IP Library Granted Patent US 9,781,148
Granted Patent B2
US 9,781,148 · App. 14/973,636 · Granted Oct 3, 2017

Methods and systems for sharing risk responses between collections of mobile communications devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,781,148
App. No.
14/973,636
Granted
Oct 3, 2017
Kind
B2
Abstract

Methods are provided for determining an enterprise risk level, for sharing security risk information between enterprises by identifying a security response by a first enterprise and then sharing the security response to a second enterprise when a relationship database profile for the first collection indicates the security response may be shared. Methods are also provided for determining whether to allow a request from an originating device where the request may have been initiated by a remote device.

Claims (44)

1. A method for determining an acceptable risk level for a collection to improve the functioning of mobile communications devices associated with the collection, the method comprising:

accessing, by a server security component, a security database including risk information received from a plurality of collections, wherein the risk information includes source information that associates the risk information with one or more collections from the plurality;

determining, by the server security component, a risk level for each collection based on the accessed risk information associated with each collection, the determined risk levels including a first risk level associated with a first collection;

determining, by the server security component, an acceptable risk level based on the determined risk levels;

providing, by the server security component to the first collection, the acceptable risk level and the first risk level;

determining, by the server security component, a new first risk level for the first collection based in part on new risk information associated with the first collection;

determining, by the server security component, a new acceptable risk level based on a plurality of determined risk levels;

providing, by the server security component to the first collection, the new acceptable risk level and the new first risk level;

comparing, by the server security component, the new first risk level to the new acceptable risk level; and,

notifying, by the server security component, the first collection when the comparison indicates that the new first risk level is more than a threshold amount greater than the new acceptable risk level.

2. The method of claim 1 , wherein providing, by the server security component to the first collection, the acceptable risk level and the first risk level includes providing the acceptable risk level and the first risk level to a first administrator device associated with a first administrator of the first collection.

3. The method of claim 1 , further comprising:

comparing, by the server security component, the first risk level to the acceptable risk level; and

alerting, by the server security component, the first collection when the comparison indicates that the first risk level is more than a threshold more than the acceptable risk level.

4. The method of claim 1 , wherein the determining, by the server security component, a new first risk level for the first collection was performed in response to the server security component receiving a request for the new first risk level from the first collection.

5. The method of claim 4 , wherein the request for the new first risk level was initiated from a device associated with an administrator of the first collection after a change was made that potentially affected the first risk level.

6. The method of claim 1 , wherein the security database further includes a plurality of security risk responses, each security risk response associated with at least one of the plurality of collections, the method further comprising:

identifying, by the server security component, a first security risk response in the security database, wherein the first security risk response is associated with the first collection;

accessing, by the server security component, a relationship database including collection profiles related to the sharing of information between the plurality of collections, wherein the relationship database includes a first collection profile indicating that the first collection permits information related to the first security risk response to be shared with a second collection of the plurality when a determined second risk level associated with the second collection is equal to or less than a second threshold more than the acceptable risk level;

comparing, by the server security component, the second risk level to the acceptable risk level; and,

providing, by the server security component, the first security risk response to the second collection when the second risk level is equal to or less than the second threshold more than the acceptable level.

7. A method for determining whether to allow a network access request, comprising:

receiving, by a destination computing device running a destination computing device security component, an access request by a terminal computing device in a series of at least one computing devices, wherein the series begins with an initial computing device, wherein the initial computing device initiates the access request, and wherein the series includes all computing devices used to transmit the access request to the destination computing device;

requesting, by the destination computing device security component, terminal source information relating to the access request from a terminal device security component running on the terminal computing device;

requesting, by the destination computing device security component, next source information relating to the access request from a next device security component running on a next computing device of the series when the destination computing device security component receives terminal source information from the terminal device security component and the terminal source information indicates that the terminal computing device is trusted, and is not the initiator of the access request, and identifies the next computing device in the series;

allowing, by the destination computing device security component, the access request:

when the destination computing device security component receives next source information from the next device security component, and

when the next source information:

indicates that the next computing device is trusted, and

indicates that the next computing device is the initial computing device and is not being controlled by a remote device; and

repeating, for additional next computing devices, requesting, by the destination computing device security component, additional next source information relating to the initiator of the access request from additional next device security components running on additional next computing devices when the destination computing device security component receives source information from a previous device security component and the previous source information indicates that the previous computing device is trusted, and is not the initiator of the access request, and identifies the additional next computing device in the series,

until the destination computing device security component receives additional next source information from an additional next device security component and the additional next source information indicates that the additional next computing device is trusted, and is the initiator of the access request.

8. A method for determining whether to allow a network access request, comprising:

receiving, by a destination computing device running a destination computing device security component, an access request by a terminal computing device in a series of at least one computing devices, wherein the series begins with an initial computing device, wherein the initial computing device is the initiator of the access request, and wherein the access request is transmitted to the destination computing device using the series;

requesting, by the destination computing device security component, terminal source information relating to the initiator of the access request from a terminal device security component running on the terminal computing device;

requesting, by the destination computing device security component, next source information relating to the initiator of the access request from a next device security component running on a next computing device when the destination computing device security component receives terminal source information from the terminal device security component and the terminal source information indicates that the terminal computing device is trusted, and is not the initiator of the access request, and identifies the next computing device in the series;

denying, by the destination computing device security component, the access request:

when the destination computing device security component does not receive next source information, or

when the destination computing device security component receives next source information from the next device security component and the next source information indicates that the next computing device is the initiator of the access request and indicates that the next computing device in the series is not trusted; and

repeating, for additional next computing devices, requesting, by the destination computing device security component, additional next source information relating to the initiator of the access request from additional next device security components running on additional next computing devices when the destination computing device security component receives source information from a previous device security component and the previous source information indicates that the previous computing device is trusted, and is not the initiator of the access request, and identifies the additional next computing device in the series;

until the destination computing device security component does not receive additional next source information from an additional next device security component, or

until the additional next source information indicates:

that the additional next computing device is not trusted, or

that the additional next computing device is the initiator of the access request.

Assignments (13)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2019
From: LINEBERRY, ANTHONY MCKAY
To: LOOKOUT, INC.
Reel/Frame 049909/0373 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2016
From: WOOTTON, BRUCE
To: LOOKOUT, INC.
Reel/Frame 040697/0086 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2016
From: BURGESS, JAMES DAVID; EVANS, DANIEL LEE; SALOMON, ARIEL; GRUBB, JONATHAN PANTERA; STRAZZERE, TIMOTHY
To: LOOKOUT, INC.
Reel/Frame 040149/0591 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2016
From: MAHAFFEY, KEVIN PATRICK; BUCK, BRIAN JAMES; ROBINSON, WILLIAM; HERING, JOHN G.; RICHARDSON, DAVID LUKE; WYATT, TIMOTHY MICHEAL; GOLOMBEK, DAVID; BARTON, KYLE; SWAMI, YOGESH
To: LOOKOUT, INC.
Reel/Frame 039969/0651 →