IP Library Granted Patent US 8,239,917
Granted Patent B2
US 8,239,917 · App. 11/928,256 · Granted Aug 7, 2012

Systems and methods for enterprise security with collaborative peer to peer architecture

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,239,917
App. No.
11/928,256
Granted
Aug 7, 2012
Kind
B2
Abstract

Systems and methods authenticate a device to operate within an enterprise system with an enterprise policy. An agent, installed on the device, analyzes the device to determine profile information of the device. The determined profile information is sent to a type 2 super peer that verifies whether the profile information conforms to the enterprise policy. If the profile information conforms to the enterprise policy, an agent trust credential is generated, within the type 2 super peer, for the agent, based upon the profile information, and issued to the agent. Authenticity of the device is verified based upon the agent trust credential. If the device is authenticated, communications with the device are permitted. If the device is not authenticated, communications with the device is prevented. In another embodiment, a method restores a device to conform to a system policy. A snapshot of critical components of the device is taken while the device is in compliance with the system policy. The critical components are monitored to identify critical components that differ from the critical components of the snapshot. If differing critical components are detected, the device is restored to conform with system policy by replacing differing critical components based upon the snapshot.

Claims (24)

1. A method for protecting an enterprise system having an enterprise policy, the enterprise system having (a) a first realm comprising a first device with a first agent installed thereupon and a second device having a second agent installed thereupon, and (b) a second realm comprising a third device with a third agent installed thereupon and a fourth device with a fourth agent installed thereupon, the method comprising:

determining:

within the first agent, a first profile of the first device,

within the second agent a second profile of the second device,

within the third agent a third profile of the third device, and

within the fourth agent a fourth profile of the fourth device;

issuing, from a first type 2 super peer of the first realm, first and second agent trust credentials to the first and second agents, respectively, when the first and second profiles conforms to the enterprise policy;

issuing, from a second type 2 super peer of the second realm, third and fourth agent trust credentials to the third and fourth agents, respectively, when the third and fourth profiles conform to the enterprise policy;

forming a first cooperative agent cell with the first and second agents based upon the first and second agent trust credentials; and

forming a first cooperative agent cell with the third and fourth agents based upon the third and fourth agent trust credential,

wherein the second type 2 super peer is different from the first type 2 super peer,

wherein the second and third devices are the same device,

wherein the second and third agents are the same agent that cooperates within both the first and second cooperative agent cells, and

wherein the second and third agent trust credentials are different from each other.

2. The method of claim 1 , wherein at least one of the first and second agent trust credentials is verified periodically.

3. The method of claim 1 , wherein at least one of the first and second agent trust credentials is verified immediately when the device attempts to connect to the enterprise system.

4. The method of claim 1 , further comprising obtaining biometric data from a user of the device by utilizing a biometric scanner and including the biometric data within the profile information.

5. The method of claim 4 , wherein the biometric scanner is one of the group including a fingerprint scanner, an iris scanner and a voice recognition system.

6. The method of claim 4 , further comprising periodically operating the biometric scanner to verify the user of the device has not changed.

7. The method of claim 1 , wherein at least one of the first and second agent trust credentials comprisea Public Key Infrastructure (PKI) certificate and a certificate extension.

8. The method of claim 1 , wherein at least one of the first and second agent trust credentials comprisea public key and a digital signature of one of the first and second type 2 super peers, respectively.

9. The method of claim 8 , wherein the the digital signature is decoded using the public key.

10. The method of claim 1 , wherein at least one of the first and second agent trust credentials comprise hard and soft credentials.

11. The method of claim 10 , wherein the hard and soft credentials are utilized to determine a level of trust for the device, the level of trust determining the level of communication between the enterprise system and the device.

Assignments (6)
SECURITY INTEREST Recorded Feb 1, 2023
From: BURSTIQ, INC.
To: TEXAS CAPITAL BANK
Reel/Frame 062561/0188 →
CHANGE OF NAME Recorded Oct 28, 2021
From: BURSTIQ ANALYTICS CORPORATION
To: BURSTIQ, INC.
Reel/Frame 057969/0082 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2018
From: TVIIM, LLC
To: BURSTIQ ANALYTICS CORPORATION
Reel/Frame 044543/0734 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2013
From: ENTERPRISE INFORMATION MANAGEMENT, INC.
To: TVIIM, LLC
Reel/Frame 030741/0913 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2012
From: INNERWALL, INC.
To: ENTERPRISE INFORMATION MANAGEMENT, INC.
Reel/Frame 028466/0072 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2007
From: HAMMOND, FRANK J., II; RICOTTA, FRANK J., JR.; DYKSTRA, HANS MICHAEL; WILLIAMS, BLAKE ANDREW; CARLANDER, STEVEN J.; GERBER, SARAH WILLIAMS
To: INNERWALL, INC.
Reel/Frame 020036/0434 →