IP Library Granted Patent US 9,479,538
Granted Patent B2
US 9,479,538 · App. 14/169,795 · Granted Oct 25, 2016

Combining network endpoint policy results

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,538
App. No.
14/169,795
Granted
Oct 25, 2016
Kind
B2
Abstract

An endpoint integrity system controls access to resources of a protected network for endpoint devices attempting to access the protected network. The system may include a number of evaluation modules that communicate with an endpoint device. The evaluation modules generate policy results for the endpoint device, in which each of the policy results assume one of three or more states, called a multi-state policy result. The multi-state policy results are combined to produce a combined Boolean policy result.

Claims (85)

1. A method comprising:

identifying, by a device, a plurality of results relating to policies associated with an endpoint,

the plurality of results including a first result and a second result,

the plurality of results being associated with a plurality of states, and

the plurality of states including:

a first state,

a second state that is different from the first state, and

a third state that is different from the first state and the second state; generating, by the device, a particular result based on the plurality of results,

the particular result including a value that corresponds to one of the first state or the second state; and

providing, by the device, the particular result.

2. The method of claim 1 ,

where the first result indicates whether a first type of software is active at the endpoint,

where the second result indicates whether a second type of software is active at the endpoint, and

where the first type of software is different from the second type of software.

3. The method of claim 1 ,

where the first state indicates that the endpoint satisfies a policy of the policies, and

where the second state indicates that the endpoint does not satisfy the policy.

4. The method of claim 1 , where the third state indicates that the endpoint does not satisfy a policy of the policies and that remediation is possible for the endpoint to satisfy the policy.

5. The method of claim 1 , where generating the particular result includes:

combining the first result and the second result based on particular criteria to obtain the particular result.

6. The method of claim 1 , where generating the particular result includes:

generating the particular result based on criteria defined by an administrator of the device.

7. The method of claim 1 , where the endpoint initiates a connection to a protected network.

8. The method of claim 1 , where providing the particular result comprises:

transmitting the particular result to a policy enforcement component that enforces access restrictions to a resource.

9. The method of claim 1 , further comprising:

generating a third result based on the plurality of results; and

providing the third result,

the particular result relating to a first access restriction,

the third result relating to a second access restriction, and

the first access restriction being different from the second access restriction.

10. A system comprising:

one or more processors to:

identify a plurality of results relating to one or more policies of an endpoint,

the plurality of results including a first result and a second result,

the plurality of results being associated with a plurality of states, and

the plurality of states including:

a first state,

a second state that is different from the first state, and

a third state that is different from the first state and the second state;

generate a particular result based on the plurality of results,

the particular result including a value that corresponds to one of the first state or the second state; and

transmit the particular result.

11. The system of claim 10 , where the one or more processors are further to:

generate a third result based on the plurality of results,

the third result including the value or another value that corresponds to one of the first state or the second state; and

provide the third result.

12. The system of claim 10 ,

where, when generating the particular result, the one or more processors are to:

generate the particular result based on the first result and the second result, and where the one or more processors are further to:

generate a third result based on the second result and a fourth result of the plurality of results, and

provide the third result.

13. The system of claim 10 ,

where the first state is a pass state, and

where the second state is a fail state.

14. The system of claim 10 , where the one or more processors are further to:

provide, for display, an interface;

receive, via the interface, one or more selections for combining two or more of the plurality of results into the particular result,

the two or more of the plurality of results including the first result and the second result; and

determine criteria for generating the particular result based on the one or more selections.

15. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by at least one processor, cause the at least one processor to:

identify a plurality of results relating to one or more policies associated with an endpoint,

the plurality of results including a first result and a second result,

the plurality of results being associated with a plurality of states, and

the plurality of states including:

a first state,

a second state that is different from the first state, and

a third state that is different from the first state and the second state;

generate a particular result based on the plurality of results,

the particular result including a value that corresponds to one of the first state or the second state; and

provide the particular result.

16. The non-transitory computer-readable medium of claim 15 , where the one or more instructions to generate the particular result include:

one or more instructions that, when executed by the at least one processor, cause the at least one processor to:

generate a first combined result based on the first result and the second result,

generate a second combined result based on a third result of the plurality of results, and

generate the particular result based on the first combined result and the second combined result.

17. The non-transitory computer-readable medium of claim 15 , where the first result indicates whether a firewall is active or whether antivirus software or spyware software is installed on the endpoint.

18. The non-transitory computer-readable medium of claim 15 , where the third state indicates that remediation associated with a policy, of the one or more policies, is possible.

19. The non-transitory computer-readable medium of claim 15 , where the one or more instructions to generate the particular result include:

one or more instructions that, when executed by the at least one processor, cause the at least one processor to:

generate the particular result based on the plurality of results by applying a Boolean expression to the first result and the second result.

20. The non-transitory computer-readable medium of claim 15 , where the instructions further comprise:

one or more instructions that, when executed by the at least one processor, cause the at least one processor to:

regulate access to a resource, of a protected network that is connected to the endpoint, based on the particular result.

Assignments (13)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 053269/0339 →
SECURITY INTEREST Recorded May 1, 2017
From: PULSE SECURE, LLC
To: JUNIPER NETWORKS, INC.
Reel/Frame 042197/0822 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2015
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 037232/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2014
From: CHICKERING, ROGER; HANNA, STEPHEN R.; FUNK, PAUL; KOUGIOURIS, PANAGIOTIS; KIRNER, PAUL JAMES
To: JUNIPER NETWORKS, INC.
Reel/Frame 032108/0020 →