IP Library Granted Patent US 12,301,610
Granted Patent B2
US 12,301,610 · App. 17/898,287 · Granted May 13, 2025

Security risk evaluation across user devices

Inventors: Rahul Deshpande (Santa Clara, CA); German Lancioni (Santa Clara, CA); Celeste Fralick (Santa Clara, CA)
Assignee: McAfee, LLC
H04L63/1433G06F21/31G06F21/44G06F21/552G06F21/577H04L63/1441G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,610
App. No.
17/898,287
Granted
May 13, 2025
Kind
B2
Abstract

Security risk evaluation across user devices is disclosed herein. An example method includes identifying a user and one or more devices associated with the user, collecting information identifying applications used by the user on the one or more devices, determining respective security sub-scores for each item of the one or more devices, computing an overall security score for the user based, at least in part, on an aggregation of the security sub-scores, and creating a user profile based on the overall security score, the user profile to enable the at least one of the one or more devices to exchange data with an external device when the overall security score meets a security score threshold, the user profile to prevent the at least one of the one or more devices from exchanging data with the external device when the overall security score does not meet the security score threshold.

Claims (51)

1. A computer system to produce security scores, the system comprising:

memory; and

one or more processors, the memory including instructions that, when executed, cause the one or more processors to at least:

determine first respective security sub-scores for respective ones of a plurality of applications used by a user;

determine second respective security sub-scores for respective ones of a plurality of devices used by the user;

compute an overall security score for the user based, at least in part, on an aggregation of the first and second respective security sub-scores;

cause at least one device of the plurality of devices, based on the at least one device requesting a message including the overall security score, to create a user profile based on the overall security score; and

cause the at least one device to prevent the at least one device from exchanging data with an external device when the overall security score does not meet a security score threshold, the prevention of the data from being exchanged enabled by the user profile.

2. The computer system of claim 1 , wherein the one or more processors are to assign unique identifiers to respective ones of the applications used by the user.

3. The computer system of claim 1 , wherein the one or more processors are to assign unique identifiers to respective ones of the plurality of devices associated with the user.

4. The computer system of claim 1 , wherein the one or more processors are to:

authenticate the user and at least one of the plurality of devices; and

report the computed overall security score to the authenticated at least one of the plurality of devices.

5. The computer system of claim 1 , wherein the one or more processors are to compute the overall security score in response to at least one of a regular time interval, an irregular time interval, or in response to one or more trigger events.

6. The computer system of claim 1 , wherein the one or more processors are to apply one or more Statistical Process Control (SPC) rules to one or more overall security scores.

7. The computer system of claim 6 , wherein the one or more processors are to report one or more security alerts to at least one of the plurality of devices, wherein a content of the one or more security alerts is based, at least in part, on the application of the one or more SPC rules.

8. The computer system of claim 1 , wherein the one or more processors are to:

decrease the overall security score responsive to collected information that indicates a lesser level of security for the user; and

increase the overall security score responsive to collected information that indicates a greater level of security for the user.

9. The computer system of claim 8 , wherein a first degree to which the overall security score is to increase or decrease corresponds to a second degree to which the collected information indicates an overall greater level of security or lesser level of security, respectively.

10. The computer system of claim 1 , wherein the plurality of devices includes at least one of an automobile, a home, a home appliance, a smart device, or a wearable device.

11. A computer-implemented method for producing a security score, the method comprising:

determining first respective security sub-scores for respective ones of a plurality of applications used by a user;

determining second respective security sub-scores for respective ones of a plurality of devices used by the user;

computing an overall security score for the user based, at least in part, on an aggregation of the first and second respective security sub-scores;

causing at least one device of the plurality of devices, based on the at least one device requesting a message including the overall security score, to create a user profile based on the overall security score; and

causing the at least one device to prevent the at least one device from exchanging data with an external device when the overall security score does not meet a security score threshold, the prevention of the data from being exchanged enabled by the user profile.

12. The computer-implemented method of claim 11 , further including applying one or more Statistical Process Control (SPC) rules to one or more overall security scores.

13. The computer-implemented method of claim 12 , further including reporting one or more security alerts to at least one of the plurality of devices, wherein a content of the one or more security alerts is based, at least in part, on the application of the one or more SPC rules.

14. The computer-implemented method of claim 11 , further including:

authenticating the user and at least one of the plurality of devices; and

reporting the overall security score to the authenticated at least one of the plurality of devices.

15. The computer-implemented method of claim 11 , wherein the computing of the overall security score for the user is repeated at least one of:

at a regular time interval;

at an irregular time interval; or

in response to one or more trigger events.

