IP Library Granted Patent US 8,935,384
Granted Patent B2
US 8,935,384 · App. 13/102,627 · Granted Jan 13, 2015

Distributed data revocation using data commands

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,935,384
App. No.
13/102,627
Granted
Jan 13, 2015
Kind
B2
Abstract

A policy proxy intercepts a data stream between a data server and a user or other device, identifies the user device, and identifies a policy in an integrated policy server applicable to the user device based on the identity of the user device. The policy proxy may identify one or more of the policy elements based on the user device, and translate the policy elements into actions involving the data stream between the data server and the user device so as to implement at least one aspect of the identified policy. The actions can comprise permitting normal exchange of data between the data server and the user device, preventing communication between the data server and the user device, or modifying the data stream between the data server and the user device.

Claims (36)

1. A method for operating a network comprising:

intercepting, at a policy proxy implemented on non-transitory computer-readable media, a data stream being exchanged between a data server and the mobile device, wherein the policy proxy is remotely and communicably connected to the mobile device over a communication network, and the data stream comprises a synchronization request and email synchronization results,

comparing, at the policy proxy, actual policy elements of the mobile device with expected policy elements of the mobile device, wherein the mobile device is not configured to support the expected policy elements; and,

modifying, at the policy proxy, the data stream in accordance with difference between the actual policy elements and the expected policy elements to bring the mobile device into compliance with the expected policy elements;

wherein modifying the data stream comprises, when the mobile device requests from the data server to synchronize with a non-empty mailbox or a non-empty folder and the policy proxy determines the mobile device does not have access to the non-empty mailbox or the non-empty folder, modifying the e-mail synchronization results from the data server to cause the mobile device to synchronize with an empty mailbox or an empty folder, respectively, and to cause the deletion of the non-empty mailbox or the non-empty folder of the mobile device respectively.

2. The method of claim 1 wherein the step of modifying the data stream results in altering data stored on the mobile device.

3. A system for operating a network comprising:

one or more memory elements;

a processor;

wherein the one or more memory elements has program instructions stored thereon for providing a policy proxy, when the program instructions are executed by the processor, the policy proxy is configured to:

intercept a data stream being exchanged between a data server and the mobile device, wherein the policy proxy is remotely and communicably connected to the mobile device over a communication network, and the policy proxy is structured to compare actual policy elements of the mobile device with expected policy elements of the mobile device, wherein the mobile device is not configured to support the expected policy elements, and the data stream comprises a synchronization request and email synchronization results;

modify the data stream in accordance with difference between the actual policy elements and the expected policy elements to bring the mobile device into compliance with the expected policy elements;

wherein modifying the data stream comprises, when the mobile device requests from the data server to synchronize with a non-empty mailbox or a non-empty folder and the policy proxy determines the mobile device does not have access to the non-empty mailbox or the non-empty folder, modifying the e-mail synchronization results from the data server to cause the mobile device to synchronize with an empty mailbox or an empty folder, respectively, and to cause the deletion of the non-empty mailbox or the non-empty folder of the mobile device respectively.

4. The system of claim 3 wherein the modified data stream results in altering data previously stored on the mobile device.

5. A computer storage device coupled to a processor, said computer storage device storing computer program instructions that when executed control the processor to perform the following functions:

intercepting, using a policy proxy, a data stream being exchanged between a data server and the mobile device, wherein the policy proxy is remotely and communicably connected to the mobile device over a communication network, and the data stream comprises a synchronization request and email synchronization results,

comparing, using the policy proxy, actual policy elements of the mobile device with expected policy elements of the mobile device, wherein the mobile device is not configured to support the expected policy elements;

modifying, using the policy proxy, the data stream in accordance with difference between the actual policy elements and the expected policy elements to bring the mobile device into compliance with the expected policy elements;

wherein the function of modifying the data stream comprises, when the mobile device requests from the data server to synchronize with a non-empty mailbox or a non-empty folder and the policy proxy determines the mobile device does not have access to the non-empty mailbox or the non-empty folder, modifying the e-mail synchronization results from the data server to cause the mobile device to synchronize with an empty mailbox or an empty folder, respectively, and to cause the deletion of the non-empty mailbox or the non-empty folder of the mobile device respectively.

6. The method of claim 1 , further comprising:

identifying the mobile device at the policy proxy;

identifying, at the policy proxy, the expected policy in a policy server applicable to the mobile device.

7. The method of claim 1 , further comprising:

translating, at the policy server, the difference between the actual policy elements and the expected policy elements into actions involving the data stream to implement the expected policy elements.

8. The method of claim 1 , wherein modifying the data stream comprises inserting, removing, or substituting data or commands in the data stream.

9. The method of claim 1 , wherein modifying the data stream comprises translating the expected policy elements into a form transmittable by the data stream and acceptable to the mobile device.

10. The method of claim 1 , wherein modifying the data stream causes the expected policy elements to be enforced upon the mobile device without requiring or using additional software on the mobile device for supporting said expected policy elements.

11. The method of claim 1 , wherein the modified data stream results in deletion of at least some of the data previously stored on the mobile device.

12. The system of claim 3 , wherein the policy proxy is further configured to:

translate the difference between the actual policy elements and the expected policy elements into actions involving the data stream to implement the expected policy elements.

13. The system of claim 3 , wherein modifying the data stream comprises translating the expected policy elements into a form transmittable by the data stream.

14. The system of claim 3 , wherein modifying the data stream causes the expected policy elements to be enforced upon the mobile device without requiring or using additional software on the mobile device for supporting said expected policy elements.

15. The system of claim 3 , wherein the modified data stream results in deletion of at least some of the data stored on the mobile device.

16. The computer storage device of claim 5 , wherein the functions further comprises:

translating the difference between the actual policy elements and the expected policy elements into actions involving the data stream to implement the expected policy elements.

17. The computer storage device of claim 5 , wherein modifying the data stream causes the expected policy elements to be enforced upon the mobile device without requiring or using additional software on the mobile device for supporting said expected policy elements.

Assignments (20)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
MERGER Recorded Sep 30, 2011
From: TD SECURITY, INC.
To: MCAFEE, INC.
Reel/Frame 027002/0510 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2011
From: GOLDSCHLAG, DAVID; SAPP, KEVIN; WALKER, DAVID
To: TRUST DIGITAL LLC
Reel/Frame 026614/0197 →