IP Library Granted Patent US 9,171,172
Granted Patent B2
US 9,171,172 · App. 13/957,893 · Granted Oct 27, 2015

Automated multi-level federation and enforcement of information management policies in a device network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,171,172
App. No.
13/957,893
Granted
Oct 27, 2015
Kind
B2
Abstract

Methods, apparatus, systems, and non-transitory computer-readable media for managing a plurality of disparate computer application and data control policies on a computing device, especially a computing device connected to a computer network, are described. In one example, at least one policy distribution point is provided that includes least one policy distribution point including at least one information management policy. A plurality of policy enforcement points, including a first policy enforcement point operating at a first policy enforcement level, and a second enforcement point operating at second policy enforcement level, are also provided. A first policy element to the first policy enforcement point, and a second policy element to the second policy enforcement point, are allocated. A management compartment in computer memory in communication with said computing device including one or more computer applications, data, and metadata specified and controlled by the information management policy is also provided.

Claims (41)

1. A method for managing a plurality of disparate computer application and data control policies on a computing device, comprising:

providing under electronic computer control at least one electronically encoded policy distribution point in electronic memory, said at least one policy distribution point including at least one electronically encoded information management policy;

providing under electronic computer control a plurality of electronically encoded policy enforcement points in electronic memory, said plurality including a first policy enforcement point operating at first policy enforcement level, and a second policy enforcement point operating at second policy enforcement level;

allocating under electronic computer control a first electronically encoded policy element to said first policy enforcement point, and a second electronically encoded policy element to said second policy enforcement point;

executing under electronic computer control a plurality of electronically encoded management compartments in computer memory in communication with said computing device, said plurality of management compartments including one or more electronically encoded computer applications, data, and metadata specified and controlled by said at least one information management policy, each of said management compartments including a management compartment policy controlling information in at rest, in motion, or in use states of said information; and

altering, by said plurality of policy enforcement points, execution environments for said computer applications according to the management compartment policy for each of said management compartments; and

moderating, by said plurality of policy enforcement points, interaction of the computer applications with other components according to the management compartment policy of the respective compartment to which each application belongs, including permitting, blocking, logging, and modifying attempts to read or write data, open or accept connections, or access resources outside of each application's environment.

2. The method of claim 1 , further comprising defining under computer control the management of computer applications that access data or metadata contained in said management compartment.

3. The method of claim 1 , further comprising defining under computer control the management of computer applications, data, and metadata contained within said management compartment.

4. The method of claim 1 , further comprising defining under computer control the management of computer applications, data, and metadata contained in two or more different management compartments.

5. The method of claim 1 , further comprising defining under computer control the management of computer applications, data, and metadata contained in two or more different instances of said management compartment.

6. The method of claim 1 , further comprising distributing under computer control said at least one information management policy through said one or more policy distribution points.

7. A system for managing under computer control a plurality of disparate computer application and data control policies on one or more computing devices, comprising:

at least one policy distribution point, said at least one policy distribution point comprising at least one information management policy;

a plurality of policy enforcement points, including a first policy enforcement point operating at first policy enforcement level and enforcing under computer control at least a first policy element of said at least one information management policy, and a second policy enforcement point operating at second policy enforcement level and enforcing under computer control at least a second policy element of said at least one information management policy;

computer memory comprising a plurality of management compartments in communication with said computing device, said plurality of management compartments including one or more computer applications, data, and metadata specified and controlled by said at least one information management policy, said plurality of management compartments including a management compartment policy controlling information in at rest, in motion, or in use states of said information; and

the plurality of policy enforcement points configured to alter execution environments for said computer applications according to the management compartment policy for each of said management compartments and to moderate interaction of the computer applications with other components according to the management compartment policy of the respective compartment to which each application belongs, including permitting, blocking, logging, and modifying attempts to read or write data, open or accept connections, or access resources outside of each application's environment.

8. The system of claim 7 , wherein said management compartment is configured to manage computer applications that access data or metadata contained in said management compartment.

9. The system of claim 7 , wherein said management compartment is configured to manage computer applications, data, and metadata contained within said management compartment.

10. The system of claim 7 , wherein said management compartment is configured to manage computer applications, data, and metadata contained in two or more different management compartments.

11. The system of claim 7 , wherein said computer applications, data, and metadata contained in two or more different instances of said management compartment.

12. The system of claim 7 , wherein said distributing said at least one information management policy is performed under computer control through said one or more policy distribution points.

