stored in the local data store with an encrypted configuration file stored at the predefined web location, if the comparison results in a match between the digital hash and the stored configuration file, wherein the comparison of the digital hash of the configuration file and the comparison of the digital hash of the encrypted configuration file are performed by an executable file that provides a key and hashing algorithm used to generate the digital hash of the configuration file, and wherein the executable file is stored at the user workstation device location that is remote from the predefined web location;

a component for releasing the remote access client from a quarantine state and establishing a virtual private network (VPN) connection between the remote access client and the remote access server, if the plurality of inspections are passed; and

a component for downloading a new executable configuration file and launching the new executable configuration file from a dynamic link library component, if the comparison between the digital hash and stored configuration file stored at the predefined web location does not result in a match.

16. The system for providing protected remote access of claim 15 further comprising a component for updating of virus definitions.

17. The system for providing protected remote access of claim 16 further comprising a component for validating that the virus definitions exist and are currently in effect.

18. The system for providing protected remote access of claim 15 further comprising a component for determining if an installed antivirus program is active and running on the remote access client.

19. The system for providing protected remote access of claim 15 further comprising a component for inspecting at least one operating system patch for a current version and timestamp.

20. The system for providing protected remote access of claim 15 further comprising a component for downloading and replacing the encrypted remote access configuration file, if the digital hash comparison of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location does not result in a match.

21. The system for providing protected remote access of claim 15 further comprising a component for forcing a failure to prevent access to the remote access server if the plurality of inspections does not pass.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE PATENT ASSIGNMENT AGREEMENT DATED NOVEMBER 30, 2021 PREVIOUSLY RECORDED AT REEL: 058426 FRAME: 0791. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2022
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058736/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058426/0791 →
CHANGE OF ADDRESS FOR ASSIGNEE Recorded Nov 3, 2016
From: OPEN INVENTION NETWORK, LLC
To: OPEN INVENTION NETWORK, LLC
Reel/Frame 040554/0020 →