IP Library Granted Patent US 8,528,042
Granted Patent B2
US 8,528,042 · App. 12/614,333 · Granted Sep 3, 2013

System, method, and device for mediating connections between policy source servers, corporate repositories, and mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,528,042
App. No.
12/614,333
Granted
Sep 3, 2013
Kind
B2
Abstract

The invention relates to providing policy from an integrated policy server to a mobile device, comprising identifying a policy in an integrated policy server applicable to the mobile device and supplying policy elements to policy transports for transmission to the mobile device. The invention also relates to providing policy from an integrated policy server to a mobile device, including identifying a policy in the integrated policy server applicable to the mobile device, determining whether the mobile device is in compliance with the policy, and supplying policy elements to policy transports for transmission to the mobile device when the mobile device is not in compliance with the policy. The invention further relates to controlling access to a data server by a mobile device, including identifying a policy in an integrated policy server applicable to the mobile device, and determining whether the mobile device is in compliance with the policy.

Claims (70)

1. A method for controlling access to a data server by a mobile device, the mobile device having policy compliance capabilities, the method comprising:

receiving, by a policy proxy, a data stream between the data server and the mobile device;

identifying the mobile device;

identifying a policy in an integrated policy server applicable to the mobile device based on the identity of the mobile device; and

determining whether the mobile device is in compliance with the policy,

wherein when the mobile device is in compliance with the policy and the data stream includes a device settings query result, the method further comprises:

adding the device settings query result to a group of one or more device settings query results, wherein the group of device settings query results is received in response to a device settings query from the data server, wherein the device settings query is translated into a form compatible with the mobile device and sent to the mobile device via a plurality of policy transports;

translating the group of device settings query results into a form compatible with the data server; and

sending the translated group of device settings query results to the data server,

wherein when the mobile device is not in compliance with the policy, the method further comprises:

obtaining a common policy to apply to the mobile device;

translating the common policy into at least first and second policy sets compatible with the mobile device; and

sending the first policy set and the second policy set to the mobile device by a first policy transport and a second policy transport, respectively.

2. The method of claim 1 , further comprising granting the mobile device access to the data server when the mobile device is in compliance with the policy when the data stream does not include a device settings query result.

3. The method of claim 1 , further comprising denying the mobile device access to the data server when the mobile device is not in compliance with the policy.

4. The method of claim 1 , wherein each of the first and second policy sets includes one or more policy elements and wherein, when the mobile device is not in compliance with the policy, the method further comprises:

assigning the first and second policy sets to the first and second policy transports; and

supplying the first and second policy sets to the first and second policy transports for transmission to the mobile device.

5. The method of claim 1 , wherein compliance with the policy is determined by detecting the presence of one or more policy indicators in the mobile device, wherein when the mobile device is not in compliance with the policy, the method further comprises:

adding a policy indicator to the first policy set before sending the first policy set to the mobile device by the first policy transport.

6. The method of claim 5 , wherein the one or more policy indicators include one or more of a digital certificate, a device configuration setting, and a policy specification.

7. The method of claim 1 , wherein compliance with the policy is determined by determining the presence of one or more device settings and comparing one or more of the device settings to one or more of the policy elements.

8. A system for controlling access to a data server by a mobile device, the mobile device having policy compliance capabilities, the system comprising:

a data server;

an integrated policy server;

at least one processor device; and

a policy proxy configured to interface with the at least one processor device to:

receive a data stream between the data server and the mobile device;

identify the mobile device;

identify a policy in an integrated policy server applicable to the mobile device based on the identity of the mobile device; and

determine whether the mobile device is in compliance with the policy,

wherein when the mobile device is in compliance with the policy and the data stream includes a device settings query result, the policy proxy is further configured to:

add the device settings query result to a group of one or more device settings query results, wherein the group of device settings query results is received in response to a device settings query from the data server, wherein the device settings query is translated into a form compatible with the mobile device and sent to the mobile device via a plurality of policy transports;

translate the group of device settings query results into a form compatible with the data server; and

send the translated group of device settings query results to the data server,

wherein when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

obtain a common policy to apply to the mobile device;

translate the common policy into at least first and second policy sets compatible with the mobile device; and

send the first policy set and the second policy set to the mobile device by a first policy transport and a second policy transport, respectively.

