IP Library Granted Patent US 10,015,145
Granted Patent B2
US 10,015,145 · App. 14/819,104 · Granted Jul 3, 2018

Unified source user checking of TCP data packets for network data leakage prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,015,145
App. No.
14/819,104
Granted
Jul 3, 2018
Kind
B2
Abstract

Systems and methods are directed towards network data leakage prevention (DLP). More specifically, the systems and methods are directed towards using TCP (Transmission Control Protocol) data packets in conjunction with the DLP monitor. The network DLP utilizes TCP data packets to carry source user identity. With the source user identity, the DLP monitor can determine if sensitive data can be transmitted based on the provided user information and corresponding DLP policies for each user. Furthermore, the DLP monitor can determine if sensitive data can also be transmitted for particular users in situations where multiple users share the same IP address.

Claims (44)

1. A method for data leakage prevention (DLP) by checking transfer control protocol (TCP) data packets, the method comprising:

establishing user information for a user with a network, the user information including secret keys for authenticating source user identity for TCP data packets being sent by a user device of the user;

intercepting a transmitted TCP data packet from the user device containing sensitive information, wherein the transmitted TCP data packet is being transmitted out of the network;

identifying, via a processor, that the transmitted TCP data packet from the user device does not contain source user-based information that is required to authenticate the user;

sending a request over a network interface to the user device that identifies source user-based information associated with the user, wherein the user device places the identified source user-based information in one or more data fields of a retransmitted TCP data packet based on a shared secret associated with the secret keys when an acknowledgment to the transmitted TCP data packet has not been received by the user device;

receiving the retransmitted TCP data packet from the user device, the retransmitted TCP data packet containing the source user-based information placed in the one or more data fields by the user device;

evaluating, via the processor, that the source user-based information included in the one or more data fields of the retransmitted TCP data packet matches the user information established with the network, thereby authenticating the identity of the user based on the shared secret;

evaluating, via the processor, corresponding policies associated with the authenticated user; and

processing, via the processor, the retransmitted TCP data packet containing sensitive information based on the evaluated policies for the authenticated user.

2. The method of claim 1 , wherein the user information for the user is established during an initial log-in with the network.

3. The method of claim 1 , wherein the user information includes a unique random identification, a standard keyed-hash message authentication code and a key used by the authentication code to generate a message authentication code.

4. The method of claim 1 , wherein the policies dictate what types of sensitive information can be transmitted by the user outside the network.

5. The method of claim 1 , wherein processing the retransmitted TCP data packet based on the evaluated policies includes blocking further transmission of the TCP data packet outside of the network.

6. The method of claim 1 , wherein processing the retransmitted TCP data packet based on the evaluated policies includes allowing the transmission of the TCP data packet outside of the network.

7. The method of claim 1 , wherein the source user-based information included in the retransmitted TCP data packet includes a message authentication code.

8. The method of claim 7 , wherein evaluating the source user-based information comprises matching the message authentication code included in the retransmitted TCP data packet by the user and the message authentication code generated via the secret keys.

9. A system for data leakage prevention (DLP) by checking transfer control protocol (TCP) data packets, the system comprising:

a memory that stores secret keys for authenticating source user identity for TCP data packets sent by each user device;

a processor associated with the memory, wherein the processor executes instructions stored in the memory to establish user information for a user associated with a network, the user information including secret keys for authenticating source user identity for TCP data packets being sent by a user device of the user; and

a network interface that intercepts a transmitted TCP data packet from the user device containing sensitive information, wherein the transmitted TCP data packet is transmitted out of the network,

wherein the processor executing instructions out of the memory identifies that the intercepted TCP data packet from the user does not contain source user-based information that is required to authenticate the user,

wherein the network interface:

sends a request to the user device that identifies source user-based information associated with the user wherein the user device places the identified source user-based information in one or more data fields of a retransmitted TCP data packet based on a shared secret associated with the secret keys of the user when an acknowledgment to the transmitted TCP data packet has not been received by the user device, and

receives the retransmitted TCP data packet,

wherein the processor identifies that the source user-based information included in the one or more data fields of the retransmitted TCP data packet matches the user information established with the network, thereby authenticating the identity of the user based on the shared secret, and processes the retransmitted TCP data packet containing sensitive information based on policies associated with the authenticated user.

10. The system of claim 9 , wherein the user information for the user is established during an initial log-in with the network.

11. The system of claim 10 , wherein the user information includes a unique random identification, a standard keyed-hash message authentication code and a key used by the authentication code to generate a message authentication code.

12. The system of claim 9 , wherein the policies dictate what types of sensitive information can be transmitted by the user outside the network.

13. The system of claim 9 , wherein processing the retransmitted TCP data packet based on the evaluated policies includes blocking further transmission of the TCP data packet outside of the enterprise network.

14. The system of claim 9 , wherein processing the retransmitted TCP data packet based on the evaluated policies includes allowing the transmission of the TCP data packet outside of the enterprise network.

15. The system of claim 9 , wherein the source user-based information included in the retransmitted TCP data packet includes a message authentication code.

16. The system of claim 15 , wherein evaluating the source user-based information comprises matching the message authentication code included in the retransmitted TCP data packet by the user and the message authentication code generated via the secret keys.

17. A non-transitory computer readable storage medium, having embodied thereon a program executable by a processor to perform a method for data leakage prevention (DLP) by checking transfer control protocol (TCP) data packets, the method comprising:

establishing user information for a user with a network, the user information including secret keys for authenticating source user identity for TCP data packets being sent by a user device;

intercepting a transmitted TCP data packet from the user device containing sensitive information, wherein the transmitted TCP data packet is being transmitted out of the network;

identifying that the transmitted TCP data packet from the user device does not contain source user-based information that is required to authenticate the user;

sending a request to the user device that identifies source user-based information that is associated with the user, wherein the user device places the identified source user-based information in one or more data fields of a retransmitted TCP data packet based on a shared secret when an acknowledgment to the transmitted TCP data packet has not been received by the user device;

receiving the retransmitted TCP data packet from the user device, the retransmitted TCP data packet containing the source user-based information placed in the one or more data fields by the user device;

evaluating that the source user-based information included in the one or more data fields of the retransmitted TCP data packet matches the user information established with the network, thereby authenticating the identity of the user based on the shared secret;

evaluating corresponding policies associated with the authenticated user; and

processing the retransmitted TCP data packet containing sensitive information based on the evaluated policies for the authenticated user.

18. The non-transitory computer readable storage medium of claim 17 , wherein the user information for the user is established during an initial log-in with the network.

19. The non-transitory computer readable storage medium of claim 17 , wherein the user information includes a unique random identification, a standard keyed-hash message authentication code and a key used by the authentication code to generate a message authentication code.

20. The non-transitory computer readable storage medium of claim 17 , wherein the policies dictate what types of sensitive information can be transmitted by the user outside the network.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
CHANGE OF NAME Recorded May 29, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046247/0114 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 037160 FRAME 0142 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0812 →
RELEASE OF REEL 037160 FRAME 0239 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0115 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037160 FRAME 0171 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0253 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - NOTES Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 037160/0142 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - TERM LOAN Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037160/0239 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - ABL Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037160/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2015
From: LING, HUI; CHEN, ZHONG; YU, CUIPING; CHENG, ZUN PING
To: DELL SOFTWARE INC.
Reel/Frame 036272/0224 →