IP Library Granted Patent US 9,485,278
Granted Patent B2
US 9,485,278 · App. 14/318,847 · Granted Nov 1, 2016

Plug-in based policy evaluation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,278
App. No.
14/318,847
Granted
Nov 1, 2016
Kind
B2
Abstract

A device may include an interface to send authentication information to a plug-in, where the authentication information is related to a client device. The interface may send a policy identifier to the plug-in, where the policy identifier identifies a policy, and may receive a policy result from the plug-in, where the policy result is produced using the authentication information and a policy requirement identified by the policy identifier, and where the policy result identifies whether the client device complies with the policy.

Claims (116)

1. A method comprising:

identifying, by a first device, information identifying a policy associated with a second device,

the second device being different than the first device,

the first device including a first server, and

the second device including a client device;

identifying, by the first device, a requirement identifier for the policy, the requirement identifier including information related to a policy

requirement that needs to be satisfied for the second device to be identified as complying with the policy;

transmitting, by a plug-in of the first device, the policy requirement and information associated with the second device to a third device,

the third device being different than the first device and the second device,

and the third device including a second server;

receiving, by the plug-in of the first device, a policy result from the third device, the policy result being received based on transmitting the policy

requirement and the information associated with the second device to the third device, and

the policy result indicating whether the second device complies with the policy; and

transmitting, by the first device and to a fourth device, an instruction,

the fourth device being different than the first device, the second device, and the third device,

the fourth device including a network device,

the instruction being based on the policy result, and

the instruction being transmitted to the fourth device to enable the fourth device to selectively grant the second device access to a network destination.

2. The method of claim 1 , where the policy result indicates that the second device does not comply with the policy, and

where transmitting the instruction comprises:

transmitting the instruction to cause the fourth device to deny the second device access to the network destination and to enable the second device to obtain particular information based on the policy result indicating that the second device does not comply with the policy,

the particular information being used by the second device to bring the second device in compliance with the policy.

3. The method of claim 1 , further comprising:

validating an identity of the second device prior to transmitting the policy requirement and the information associated with the second device.

4. The method of claim 3 , further comprising:

receiving a user name and password associated with the second device,

where validating the identity of the second device includes:

determining whether the user name and password are valid.

5. The method of claim 1 , where identifying the information identifying the policy includes:

identifying the information identifying the policy based on information identifying a user of the second device.

6. The method of claim 1 , where the policy result indicates that the second device complies with the policy, and

where transmitting the instruction comprises:

transmitting the instruction to cause the fourth device to grant the second device access to the network destination based on the policy result indicating that the second device complies with the policy.

7. The method of claim 1 , where receiving the policy result includes:

receiving information that includes:

information identifying a user associated with the second device,

the information identifying the policy, and

information indicating whether the policy requirement has been met by the second device.

8. A system comprising:

a first device to:

identify information identifying a policy associated with a second device,

the second device being different than the first device,

the first device including a first server, and

the second device including a client device;

identify a requirement identifier for the policy,

the requirement identifier including information related to a policy requirement that needs to be satisfied for the second device to be identified as complying with the policy;

transmit, by a plug-in of the first device, the policy requirement and information associated with the second device to a third device,

the third device being different than the first device and the second device, and

the third device including a second server;

receive, by the plug-in of the first device, a result from the third device,

the result being received based on transmitting the policy requirement and the information associated with the second device to the third device, and

the result indicating whether the second device complies with the policy; and transmit, to a fourth device, an instruction,

the fourth device being different than the first device, the second device, and the third device,

the fourth device including a network device,

the instruction being based on the result, and

the instruction being transmitted to the fourth device to enable the fourth device to selectively grant the second device access to a network destination.

9. The system of claim 8 ,

where the first server includes a remote authentication dial-in user service (RADIUS) server, and

where the RADIUS server is to:

perform user authentication to validate an identity of the second device.

10. The system of claim 9 , where, when performing the user authentication, the RADIUS server is to:

determine whether a user name and password, of a user associated with the second device, are valid.

11. The system of claim 8 ,

where the second server includes a policy server, and

where the network device includes a network access device.

12. The system of claim 8 , where, when receiving the result, the plug-in of the first device is to:

receive information that includes:

information identifying a user associated with the second device,

the information identifying the policy, and

information indicating whether the policy requirement has been met by the second device.

13. The system of claim 8 , where the policy relates to an antivirus software, and

where the result indicates whether the second device is running the antivirus software.

14. The system of claim 8 , where, when identifying the information identifying the policy, the first device is to:

identify the information identifying the policy based on:

a user name of a user of the second device,

information identifying the network destination, or

information identifying a port, of the second device, that is used to access the fourth device.

15. The system of claim 8 , where the result indicates that the second device does not comply with the policy, and

where, when transmitting the instruction, the first device is to:

transmit the instruction to cause the fourth device to deny the second device access to the network destination and to enable the second device to obtain particular information,

the particular information being used by the second device to bring the second device in compliance with the policy.

16. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by a first device, cause the first device to:

identify information identifying a policy associated with a second device,

the second device being different than the first device,

the first device including a first server, and

the second device including a client device;

identify a requirement identifier for the policy,

the requirement identifier including information related to a policy requirement that needs to be satisfied for the second device to be identified as complying with the policy;

transmit, by a plug-in of the first device, the policy requirement and information associated with the second device to a third device,

the third device being different than the first device and the second device, and

the third device including a second server;

receive, by the plug-in of the first device, a result from the third device,

the result being received based on transmitting the policy requirement and the information associated with the second device to the third device, and

the result indicating whether the second device complies with the policy; and

transmit, to a fourth device, an instruction,

the fourth device being different than the first device, the second device, and the third device,

the fourth device including a network device,

the instruction being based on the result, and

the instruction being transmitted to the fourth device to enable the fourth device to selectively grant the second device access to a network destination.

17. The non-transitory computer-readable medium of claim 16 , where the one or more instructions to identify the information identifying the policy include:

one or more instructions to identify the information identifying the policy based on:

information identifying a user of the second device,

information identifying the network destination, or

information identifying a port, of the second device, that is used to access the fourth device.

18. The non-transitory computer-readable medium of claim 16 , where the instructions further comprise:

one or more instructions to validate an identity of the second device prior to transmitting the policy requirement and the information associated with the second device.

19. The non-transitory computer-readable medium of claim 16 , where the one or more instructions to receive the result include:

one or more instructions to receive information that includes:

information identifying a user associated with the second device,

the information identifying the policy, and

information indicating whether the policy requirement has been met by the second device.

20. The non-transitory computer-readable medium of claim 16 , where the result indicates that the second device does not comply with the policy, and

where the one or more instructions to transmit the instruction include:

one or more instructions to transmit the instruction to cause the fourth device to deny the second device access to the network destination and to enable the second device to download software from a fifth device,

the software being downloaded by the second device to bring the second device in compliance with the policy.

Assignments (13)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 053269/0339 →
SECURITY INTEREST Recorded May 1, 2017
From: PULSE SECURE, LLC
To: JUNIPER NETWORKS, INC.
Reel/Frame 042197/0822 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2015
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 037232/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2014
From: ERICKSON, STEVEN; TAVAKOLI, OLIVER KOUROSH
To: JUNIPER NETWORKS, INC.
Reel/Frame 033208/0906 →