IP Library Granted Patent US 11,050,794
Granted Patent B2
US 11,050,794 · App. 16/521,083 · Granted Jun 29, 2021

Generating security policies for end-user devices using group rankings and partial policy determinations

Inventors: Shuva Brata Deb (Bengaluru, IN); Edward G. Quackenbush (Oakton, VA); Scott Volk (North Easton, MA); Kurt Severance (Maynard, MA)
Assignee: EMC IP Holding Company LLC
H04L63/205G06Q10/0635H04L63/102H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,050,794
App. No.
16/521,083
Granted
Jun 29, 2021
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for generating security policies for end-user devices using group rankings and partial policy determinations are provided herein. An example computer-implemented method includes ranking end-user device groups within an enterprise, wherein each of the groups is associated with one or more security-related policy settings; assigning a given end-user device to two or more of the groups based on device parameters attributed to the given end-user device; generating a policy for the given end-user device by performing partial policy determinations across the two or more groups to which the given end-user device is assigned, wherein performing the partial policy determinations comprises defining, in an order based at least in part on the ranking of the groups, security-related settings from the two or more groups, until all security-related settings required by the policy are defined; and outputting the policy to the given end-user device.

Claims (44)

1. A computer-implemented method comprising:

ranking a set of multiple end-user device groups within at least one enterprise, wherein each of the multiple end-user device groups is associated with one or more security-related policy settings;

assigning a given end-user device to two or more of the multiple end-user device groups based at least in part on one or more device parameters attributed to the given end-user device;

generating a policy for the given end-user device by performing partial policy determinations across the two or more end-user device groups to which the given end-user device is assigned, wherein performing the partial policy determinations comprises:

performing the partial policy determinations in response to a change to at least one of the one or more device parameters attributed to the given end-user device; and

defining, in an order based at least in part on the ranking of the multiple end-user device groups, security-related settings from the two or more end-user device groups, until all security-related settings required by the policy are defined; and

outputting the policy to at least the given end-user device;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein outputting the policy to at least the given end-user device comprises configuring one or more device parameters of the given end-user device in accordance with the policy.

3. The computer-implemented method of claim 1 , wherein performing the partial policy determinations comprises performing the partial policy determinations in response to a re-assignment of the given end-user device to two or more of the multiple end-user device groups.

4. The computer-implemented method of claim 1 , wherein the multiple end-user device groups are distinguished on at least a geographic basis.

5. The computer-implemented method of claim 1 , wherein the multiple end-user device groups are distinguished on at least an operating system basis.

6. The computer-implemented method of claim 1 , wherein the multiple end-user device groups are distinguished on at least a substantive task-related basis.

7. The computer-implemented method of claim 1 , wherein one of the multiple end-user device groups comprises a default group encompassing all end-user devices within the at least one enterprise.

8. The computer-implemented method of claim 7 , wherein the default group is associated with all of the security-related settings required by the policy.

9. The computer-implemented method of claim 1 , further comprising:

defining the one or more security-related policy settings associated with each of the multiple end-user device groups.

10. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to rank a set of multiple end-user device groups within at least one enterprise, wherein each of the multiple end-user device groups is associated with one or more security-related policy settings;

to assign a given end-user device to two or more of the multiple end-user device groups based at least in part on one or more device parameters attributed to the given end-user device;

to generate a policy for the given end-user device by performing partial policy determinations across the two or more end-user device groups to which the given end-user device is assigned, wherein performing the partial policy determinations comprises:

performing the partial policy determinations in response to a change to at least one of the one or more device parameters attributed to the given end-user device; and

defining, in an order based at least in part on the ranking of the multiple end-user device groups, security-related settings from the two or more end-user device groups, until all security-related settings required by the policy are defined; and

to output the policy to at least the given end-user device.

11. The non-transitory processor-readable storage medium of claim 10 , wherein outputting the policy to at least the given end-user device comprises configuring one or more device parameters of the given end-user device in accordance with the policy.

12. The non-transitory processor-readable storage medium of claim 10 , wherein performing the partial policy determinations comprises performing the partial policy determinations in response to a re-assignment of the given end-user device to two or more of the multiple end-user device groups.

13. The non-transitory processor-readable storage medium of claim 10 , wherein the multiple end-user device groups are distinguished on at least one of a geographic basis, an operating system basis, and a substantive task-related basis.

14. The non-transitory processor-readable storage medium of claim 10 , wherein the program code when executed by the at least one processing device causes the at least one processing device:

to define the one or more security-related policy settings associated with each of the multiple end-user device groups.

15. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to rank a set of multiple end-user device groups within at least one enterprise, wherein each of the multiple end-user device groups is associated with one or more security-related policy settings;

to assign a given end-user device to two or more of the multiple end-user device groups based at least in part on one or more device parameters attributed to the given end-user device;

to generate a policy for the given end-user device by performing partial policy determinations across the two or more end-user device groups to which the given end-user device is assigned, wherein performing the partial policy determinations comprises:

performing the partial policy determinations in response to a change to at least one of the one or more device parameters attributed to the given end-user device; and

defining, in an order based at least in part on the ranking of the multiple end-user device groups, security-related settings from the two or more end-user device groups, until all security-related settings required by the policy are defined; and

to output the policy to at least the given end-user device.

16. The apparatus of claim 15 , wherein outputting the policy to at least the given end-user device comprises configuring one or more device parameters of the given end-user device in accordance with the policy.

17. The apparatus of claim 15 , wherein performing the partial policy determinations comprises performing the partial policy determinations in response to a re-assignment of the given end-user device to two or more of the multiple end-user device groups.

18. The apparatus of claim 15 , wherein the multiple end-user device groups are distinguished on at least one of a geographic basis, an operating system basis, and a substantive task-related basis.

19. The apparatus of claim 15 , wherein one of the multiple end-user device groups comprises a default group encompassing all end-user devices within the at least one enterprise.

20. The apparatus of claim 15 , wherein the at least one processing device is further configured:

to define the one or more security-related policy settings associated with each of the multiple end-user device groups.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2019
From: DEB, SHUVA BRATA; QUACKENBUSH, EDWARD G.; VOLK, SCOTT; SEVERANCE, KURT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049850/0257 →