IP Library Granted Patent US 9,756,047
Granted Patent B1
US 9,756,047 · App. 14/517,723 · Granted Sep 5, 2017

Embedding security posture in network traffic

Inventors: Suresh Kumar Batchu (Milpitas, CA); Mansu Kim (Cupertino, CA)
Assignee: MOBILE IRON, INC.
H04L63/0876G06F21/44G06F21/57G06F21/577H04L63/102H04W12/08H04W12/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,756,047
App. No.
14/517,723
Granted
Sep 5, 2017
Kind
B1
Abstract

Embedding security posture in network traffic is disclosed. Security posture information is received. The security posture information is embedded into a message. The message including the security posture information is sent from a mobile device to a service node. The service node uses the security posture information to validate the mobile device to access a service. The service accesses the service based at least in part on the validation.

Claims (73)

1. A method, comprising:

receiving from a device management server security posture information that includes a posture value;

embedding the security posture information into a message;

sending the message including the security posture information from a mobile device to a service node, wherein the service node is configured to:

negotiate with the device management server regarding a data structure associated with the security posture information;

validate the mobile device to access a service using the security posture information, wherein the data structure includes a mapping of one or more security postures to corresponding posture values; and

in the event the security posture information does not validate the mobile device based on the posture value the service node is configured to communicate with the device management server to validate the mobile device; and

accessing the service based at least in part on the validation.

2. The method of claim 1 , further comprising:

sending, from the mobile device to the device management server, state information, wherein the state information is used at the device management server to generate the security posture information.

3. The method of claim 2 , wherein the state information includes one or more of mobile device state information, application inventory information, and policy state information.

4. The method of claim 2 , wherein sending the state information comprises sending the state information from a management agent on the mobile device to the device management server.

5. The method of claim 2 , wherein the device management server is configured to perform the steps of:

receiving the state information;

determining a posture of the mobile device at least in part by applying rules to the state information;

generating the security posture information including a security posture value indicating the security posture of the mobile device; and

sending the security posture information to the mobile device.

6. The method of claim 1 , further comprising:

determining a posture of the mobile device based at least in part on state information; and

generating the security posture information indicating the posture of the mobile device.

7. The method of claim 6 , wherein determining the posture is performed at a management agent on the mobile device, and further comprising sending the security posture information to a managed application on the mobile device.

8. The method of claim 6 , wherein determining the posture is performed at a virtual private network client on the mobile device.

9. The method of claim 1 , wherein the steps of receiving, embedding, sending, and accessing are performed at least in part at a virtual private network client on the mobile device.

10. The method of claim 1 , wherein receiving the security posture information includes:

receiving the security posture information at a mobile device management agent; and

providing the security posture information to a managed application.

11. The method of claim 10 , wherein the managed application embeds the security posture information into the message.

12. The method of claim 1 , wherein the embedding step includes;

embedding the security posture information into a header of a hypertext transfer protocol (HTTP) message.

13. The method of claim 1 , wherein the embedding step includes:

embedding the security posture information into a Wi-Fi user profile associated with the mobile device.

14. The method of claim 1 , wherein the embedding step includes:

adding the security posture information to a portion of the message, wherein the message includes information to be sent to the service node irrespective of the security posture information.

15. The method of claim 1 , wherein the security posture information includes one or more of mobile device posture information, timestamp information, and a service identifier associated with the service node.

16. The method of claim 1 , wherein the security posture information includes a first set of security posture information generated at the mobile device and a second set of security posture information generated at a device management server.

17. The method of claim 16 , wherein the service node is configured to perform the steps of:

selecting a set of security posture information based at least in part on timestamp information included in the sets of security posture information; and

analyzing the selected set of security posture information.

18. The method of claim 1 , wherein the security posture information is encrypted at the device management server using encryption information associated with the service node.

19. The method of claim 18 , wherein the service node is configured to perform the steps of:

receiving the message including the security posture information; and

using the encryption information associated with the service node to extract the security posture information from the message.

20. The method of claim 1 , wherein the service node is configured to perform the steps of:

analyzing the security posture information; and

providing the mobile device access to the service based at least in part on the analysis of the security posture information.

21. The method of claim 20 , wherein analyzing the security posture information includes:

applying a policy to one or more of a security posture value and a security posture expiration time included in the security posture information;

determining that the mobile device is validated to access the service based at least in part on the application of the policy; and

providing the mobile device access to the service based at least in part on the determination.

22. The method of claim 1 , wherein the service node is configured to perform the steps of:

analyzing the security posture information; and

denying access the mobile device access to the service based at least in part on the analysis of the security posture information.

23. The method of claim 22 , wherein the service node is further configured to perform the step of providing information to the mobile device including operations to be performed to gain access to the service.

24. The method of claim 1 , wherein the service node registers the service with device management server at least in part by determining one or more of a service identifier associated with the service, encryption information associated with the service node, a communication protocol, one or more security values, and a security posture expiration period.

25. The method of claim 1 , wherein the security posture information is embedded into the message based at least in part on a frequency requirement associated with the service.

26. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

receive from a device management server security posture information that includes a posture value;

embed the security posture information into a message;

send the message including the security posture information from a mobile device to a service node, wherein the service node is configured to:

negotiate with the device management server regarding a data structure associated with the security posture information;

validate the mobile device to access a service using the security posture information, wherein the data structure includes a mapping of one or more security postures to corresponding posture values; and

in the event the security posture information does not validate the mobile device based on the posture value the service node is configured to communicate with the device management server to validate the mobile device; and

access the service based at least in part on the validation.

27. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving from a device management server security posture information that includes a posture value;

embedding the security posture information into a message;

sending the message including the security posture information from a mobile device to a service node, wherein the service node is configured to:

negotiate with the device management server regarding a data structure associated with the security posture information;

validate the mobile device to access a service using the security posture information, wherein the data structure includes a mapping of one or more security postures to corresponding posture values; and

in the event the security posture information does not validate the mobile device based on the posture value the service node is configured to communicate with the device management server to validate the mobile device; and

accessing the service based at least in part on the validation.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2015
From: BATCHU, SURESH KUMAR; KIM, MANSU
To: MOBILE IRON, INC.
Reel/Frame 034834/0154 →
Continuity (1)
Provisional Application 61892363 · Oct 17, 2013