IP Library Granted Patent US 8,301,769
Granted Patent B2
US 8,301,769 · App. 12/821,060 · Granted Oct 30, 2012

Classifying an operating environment of a remote computer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,301,769
App. No.
12/821,060
Granted
Oct 30, 2012
Kind
B2
Abstract

Systems and techniques are provided for controlling requests for resources from remote computers. A remote computer's ability to access a resource is determined based upon the computer's operating environment. The computer or computers responsible for controlling access to a resource will interrogate the remote computer to ascertain its operating environment. The computer or computers responsible for controlling access to a resource may, for example, download one or more interrogator agents onto the remote computer to determine its operating environment. Based upon the interrogation results, the computer or computers responsible for controlling access to a resource will control the remote computer's access to the requested resource.

Claims (28)

1. A method for classifying an operating environment of a remote computer, the method comprising:

maintaining a list of zones of trust in memory, each zone of trust associated with a set of resources; and

executing instructions stored in memory, wherein execution of the instructions by a processor:

selects a zone of trust from the list of zones of trust, wherein the selected zone of trust is defined by a signature comprising one or more literal values concerning a computer state,

compares the one or more literal values with a corresponding state of the operating environment of the remote computer, and

classifies the operating environment of the remote computer into the selected zone of trust when the one or more literal values are true for the operating environment, wherein classification into the selected zone of trust includes access to the set of resources associated with the selected zone of trust, wherein the list of zones of trust is further associated with a community of one or more users within a realm, the realm including one or more authorized users each associated with a remote computer and an authentication server.

2. The method of claim 1 , further comprising installing a process object on the classified remote computer, the process object for accessing a set of resources associated with the selected zone of trust.

3. The method of claim 2 , wherein the process object is a security process object.

4. The method of claim 1 , wherein the literal values include agent literal values.

5. The method of claim 1 , wherein the literal values include artifact literal values.

6. The method of claim 1 , wherein the one or more literal values are in conjunctive normal form.

7. The method of claim 1 , wherein the one or more literal values include a combination of agent literal values and artifact literal values.

8. A system for classifying an operating environment of a remote computer, the system comprising:

a policy server that:

maintains a list of zones of trust in memory, each zone of trust associated with a set of resources,

selects a zone of trust from the list of zones of trust, wherein the selected zone of trust is defined by a signature comprising one or more literal values concerning a computer state, and

compares the one or more literal values with a corresponding state of the operating environment of the authenticated remote computer; and

an end point control server for classifying the operating environment of the authenticated remote computer into the selected zone of trust when the one or more literal values are true for the operating environment, wherein classification into the selected zone of trust includes access to the set of resources associated with the selected zone of trust, and wherein the list of zones of trust is further associated with a community of one or more users within a realm, the realm including one or more authorized users each associated with a remote computer and an authentication server.

9. The system of claim 8 , wherein the signature for the selected zone of trust further includes a list of provisioned process objects required for accessing the set of resources associated with the selected zone of trust.

10. The system of claim 9 , wherein a process object from the list of provisioned process objects is installed on the classified remote computer, the installed process object for accessing a set of resources associated with the selected zone of trust.

11. The system of claim 10 , wherein the process object is a security process object.

12. The system of claim 11 , wherein the end point control server provides and activates the security process object.

13. The system of claim 8 , wherein the signature for the selected zone of trust further includes agents running on the remote computer.

14. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for classifying an operating environment of a remote computer, the method comprising:

maintaining a list of zones of trust in memory, each zone of trust associated with a set of resources;

selecting a zone of trust from the list of zones of trust, wherein the selected zone of trust is defined by a signature comprising one or more literal values concerning a computer state;

comparing the one or more literal values with a corresponding state of the operating environment of the remote computer; and

classifying the operating environment of the remote computer into the selected zone of trust when the one or more literal values are true for the operating environment wherein classification into the selected zone of trust includes access to the set of resources associated with the selected zone of trust, and wherein the list of zones of trust is further associated with a community of one or more users within a realm, the realm including one or more authorized users each associated with a remote computer and an authentication server.

Assignments (15)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041072 FRAME: 235. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT. Recorded Apr 5, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042245/0523 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041072/0235 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2010
From: HOPEN, CHRIS; TOMLINSON, GARY; ANANDAM, PARVEZ; YOUNG, BRIAN; FLAGG, ALAN
To: AVENTAIL CORPORATION
Reel/Frame 024729/0158 →
MERGER Recorded Jul 22, 2010
From: AVENTAIL CORPORATION
To: AVENTAIL LLC
Reel/Frame 024729/0173 →