IP Library Granted Patent US 8,935,311
Granted Patent B2
US 8,935,311 · App. 13/364,214 · Granted Jan 13, 2015

Generalized policy server

Inventors: Clifford L. Hannel (Westlake Village, CA); Laurence R. Lipstone (Westlake, CA); David S. Schneider (Westlake, CA)
Assignee: SonicWALL, Inc.
H04L63/0218H04L63/0227H04L63/0263H04L63/0272H04L63/04H04L63/101H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,935,311
App. No.
13/364,214
Filed
Feb 1, 2012
Granted
Jan 13, 2015
Kind
B2
Art Unit
2414
USPC
370/252
Abstract

A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter use a local copy of an access control database to determine whether an access request made by a user. Changes made by administrators in the local copies are propagated to all of the other local copies. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to of access policies which define access in terms of the user groups and information sets.

Claims (34)

1. A method for controlling access to network information, the method comprising:

storing a local copy of one or more policies in memory, the one or more policies limiting access to the network information, wherein at least one policy of the one or more policies includes at least a predefined temporal condition and a class of service associated with the pre-defined temporal condition, wherein the pre-defined temporal condition defines a time period, and wherein the at least one policy including the pre-defined temporal condition is applicable only during the defined time period;

receiving a request from a user concerning access to information in a network;

executing instructions stored in memory, wherein execution of the instructions by a processor:

determines that the user is authorized to access the requested network information based on at least the local copy of the one or more policies, wherein the predefined temporal condition is satisfied,

applies the class of service associated with the pre-defined temporal condition, identifies a path through a plurality of devices in the network, the plurality of devices including a server hosting the requested network information, a plurality of access filters, and a user device associated with the user, and

encrypts a message containing the requested network information for transmission between the server and a first access filter from the plurality of access filters, wherein a plurality of transmissions of the message between device pairs in the path is encrypted separately.

2. The method of claim 1 , further comprising storing in memory information regarding identification and certification for the server, the plurality of access filters, and the user device.

3. The method of claim 1 , wherein the encrypted message is decrypted at the first access filter for access checking before transmitting to a second access filter.

4. The method of claim 1 , wherein encryption between a device pair forms a tunnel between a device pair, and wherein the tunnel is extended to a next device based on the encryption between the device pair.

5. The method of claim 4 , wherein identifying the path is based on current network routing conditions.

6. The method of claim 1 , wherein variable levels of encryption are used in the path.

7. The method of claim 6 , further comprising selecting a level of encryption based on a trust level between a device pair.

8. An apparatus for controlling access to network information, the apparatus comprising:

memory for storing a local copy of one or more policies, the one or more policies limiting access to the network information, wherein at least one policy of the one or more policies includes at least a pre-defined temporal condition and a class of service associated with the pre-defined temporal condition, wherein the pre-defined temporal condition defines a time period, and wherein the at least one policy including the pre-defined temporal condition is applicable only during the defined time period;

a network interface for receiving a request from a user concerning access to information in a network;

a processor for executing instructions stored in memory, wherein execution of the instructions by the processor:

determines that the user is authorized to access the requested network information based on at least the local copy of the one or more policies, wherein the predefined temporal condition is satisfied,

applies the class of service associated with the pre-defined temporal condition,

identifies a path through a plurality of devices in the network, the plurality of devices including a server hosting the requested network information, a plurality of access filters, and a user device associated with the user, and

encrypts a message containing the requested network information for transmission between the server and a first access filter from the plurality of access filters, wherein a plurality of transmissions of the message between device pairs in the path is encrypted separately.

9. The apparatus of claim 8 , further comprising storing in memory information regarding identification and certification for the server, the plurality of access filters, and the user device.

10. The apparatus of claim 8 , wherein the encrypted message is decrypted at the first access filter for access checking before transmitting to a second access filter.

11. The apparatus of claim 8 , wherein encryption between a device pair forms a tunnel between a device pair, and wherein the tunnel is extended to a next device based on the encryption between the device pair.

12. The apparatus of claim 8 , wherein identifying the path is based on current network routing conditions.

13. The apparatus of claim 8 , wherein variable levels of encryption are used in the path.

14. The apparatus of claim 13 , further comprising selecting a level of encryption based on a trust level between a device pair.

15. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for controlling access to network information, the method comprising:

storing a local copy of one or more policies, the one or more policies limiting access to the network information, wherein at least one policy of the one or more policies includes at least a pre-defined temporal condition and a class of service associated with the pre-defined temporal condition, wherein the pre-defined temporal condition defines a time period, and wherein the at least one policy including the pre-defined temporal condition is applicable only during the defined time period;

receiving a request from a user concerning access to information in a network;

determining that the user is authorized to access the requested network information based on at least the local copy of the one or more policies, wherein the pre-defined temporal condition is satisfied;

applying the class of service associated with the pre-defined temporal condition;

identifying a path through a plurality of devices in the network, the plurality of devices including a server hosting the requested network information, a plurality of access filters, and a user device associated with the user; and

encrypting a message containing the requested network information for transmission between the server and a first access filter from the plurality of access filters, wherein a plurality of transmissions of the message between device pairs in the path is encrypted separately.

Assignments (25)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
MERGER Recorded Jan 4, 2016
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037403/0608 →
CONVERSION AND NAME CHANGE Recorded Jan 4, 2016
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037426/0451 →
MERGER Recorded Feb 2, 2012
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 027644/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: KENDALL HOLDINGS LLC
To: SONICWALL, INC.
Reel/Frame 027644/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: REDLEAF GROUP, INC.
To: MARSHMAN RESEARCH LLC
Reel/Frame 027644/0013 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: MARSHMAN RESEARCH LLC
To: KENDALL HOLDINGS LLC
Reel/Frame 027643/0991 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: REDLEAF GROUP, INC.
To: SONICWALL, INC.
Reel/Frame 027643/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: INTERNET DYNAMICS, INC.
To: REDLEAF GROUP, INC.
Reel/Frame 027643/0929 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2012
From: HANNEL, CLIFFORD; LIPSTONE, LAURENCE R.; SCHNEIDER, DAVID S.
To: INTERNET DYNAMICS, INC.
Reel/Frame 027643/0885 →
CHANGE OF NAME Recorded Feb 2, 2012
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 027644/0177 →
Continuity (8)
Continuation 12850587 · Aug 4, 2010
Continuation 11897626 · Aug 31, 2007
Continuation 09720277
Continuation In Part 09034507 · Mar 4, 1998
Provisional Application 60039542 · Mar 10, 1997
Provisional Application 60040262 · Mar 10, 1997
Provisional Application 60091130 · Jun 29, 1998
Related Publication 20120198232A1 · Aug 2, 2012