IP Library Granted Patent US 11,855,996
Granted Patent B1
US 11,855,996 · App. 18/069,349 · Granted Dec 26, 2023

Systems and methods for controlling access

Inventors: Juta Gurinavi{hacek over (c)}iūtė (Vilnius, LT); Carlos Eliseo Salas Lumbreras (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/102G06F8/61H04L63/107H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,855,996
App. No.
18/069,349
Granted
Dec 26, 2023
Kind
B1
Abstract

An administrator creates an access policy for a network resource using an access server. The access policy may specify device characteristics that are needed to access the network resource. These characteristics may relate to the type of user device, the computing environment of the user device, installed applications and versions, installed certificates, and physical characteristics. The access policy for the network resource may be assigned to a user or to groups of users. Later, when the user attempts to access the network resource, an application installed on the user device provides a file containing the characteristics of the user device to the access server. The access server determines whether the characteristics of the file satisfies the access policy associated with the user and network resource, and if so permits access to the network resource. Else, access to the network resource is denied.

Claims (61)

1. A method for controlling access to network resources:

installing a device information application on a user device associated with a user;

requesting access to a network resource associated with a server from the user device through a network;

collecting characteristics of the user device by the device information application;

generating a device information file by the device information application using the characteristics of the user device by the device information application;

providing the device information file to the server by the device information application;

receiving access to the network resource by the user device, wherein the access is based on a comparison of the device information file to an access policy associated with the user and/or the network resource;

receiving a request for a new device information file by the device information application after an amount of time has elapsed since the user device received access to the network resource;

in response to the request, generating the new device information file by the device information application using the characteristics of the user device by the device information application; and

providing the device information file to the server by the device information application.

2. The method of claim 1 , further comprising receiving a request for the device information file from the server device by the device information application through the network.

3. The method of claim 1 , wherein the characteristics of the user device comprises one or more of characteristics of an operating system installed on the user device, characteristics of one or more applications installed on the user device, characteristics of one or more certificates installed on the user device, a time, and a location of the user device.

4. The method of claim 3 , wherein the characteristics of the operating system include a type and a version number of the operating system.

5. The method of claim 3 , wherein the characteristics of the one or more applications include information about an antivirus application installed on the user device.

6. The method of claim 1 , wherein the device information file includes a current location of the user device.

7. The method of claim 1 , further comprising:

receiving a denial of access to the network resource, wherein the denial identifies at least one application not installed on the user device;

installing the at least one application; and

receiving access to the network resource.

8. The method of claim 1 , further comprising:

receiving a denial of access to the network resource, wherein the denial identifies a version number of at least one application installed on the user device;

upgrading the at least one application to the identified version number; and

receiving access to the network resource.

9. A system for controlling access to users and user devices comprising:

at least one processor; and

a non-transitory computer-readable medium with computer-executable instructions stored thereon that when executed by the at least one processor cause the system to:

install a device information application on a user device associated with a user;

receive a request for access to a network resource associated with the system from the user device through a network;

collect characteristics of the user device using the device information application;

generate a device information file using the device information application from the characteristics of the user device;

receive the device information file from the device information application;

provide the user device access to the network resource, wherein the access is based on a comparison of the device information file to an access policy associated with the user and/or the network resources;

receive a request for a new device information file after an amount of time has elapsed since the user device received access to the network resource;

in response to the request, generate the new device information file using the characteristics of the user device; and

provide the device information file.

10. The system of claim 9 , further comprising computer-executable instructions that when executed by the at least one processor cause the system to request the device information file from the device information application.

11. The system of claim 9 , wherein the characteristics of the user device comprises one or more of characteristics of an operating system installed on the user device, characteristics of one or more applications installed on the user device, characteristics of one or more certificates installed on the user device, a time, and a location of the user device.

12. The system of claim 11 , wherein the characteristics of the operating system include a type and a version number of the operating system.

13. The system of claim 11 , wherein the characteristics of the one or more applications include information about an antivirus application installed on the user device.

14. The system of claim 9 , wherein the device information file includes a current location of the user device.

15. The system of claim 9 , further comprising computer-executable instructions that when executed by the at least one processor cause the system to:

provide a denial of access to the network resource to the user device, wherein the denial identifies at least one application not installed on the user device;

determine that the at least one application has been installed on the user device; and

provide access to the network resource to the user device in response to the determination.

16. The system of claim 9 , further comprising computer-executable instructions that when executed by the at least one processor cause the system to:

provide a denial of access to the network resource to the user device, wherein the denial identifies a version number of at least one application installed on the user device;

determine that the at least one application has been upgraded to the identified version number on the user device; and

provide access to the network resource to the user device in response to the determination.

17. A non-transitory computer-readable medium with computer-executable instructions stored thereon that when executed by the at least one processor cause a system to:

install a device information application on a user device associated with a user;

receive a request for access to a network resource associated with the system from the user device through a network;

collect characteristics of the user device using the device information application;

generate a device information file using the device information application from the characteristics of the user device;

receive the device information file from the device information application;

provide the user device access to the network resource, wherein the access is based on a comparison of the device information file to an access policy associated with the user and/or the network resource

receive a request for a new device information file after an amount of time has elapsed since the user device received access to the network resource;

in response to the request, generate the new device information file using the characteristics of the user device; and

provide the new device information file.

18. The computer-readable medium of claim 17 , further comprising computer-executable instructions that when executed by the at least one processor cause the system to request the device information file from the device information application.

19. The computer-readable medium of claim 17 , wherein the characteristics of the user device comprises one or more of characteristics of an operating system installed on the user device, characteristics of one or more applications installed on the user device, characteristics of one or more certificates installed on the user device, a time, and a location of the user device.

20. The computer-readable medium of claim 19 , wherein the characteristics of the operating system include a type and a version number of the operating system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: UAB 360 IT
To: 720 IT, UAB
Reel/Frame 073446/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: GURINAVICIUTE, JUTA; SALAS LUMBRERAS, CARLOS ELISEO
To: UAB 360 IT
Reel/Frame 065567/0047 →
Continuity (1)
Continuation 18083745 · Dec 19, 2022