IP Library Granted Patent US 9,552,491
Granted Patent B1
US 9,552,491 · App. 12/327,668 · Granted Jan 24, 2017

Systems and methods for securing data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,552,491
App. No.
12/327,668
Granted
Jan 24, 2017
Kind
B1
Abstract

Systems and methods for securing data are disclosed. An administrative system may create a secure configuration. The secure configuration may disable functionality of a managed node that compromises sensitive data. However, the secure configuration may not prevent all user access to the managed node. The administrative system may deploy the secure configuration to at least one managed node. The administrative system may cause the secure configuration to be applied to the at least one managed node.

Claims (38)

1. A method for securing data on a managed device, the method being performed by an administrative system that is connected to a managed device over a network, comprising:

detecting, by the administrative system, an event related to the managed device that triggers application of a secure configuration, wherein the event comprises determining that a user of the managed device is an employee whose employment has been or will be terminated;

in response to detecting the event, searching the data on the managed device and determining whether the data is sensitive without any prior knowledge of the data and dynamically creating, by the administrative system, the secure configuration based on the event;

wherein the secure configuration, when applied, disables functionality of the managed device that compromises sensitive data but does not prevent all user access to the managed device, wherein the secure configuration, when applied, restricts functionality of the managed device to read-only while allowing writes initiated by an operating system to a memory page file, wherein the functionality of the managed device that is disabled by the secure configuration comprises formatting a disk, encrypting the disk, copying files via system ports, and taking screenshots;

deploying, by the administrative system, the secure configuration to the managed device;

causing, by the administrative system, the secure configuration to be applied to the managed device;

in response to the secure configuration being applied to the managed device, receiving by the administrative system, a status message from the managed device indicating that the managed device is in a secure mode that allows the user of the managed device to at least view files on the managed device; and

wherein the administrative system waits to detect an event that indicates that the secure configuration is no longer necessary, causing the secure configuration to be released from the managed device and the managed device to send to the administrative system a normal status message.

2. The method of claim 1 , wherein the functionality of the managed device that is disabled by the secure configuration further comprises at least one of modifying, deleting, renaming, transferring, and copying the sensitive data.

3. The method of claim 1 , wherein the secure configuration changes settings of the managed device when the secure configuration is applied to the managed device, and wherein the settings comprise at least one of file settings, directory settings, function settings, port settings, device settings, and application settings.

4. The method of claim 1 , wherein the secure configuration changes user permissions of the managed device when the secure configuration is applied to the managed device.

5. The method of claim 1 , wherein causing the secure configuration to be applied to the managed device comprises instructing the managed device to apply the secure configuration.

6. The method of claim 1 , wherein causing the secure configuration to be applied to the managed device is performed automatically in response to detecting the event.

7. The method of claim 1 , wherein causing the secure configuration to be applied to the managed device is performed manually in response to user input.

8. The method of claim 1 , wherein the secure configuration is deployed to the managed device before another event is detected that makes securing the data on the managed device desirable.

9. The method of claim 1 , wherein the secure configuration is deployed to the managed device after another event is detected that makes securing the data on the managed device desirable.

10. An administrative system that is configured for securing data on a managed device connected to the administrative system over a network, the administrative system comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

detect an event related to the managed device that triggers application of a secure configuration, wherein the event comprises determining that a user of the managed device is an employee whose employment has been or will be terminated;

in response to detecting the event, search the data on the managed device and determine whether the data is sensitive without any prior knowledge of the data, wherein the administrative system dynamically creates the secure configuration based on the event;

wherein the secure configuration, when applied, disables functionality of the managed device that compromises sensitive data but does not prevent all user access to the managed device, wherein the secure configuration, when applied, restricts functionality of the managed device to read-only while allowing writes initiated by an operating system to a memory page file, wherein the functionality of the managed device that is disabled by the secure configuration comprises formatting a disk, encrypting the disk, copying files via system ports, and taking screenshots;

deploy, by the administrative system, the secure configuration to the managed device;

cause the secure configuration to be applied to the managed device;

in response to the secure configuration being applied to the managed device, receive by the administrative system, a status message from the managed device indicating that the managed device is in a secure mode that allows the user of the managed device to at least view files on the managed device; and

wherein the administrative system waits to detect an event that indicates that the secure configuration is no longer necessary, causing the secure configuration to be released from the managed device and the managed device to send to the administrative system a normal status message.

11. The administrative system of claim 10 , wherein the functionality of the managed device that is disabled by the secure configuration further comprises at least one of modifying, deleting, renaming, transferring, and copying the sensitive data.

12. The administrative system of claim 10 , wherein the secure configuration changes settings of the managed device when the secure configuration is applied to the managed device, and wherein the settings comprise at least one of file settings, directory settings, function settings, port settings, device settings, and application settings.

13. The administrative system of claim 10 , wherein the secure configuration changes user permissions of the managed device when the secure configuration is applied to the managed device.

14. A non-transitory computer-readable medium for securing data on a managed device connected to an administrative system over a network, the computer-readable medium comprising executable instructions for:

detecting an event related to the managed device that triggers application of a secure configuration, wherein the event comprises determining that a user of the managed device is an employee whose employment has been or will be terminated;

in response to detecting the event, searching the data on the managed device and determining whether the data is sensitive without any prior knowledge of the data and dynamically creating, by the administrative system, the secure configuration based on the event;

wherein the secure configuration, when applied, disables functionality of the managed device that compromises sensitive data but does not prevent all user access to the managed device, wherein the secure configuration, when applied, restricts functionality of the managed device to read-only while allowing writes initiated by an operating system to a memory page file, wherein the functionality of the managed device that is disabled by the secure configuration comprises formatting a disk, encrypting the disk, copying files via system ports, and taking screenshots;

deploying, by the administrative system, the secure configuration to the managed device;

causing the secure configuration to be applied to the managed device;

in response to the secure configuration being applied to the managed device, receiving by the administrative system, a status message from the managed device indicating that the managed device is in a secure mode that allows the user of the managed device to at least view files on the managed device; and

wherein the administrative system waits to detect an event that indicates that the secure configuration is no longer necessary, causing the secure configuration to be released from the managed device and the managed device to send to the administrative system a normal status message.

Assignments (32)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
NUNC PRO TUNC ASSIGNMENT Recorded Sep 21, 2016
From: LANDESK SOFTWARE, INC.
To: CRIMSON CORPORATION
Reel/Frame 039819/0845 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: LANDESK SOFTWARE, INC.
Reel/Frame 030993/0622 →
PATENT SECURITY AGREEMENT Recorded Jul 13, 2012
From: LANDESK SOFTWARE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028541/0782 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 29, 2012
From: D.E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C., AS AGENT
To: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
Reel/Frame 027783/0491 →
PATENT SECURITY AGREEMENT Recorded Sep 30, 2010
From: LAN DESK SOFTWARE, INC.; CRIMSON CORPORATION
To: D. E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C. AS AGENT
Reel/Frame 025095/0982 →
PATENT SECURITY AGREEMENT Recorded Sep 28, 2010
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 025056/0391 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2008
From: GIFOROS, PETROS GEORGE; PIMENTEL, PLINIO
To: LANDESK SOFTWARE INC.
Reel/Frame 021939/0789 →