IP Library Granted Patent US 10,382,398
Granted Patent B2
US 10,382,398 · App. 14/319,145 · Granted Aug 13, 2019

Application signature authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,398
App. No.
14/319,145
Granted
Aug 13, 2019
Kind
B2
Abstract

An appliance works in conjunction with an agent on a remote device to control application access to a corporate network. In conjunction with an SSL tunnel and policy operating at the appliance, granular application control may be implemented. In particular, a device user may determine what applications from a set of applications may access the corporate network and which applications do not access the network. The applications may be analyzed to determine whether the application is good or bad, as what security configurations, approvals and denials are associated with the application.

Claims (63)

1. A method for establishing a connection, the method comprising:

establishing a connection between a user client device and a server, the user client device having a plurality of applications, wherein the connection is established by the server and the user client device communicating over a computer network;

receiving data from the user client device via the established connection, the received data including authentication information for authenticating a user of the user client device;

classifying the user client device based on an identified device type of the user client device and an identified user type of the authenticated user, wherein the user client device classification is associated with an application control policy that allows application access to specified application data;

receiving application information derived from a requested application of the plurality of applications from the user client device in accordance with the application control policy associated with the user client device classification, wherein the application information derived from the requested application includes a signature generated at the user client device, and the signature is generated from an application certificate corresponding to the requested application; and

comparing the signature included in the application information to authorization information stored at the server, wherein the requested application is approved or denied based on the comparison.

2. The method of claim 1 , wherein the signature includes a hash of at least the application certificate.

3. The method of claim 2 , wherein a failed request to access a corporate network is detected from a trusted user and client device pair.

4. The method of claim 3 , wherein the hash of the at least application certificate is added to the application information for the failed request, and subsequent requests having the added hash of the at least application certificate or including information that is listed in a list of failed requests corresponding to the application will be denied.

5. The method of claim 2 , wherein the hash is also created from the application information.

6. The method of claim 5 , wherein the hash changes based on changes to the application information.

7. The method of claim 1 , further comprising:

comparing the signature to a table of application signatures and corresponding application classifications; and

processing traffic for the application based on the application classification.

8. The method of claim 7 , further comprising identifying that the application is classified as a bad application, and blocking the application traffic based on identifying that the application is classified as the bad application.

9. The method of claim 7 , further comprising identifying that the application is classified as a good application, and allowing the application traffic based on identifying that the application is classified as the good application.

10. The method of claim 1 , further comprising collecting application level information; and comparing the application level information to an application policy to identify compliance of the application.

11. The method of claim 10 , further comprising adding a code signature for a trusted application to a list of code signatures that are acceptable for the trusted application.

12. The method of claim 1 , further comprising identifying that the application information does not satisfy a policy rule; and processing traffic for the requested application based on the application information corresponding to a trusted application.

13. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for establishing a connection, the method comprising:

establishing a connection between a user client device and a server, the user client device having a plurality of applications;

receiving data from the user client device via the established connection, the received data including authentication information for authenticating a user of the user client device;

classifying the user client device based on an identified device type of the user client device and an identified user type of the authenticated user, wherein the user client device classification is associated with an application control policy that allows application access to specified application data;

receiving application information derived from a requested application of the plurality of applications from the user client device in accordance with the application control policy associated with the user client device classification, wherein the application information derived from the requested application includes a signature generated at the user client device, and the signature is generated from an application certificate corresponding to the requested application; and

comparing the signature included in the application information to authorization information stored at the server, wherein the requested application is approved or denied based on the comparison.

14. The non-transitory computer readable storage medium of claim 13 , wherein the signature includes a hash of at least the application certificate.

15. The non-transitory computer readable storage medium of claim 14 , wherein a failed request to access a corporate network is detected from a trusted user and client device pair.

16. The non-transitory computer readable medium of claim 15 , wherein the hash of the at least application certificate is added to the application information for the failed request, and subsequent requests having the added hash of the at least application certificate or including information that is listed in a list of failed requests corresponding to the application will be denied.

17. The non-transitory computer readable storage medium of claim 13 , wherein the hash is also created from the application information.

18. The non-transitory computer readable medium of claim 17 , wherein the hash changes based on changes to the application information.

19. The non-transitory computer readable storage medium of claim 13 , the program further executable to:

compare the hash to a table of application hashes and corresponding application classifications; and

process traffic for the application based on the application classification.

20. The non-transitory computer readable storage medium of claim 19 , the program further executable to identify that the application is classified as a bad application, wherein the application traffic corresponding to the bad application is blocked after the application is identified as being classified as the bad application.

21. The non-transitory computer readable storage medium of claim 19 , the program further executable to identify that the application is classified as a good application, wherein the application traffic corresponding to the good application is blocked after the application is identified as being classified as the good application.

22. The non-transitory computer readable storage medium of claim 13 , the program further executable to:

collect application level information; and

compare the application level information to an application policy to

compliance of the application.

23. The non-transitory computer readable storage medium of claim 13 , the program further executable to:

identify that the application information does not satisfy a policy rule; and process traffic for the requested application of based on the application information corresponding to a trusted application.

24. The non-transitory computer readable storage medium of claim 23 , the program further executable to add a code signature for the trusted application to a list of code signatures that are acceptable for the trusted application.

25. A system for establishing a connection, the system including:

a server in communication with a user client device, the server including a processor, memory, and one or more applications stored in memory at the server and executable to establish a connection between a user client device and the server, the user client device having a plurality of applications, wherein the server:

receives data from the user client device via the established connection, the received data including authentication information for authenticating a user of the user client device;

classifies the user client device based on an identified device type of the user client device and an identified user type of the authenticated user, wherein the user client device classification is associated with an application control policy that allows application access to specified application data;

receives application information derived from a requested application of the plurality of applications from the user client device in accordance with the application control policy associated with the user client device classification, the application information derived from the requested application includes a signature generated at the user client device, and the signature is generated from an application certificate corresponding to the requested application, and

compares the signature included in the application information to authorization information stored at the server, wherein the requested application is approved or denied based on the comparison.

26. The system of claim 25 , wherein the signature includes a hash of at least the application certificate.

27. The system of claim 26 , wherein a failed request to access a corporate network is detected from a trusted user and client device pair.

28. The system of claim 27 , wherein the hash of the at least application certificate is added to the application information for the failed request, and subsequent requests having the added hash of the at least application certificate or including information that is listed in a list of failed requests corresponding to the application will be denied.

29. The system of claim 26 , wherein the hash is also created from the application information.

30. The system of claim 29 , wherein the hash changes based on changes to the application information.

31. The system of claim 25 , wherein the server:

compares the signature to a table of application signatures and corresponding application classifications; and

process traffic for the application based on the application classification.

32. The system of claim 31 , wherein the server is further executable to block the application traffic when the application is classified as a bad application.

33. The system of claim 25 , wherein the server is further executable to allow the application traffic when the application is classified as a good application.

34. The system of claim 25 , wherein the server is further executable to:

collect application level information; and

compare the application level information to an application policy to identify compliance of the application.

35. The system of claim 25 , wherein the server is further executable to identify that the application information does not satisfy a policy rule and to process traffic for the requested application based on the application information corresponding to a trusted application.

36. The system of claim 25 , wherein the server is further executable to add a code signature for a trusted application to a list of code signatures that are acceptable for the trusted application.

Assignments (11)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2017
From: PETERSON, CHRIS D.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 044326/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2017
From: MEDAPPA, CHEMIRA; TELEHOWSKI, DAVID
To: SONICWALL US HOLDINGS INC.
Reel/Frame 044723/0757 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →