IP Library Patent Application 14319136
Patent Application
App. No. 14/319,136

IDENTIFICATION OF UNAUTHORIZED APPLICATION DATA IN A CORPORATE NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/319,136
Abstract

An appliance works in conjunction with an agent on a remote device to control application access to a corporate network. In conjunction with an SSL tunnel and policy operating at the appliance, granular application control may be implemented. In particular, a device user may determine what applications from a set of applications may access the corporate network and which applications do not access the network. The policies applied to application traffic may be generated by an administrator. Policies may also be applied from a remote server to data stored on the user device.

Claims (51)

1 . A method for establishing a connection, comprising:

establishing a connection between a user client device and a server, the user client device having a plurality of applications;

receiving by a server a list of applications on a user device requesting access to a corporate network;

granting corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.

2 . The method of claim 1 , wherein the connection is a virtual private network tunnel.

3 . The method of claim 1 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.

4 . The method of claim 1 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.

5 . The method of claim 1 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.

6 . The method of claim 1 , wherein the rule set allows a single rule to control both device level corporate network access and application level corporate network access.

7 . The method of claim 1 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.

8 . The method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.

9 . The method of claim 1 , wherein the policy controls data access by an application at the user client device.

10 . The method of claim 1 , wherein the rule set controls whether application data is transmitted to the corporate network.

11 . The method of claim 1 , wherein the policy is enforced at the server.

12 . The method of claim 11 , further comprising:

modifying the rule set; and

applying the modified rule set to application data at the user client device.

13 . A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for establishing a connection, the method comprising:

establishing a connection between a user client device and a server, the user client device having a plurality of applications;

applying a policy created at a server to data at the user client device; and

controlling data access at the user client device based on the policy. establishing a connection between a user client device and a server, the user client device having a plurality of applications;

receiving by a server a list of applications on a user device requesting access to a corporate network;

granting corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.

14 . The non-transitory computer readable storage medium of claim 13 , wherein the connection is a virtual private network tunnel.

15 . The non-transitory computer readable storage medium of claim 13 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.

16 . The non-transitory computer readable storage medium of claim 13 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.

17 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.

18 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set controls device level corporate network access and application level corporate network access.

19 . The non-transitory computer readable storage medium of claim 13 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.

20 . The non-transitory computer readable storage medium of claim 13 , the method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.

21 . The non-transitory computer readable storage medium of claim 13 , wherein the policy controls data access by an application at the user client device.

22 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set controls whether application data is transmitted to the corporate network.

23 . The non-transitory computer readable storage medium of claim 13 , wherein the policy is created at the server.

24 . The non-transitory computer readable storage medium of claim 23 , further comprising:

modifying the rule set; and

applying the modified rule set to application data at the user client device.

25 . A system for establishing a connection, the system including:

a server in communication with a user client device, the server including a processor, memory, and one or more applications stored in memory at the server and executable to establish a connection between a user client device and a server, the user client device having a plurality of applications, receive by a server a list of applications on a user device requesting access to a corporate network, and grant corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.

26 . The system of claim 25 , wherein the connection is a virtual private network tunnel.

27 . The system of claim 25 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.

28 . The system of claim 25 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.

29 . The system of claim 25 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.

30 . The system of claim 25 , wherein the rule set controls device level corporate network access and application level corporate network access.

31 . The system of claim 25 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.

32 . The system of claim 25 , the method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.

33 . The system of claim 25 , wherein the policy controls data access by an application at the user client device.

34 . The system of claim 25 , wherein the rule set controls whether application data is transmitted to the corporate network.

35 . The system of claim 25 , wherein the policy is created at the server.

36 . The system of claim 35 , further comprising:

modifying the rule set; and

applying the modified rule set to application data at the user client device.

Assignments (17)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2018
From: TELEHOWSKI, DAVID
To: SONICWALL US HOLDINGS INC.
Reel/Frame 046287/0434 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2018
From: KAUFFMAN, JEFFREY
To: SONICWALL US HOLDINGS INC.
Reel/Frame 046287/0479 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2018
From: PETERSON, CHRISTOPHER D.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 045522/0542 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
CHANGE OF NAME Recorded Nov 2, 2016
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 040551/0885 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2016
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE INC.
Reel/Frame 040520/0220 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →