IP Library Granted Patent US 10,911,415
Granted Patent B1
US 10,911,415 · App. 16/412,395 · Granted Feb 2, 2021

Remote access service inspector

Inventors: Colin Lee Feeser (Atlanta, GA); Anthony W. Ondrus (Kennesaw, GA); Steven J. Sanders (Sugar Hill, GA)
Assignee: OPEN INVENTION NETWORK LLC
H04L63/0428G06F16/137H04L12/4641H04L63/0272H04L63/10H04L63/145H04L63/1441H04L63/20H04L67/04H04L67/08H04L67/34H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,911,415
App. No.
16/412,395
Granted
Feb 2, 2021
Kind
B1
Abstract

A method, system, and computer program product for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections. A remote access configuration file is created for the remote access client. A digital hash of the configuration file is then generated. The digital hash is compared with a configuration file stored at a predefined web location. If the comparison results in a match between the digital hash and the stored configuration file, a digital hash comparison is performed between an encrypted remote access configuration file and an encrypted configuration file stored at the predefined web location. If the plurality of inspections are passed, the remote access client is released from a quarantine state and a virtual private network (VPN) connection to the remote access server is established.

Claims (58)

1. A method, comprising:

comparing, by an executable file, a digital hash of an encrypted remote access configuration file with an encrypted configuration file stored at a predefined web location;

releasing a remote access client from a quarantine state and establishing a connection between the remote access client and a remote access server, when a plurality of inspections are passed;

downloading a new executable configuration file and launching the new executable configuration file, when the comparing does not result in a match;

forcing a failure to prevent access to the remote access server when the plurality of inspections are not passed; and

performing an additional hash comparison of a dynamic linked library and downloading a new dynamic linked library based on establishing the connection and clearing of the quarantine state.

2. The method of claim 1 , further comprising:

updating of virus definitions.

3. The method of claim 2 , further comprising:

validating that the virus definitions exist and are currently in effect.

4. The method of claim 1 , further comprising:

determining if an installed antivirus program is active and running on the remote access client.

5. The method of claim 1 , further comprising:

inspecting at least one operating system patch for a current version and timestamp.

6. The method of claim 1 , further comprising:

generating the digital hash of the encrypted remote access configuration file.

7. The method of claim 1 , further comprising:

downloading and replacing the encrypted remote access configuration file.

8. The method of claim 7 , wherein the downloading and replacing occurs when the comparing a digital hash of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location does not result in a match.

9. A computer program product comprising a non-transitory computer readable storage medium having computer readable code embedded therein, the computer readable medium comprising:

program instructions that compare, by an executable file, a digital hash of an encrypted remote access configuration file with an encrypted configuration file stored at a predefined web location;

program instructions that release a remote access client from a quarantine state and establish a connection between the remote access client and a remote access server, when a plurality of inspections are passed;

program instructions that download a new executable configuration file and launch the new executable configuration file, when the comparison does not result in a match; and

program instructions that force a failure to prevent access to the remote access server when the plurality of inspections are not passed;

program instructions that perform an additional hash comparison of a dynamic linked library and download a new dynamic linked library based on the establishment of the connection and the quarantine state being cleared.

10. The non-transitory computer readable storage medium of claim 9 , further comprising:

program instructions that update a plurality of virus definitions.

11. The non-transitory computer readable storage medium of claim 10 , further comprising:

program instructions that validate that the virus definitions exist and are currently in effect.

12. The non-transitory computer readable storage medium of claim 9 , further comprising:

program instructions that determine if an installed antivirus program is active and run on the remote access client.

13. The non-transitory computer readable storage medium of claim 9 , further comprising:

program instructions that inspect at least one operating system patch for a current version and timestamp.

14. The non-transitory computer readable storage medium of claim 9 , further comprising:

program instructions that generate the digital hash of the encrypted remote access configuration file.

15. The non-transitory computer readable storage medium of claim 9 , further comprising:

program instructions that download and replace the encrypted remote access configuration file when the program instructions that compare an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location do not result in a match.

16. The non-transitory computer readable storage medium of claim 9 , wherein the program instructions that enable forcing of the failure based on the plurality of inspections not passing are associated with settings for at least one check contained in the remote access configuration file.

17. A system, comprising:

a local data store; and

a processor that executes a plurality of components including:

a component that compares a digital hash of an encrypted remote access configuration file with an encrypted configuration file stored at a predefined web location;

a component that releases a remote access client from a quarantine state and establishes a connection between the remote access client and a remote access server, when a plurality of inspections are passed;

a component that downloads a new executable configuration file and launches the new executable configuration file, when the comparison does not result in a match;

a component that forces a failure to prevent access to the remote access server when the plurality of inspections are not passed;

a component that performs an additional hash comparison of a dynamic linked library and downloads a new dynamic linked library based on the establishment of the connection and the quarantine state being cleared.

18. The system of claim 17 , further comprising:

a component that updates virus definitions.

19. The system of claim 18 , further comprising:

a component that validates that the virus definitions exist and are currently in effect.

20. The system of claim 17 , further comprising:

a component that determines if an installed antivirus program is active and runs on the remote access client.

21. The system of claim 17 , further comprising:

a component that inspects at least one operating system patch for a current version and timestamp.

22. The system of claim 17 , further comprising:

a component that generates the digital hash of the remote access configuration file.

23. The system for providing protected remote access of claim 17 further comprising a component that downloads and replaces the encrypted remote access configuration file, if the digital hash comparison of an encrypted remote access configuration file with an encrypted configuration file stored at the predefined web location does not result in a match.

24. The system for providing protected remote access of claim 17 , wherein the remote access configuration file contains settings for at least one check that enables the failure to be forced when the plurality of inspections are not passed.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE PATENT ASSIGNMENT AGREEMENT DATED NOVEMBER 30, 2021 PREVIOUSLY RECORDED AT REEL: 058426 FRAME: 0791. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2022
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058736/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058426/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2020
From: FEESER, COLIN LEE; ONDRUS, ANTHONY W.; SANDERS, STEVEN J.
To: SOUTHERN COMPANY SERVICES, INC.
Reel/Frame 054688/0296 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2020
From: SOUTHERN COMPANY SERVICES, INC.
To: OPEN INVENTION NETWORK LLC
Reel/Frame 054688/0311 →
Continuity (4)
Continuation 15621402 · Jun 13, 2017
Continuation 15175935 · Jun 7, 2016
Continuation 14501403 · Sep 30, 2014
Continuation 11686113 · Mar 14, 2007