IP Library Granted Patent US 9,560,049
Granted Patent B2
US 9,560,049 · App. 12/128,103 · Granted Jan 31, 2017

Method and system for optimizing network access control

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,560,049
App. No.
12/128,103
Granted
Jan 31, 2017
Kind
B2
Abstract

A method and system for optimizing network access control are disclosed. For example, the method includes receiving an access request to a network from a device. Then, the method determines if each one of one or more critical updates of said device is current and if each one of one or more non-critical updates of the device is current. The method concludes by granting the access request to the network if each one of the one or more critical updates of the device is current, even if at least one non-critical update of the one or more non-critical updates of the device is not current.

Claims (75)

1. A method for optimizing network access control, comprising:

in a server comprising one or more processors communicatively coupled to a network:

receiving, from a policy manager, a timestamp for each of one or more current critical updates and one or more current non-critical updates;

maintaining a list of current critical updates and current non-critical updates for one or more devices communicatively coupled to the network, wherein said list comprises said timestamp for each of said one or more current critical updates and said one or more current non-critical updates; and

for all access requests to the network from a device of the one or more devices communicatively coupled to the network:

receiving, in the server, an access request to the network from said device;

determining if each one of said one or more critical updates of said device is current;

determining if each one of said one or more non-critical updates of said device is current;

granting to the device said access request to said network if each one of said one or more critical updates of said device is current, even if at least one non-critical update of said one or more non-critical updates of said device is not current; and

if at least one critical update of said one or more critical updates of said device is not current:

denying said access request to said network; and

providing to said device at least one current critical update;

wherein said determining steps comprise:

receiving a critical update timestamp and a non-critical update timestamp from said device; and

comparing said critical update timestamp from said device with said timestamp for each of said current critical updates and comparing said non-critical update timestamp from said device with said timestamp for each of said current non-critical updates in said list.

2. The method of claim 1 , wherein said providing to said device at least one current critical update occurs during multiple connections of said device to said network.

3. The method of claim 1 , further comprising:

for all access requests to the network from the device, determining if said at least one non-critical update is to be updated on the device before granting said access request.

4. The method of claim 3 , wherein said determining if said at least one non-critical update is to be updated before granting said access request comprises:

generating a random number;

comparing said random number to a predefined threshold value; and

if said random number is less than or equal to said predefined threshold value, providing at least one current non-critical update.

5. The method of claim 4 , wherein said providing at least one current non-critical update occurs over multiple connections of said device to said network.

6. The method of claim 4 , wherein if said random number is greater than said predefined threshold value, providing access to said network without providing at least one current non-critical update.

7. The method of claim 4 , wherein said predefined threshold value is gradually increased over a predefined period of time until said predefined threshold value equals a maximum value.

8. A non-transitory computer-readable medium having stored thereon a plurality of instructions, said plurality of instructions including instructions which, when executed by one or more processors of a server, cause said one or more processors to perform steps of a method for optimizing network access control, the steps comprising:

receiving, from a policy manager, a timestamp for each of one or more current critical updates and one or more current non-critical updates;

maintaining a list of current critical updates and current non-critical updates for one or more devices communicatively coupled to the network, wherein said list comprises said timestamp for each of said one or more current critical updates and said one or more current non-critical updates; and

for all access requests to the network from a device of the one or more devices communicatively coupled to the network:

receiving, in the server, an access request to the network from said device;

determining if each one of said one or more critical updates of said device is current;

determining if each one of said one or more non-critical updates of said device is current; and

granting to the device said access request to said network if each one of said one or more critical updates of said device is current, even if at least one non-critical update of said one or more non-critical updates of said device is not current; and

if at least one critical update of said one or more critical updates of said device is not current:

denying said access request to said network; and

providing to said device at least one current critical update;

wherein said determining steps comprise:

receiving a critical update timestamp and a non-critical update timestamp from said device; and

comparing said critical update timestamp from said device with said timestamp for each of said current critical updates and comparing said non-critical update timestamp from said device with said timestamp for each of said current non-critical updates in said list.