9. The system of claim 8 , wherein, when the mobile device is in compliance with the policy, the policy proxy is further configured to grant the mobile device access to the data server when the data stream does not include a device settings query result.

10. The system of claim 8 , wherein, when the mobile device is not in compliance with the policy, the policy proxy is further configured to deny the mobile device access to the data server.

11. The system of claim 8 , wherein each of the first and second policy sets includes one or more policy elements, and wherein, when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

assign the first and second policy sets to the first and second policy transports; and

supply the first and second policy sets to the first and second policy transports for transmission to the mobile device.

12. The system of claim 8 , wherein compliance with the policy is determined by detecting the presence of one or more policy indicators in the mobile device, wherein when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

add a policy indicator to the first policy set before sending the first policy set to the mobile device by the first policy transport.

13. The system of claim 12 , wherein the one or more policy indicators include one or more of a digital certificate, a device configuration setting, and a policy specification.

14. The system of claim 8 , wherein compliance with the policy is determined by determining the presence of one or more device settings and comparing one or more of the device settings to one or more of the policy elements.

15. A device for controlling access to a data server by a mobile device, the mobile device having policy compliance capabilities, the device comprising at least one processor device and a policy proxy configured to interface with the at least one processor device to:

receive a data stream between the data server and the mobile device;

identify the mobile device;

identify a policy in an integrated policy server applicable to the mobile device based on the identity of the mobile device; and

determine whether the mobile device is in compliance with the policy,

wherein when the mobile device is in compliance with the policy and the data stream includes a device settings query result, the policy proxy is further configured to:

add the device settings query result to a group of one or more device settings query results, wherein the group of device settings query results is received in response to a device settings query from the data server, wherein the device settings query is translated into a form compatible with the mobile device and sent to the mobile device via a plurality of policy transports;

translate the group of device settings query results into a form compatible with the data server; and

send the translated group of device settings query results to the data server,

wherein when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

obtain a common policy to apply to the mobile device;

translate the common policy into at least first and second policy sets compatible with the mobile device; and

send the first policy set and the second policy set to the mobile device by a first policy transport and a second policy transport, respectively.

16. The device of claim 15 , wherein, when the mobile device is in compliance with the policy, the policy proxy is further configured to grant the mobile device access to the data server when the data stream does not include a device settings query result.

17. The device of claim 15 , wherein, when the mobile device is not in compliance with the policy, the policy proxy is further configured to deny the mobile device access to the data server.

18. The device of claim 15 , wherein each of the first and second policy sets includes one or more policy elements, and wherein, when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

assign the first and second policy sets to the first and second policy transports; and

supply the first and second policy sets to the first and second policy transports for transmission to the mobile device.

19. The device of claim 15 , wherein compliance with the policy is determined by detecting the presence of one or more policy indicators in the mobile device, wherein when the mobile device is not in compliance with the policy, the policy proxy is further configured to:

add a policy indicator to the first policy set before sending the first policy set to the mobile device by the first policy transport.

20. The device of claim 19 , wherein the one or more policy indicators include one or more of a digital certificate, a device configuration setting, and a policy specification.

21. The device of claim 15 , wherein compliance with the policy is determined by determining the presence of one or more device settings and comparing one or more of the device settings to one or more of the policy elements.

Assignments (22)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jun 24, 2010
From: TD SECURITY, INC.
To: MCAFEE, INC.
Reel/Frame 024588/0138 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2010
From: SAPP, KEVIN; GOLDSCHLAG, DAVID; WALKER, DAVID
To: TD SECURITY, INC. D/B/A TRUST DIGITAL, INC.
Reel/Frame 024443/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2010
From: SAPP, KEVIN; GOLDSCHLAG, DAVID; WALKER, DAVID
To: TD SECURITY, INC. D/B/A TRUST DIGITAL, INC.
Reel/Frame 024319/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2010
From: SAPP, KEVIN; GOLDSCHLAG, DAVID; WALKER, DAVID
To: TRUST DIGITAL
Reel/Frame 023746/0651 →