IP Library Granted Patent US 10,021,137
Granted Patent B2
US 10,021,137 · App. 14/583,687 · Granted Jul 10, 2018

Real-time mobile security posture

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,021,137
App. No.
14/583,687
Granted
Jul 10, 2018
Kind
B2
Abstract

In an example, a system and method for real-time mobile security posture updates is provided. A mobile device management (MDM) agent may run on the mobile device, and may register with the operating system one or more mobile security posture change events that may affect the mobile security posture. These may include, for example, installation of an MDM agent, uninstallation of a program, connecting to a secured or unsecured network, or similar. When any such event occurs, the OS lodges the event with the MDM agent, which then communicates with an MDM server engine to potentially receive new security instructions. Lodging the event may include providing a joint user-and-device authentication to the MDM server, such as via SAML.

Claims (50)

1. A non-enterprise computing device for accessing enterprise computing resources, comprising:

a network interface;

an operating system; and

logic, including at least a processor and a memory, comprising a mobile device management (MDM) agent operable for providing the non-enterprise computing device conditional access to enterprise resources, comprising:

registering with an MDM server of an enterprise the non-enterprise computing device as a non-enterprise computing device lacking enterprise control of software installation, and receiving a certificate configured to provide access to resources of the enterprise;

receiving from the MDM server instructions regarding a security posture to monitor;

registering a security posture event with the operating system;

entering a sleep mode;

waking after receiving from the operating system a notification of a security posture change event;

notifying the MDM server of the security posture change event;

receiving a security modification instruction from the MDM server; and

enforcing the security modification instruction on the computing apparatus.

2. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the MDM agent is further operable for providing a joint user-and-device authentication token to an identity provider.

3. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the MDM agent is further operable for receiving notification of the security posture change event from the operating system.

4. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the MDM agent is further operable to run as a background process.

5. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the MDM agent is further operable to run as a background process with elevated privileges.

6. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the MDM agent is further operable to run within a trusted execution environment (TEE).

7. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is installation of a program.

8. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is uninstallation of a program.

9. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is encountering a candidate malicious object.

10. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is a change in location.

11. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is connecting to an unsecured network.

12. The non-enterprise computing device for accessing enterprise computing resources of claim 1 , wherein the security posture change event is a change in biometric authentication.

13. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions for a computing apparatus to provide a mobile device management (MDM) agent operable for providing the non-enterprise computing device conditional access to enterprise resources, comprising:

registering with an MDM server of an enterprise the non-enterprise computing device as a non-enterprise computing device lacking enterprise control of software installation, and receiving a certificate configured to provide access to resources of the enterprise, via a network interface;

receiving from the MDM manager server instructions regarding a security posture to monitor;

registering a security posture event with an operating system;

entering a sleep mode;

waking after receiving from the operating system a notification of a security posture change event;

notifying the MDM server of the security posture change event via the network interface;

receiving a security modification instruction from the MDM server; and

enforcing the security modification instruction on the computing apparatus.

14. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the MDM agent is further operable for providing a joint user-and-device authentication token to an identity provider.

15. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the MDM agent is further operable for receiving notification of the security posture change event from the operating system.

16. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the MDM agent is further operable to run as a background process.

17. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the MDM agent is further operable to run as a background process with elevated privileges.

18. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the MDM agent is further operable to run within a trusted execution environment (TEE).

19. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the security posture change event is installation of a program.

20. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the security posture change event is uninstallation of a program.

21. The one or more tangible, non-transitory computer-readable mediums of claim 13 , wherein the security posture change event is encountering a candidate malicious object.

22. A computer-implemented method of providing mobile device management (MDM), comprising:

registering with an MDM server of an enterprise a non-enterprise computing device as a non-enterprise computing device lacking enterprise control of software installation, and receiving a certificate configured to provide access to resources of an enterprise, via a network interface;

receiving from the MDM server instructions regarding a security posture to monitor;

registering a security posture event with the operating system;

entering a sleep mode;

waking after receiving from the operating system a notification of a security posture change event;

notifying the MDM server of the security posture change event via the network interface;

receiving a security modification instruction from the MDM server; and

enforcing the security modification instruction.

23. The method of claim 22 , further comprising providing a joint user-and-device authentication token to an identity provider.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2015
From: CHAHAL, SUDIP; TATOURIAN, IGOR
To: MCAFEE, INC.
Reel/Frame 035108/0455 →