IP Library Granted Patent US 9,602,372
Granted Patent B2
US 9,602,372 · App. 14/719,805 · Granted Mar 21, 2017

Using endpoint host checking to classify unmanaged devices in a network and to improve network location awareness

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,602,372
App. No.
14/719,805
Granted
Mar 21, 2017
Kind
B2
Abstract

A device receives, from a managed device, endpoint information associated with an unmanaged device connected to the managed device in a network. The device also receives unmanaged device information that partially identifies the unmanaged device, and completely identifies the unmanaged device based on the endpoint information and the unmanaged device information.

Claims (60)

1. A method, comprising:

receiving, by a computing device and from a first device, endpoint information associated with an endpoint device connected to the first device in a network, the endpoint information comprising configuration settings of the first device for the endpoint device;

receiving, by the computing device, device information associated with the endpoint device;

determining, by the computing device, that the endpoint device comprises a particular type of device based on the device information;

determining, by the computing device, that the endpoint device comprises a particular model of the particular type of device based on the endpoint information; and

selecting a network functionality for providing to the endpoint device based on the endpoint device comprising the particular model of the particular type of device.

2. The method of claim 1 , further comprising:

selecting a further network functionality for providing to the endpoint device based on the device information.

3. The method of claim 1 , where the selected network functionality includes one or more of:

access privileges associated with the network,

firewall privileges associated with the network, or

authorization information associated with the network.

4. The method of claim 1 , where the first device includes a host checking client for obtaining information associated with accessing the network.

5. The method of claim 1 , where the endpoint device does not include a host checking client for obtaining information associated with accessing the network.

6. The method of claim 1 , where the computing device includes a network admission control (NAC) device; and

where receiving the endpoint information includes:

receiving endpoint integrity check information related to an endpoint integrity check performed by the first device and in connection with the endpoint device.

7. A device, comprising:

a processor to:

receive, from a first device, endpoint information associated with an endpoint device connected to the first device in a network, the endpoint information comprising configuration settings of the first device for the endpoint device,

receive device information associated with the endpoint device,

determine that the endpoint device comprises a particular type of device based on the device information,

determine that the endpoint device comprises a particular model of the particular type of device based on the endpoint information,

select a network functionality for providing to the endpoint device based on the endpoint device comprising the particular model of the particular type of device,

the endpoint device using the network functionality in conjunction with accessing the network.

8. The device of claim 7 , where the selected network functionality includes one or more of:

access privileges associated with the network,

firewall privileges associated with the network, or

authorization information associated with the network.

9. The device of claim 7 , where the first device includes a host checking client that obtains information associated with accessing the network.

10. The device of claim 7 , where the endpoint device does not include a host checking client that obtains information associated with accessing the network.

11. The device of claim 7 , where, when determining that the endpoint device comprises the particular type of device, the processor is to:

determine that the endpoint device comprises a printer based on the device information.

12. The device of claim 7 , where, when obtaining the endpoint information, the processor is to:

obtain configuration settings for a printer, and

where, when determining that the endpoint device comprises the particular model of the particular type of device, the processor is further to:

determine that the printer comprises a particular model printer based on the configuration settings.

13. A non-transitory computer-readable medium storing executable computer instructions, the instructions configured to, in response to being executed, perform steps comprising:

receiving, from a first device, endpoint information associated with an endpoint device connected to the first device in a network, the endpoint information comprising configuration settings of the first device for the endpoint device;

receiving device information associated with the endpoint device;

determining that the endpoint device comprises a particular type of device based on the device information;

determining that the endpoint device comprises a particular model of the particular type of device based on the endpoint information; and

selecting a network functionality for providing to the endpoint device based on the endpoint device comprising the particular model of the particular type of device.

14. The method of claim 13 , further comprising:

selecting a further network functionality for providing to the endpoint device based on the device information.

15. The method of claim 13 , where the selected network functionality includes one or more of:

access privileges associated with the network,

firewall privileges associated with the network, or

authorization information associated with the network.

16. The method of claim 13 , where the first device includes a host checking client for obtaining information associated with accessing the network.

17. The method of claim 13 , where the endpoint device does not include a host checking client for obtaining information associated with accessing the network.

18. The method of claim 13 , where receiving the endpoint information includes:

receiving endpoint integrity check information related to an endpoint integrity check performed by the first device and in connection with the endpoint device.

19. A method, comprising:

receiving, by a network admission control (“NAC”) device computing device and from a first device, endpoint integrity check information related to an endpoint integrity check performed by the first device in connection associated with an endpoint device connected to the first device in a network, the endpoint information comprising configuration settings of the first device for the endpoint device;

receiving, by the NAC computing device, device information associated with the endpoint device;

determining, by the NAC computing device, that the endpoint device comprises a particular type of device based on the device information;

determining, by the NAC computing device, that the endpoint device comprises a particular model of the particular type of device based on the endpoint integrity check information; and

selecting a network functionality for providing to the endpoint device based on the endpoint device comprising the particular model of the particular type of device; and

providing the network functionality to the endpoint device.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 053269/0339 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded May 1, 2017
From: PULSE SECURE, LLC
To: JUNIPER NETWORKS, INC.
Reel/Frame 042197/0822 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2015
From: VENABLE, JEFFREY C., SR.
To: JUNIPER NETWORKS, INC.
Reel/Frame 036997/0447 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2015
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 036997/0453 →