IP Library Granted Patent US 11,652,823
Granted Patent B1
US 11,652,823 · App. 18/083,745 · Granted May 16, 2023

Systems and methods for controlling access

Inventors: Juta Gurinavi{hacek over (c)}iūtė (Vilnius, LT); Carlos Eliseo Salas Lumbreras (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,823
App. No.
18/083,745
Granted
May 16, 2023
Kind
B1
Abstract

An administrator creates an access policy for a network resource using an access server. The access policy may specify device characteristics that are needed to access the network resource. These characteristics may relate to the type of user device, the computing environment of the user device, installed applications and versions, installed certificates, and physical characteristics. The access policy for the network resource may be assigned to a user or to groups of users. Later, when the user attempts to access the network resource, an application installed on the user device provides a file containing the characteristics of the user device to the access server. The access server determines whether the characteristics of the file satisfies the access policy associated with the user and network resource, and if so permits access to the network resource. Else, access to the network resource is denied.

Claims (56)

1. A method for controlling access to users and user devices comprising:

receiving, by a server through a network, a request to access a network resource from a user device;

in response to the request, determining, by the server, at least one access policy that applies to the network resource;

receiving, by the server through the network, a device information file from the user device, wherein the device information file comprises characteristics of the user device;

based on the device information file, determining, by the server, that the user device complies with the at least one access policy;

in response to the determination that the user device complies with the at least one access policy, allowing, by the server, the user to access the network resource through the network using the user device;

determining, by the server, that an amount of time has elapsed since the determination that the user device complies with the at least one access policy, wherein the amount of time is specified in the at least one access policy and is based on a risk value associated with the network resource; and in response to the determination that the amount of time has elapsed and while allowing the user to access the network resource:

requesting, by the server, a new device information file from the user device through the network; and

based on the new device information file, determining, by the server, whether the user device still complies with the at least one access policy.

2. The method of claim 1 , wherein the user device is associated with the user and further wherein the at least one access policy is determined by the user or the user device.

3. The method of claim 2 , further comprising authenticating the user.

4. The method of claim 1 , further comprising:

providing a device information application to the user device by the server through the network; and

receiving the device information file from the device information application on the user device through the network.

5. The method of claim 1 , wherein the characteristics of the user device one or more of characteristics of an operating system installed on the user device, characteristics of one or more applications installed on the user device, characteristics of one or more certificates installed on the user device, a current time, and a location of the user device.

6. The method of claim 5 , wherein the information about the operating system includes a type and a version number of the operating system.

7. The method of claim 5 , wherein the information about one or more applications includes information about an antivirus application installed on the user device.

8. The method of claim 1 , wherein the device information file comprises a current location of the user device.

9. The method of claim 1 , wherein determining the at least one access policy that applies to the network resource for the user by the server comprises determining a team associated with the user and determining the at least one access policy that applies to the network resource for the team associated with the user, or determining an organization associated with the user and determining the at least one access policy that applies to the network resource for the organization associated with the user.

10. The method of claim 1 , further comprising, based on the device information file, determining that the user device does not comply with the at least one access policy by the server, and in response to the determination:

denying the user device access to the network resource; and

providing information to the user device regarding why the user device does comply with the at least one access policy.

11. The method of claim 1 , further comprising:

if it is determined that the user device still complies with the at least one access policy, continuing to allow the user to access the network resource.

12. The method of claim 1 , further comprising:

if it is determined that the user device no longer complies with the at least one access policy, denying the user access to the network resource.

13. A system for controlling access to users and user devices comprising:

at least one processor; and

a non-transitory computer-readable medium with computer-executable instructions stored thereon that when executed by the at least one processor cause the system to:

receive a request to access a network resource from a user device;

in response to the request, determine at least one access policy that applies to the network resource;

receive a device information file from the user device, wherein the device information file comprises characteristics of the user device;

based on the device information file, determine that the user device complies with the at least one access policy; and

in response to the determination that the user device complies with the at least one access policy, allow the user to access the network resource through the network using the user device;

determine that an amount of time has elapsed since the determination that the user device complies with the at least one access policy, wherein the amount of time is specified in the at least one access policy and is based on a risk value associated with the network resource; and

in response to the determination that the amount of time has elapsed and while allowing the user to access the network resource:

request a new device information file from the user device through the network; and

based on the new device information file, determine whether the user device still complies with the at least one access policy.

14. The system of claim 13 , wherein the user device is associated with the user and further wherein the at least one access policy is determined by the user or the user device.

15. The system of claim 14 , further comprising authenticating the user.

16. The system of claim 13 , further comprising computer-executable instructions that when executed by the at least one processor cause the system to:

provide a device information application to the user device; and

receive the device information file from the device information application on the user device.

17. The system of claim 13 , wherein the characteristics of the user device one or more of characteristics of an operating system installed on the user device, characteristics of one or more applications installed on the user device, characteristics of one or more certificates installed on the user device, a current time, and a location of the user device.

18. The system of claim 17 , wherein the information about the operating system includes a type and a version number of the operating system.

19. The system of claim 17 , wherein the information about one or more applications includes information about an antivirus application installed on the user device.

20. A non-transitory computer-readable medium with computer-executable instructions stored thereon that when executed by at least one processor cause a system to:

receive a request to access a network resource from a user device;

in response to the request, determine at least one access policy that applies to the network resource;

receive a device information file from the user device, wherein the device information file comprises characteristics of the user device;

based on the device information file, determine that the user device complies with the at least one access policy; and

in response to the determination that the user device complies with the at least one access policy, allow the user to access the network resource through the network using the user device;

determine that an amount of time has elapsed since the determination that the user device complies with the at least one access policy, wherein the amount of time is specified in the at least one access policy and is based on a risk value associated with the network resource; and

in response to the determination that the amount of time has elapsed and while allowing the user to access the network resource:

request a new device information file from the user device through the network; and

based on the new device information file, determine whether the user device still complies with the at least one access policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: UAB 360 IT
To: 720 IT, UAB
Reel/Frame 073446/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: GURINAVICIUTE, JUTA; SALAS LUMBRERAS, CARLOS ELISEO
To: UAB 360 IT
Reel/Frame 063232/0610 →
Cited By (3)
US 12,470,924 US 12,676,865 US 12,718,090