9. The computer readable medium of claim 8 , the steps further comprising:

for all access requests to the network from the device, determining if said at least one non-critical update is to be updated on the device before granting said access request.

10. The computer readable medium of claim 9 , wherein said determining if said at least one non-critical update is to be updated before granting said access request comprises:

generating a random number;

comparing said random number to a predefined threshold value; and

if said random number is less than or equal to said predefined threshold value, providing at least one current non-critical update.

11. The computer readable medium of claim 10 , wherein if said random number is greater than said predefined threshold value, providing access to said network without providing at least one current non-critical update.

12. The computer readable medium of claim 10 , wherein said predefined threshold value is gradually increased over a predefined period of time until said predefined threshold value equals a maximum value.

13. A system for optimizing network access control, comprising:

an application server comprising one or more processors communicatively coupled to a network;

a database communicatively coupled to said one or more processors of the application server, the database configured for storing one or more current critical updates and one or more current non-critical updates; and

a policy manager communicatively coupled to said one or more processors of the application server, the policy manager configured for updating said one or more current critical updates and said one or more current non-critical updates;

the one or more processors of the application server configured for:

receiving, from the policy manager, a timestamp for each of one or more current critical updates and one or more current non-critical updates;

maintaining a list of current critical updates and current non-critical updates for one or more devices communicatively coupled to the network, wherein said list comprises said timestamp for each of said one or more current critical updates and said one or more current non-critical updates; and

for all access requests to the network from a device of the one or more devices communicatively coupled to the network:

receiving, in the server, an access request to the network from said device;

determining if each one of said one or more critical updates of said device is current;

determining if each one of said one or more non-critical updates of said device is current; and

granting to the device said access request to said network if each one of said one or more critical updates of said device is current, even if at least one non-critical update of said one or more non-critical updates of said device is not current; and

if at least one critical update of said one or more critical updates of said device is not current:

denying said access request to said network; and

providing to said device at least one current critical update;

wherein said determining comprises:

receiving a critical update timestamp and a non-critical update timestamp from said device; and

comparing said critical update timestamp from said device with said timestamp for each of said current critical updates and comparing said non-critical update timestamp from said device with said timestamp for each of said current non-critical updates in said list.

14. The system of claim 13 , wherein said application server determines if said at least one non-critical update is to be updated on the device before granting said access request.

15. The system of claim 14 , wherein said application server further comprises, in a storage device communicatively coupled to the one or more processors:

a certificate of health; and

a policy cache.

16. The system of claim 15 , wherein said policy cache stores timestamps received from said policy manager for said one or more current critical updates and said one or more current non-critical updates.

17. The system of claim 15 , wherein said certificate of health comprises:

a critical update timestamp;

a non-critical update timestamp; and

at least one policy tag.

18. The system of claim 15 , the one or more processors of the application server further configured to issue said certificate of health to said device if said device receives at least one critical update or non-critical update.

Assignments (14)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: ARRIS TECHNOLOGY, INC.
To: ARRIS ENTERPRISES, INC.
Reel/Frame 060791/0583 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 049820 FRAME: 0495. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jul 25, 2019
From: ARRIS ENTERPRISES, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 049858/0161 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
CHANGE OF NAME Recorded Jul 2, 2019
From: ARRIS ENTERPRISES. INC
To: ARRIS
Reel/Frame 049669/0652 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS, INC.; BIG BAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
Reel/Frame 048825/0294 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2015
From: ARRIS TECHNOLOGY, INC
To: ARRIS ENTERPRISES, INC.
Reel/Frame 037328/0341 →
MERGER AND CHANGE OF NAME Recorded Mar 10, 2015
From: GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT CORPORATION
To: ARRIS TECHNOLOGY, INC.
Reel/Frame 035176/0620 →
SECURITY AGREEMENT Recorded May 28, 2013
From: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS; BIGBAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 030498/0023 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2008
From: SRINIVASAN, BABU
To: GENERAL INSTRUMENT CORPORATION
Reel/Frame 021009/0035 →