13. An apparatus for managing a plurality of disparate computer application and data control policies on at least one computing device, comprising:

electronic computer memory in communication with said computing device including a plurality of electronically encoded policy enforcement points configured to receive under electronic computer control at least one electronically encoded information management policy, comprising at least a first policy element and a second policy element, from one or more policy distribution points, said policy enforcement points further including a first policy enforcement point operating at first policy enforcement level, and a second enforcement point operating at second policy enforcement level, said first policy element being allocated under electronic computer control to said first policy enforcement point, and said second policy element being allocated under electronic computer control to a second policy enforcement point;

a plurality of electronically encoded management compartments in computer memory in communication with said computing device, each of such management compartments including one or more computer applications, data, and metadata specified and controlled by one of said at least one information management policies, said management compartment including a management compartment policy controlling information in at rest, in motion, or in use states of said information; and

the plurality of policy enforcement points configured to alter execution environments for said computer applications according to the management compartment policy for each of said management compartments and to moderate interaction of the computer applications with other components according to the management compartment policy of the respective compartment to which each application belongs, including permitting, blocking, logging, and modifying attempts to read or write data, open or accept connections, or access resources outside of each application's environment.

14. The apparatus of claim 13 , further comprising a capability for defining under computer control the management of computer applications that access data or metadata contained in each of said management compartments.

15. The apparatus of claim 13 , further comprising a capability for defining under computer control the management of computer applications, data, and metadata contained within each of said management compartments.

16. The apparatus of claim 13 , further comprising a capability for defining under computer control the management of computer applications, data, and metadata contained in two or more disparate management compartments.

17. The apparatus of claim 13 , further comprising a capability for defining under computer control the management of computer applications, data, and metadata contained in two or more disparate instances of at least one of said management compartments.

18. The apparatus of claim 13 , further comprising a capability for distributing under computer control said at least one information management policy through said one or more policy distribution points.

19. A non-transitory computer readable medium containing a computer program product providing electronically encoded data and instructions configured to enable a computer to manage a plurality of disparate electronically encoded computer application and data control policies on at least one computing device, said computer program product comprising electronically encoded instructions to enable said computer to:

establish and operate under computer control a plurality of electronically encoded policy enforcement points configured to receive under computer control at least one electronically encoded information management policy provided by one or more electronically encoded policy distribution points, said policy enforcement points further including a first policy enforcement point operating at first policy enforcement level, and a second enforcement point operating at second policy enforcement level, said first policy element being allocated under computer control to said first policy enforcement point, and said second policy element being allocated under computer control to a second policy enforcement point;

execute and operate under computer control a plurality of electronically encoded management compartments in computer memory in communication with said computing device, said plurality of management compartments including one or more computer applications, data, and metadata specified and controlled by said at least one information management policy, each of said management compartments including a management compartment policy controlling information in at rest, in motion, or in use states of said information; and

alter, by said plurality of policy enforcement points, execution environments for said computer applications according to the management compartment policy for each of said management compartments; and

moderate, by said plurality of policy enforcement points, interaction of the computer applications with other components according to the management compartment policy of the respective compartment to which each application belongs, including permitting, blocking, logging, and modifying attempts to read or write data, open or accept connections, or access resources outside of each application's environment.

20. The non-transitory computer readable medium of claim 19 , further comprising defining under computer control the management of computer applications that access data or metadata contained in said management compartment.

21. The non-transitory computer readable medium of claim 19 , further comprising defining under computer control the management of computer applications, data, and metadata contained within said management compartment.

22. The non-transitory computer readable medium of claim 19 , further comprising defining under computer control the management of computer applications, data, and metadata contained in two or more different management compartments.

23. The non-transitory computer readable medium of claim 19 , further comprising defining under computer control the management of computer applications, data, and metadata contained in two or more different instances of said management compartment.

24. The non-transitory computer readable medium of claim 19 , further comprising distributing under computer control said at least one information management policy through said one or more policy distribution points.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: CELLSEC, INC.
To: PULSE SECURE, LLC.
Reel/Frame 060903/0497 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Mar 17, 2017
From: CELLSEC, INC.
To: GOLDSCHLAG, DAVID; WEISS, YOAV; ACCEL XI L.P.; ACCEL STRATEGIC PARTNERS; ACCEL INVESTORS 2012 L.L.C.; SVIC NO. 22 NEW TECHNOLOGY BUSINESS INVESTMENT L.L.P.; THE MOSS YAMANOUCHI FAMILY TRUST; TRANSPLAN ENTERPRISES; GLASER INVESTMENTS; MARKER LANTERN III LTD.
Reel/Frame 041619/0122 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2016
From: GOLDSCHLAG, DAVID; WEISS, YOAV; GINTER, KARL; BARTMAN, MICHAEL
To: CELLSEC, INC.
Reel/Frame 040118/0550 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2015
From: GOLDSCHLAG, DAVID, MR.; BARTMAN, MICHAEL, MR.; GINTER, KARL, MR.; WEISS, YOAV, MR
To: CELLSEC, INC
Reel/Frame 036398/0521 →