16. A non-transitory computer readable medium storing a program for producing security scores, comprising computer executable instructions to cause one or more processing units to, at least:

determine first respective security sub-scores for respective ones of a plurality of applications used by a user;

determine second respective security sub-scores for respective ones of a plurality of devices used by the user;

compute an overall security score for the user based, at least in part, on an aggregation of the first and second respective security sub-scores;

cause at least one device of the plurality of devices, based on the at least one device requesting a message including the overall security score, to create a user profile based on the overall security score; and

cause the at least one device to prevent the at least one device from exchanging data with an external device when the overall security score does not meet a security score threshold, the prevention of the data from being exchanged enabled by the user profile.

17. The non-transitory computer readable medium of claim 16 , wherein the instructions when executed, cause the one or more processing units to apply one or more Statistical Process Control (SPC) rules to one or more overall security scores.

18. The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, cause the one or more processing units to report one or more security alerts to the at least one device, wherein a content of the one or more security alerts is based, at least in part, on the application of the one or more SPC rules.

19. The non-transitory computer readable medium of claim 18 , wherein the instructions, when executed, cause the one or more processing units to:

authenticate the user and at least one of the plurality of devices; and

report the computed overall security score to the authenticated at least one of the plurality of devices.

20. The non-transitory computer readable medium of claim 16 , wherein the instructions to compute the overall security score for the user are executed at least one of:

at a regular time interval;

at an irregular time interval; or

in response to one or more trigger events.

Assignments (3)
CHANGE OF NAME Recorded Nov 15, 2022
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 061938/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2022
From: FRALICK, CELESTE
To: MCAFEE, LLC
Reel/Frame 061938/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2022
From: DESHPANDE, RAHUL; LANCIONI, GERMAN
To: MCAFEE, INC.
Reel/Frame 061885/0303 →
Continuity (4)
Continuation 17025848 · Sep 18, 2020
Continuation 15912440 · Mar 5, 2018
Provisional Application 62470714 · Mar 13, 2017
Related Publication 20220417279A1 · Dec 29, 2022
References Cited (23)
US 10785251B2 · Deshpande et al. · 2020 [cited by applicant]
US 10929923B1 · Nguyen · 2021 [cited by examiner]
US 11438368B2 · Deshpande et al. · 2022 [cited by applicant]
US 20090199264A1 · Lang · 2009 [cited by applicant]
US 20130097709A1 · Basavapatna · 2013 [cited by examiner]
US 20140173738A1 · Condry et al. · 2014 [cited by applicant]
US 20160205127A1 · Roehl et al. · 2016 [cited by applicant]
US 20170345003A1 · Spears et al. · 2017 [cited by applicant]
US 20170346824A1 · Mahabir · 2017 [cited by examiner]
US 20180262524A1 · Deshpande et al. · 2018 [cited by applicant]
US 20210006586A1 · Deshpande et al. · 2021 [cited by applicant]
WO 2018169713 · 2018 [cited by applicant]
International Searching Authority, “Search Report and Written Opinion,” issued in connection with International Patent Application No. PCT/US2018/020976, dated Jun. 15, 2018, 11 pages. [cited by applicant]
Patent Cooperation Treaty, “International Preliminary Report on Patentability,” issued in connection with International Application No. PCT/US2018/020976, dated Sep. 17, 2019, 1 page. [cited by applicant]
Patent Cooperation Treaty, “Written Opinion of the International Searching Authority,” issued in connection with International Application No. PCT/US2018/020976, dated Sep. 17, 2019, 6 pages. [cited by applicant]
European Patent Office, “Communication pursuant to Article 94(3) EPC,” issued in connection with European Patent Application No. 18712368.2, dated Aug. 6, 2020, 7 pages. [cited by applicant]
European Patent Office, “Intention to Grant,” issued in connection with European Patent Application No. 18712368.2, dated Jul. 1, 2021, 7 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 15/912,440, dated Oct. 8, 2019, 20 pages. [cited by applicant]
United States Patent and Trademark Office, “Final Office Action,” issued in connection with U.S. Appl. No. 15/912,440, dated Feb. 20, 2020, 21 pages. [cited by applicant]
United States Patent and Trademark Office, “Advisory Action,” issued in connection with U.S. Appl. No. 15/912,440, dated Apr. 24, 2020, 3 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 15/912,440, dated May 19, 2020, 8 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 17/025,848, dated May 2, 2022, 9 pages. [cited by applicant]
European Patent Office, “Decision to grant a European patent”, issued in connection with European patent Application No. 187123682.2, dated Nov. 25, 2021, 2 pages. [cited by applicant]