IP Library Granted Patent US 10,554,662
Granted Patent B2
US 10,554,662 · App. 14/866,800 · Granted Feb 4, 2020

Security service for an unmanaged device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,554,662
App. No.
14/866,800
Granted
Feb 4, 2020
Kind
B2
Abstract

Particular embodiments described herein provide for a network element that can be configured to receive, from an electronic device, a request to access a network service. In response to the request, the network element can send data related to the network service to the electronic device and add a test link to the data related to the network service. The network element can also be configured to determine if the test link was successfully executed and classify the electronic device as untrusted if the test link was not successfully executed.

Claims (52)

1. At least one non-transitory machine readable medium comprising one or more instructions that when executed by at least one processor, cause the at least one processor to:

receive, from an electronic device, a request to access a network service;

send, to the electronic device in response to the request, data related to the network service that includes a test link, wherein the test link causes the electronic device to execute a new request routed via a specified pathway to a pre-defined network element in the network service;

determine whether the new request was routed via the specified pathway to the pre-defined network element in the network service; and

classify the electronic device as untrusted based on a determination that the new request was not routed to the pre-defined network element.

2. The at least one non-transitory machine readable medium of claim 1 , wherein the request to access the network service is received by a reverse proxy module.

3. The at least one non-transitory machine readable medium of claim 1 , wherein credentials to access the requested network service are obtained from an identity provider.

4. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by the at least one processor, further cause the at least one processor to:

communicate instructions to the electronic device as to how the electronic device could be classified as trusted.

5. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by the at least one processor, further cause the at least one processor to:

classify the electronic device as trusted based on a determination that the new request was routed to the pre-defined network element.

6. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by at least one processor, further cause the at least one processor to:

block access to the network service based on the electronic device being classified as untrusted.

7. The at least one non-transitory machine readable medium of claim 1 , wherein the test link is not readily identifiable by a user of the electronic device.

8. The at least one non-transitory machine readable medium of claim 1 , wherein the electronic device is an unmanaged device.

9. An apparatus comprising:

a network services platform configured to:

receive, from an electronic device, a request to access a network service;

send, to the electronic device in response to the request, data related to the network service that includes a test link, wherein the test link causes the electronic device to issue a new request routed via a specified pathway to a pre-defined network element in the network service;

determine whether the new request was routed via the specified pathway to the pre-defined network element in the network service; and

classify the electronic device as untrusted based on a determination that the new request was not routed to the pre-defined network element.

10. The apparatus of claim 9 , wherein the request to access the network service is received by a reverse proxy module.

11. The apparatus of claim 9 , wherein credentials to access the requested network service are obtained from an identity provider.

12. The apparatus of claim 9 , wherein the network services platform is further configured to:

communicate instructions to the electronic device as to how the electronic device could be classified as trusted.

13. The apparatus of claim 9 , wherein the network services platform is further configured to:

classify the electronic device as trusted based on a determination that the new request was routed to the pre-defined network element.

14. The apparatus of claim 9 , wherein the network services platform is further configured to:

block access to the network service based on the electronic device being classified as untrusted.

15. The apparatus of claim 9 , wherein the test link is not readily identifiable by a user of the electronic device.

16. The apparatus of claim 9 , wherein the electronic device is an unmanaged device.

17. A method comprising:

receiving, from an electronic device, a request to access a network service;

sending, to the electronic device in response to the request, data related to the network service that includes a test link, wherein the test link causes the electronic device to execute a new request routed via a specified pathway to a pre-defined network element in the network service;

determining whether the new request was routed via the specified pathway to the pre-defined network element in the network service; and

classifying the electronic device as untrusted based on a determination that the new request was not routed to the pre-defined network element.

18. The method of claim 17 , wherein the request to access the network service is received by a reverse proxy module.

19. The method of claim 17 , wherein credentials to access the requested network service are obtained from an identity provider.

20. The method of claim 17 , further comprising:

communicating instructions to the electronic device as to how the device could be classified as trusted.

21. The method of claim 17 , further comprising:

classifying the device as trusted based on the determination that the new request was routed to the pre-defined network element.

22. The method of claim 17 , further comprising:

blocking access to the network service based on the electronic device being classified as untrusted.

23. The method of claim 17 , wherein the test link is not readily identifiable by a user of the electronic device.

24. A system for providing a security service for an unmanaged device, the system comprising:

a network services platform configured for:

receiving, from an electronic device, a request to access a network service;

sending, to the electronic device in response to the request, data related to the network service that includes a test link, wherein the test link causes the electronic device to execute a new request routed via a specified pathway to a pre-defined network element in the network service;

determining whether the new request was routed via the specified pathway to the pre-defined network element in the network service; and

classifying the electronic device as untrusted based on a determination that the new request was not routed to the pre-defined network element.

25. The system of claim 24 , wherein credentials to access the requested network service are obtained from an identity provider.

Assignments (18)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →