IP Library Granted Patent US 11,805,418
Granted Patent B2
US 11,805,418 · App. 16/569,606 · Granted Oct 31, 2023

System and method for location-based endpoint security

Inventors: Anil Kaushik (Karnataka, IN); Sathwikh Gopady Narasimha (Karnataka, IN)
Assignee: Sophos Limited
H04W12/37H04W12/122H04W12/63H04W12/79
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,418
App. No.
16/569,606
Granted
Oct 31, 2023
Kind
B2
Abstract

Methods, systems and computer readable media for location-based endpoint security are described.

Claims (35)

1. A computer-implemented method, comprising:

receiving, at an endpoint device, access point location information for one or more access points;

determining, at the endpoint device, an endpoint location of the endpoint device based on the access point location information and signal characteristics of wireless signals received by the endpoint device from at least one of the one or more access points, wherein determining the endpoint location includes determining a radio frequency fingerprint for the wireless signals received by the endpoint device;

receiving, at the endpoint device, a request for data communication from an application that executes on the endpoint device;

applying, at the endpoint device, one or more data communication policies for the data communication with the at least one of the one or more access points based on the endpoint location; and

selectively permitting the data communication from the application that executes on the endpoint device, based on the endpoint location and the one or more data communication policies, wherein the data communication by the application is permitted when the endpoint location is a first location and is not permitted when the endpoint location is a second location different from the first location.

2. The computer-implemented method of claim 1 , further comprising providing, by the endpoint device, the endpoint location to the one or more access points.

3. The computer-implemented method of claim 1 , wherein the access point location information includes a latitude and longitude for respective ones of the one or more access points.

4. The computer-implemented method of claim 1 , wherein determining the endpoint location includes performing a triangulation operation using the signal characteristics of the wireless signals.

5. A threat management system, comprising:

one or more processors; and

a nontransitory computer readable medium coupled to the one or more processors, wherein the nontransitory computer readable medium has stored thereon software instructions that, when executed by the one or more processors, causes the one or more processors to perform operations including:

receiving, at an endpoint device, access point location information for one or more access points;

determining, at the endpoint device, an endpoint location of the endpoint device based on the access point location information and signal characteristics of wireless signals received by the endpoint device from at least one of the one or more access points, wherein determining the endpoint location includes determining a radio frequency fingerprint for the wireless signals received by the endpoint device;

receiving, at the endpoint device, a request for data communication from an application that executes on the endpoint device;

applying, at the endpoint device, one or more data communication policies for the data communication with the at least one of the one or more access points based on the endpoint location; and

selectively permitting the data communication from the application that executes on the endpoint device, based on the endpoint location and the one or more data communication policies, wherein the data communication by the application is permitted when the endpoint location is a first location and is not permitted when the endpoint location is a second location different from the first location.

6. The system of claim 5 , wherein the operations further comprise providing, by the endpoint device, the endpoint location to the one or more access points.

7. The system of claim 5 , wherein the access point location information includes a latitude and longitude for respective ones of the one or more access points.

8. The system of claim 5 , wherein determining the endpoint location includes performing a triangulation operation using the signal characteristics of the wireless signals.

9. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, causes the one or more processors to perform operations including:

receiving, at an endpoint device, access point location information for one or more access points;

determining, at the endpoint device, an endpoint location of the endpoint device based on the access point location information and signal characteristics of wireless signals received by the endpoint device from at least one of the one or more access points, wherein determining the endpoint location includes determining a radio frequency fingerprint for the wireless signals received by the endpoint device;

receiving, at the endpoint device, a request for data communication from an application that executes on the endpoint device;

applying, at the endpoint device, one or more data communication policies for the data communication with the at least one of the one or more access points based on the endpoint location; and

selectively permitting the data communication from the application that executes on the endpoint device, based on the endpoint location and the one or more data communication policies, wherein the data communication by the application is permitted when the endpoint location is a first location and is not permitted when the endpoint location is a second location different from the first location.

10. The nontransitory computer readable medium of claim 9 , wherein the operations further comprise providing, by the endpoint device, the endpoint location to the one or more access points.

11. The computer-implemented method of claim 1 , wherein selectively permitting data communication from the application further comprises selectively permitting the data communication from the application based on a time of the data communication.

12. The computer-implemented method of claim 11 , wherein the endpoint location is in an office, the time of data communication is during working hours, and selectively permitting the data communication comprises allowing only corporate applications to perform the data communication.

13. The computer-implemented method of claim 11 , wherein the endpoint location is near a meeting room, the time of data communication is during a meeting time, and selectively permitting the data communication comprises blocking social network applications from performing the data communication.

14. The system of claim 5 , wherein selectively permitting data communication from the application further comprises selectively permitting the data communication from the application based on a time of the data communication.

15. The system of claim 14 , wherein the endpoint location is in an office, the time of data communication is during working hours, and selectively permitting the data communication comprises allowing only corporate applications to perform the data communication.

16. The system of claim 14 , wherein the endpoint location is near a meeting room, the time of data communication is during a meeting time, and selectively permitting the data communication comprises blocking social network applications from performing the data communication.

17. The nontransitory computer readable medium of claim 9 , wherein selectively permitting data communication from the application further comprises selectively permitting the data communication from the application based on a time of the data communication.

18. The nontransitory computer readable medium of claim 17 , wherein the endpoint location is in an office, the time of data communication is during working hours, and selectively permitting data communication comprises allowing only corporate applications to perform the data communication.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2020
From: KAUSHIK, ANIL; NARASIMHA, SATHWIKH GOPADY
To: SOPHOS LIMITED
Reel/Frame 051714/0917 →