IP Library Granted Patent US 8,341,693
Granted Patent B2
US 8,341,693 · App. 12/972,410 · Granted Dec 25, 2012

Enterprise-wide security system for computer devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,341,693
App. No.
12/972,410
Granted
Dec 25, 2012
Kind
B2
Abstract

A system and method for securing data in mobile devices ( 104 ) includes a computing mode ( 102 ) and a plurality of mobile devices ( 104 ). A node security program ( 202 ) executed in the computing node ( 102 ) interfaces with a device security program ( 204 ) executed at a mobile device ( 104 ). The computing node ( 102 ) is responsible for managing the security based on a node security profile ( 208 ) interpreted by a node security program ( 202 ) executed in the computing node ( 102 ). A device discovery method and arrangement ( 106 ) also detects and locates various information ( 120 ) about the mobile devices ( 104 ) based on a scan profile ( 206 ).

Claims (41)

1. A method, comprising:

communicating with a mobile device from a computing node, wherein the computing node includes a node security program configured to interpret a node security profile of the computing node, wherein the node security profile sets security parameters for managing security between the computing node, the mobile device, and a network resource, and wherein the computing node is separate from the mobile device and communicates with the mobile device via a communication link;

evaluating the node security profile to determine whether the computing node is authorized to transfer a device security profile to the mobile device, wherein the device security profile sets security parameters for the mobile device;

transferring the device security profile to the mobile device if the computing node is authorized to transfer the device security profile;

evaluating at least one security parameter of the node security profile in order to manage a process involving data being communicated between the computing node and the mobile device and the network resource;

determining that the process is not authorized based on the at least one security parameter, wherein the at least one security parameter includes information, based on a mobile device parameter, identifying the computing node as not being authorized; and

preventing the process from executing when it is determined that the process is not authorized based on the at least one security parameter.

2. The method of claim 1 , further comprising:

transmitting a device security application to the mobile device based on determining that the process is not authorized, wherein the device security application, when executed, locks the mobile device for usage purposes.

3. The method of claim 1 , wherein the process is associated with an unauthorized incoming process to the computing node.

4. The method of claim 1 , wherein the process is associated with an unauthorized outgoing process to the mobile device.

5. The method of claim 1 , wherein the process is associated with a data transfer associated with the mobile device.

6. The method of claim 1 , wherein the process is associated with a data synchronization involving the mobile device.

7. The method of claim 1 , wherein the process is associated with password protection in the context of a data transfer.

8. The method of claim 1 , wherein the process is associated with a file and a program access associated with the mobile device.

9. The method of claim 1 , wherein the process is associated with accessing files from a network.

10. The method of claim 1 , wherein the security profile comprises at least one of a text, .ini and binary, XML format.

11. Logic encoded in non-transitory tangible computer readable media that includes code for execution and when executed by a processor is operable to perform operations comprising:

communicating with a mobile device from a computing node, wherein the computing node includes a node security program configured to interpret a node security profile of the computing node, wherein the node security profile sets security parameters for managing security between the computing node, the mobile device, and a network resource, and wherein the computing node is separate from the mobile device and communicates with the mobile device via a communication link;

evaluating the node security profile to determine whether the computing node is authorized to transfer a device security profile to the mobile device, wherein the device security profile sets security parameters for the mobile device based on at least one of time and a location of the mobile device;

transferring the device security profile to the mobile device if the computing node is authorized to transfer the device security profile;

evaluating at least one security parameter of the node security profile in order to manage a process involving data being communicated between the computing node and the mobile device and the network resource;

determining that the process is not authorized based on the at least one security parameter, wherein the at least one security parameter includes information, based on a mobile device parameter, identifying the computing node as not being authorized; and

preventing the process from executing when it is determined that the process is not authorized based on the at least one security parameter.

12. The logic of claim 11 , wherein the processor is operable to perform further operations comprising:

transmitting a device security application to the mobile device based on determining that the process is not authorized, wherein the device security application, when executed, locks the mobile device for usage purposes.

13. The logic of claim 11 , wherein the process is associated with a data transfer associated with the mobile device.

14. The logic of claim 11 , wherein the process is associated with a data synchronization involving the mobile device.

15. The logic of claim 11 , wherein the process is associated with a file and a program access associated with the mobile device.

16. The logic of claim 11 , wherein the process is associated with accessing files from a network.

17. An apparatus, comprising:

a computing node that includes a node security program configured to interpret a node security profile, the apparatus being configured for:

communicating with a mobile device via a communication link, wherein the computing node is separate from the mobile device, and wherein the node security profile sets security parameters for managing security between the computing node, the mobile device, and a network resource;

evaluating the node security profile to determine whether the computing node is authorized to transfer a device security profile to the mobile device, wherein the device security profile sets security parameters for the mobile device based on at least one of time and a location of the mobile device;

transferring the device security profile to the mobile device if the computing node is authorized to transfer the device security profile;

evaluating at least one security parameter of the node security profile in order to manage a process involving data being communicated between the computing node and the mobile device and the network resource;

determining that the process is not authorized based on the at least one security parameter, wherein the at least one security parameter includes information, based on a mobile device parameter, identifying the computing node as not being authorized; and

preventing the process from executing when it is determined that the process is not authorized based on the at least one security parameter.

18. The apparatus of claim 17 , wherein the process is associated with a data synchronization involving the mobile device.

19. The apparatus of claim 17 , wherein the process is associated with a file and a program access associated with the mobile device.

20. The apparatus of claim 17 , wherein the process is associated with accessing files from a network.

Assignments (13)
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →