IP Library Granted Patent US 12,107,845
Granted Patent B2
US 12,107,845 · App. 16/638,114 · Granted Oct 1, 2024

Remote access computer security

Inventor: Mark Mishaev (Be'er-Sheva, IL)
Assignee: CORONET CYBER SECURITY LTD.
H04L63/0823H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,845
App. No.
16/638,114
Granted
Oct 1, 2024
Kind
B2
Abstract

A computer implemented method of remote access computer security, the method comprising steps a computer processor is programmed to perform, the steps comprising: by a computer, receiving and combing data on a client device, data on a user of the client device, data on a network, and data on an information technology service, determining a policy for controlling remote access to the information technology service based on the combined data, and controlling remote access of the user to the information technology service using the remote client device over the network, based on the determined policy.

Claims (29)

1. A computer implemented method of remote access computer security, the method comprising steps a computer processor is programmed to perform, the steps comprising:

by a computer, receiving and combining data on a client device, data on a user of the client device, data on a network, and data on an information technology service accessible through the network, said receiving of the data on the client device comprising receiving a digital certificate indicating of installation on the client device of a client application extracting data on the client device from configuration data of the client device;

determining a policy for controlling remote access to the information technology service according to the combined data; and

applying the determined policy on the user by restricting activity of the user on the information technology service according to the determined policy.

2. The method of claim 1 , wherein the data on the client device comprises data on configuration of the client device.

3. The method of claim 1 , wherein the data on the client device comprises data listing at least one application installed on the client device.

4. The method of claim 1 , wherein the data on the client device comprises data on a status of at least one application installed on the client device.

5. The method of claim 1 , wherein said receiving of the data on the client device comprises communicating with a client application running on the client device and extracting at least a part of the data on the client device from configuration data of the client device.

6. The method of claim 1 , wherein said receiving of the data on the network comprises communicating with a client application running on the client device and extracting at least a part of the data on the network, on the client device, from communication data pertaining to the network, while the client device is connected to the network.

7. The method of claim 1 , wherein said receiving of the data on the network comprises communicating with a client application running on the client device and extracting at least a part of the data on the network from a scan for access points carried out by the client device.

8. The method of claim 1 , wherein said receiving of the data on the network comprises receiving data on the network from at least one client device other than the client device in use by the user.

9. The method of claim 1 , wherein said receiving of the data on the information technology service comprises receiving data on configuration of the information technology service.

10. The method of claim 1 , wherein said receiving of the data on the information technology service comprises receiving data on user-configuration of the information technology service.

11. The method of claim 1 , further comprising: while the user is communicating with the information technology service using the client device over the network, periodically updating the combined data with new data, re-determining the policy in light of the updated combined data, and restricting the activity according to the re-determined policy.

12. An apparatus for remote access computer security, the apparatus comprising:

a processor of a computer;

a data receiver, implemented on the processor, configured to receive and combine data on a client device, data on a user of the client device, data on a network, and data on an information technology service accessible through the network and to receive at least a part of the data on the client device, by receiving a digital certificate indicating installation on the client device of a client application extracting data on the client device from configuration data of the client device;

a policy determiner, in communication with said data receiver, configured to determine a policy for controlling remote access to the information technology service according to the combined data; and

an access controller, configured to apply the determined policy on the user by restricting activity of the user on the information technology service according to the determined policy.

13. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the client device, by communicating with a client application running on the client device and extracting at least a part of the data on the client device from configuration data of the client device.

14. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the network, by communicating with a client application running on the client device and extracting data on the network, on the client device, from communication data pertaining to the network, while the client device is connected to the network.

15. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the network, by communicating with a client application running on the client device and extracting data on the network from a scan for access points carried out by the client device.

16. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the network, by receiving data on the network from at least one client device other than the client device in use by the user.

17. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the information technology service, by receiving data on configuration of the information technology service.

18. The apparatus of claim 12 , wherein said data receiver is further configured to receive at least a part of the data on the information technology service, by receiving data on user-configuration of the information technology service.

19. A non-transitory computer readable medium storing computer processor executable instructions for performing steps of remote access computer security on a computer, the steps comprising:

by the computer, receiving and combining data on a client device, data on a user of the client device, data on a network, and data on an information technology service accessible through the network, said receiving of the data on the client device comprising receiving a digital certificate indicating installation on the client device of a client application extracting data on the client device from configuration data of the client device;

determining a policy for controlling access to the information technology service according to the combined data; and

applying the determined policy on the user by restricting activity of the user on the information technology service according to the determined policy.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Oct 2, 2024
From: KREOS CAPITAL VII AGGREGATOR SCSP
To: CORONET CYBER SECURITY LTD.
Reel/Frame 068773/0928 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2024
From: BANK LEUMI LE-ISRAEL B.M.
To: CORONET CYBER SECURITY LTD.
Reel/Frame 068733/0209 →
SECURITY INTEREST Recorded Sep 26, 2024
From: CORONET CYBER SECURITY LTD.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 068714/0419 →
SECURITY INTEREST Recorded Oct 30, 2023
From: CORONET CYBER SECURITY LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 065379/0536 →
RELEASE OF SECURITY INTEREST Recorded Nov 6, 2022
From: BANK LEUMI LE-ISRAEL B.M.
To: CORONET CYBER SECURITY LTD.
Reel/Frame 061667/0450 →
SECURITY INTEREST Recorded Nov 2, 2022
From: CORONET CYBER SECURITY LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 061624/0167 →
SECURITY INTEREST Recorded Jun 22, 2021
From: CORONET CYBER SECURITY LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 056610/0652 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2020
From: MISHAEV, MARK
To: CORONET CYBER SECURITY LTD.
Reel/Frame 051873/0595 →
Continuity (1)
Related Publication 20200244646A1 · Jul 30, 2020