IP Library Granted Patent US 8,185,933
Granted Patent B1
US 8,185,933 · App. 13/019,162 · Granted May 22, 2012

Local caching of endpoint security information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,185,933
App. No.
13/019,162
Granted
May 22, 2012
Kind
B1
Abstract

In general, the principles of this invention are directed to techniques of locally caching endpoint security information. In particular, a local access module caches endpoint security information maintained by a remote server. When a user attempts to access a network resource through an endpoint device, the endpoint device sends authentication information and health information to the local access module. When the local access module receives the authentication information and the health information, the local access module controls access to the network resource based on the cached endpoint security information, the authentication information, and a security state of the endpoint device described by the health information.

Claims (44)

1. A method of controlling access of a plurality of local endpoint devices to a remote network resource by an edge router local to the plurality of local endpoint devices and remote from the remote network resource, wherein the edge router routes packets to the local endpoint devices and provides network access to the local endpoint devices, wherein a remote access control server local to the remote network resource controls access to the remote network resource, and wherein the edge router controls access to the remote network resource on behalf of the remote access control server, the method comprising:

locally caching, by the edge router, a set of endpoint security information maintained by the remote access control server, wherein the locally cached set of endpoint security information specifies one or more policies to control access to the remote network resource by the plurality of local endpoint devices; and

controlling, by the edge router on behalf of the remote access control server, access to the remote network resource by a first one of the endpoint devices based on the locally cached endpoint security information, an identity of a user of the first one of the endpoint devices, and a security state of the first one of the endpoint devices.

2. The method of claim 1 , wherein the policies comprise a plurality of user role policies and a plurality of endpoint health policies, wherein each of the user role policies contains a mapping between a username and a list of roles associated with the username, and wherein each of the endpoint health policies provides a list of user roles that are incompatible with access to a network resource for endpoint devices having a particular security state, and wherein controlling access comprises:

authenticating the user;

in response to authenticating the user, determining the list of roles associated with the identity of the user based on the user role policies;

removing invalid roles from the list of roles based on application of the one or more endpoint health policies to the security state of the first one of the endpoint devices;

generating device-specific access rights for the first one of the endpoint devices based on remaining roles in the list of roles associated with the identity of the user after removing the invalid roles when there is at least one remaining role in the list of roles; and

governing access to the remote network resource based on the device-specific access rights for the first one of the endpoint devices.

3. The method of claim 2 , wherein at least one of the one or more policies denies access to users of a defined role when the users of the defined role are using an endpoint device that is hosting malicious software.

4. The method of claim 3 , wherein the at least one of the one or more policies grants access to users of roles other than the defined role when the users of the roles other than the defined role are using an endpoint device that is hosting the malicious software.

5. The method of claim 2 , wherein at least one of the one or more policies grants access to users of a defined role when the users of the defined role are using an endpoint device that is executing antivirus software.

6. The method of claim 2 , further comprising requesting a current version of one of the endpoint health policies from the remote server when the current version of the one of the endpoint health policies is not cached locally.

7. The method of claim 2 , further comprising requesting a current version of the user role policy for the user from the remote server when the current version of the user role policy is not cached locally.

8. The method of claim 1 , further comprising:

establishing a virtual private network (VPN) connection between the edge router and a remote device that is local to the remote network resource; and

after determining that the first one of the endpoint devices is permitted to access the remote network resource, retrieving the remote network resource via the VPN.

9. The method of claim 1 , further comprising:

receiving, by the edge router, authentication information that describes the user from the first one of the endpoint devices, wherein the authentication information specifies the identity of the user; and

receiving, by the edge router, health information that describes the security state of the first one of the endpoint devices.

10. The method of claim 9 , wherein the health information specifies whether a software application is installed on the first one of the endpoint devices.

11. The method of claim 9 , wherein receiving health information comprises receiving health information from an endpoint defense agent installed on the first one of the endpoint devices.

12. The method of claim 9 , further comprising:

forwarding the authentication information and the health information to the remote server,

wherein controlling access by the edge router on behalf of the remote access control server comprises:

after forwarding the authentication information and the health information to the remote server, beginning a timeout period;

determining that a connection between the edge router and the remote access control server has failed when the timeout period expires before receiving a response from the remote access control server; and

controlling access by the edge router on behalf of the remote access control server when the connection between the edge router and the remote access control server is determined to have failed.

