IP Library Granted Patent US 8,259,568
Granted Patent B2
US 8,259,568 · App. 11/877,656 · Granted Sep 4, 2012

System and method for controlling mobile device access to a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,259,568
App. No.
11/877,656
Granted
Sep 4, 2012
Kind
B2
Abstract

The invention provides a method for managing access to a network resource on a network from a mobile device, the method including the steps of intercepting a data stream from the mobile device attempting to access the network resource, extracting information from the intercepted data stream relating to at least one of the mobile device or a user of the mobile device, accessing at least one of enterprise service based information and third party information regarding at least one of the mobile device or the user of the mobile device, determining whether the mobile device is authorized to access the network resource, preparing an access decision that specifies whether the mobile device is authorized to access the network resource, and storing the access decision in a database on the network. The method may also include the step of enforcing the access decision by granting access to the mobile device to the network resource if the mobile device is determined to be authorized and denying access to the mobile device to the network resource if the mobile device is determined not to be authorized.

Claims (46)

1. A method comprising:

intercepting a data stream from a mobile device attempting to access a network resource, wherein the data stream is an application level data stream;

extracting information from the intercepted data stream relating to the mobile device;

accessing enterprise service based information and third party information regarding at least one of the mobile device or a user of the mobile device;

determining whether the mobile device is authorized to access the network resource;

preparing an access decision based at least on whether an anti-virus application is present on the mobile device;

storing the access decision in a database on a network;

evaluating a subsequent attempt to access the network resource;

accessing a cache in order to determine whether a previous attempt to access the network resource was successful; and

permitting the mobile device to access the network resource based on data provided in the cache.

2. The method of claim 1 , wherein the access decision includes information regarding at least one of a health profile of the mobile device, the authenticity of the mobile device or a user of the mobile device, or the authorization of the mobile device or the user of the mobile device to access the network resource.

3. The method of claim 1 , further comprising enforcing the access decision by granting access to the mobile device to the network resource if the mobile device is determined to be authorized and denying access to the mobile device to the network resource if the mobile device is determined not to be authorized.

4. The method of claim 1 , further comprising storing the extracted information in the database.

5. The method of claim 1 , wherein the data stream is an application data stream.

6. The method of claim 1 , wherein the enterprise service based information includes at least one of information stored within a database and information stored within a directory service.

7. The method of claim 1 , wherein the third party information includes a certificate authority.

8. A method for managing access to a network resource on a network from a mobile device, the method comprising:

intercepting a data stream from the mobile device attempting to access the network resource;

extracting information from the intercepted data stream relating to at least one of the mobile device or a user of the mobile device;

submitting a query to a compliance server to determine whether the mobile device is authorized to access the network resource;

receiving a response from the compliance server; and

if the received response indicates that the query was not received by the compliance server, accessing a decision cache to determine if the decision cache includes cached information regarding whether the mobile device has been granted access or denied access during a previous attempt to access the network resource, and granting or denying the mobile device access to the network resource based on the cached information in the decision cache, and wherein the access to the network is at least based on whether an anti-virus application is present on the mobile device.

9. The method of claim 8 , further comprising granting the mobile device access to the network resource if the mobile device is authorized to access the network resource.

10. The method of claim 8 , further comprising denying the mobile device access to the network resource if the mobile device is not authorized to access the network resource.

11. A method for managing access to a network resource on a network from a mobile device, the method comprising:

intercepting a data stream from the mobile device attempting to access the network resource;

extracting information from the intercepted data stream relating to at least one of the mobile device or a user of the mobile device;

submitting a query to a compliance server to determine whether the mobile device is authorized to access the network resource;

receiving a response from the compliance server;

if the received response indicates that the query was not received by the compliance server, prohibiting the mobile device access to the network resource;

accessing a cache in order to determine whether a previous attempt to access the network resource was successful; and

permitting the mobile device to access the network resource based on data provided in the cache, and wherein the access to the network resource is at least based on whether an anti-virus application is present on the mobile device.

12. A method for managing access to a network resource on a network from a mobile device, the method comprising:

intercepting a data stream from the mobile device attempting to access the network resource;

extracting information from the intercepted data stream relating to at least one of the mobile device or a user of the mobile device;

submitting a query to a compliance server to determine whether the mobile device is authorized to access the network resource;

receiving a response from the compliance server;

if the received response indicates that the query was not received by the compliance server, denying the mobile device access to the network resource;

accessing a cache in order to determine whether a previous attempt to access the network resource was successful; and

permitting the mobile device to access the network resource based on data provided in the cache, and wherein the access to the network resource is at least based on whether an anti-virus application is present on the mobile device.

13. A method for managing access to a network resource on a network from a mobile device, the method comprising:

intercepting a data stream from the mobile device attempting to access the network resource;

extracting information from the intercepted data stream relating to at least one of the mobile device or a user of the mobile device;

accessing a decision cache to determine whether the mobile device has been granted access or denied access during a previous attempt to access the network resource;

if the decision cache includes cached information regarding whether the mobile device has been granted access or denied access during a previous attempt to access the network resource, granting or denying the mobile device access to the network resource based on the cached information in the decision cache, wherein the access to the network is at least based on whether an anti-virus application is present on the mobile device; and

if the decision cache does not include cached information regarding whether the mobile device has been granted access or denied access during a previous attempt to access the network resource, submitting a query to a compliance server to determine whether the mobile device is authorized to access the network resource.

Assignments (20)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
MERGER Recorded Jun 24, 2010
From: TD SECURITY, INC.
To: MCAFEE, INC.
Reel/Frame 024588/0138 →
SECURITY INTEREST Recorded Jan 12, 2009
From: TD SECURITY, INC. D/B/A TRUST DIGITAL, INC.
To: MMV FINANCE, INC.
Reel/Frame 022193/0854 →
SECURITY AGREEMENT Recorded Dec 24, 2008
From: TD SECURITY, INC.
To: SQUARE 1 BANK
Reel/Frame 022044/0349 →