IP Library Granted Patent US 8,601,562
Granted Patent B2
US 8,601,562 · App. 12/331,898 · Granted Dec 3, 2013

Policy enforcement using ESSO

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,601,562
App. No.
12/331,898
Granted
Dec 3, 2013
Kind
B2
Abstract

A method for enforcing policies used with a computer client, the method including receiving, at policy decision point (PDP) processor, information from a single sign-on (SSO) system indicating an occurrence of an event of interest on the computer client, performing, using the PDP processor, a policy check in response to the occurrence of the event of interest, wherein a policy check result is generated, and providing the generated policy check result to the SSO system.

Claims (42)

1. A method for enforcing policies used with a computer client, the method comprising:

receiving, at policy decision point (PDP) processor, information from an enterprise single sign-on (ESSO) system indicating an occurrence of an event of interest of a client application running on the computer client;

performing, using the PDP processor and the information from the ESSO system, a policy check in response to the occurrence of the event of interest, wherein a policy check result is generated; and

providing the generated policy check result to a policy enforcement point (PEP), the PEP being the ESSO system configured for policy enforcement at the computer client, wherein the ESSO system forces a shutdown of the client application running on the computer client and the enforcement is transparent to the client application.

2. The method of claim 1 wherein performing the policy check includes performing a separation of duty policy check.

3. The method of claim 2 wherein the separation of duty policy check is a dynamic separation of duty policy check.

4. The method of claim 1 wherein the event of interest is selected from the group consisting of launching a computer application, logging onto the computer application, attempting to start the computer application, accessing a webpage, and accessing a remote server.

5. The method of claim 1 further comprising limiting access to a computer application until the policy check result is generated.

6. The method of claim 1 further comprising limiting access to a computer application as a function of the policy check result.

7. The method of claim 1 further comprising automating a logon process of a computer application as a function of the policy check result.

8. The method of claim 1 further comprising receiving, at the PDP processor, information relating to events of interest on a plurality of computer clients.

9. The method of claim 8 wherein the events of interest are selected from the group consisting of attempting access to a computer application, accessing the computer application, shutting down of the computer application, and logging off of the computer application.

10. The method of claim 9 further comprising preventing access to a computer application running on a first computer client in response to a computer application running on a second computer client.

11. The method of claim 1 further comprising storing the policy check result in a log file.

12. The method of claim 1 further comprising maintaining a list of active computer applications based upon the information received from the ESSO system.

13. The method of claim 12 wherein the list of active computer applications relates to a plurality of computer clients.

14. The method of claim 13 wherein the performing the policy check is performed using the list of active computer applications.

15. The method of claim 12 further comprising updating the list of active computer applications in response to at least one of a shutdown event and a logoff event.

16. A policy enforcement system for use with a computer client configured to execute computer applications, the system comprising:

a first hardware processor coupled to memory configured as an enterprise single sign-on (ESSO) system that is configured to monitor the computer client for an occurrence of an event of interest of a running client application;

a second hardware processor coupled to memory configured as a policy decision point (PDP) in communication with the ESSO system and configured to:

receive from the processor configured as an ESSO system an indication of the occurrence of the event of interest;

perform a policy check in response to the occurrence of the event of interest;

provide a policy check result to the processor configured as an ESSO system; and

wherein the processor configured as an ESSO system is further configured to manage the computer application as a function of the policy check result wherein the ESSO system forces a shutdown of the client application running on the computer client and forcing the shutdown is transparent to the client application.

17. The system of claim 16 wherein the processor configured as a PDP is configured to perform a separation of duty policy check.

18. The system of claim 17 wherein the separation of duty policy check is a dynamic separation of duty policy check.

19. The system of claim 16 wherein the event of interest is selected from the group consisting of launching a computer application, logging onto the computer application, attempting to start the computer application, accessing a webpage, and accessing a remote server.

20. The system of claim 16 wherein the processor configured as an ESSO system is configured to limit access to the computer application until the policy check result is generated.

21. The system of claim 16 wherein the processor configured as an ESSO system is further configured to automate the logon process of the computer application as a function of the policy check result.

22. The system of claim 16 wherein the processor configured as a PDP processor is further configured to receive information relating to events of interests on a plurality of computer clients.

23. The system of claim 22 wherein the events of interest are selected from the group consisting of attempting access to the computer application, accessing the computer application, shutting down of the computer application, and logging off of the computer application.

24. The system of claim 16 wherein the processor configured as a PDP processor is configured to identify a policy violation in response to a computer application running on another computer client.

25. The system of claim 16 wherein the processor configured as a PDP processor is configured to store the policy check result in a log file.

26. The system of claim 16 wherein the processor configured as a PDP processor is further configured to maintain a list of active computer applications based upon the information received from the ESSO system.

27. The system of claim 26 wherein the list of active computer applications relates to a plurality of computer clients.

28. The system of claim 27 wherein the processor configured as a PDP processor is further configured to perform the policy check using the list of active computer applications.

29. The system of claim 26 wherein the processor configured as a PDP processor is further configured to update the list of active computer applications in response to at least one of a shutdown event and a logoff event.

30. A method for enforcing policies used with a plurality of computer clients, the method comprising:

receiving, at policy decision point (PDP) processor, information from an enterprise single sign-on (ESSO) system indicating an occurrence of an event of interest of a first client application on one of the plurality of computer clients, the event associated with a user identity, wherein the PDP processor is a hardware processor coupled to memory;

performing, using the PDP processor and the information from the ESSO system, a dynamic segregation of duty policy check, the policy check including checking a list indicating currently active applications associated with the user identity, wherein a policy check result is generated, the policy check being performed in response to the occurrence of the event of interest; and

providing the generated policy check result to the ESSO system for policy enforcement at one or more of the plurality of computer clients, the enforcement being performed by the ESSO system and includes forcing a shutdown of at least one of the currently active applications, the enforcement being transparent to the first client application and the currently active applications.

Assignments (21)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK. NATIONAL ASSOCIATION
To: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
Reel/Frame 070086/0008 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2019
From: CORE SECURITY SDI CORPORATION
To: HELP/SYSTEMS, LLC
Reel/Frame 048390/0927 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: COURION CORPORATION; CORE SDI, INC.; CORE SECURITY TECHNOLOGIES, INC.
Reel/Frame 044535/0830 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040298/0816 →
CHANGE OF NAME Recorded Jul 1, 2016
From: COURION CORPORATION
To: CORE SECURITY SDI CORPORATION
Reel/Frame 039240/0188 →
SECURITY INTEREST Recorded Dec 29, 2015
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 037374/0301 →
RELEASE OF SECURITY INTEREST Recorded Nov 24, 2015
From: COMPASS HORIZON FUNDING COMPANY LLC
To: COURION CORPORATION
Reel/Frame 037128/0845 →
SECURITY INTEREST Recorded Feb 28, 2011
From: COURION CORPORATION
To: COMPASS HORIZON FUNDING COMPANY LLC
Reel/Frame 025856/0991 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2009
From: MILAS, BRIAN T.
To: COURION CORPORATION
Reel/Frame 022180/0176 →