13. The method of claim 1 , further comprising attempting to retrieve a portion of the endpoint security information from the remote server when the cached endpoint security information is not a current version of the endpoint security information maintained by the remote server.

14. An edge router device for controlling access of a plurality of local endpoint devices to a remote network resource, wherein the edge router is local to the plurality of local endpoint devices and remote from the remote network resource, wherein the edge router routes packets to the local endpoint devices and provides network access to the local endpoint devices, wherein a remote access control server local to the remote network resource controls access to the remote network resource, and wherein the edge router controls access to the remote network resource on behalf of the remote access control server, the edge router device comprising:

a memory storing instructions for a local access module; and

a processor configured to execute the instructions for the local access module to locally cache a set of endpoint security information maintained by the remote access control server, wherein the locally cached set of endpoint security information specifies one or more policies to control access to the remote network resource by the plurality of local endpoint devices, and control, on behalf of the remote access control server, access to the remote network resource by a first one of the endpoint devices based on the locally cached endpoint security information, an identity of a user of the first one of the endpoint devices, and a security state of the first one of the endpoint devices.

15. The edge router device of claim 14 , wherein the local access module is configured to establish a virtual private network (VPN) connection between the edge router and a remote device that is local to the remote network resource, and, after determining that the first one of the endpoint devices is permitted to access the remote network resource, retrieve the remote network resource via the VPN.

16. The edge router device of claim 14 , wherein the local access module is configured to receive authentication information that describes the user from the first one of the endpoint devices, wherein the authentication information specifies the identity of the user, and receive health information that describes the security state of the first one of the endpoint devices.

17. The edge router device of claim 16 , wherein the health information specifies whether a software application is installed on the first one of the endpoint devices.

18. The edge router device of claim 16 , wherein the local access module is configured to receive health information from an endpoint defense agent installed on the first one of the endpoint devices.

19. The edge router device of claim 16 , wherein the local access module is configured to forward the authentication information and the health information to the remote server, and wherein to control access on behalf of the remote access control server, the local access module is configured to, after forwarding the authentication information and the health information to the remote server, begin a timeout period, determine that a connection between the edge router and the remote access control server has failed when the timeout period expires before receiving a response from the remote access control server, and control access on behalf of the remote access control server when the connection between the edge router and the remote access control server is determined to have failed.

20. The edge router device of claim 9 , wherein the local access module is configured to attempt to retrieve a portion of the endpoint security information from the remote server when the cached endpoint security information is not a current version of the endpoint security information maintained by the remote server.

21. A system comprising:

a plurality of local endpoint devices; and

an edge router device for controlling access of the plurality of local endpoint devices to a remote network resource, wherein the edge router is local to the plurality of local endpoint devices and remote from the remote network resource, wherein the edge router routes packets to the local endpoint devices and provides network access to the local endpoint devices, wherein a remote access control server local to the remote network resource controls access to the remote network resource, and wherein the edge router controls access to the remote network resource on behalf of the remote access control server, wherein the edge router device is configured to locally cache a set of endpoint security information maintained by the remote access control server, wherein the locally cached set of endpoint security information specifies one or more policies to control access to the remote network resource by the plurality of local endpoint devices, and control, on behalf of the remote access control server, access to the remote network resource by a first one of the endpoint devices based on the locally cached endpoint security information, an identity of a user of the first one of the endpoint devices, and a security state of the first one of the endpoint devices.

22. A non-transitory computer-readable storage medium comprising instructions that, when executed, cause a processor of an edge router device for controlling access of a plurality of local endpoint devices to a remote network resource, wherein the edge router is local to the plurality of local endpoint devices and remote from the remote network resource, wherein the edge router routes packets to the local endpoint devices and provides network access to the local endpoint devices, wherein a remote access control server local to the remote network resource controls access to the remote network resource, and wherein the edge router controls access to the remote network resource on behalf of the remote access control server, to:

locally cache a set of endpoint security information maintained by the remote access control server, wherein the locally cached set of endpoint security information specifies one or more policies to control access to the remote network resource by the plurality of local endpoint devices; and

control, on behalf of the remote access control server, access to the remote network resource by a first one of the endpoint devices based on the locally cached endpoint security information, an identity of a user of the first one of the endpoint devices, and a security state of the first one of the endpoint devices.

Assignments (12)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034036/0904 →
SECURITY INTEREST Recorded Oct 23, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034037/0526 →