IP Library Granted Patent US 9,380,047
Granted Patent B2
US 9,380,047 · App. 13/921,297 · Granted Jun 28, 2016

Insecure connection prohibition

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,380,047
App. No.
13/921,297
Granted
Jun 28, 2016
Kind
B2
Abstract

A server system may be configured to receive a request for a connection from a client application. The server system may also be configured to determine if the client application is permitted to connect with the server. The connection with the client application may be prohibited if the server determines that the client application is not permitted to connect with the server. A secure connection with the client application may be permitted if the server determines that the client application is permitted to connect with the server. The secure connection may be established with the security protocol settings specified by a process on the server or shared security protocol settings specified by on a server system-wide basis.

Claims (75)

1. A method, comprising:

receiving, by a server, a request for a connection from a client application, wherein the server hosts a plurality of processes;

determining, by the server, whether to prohibit or permit the connection with the client application based on whether or not the client application can use a secure connection;

determining, by the server, if connection security protocol settings are specified by one process on the server or if connection security protocol settings are specified on a system-wide basis on the server;

prohibiting, by the server, the connection with the client application if the server determines that the client application cannot use a secure connection; and

permitting, by the server, a secure connection with the client application if the server determines that the client application can use a secure connection, wherein the permitted secure connection is established with one of:

the one process on the server, if the connection security protocol settings are specified by the one process on the server; and

the server on the system-wide basis, if the connection security protocol settings are specified on the system-wide basis of the server.

2. The method of claim 1 , further comprising:

permitting, by the server, an insecure connection with the client application if the server determines that the client application is permitted to connect with the server and that the client application is allowed to have an insecure connection with the server.

3. The method of claim 2 , further comprising transferring data to the client application through one of:

the permitted secure connection; and

the permitted insecure connection.

4. The method of claim 2 , in which the connection security protocol comprises a secure socket layer/transport layer security (SSL/TLS) protocol.

5. The method of claim 2 , in which:

the connection security protocol settings used to establish the secure connection are indicated by an SSL/TLS handshake between the client application and the server, and

different security protocol settings are used to establish secure connections between the server and different client applications.

6. The method of claim 1 , further comprising:

creating a certificate; and

sending the certificate to a client.

7. The method of claim 6 , in which determining if the client application is permitted to connect with the server comprises:

requesting the certificate from the client application;

receiving the certificate from the client application; and

processing the certificate to validate or invalidate the client application.

8. A computer program product, comprising:

a non-transitory computer readable medium comprising code to perform the steps of:

receiving a request for a connection from a client application, wherein the server hosts a plurality of processes;

determining whether to prohibit or permit the connection with the client application based on whether or not the client application can use a secure connection;

determining if connection security protocol settings are specified by one process on the server or if connection security protocol settings are specified on a system-wide basis on the server;

prohibiting the connection with the client application if the client application cannot use a secure connection; and

permitting a secure connection with the client application if the client application can use a secure connection, wherein the permitted secure connection is established with one of:

the one process on the server, if the connection security protocol settings are specified by the one process on the server; and

the server on the system-wide basis, if the connection security protocol settings are specified on the system-wide basis of the server.

9. The computer program product of claim 8 , in which the medium further comprises code to perform the steps of:

permitting an insecure connection with the client application if the server determines that the client application is permitted to connect with the server and that the client application is allowed to have an insecure connection with the server.

10. The computer program product of claim 9 , in which the medium further comprises code to perform the step of transferring data to the client application through one of:

the permitted secure connection; and

the permitted insecure connection.

11. The computer program product of claim 9 , in which the connection security protocol comprises a secure socket layer/transport layer security (SSL/TLS) protocol.

12. The computer program product of claim 9 , in which:

the connection security protocol settings used to establish the secure connection are indicated by an SSL/TLS handshake between the client application and the server, and

different security protocol settings are used to establish secure connections between the server and different client applications.

13. The computer program product of claim 8 , in which the medium further comprises code to perform the steps of:

creating a certificate; and

sending the certificate to a client.

14. The computer program product of claim 13 , in which determining if the client application is permitted to connect with the server comprises:

requesting the certificate from the client application;

receiving the certificate from the client application; and

processing the certificate to validate or invalidate the client application.

15. An apparatus, comprising:

a memory; and

a processor coupled to the memory, the processor configured to execute the steps of:

receiving a request for a connection from a client application, wherein the server hosts a plurality of processes;

determining whether to prohibit or permit the connection with the client application based on whether or not the client application can use a secure connection;

determining, by the server, if connection security protocol settings are specified by one process on the server or if connection security protocol settings are specified on a system-wide basis on the server;

prohibiting the connection with the client application if the client application cannot use a secure connection;

permitting a secure connection with the client application if the client application can use a secure connection, wherein the permitted secure connection is established with one of:

the one process on the server, if the connection security protocol settings are specified by the one process on the server; and

the server on the system-wide basis, if the connection security protocol settings are specified on the system-wide basis of the server.

16. The apparatus of claim 15 , in which the processor is further configured to perform the steps of:

permitting an insecure connection with the client application if the server determines that the client application is permitted to connect with the server and that the client application is allowed to have an insecure connection with the server.

17. The apparatus of claim 16 , in which the processor is further configured to perform the step of transferring data to the client application through one of:

the permitted secure connection; and

the permitted insecure connection.

18. The apparatus of claim 16 , in which the connection security protocol comprises a secure socket layer/transport layer security (SSL/TLS) protocol.

19. The apparatus of claim 15 , in which:

the connection security protocol settings used to establish the secure connection are indicated by an SSL/TLS handshake between the client application and the server; and

different security protocol settings are used to establish secure connections between the server and different client applications.

20. The apparatus of claim 15 , in which the processor is further configured to perform the steps of:

creating a certificate; and

sending the certificate to a client.

21. The apparatus of claim 20 , in which determining if the client application is permitted to connect with the server comprises:

requesting the certificate from the client application;

receiving the certificate from the client application; and

processing the certificate to validate or invalidate the client application.

Assignments (7)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 044416/0114 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →
SECURITY INTEREST Recorded Oct 6, 2016
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 039960/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2013
From: SCHULTZ, JASON C; HEIT, JAMES R; BERGERSON, ROBERT L
To: UNISYS CORPORATION
Reel/Frame 030882/0698 →