IP Library Granted Patent US 10,044,765
Granted Patent B2
US 10,044,765 · App. 15/209,125 · Granted Aug 7, 2018

Method and apparatus for centralized policy programming and distributive policy enforcement

Inventors: Boris Yanovsky (Saratoga, CA); Roman Yanovsky (Los Altos, CA)
Assignee: SonicWALL Inc.
H04L63/205H04L41/0893H04L63/101H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,765
App. No.
15/209,125
Granted
Aug 7, 2018
Kind
B2
Abstract

A method and apparatus for centralized policy programming and distributive policy enforcement is described. A method comprises centrally maintaining a plurality of policy definitions for one or more subscribers, generating policy configurations using the plurality of policy definitions, each of the policy configurations being specific to one of the plurality of policy definitions, and disseminating the policy configurations to the appropriate ones of the subscribers' networks.

Claims (32)

1. A method for generating distributable network policy definitions, the method comprising:

executing instructions stored at a memory, wherein the execution of the instructions by a hardware processor:

receives a first network policy parameter from a user, the first network policy parameter including one or more rules that govern network activity,

receives a second network policy parameter from the user, the second network policy parameter including information about a first set of one or more network devices to which the one or more rules of the first network policy parameter apply,

receives a third network policy parameter from the user, the third network policy parameter including a rule trigger event, the rule trigger event indicating to a network policy generator that a network policy configuration should be generated based on the first, second, and third network policy parameters, wherein the network policy configuration associates a plurality of different vendors with one or more software program versions to be installed on the first set of one or more network devices,

identifies the first, second, and third network policy parameters as collectively forming a network policy definition associated with a first subscriber and stored at a globally accessible server, wherein the network policy definition requires the one or more software versions to be consistent with the network policy configuration that associates the plurality of different vendors with the one or more software program versions, and

storing the second network policy definition in the globally accessible server, wherein the second network policy definition is associated with a configuration associated with a second set of one or more network devices and at least a second subscriber that is different from the first subscriber.

2. The method of claim 1 , wherein a security function is associated with at least one of the first, the second, and the third policy network parameter according to a rule of the one or more rules identifies that a message be provided for display at a computer associated with a first user group.

3. The method of claim 2 , wherein a first access request is received from the computer associated with the first user group before the message is provided to the computer associated with the first user group, and the message displayed at the computer associated with the first user group identifies that a software configuration at the computer associated with the first user group must be updated before the access request will be allowed.

4. The method of claim 3 , wherein the software configuration at the computer associated with the first user group is updated after the message is displayed at the computer associated with the first user group, and the first access request is allowed after the software configuration at the computer is updated.

5. The method of claim 1 , wherein a security function associated with a rule of the one or more rules includes denying access to an access request from a computer associated with a first user group after the access request is received from the computer associated with the first user group.

6. The method of claim 1 , wherein the execution of the instructions by the computer processor identifies that a software configuration at a computer associated with a first user group should be updated according to the network policy definition, the network policy definition identifying that access requests from the computer associated with the first user group can be allowed for a first period of time after a first access request is received from the computer associated with the user group, and the first access request is allowed for the first period of time according to the network policy definition.

7. The method of claim 1 , wherein the network policy definition is stored at a computing device implementing the function of a choke point that controls the allowance of access requests associated from computers attempting to access resources in a computer network, and the choke point enforces the network policy definition according to at least one rule of the one or more rules.

8. The method of claim 7 , wherein the computing device implementing the function of the choke point is a host computer at the computer network.

9. The method of claim 1 , wherein the network policy definition is associated with a first local area network (LAN) and the second network policy definition is associated with a second local area network (LAN).

10. The method of claim 1 , wherein at least one of the network policy definition and the second network policy definition stored at the globally accessible server are accessible to a first user group and the second network policy definition cannot be configured by a user of the second user group.

11. The method of claim 10 , wherein one or more users associated with the first user group and one or more users associated with the second user group are each associated with a single organization.

12. An apparatus for generating distributable network policy definitions, the apparatus comprising:

a network interface that:

receives a first network policy parameter from a user, the first network policy parameter including one or more rules that govern network activity,

receives a second network policy parameter from the user, the second network policy parameter including information about a first set of one or more network devices to which the one or more rules of the first network policy parameter apply, and

receives a third network policy parameter from the user, the third network policy parameter including a rule trigger event, the rule trigger event indicating to a network policy generator that a network policy configuration should be generated based on the first, second, and third network policy parameters, wherein the network policy configuration associates a plurality of different vendors associated with one or more specific software program versions that should be installed on the first set of one or more network devices;

a memory; and

a computer processor executing instructions out of the memory, wherein the execution of the instructions by the computer processor identifies that the first, second, and third network policy parameters as collectively forming a network policy definition associated with a first subscriber and stored at a globally accessible server, wherein the network policy definition requires the one or more software versions to be consistent with the network policy configuration that associates the plurality of different vendors with the one or more software program versions, and wherein the second network policy definition is also stored in the globally accessible server, wherein the second network policy definition is associated with a configuration associated with a second set of one or more network devices and at least a second subscriber that is different from the first subscriber.

13. The apparatus of claim 12 , wherein a security function is associated with at least one of the first, the second, and the third policy network parameter according to a rule of the one or more rules identifies that a message be provided for display at a computer associated with a first user group.

14. The apparatus of claim 13 , wherein a first access request is received from the computer associated with the first user group before the message is provided to the computer associated with the first user group, and the message displayed at the computer associated with the first user group identifies that a software configuration at the computer associated with the first user group must be updated before the access request will be allowed.

15. The apparatus of claim 14 , wherein the software configuration at the computer associated with the first user group is updated after the message is displayed at the computer associated with the first user group, and the first access request is allowed after the software configuration at the computer is updated.

16. The apparatus of claim 12 , wherein a security function associated with a rule of the one or more rules includes denying access to an access request from a computer associated with a first user group after the access request is received from the computer associated with the first user group.

17. The apparatus of claim 12 , wherein the execution of the instructions by the computer processor identifies that a software configuration at a computer associated with a first user group should be updated according to the network policy definition, the network policy definition identifying that access requests from the computer associated with the first user group can be allowed for a first period of time after a first access request is received from the computer associated with the user group, and the first access request is allowed for the first period of time according to the network policy definition.

18. The apparatus of claim 12 , wherein the network policy definition is stored at a computing device implementing the function of a choke point that controls the allowance of access requests associated from computers attempting to access resources in a computer network, and the choke point enforces the network policy definition according to at least one rule of the one or more rules.

19. The apparatus of claim 18 , wherein the computing device implementing the function of the choke point is a host computer at the computer network.

20. The apparatus of claim 12 , wherein the network policy definition and a second network policy definition are stored at a server globally accessible to a first user group and to a second user group.

Assignments (12)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
CHANGE OF NAME Recorded Apr 30, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046040/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 046040/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 045788/0664 →
CHANGE OF NAME Recorded Mar 29, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045788/0027 →
CONVERSION AND NAME CHANGE Recorded Aug 5, 2016
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 039590/0654 →
MERGER Recorded Aug 5, 2016
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 039353/0978 →
CHANGE OF NAME Recorded Aug 5, 2016
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 039353/0795 →
MERGER Recorded Aug 5, 2016
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 039353/0608 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2016
From: YANOVSKY, BORIS; YANOVSKY, ROMAN
To: SONICWALL, INC.
Reel/Frame 039320/0216 →
Continuity (2)
Continuation 10105575 · Mar 25, 2002
Related Publication 20160323323A1 · Nov 3, 2016