IP Library › Granted Patent US 7,739,724
Granted Patent B2
US 7,739,724 · App. 11/174,205 · Granted Jun 15, 2010

Techniques for authenticated posture reporting and associated enforcement of network access

Assignee: Intel Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,739,724
App. No.
11/174,205
Granted
Jun 15, 2010
Kind
B2
Abstract

Architectures and techniques that allow a firmware agent to operate as a tamper-resistant agent on a host platform that may be used as a trusted policy enforcement point (PEP) on the host platform to enforce policies even when the host operating system is compromised. The PEP may be used to open access control and/or remediation channels on the host platform. The firmware agent may also act as a local policy decision point (PDP) on the host platform in accordance with an authorized enterprise PDP entity by providing policies if a host trust agent is non-responsive and may function as a passive agent when the host trust agent is functional.

Claims (15)

1. An apparatus comprising:

a network interface;

a processor coupled with the network interface to support one or more software agents; and

a firmware agent coupled with the processor and the network interface to gather security information from the one or more security agents and to transmit a report including a security profile corresponding to the security information to a remote device via the network interface and to configure the network interface according to access control information received from the remote device via the network interface wherein network access limitations are determined from one or more access control lists (ACLs) received from a network access policy decision point (PDP) that include usage constraints related to one or more of: location of the host electronic device, type of connection, time of day, firmware agent mode, host electronic device mode, and is cryptographically bound to a pre-selected configuration of the firmware agent.

2. The apparatus of claim 1 wherein at least one of the security agents comprises a software agent to be executed by the processor.

3. The apparatus of claim 1 wherein at least one of the security agents comprises a hardware agent coupled with the processor.

4. The apparatus of claim 1 wherein the remote device comprises a network access policy decision point (PDP).

5. A system comprising:

a network interface;

a cable connected to the network interface;

a processor coupled with the network interface to support one or more software agents; and

a firmware agent coupled with the processor and the network interface to gather security information from the one or more security agents and to transmit a report including a security profile corresponding to the security information to a remote device via the network interface and to configure the network interface according to access control information received from the remote device via the network interface wherein network access limitations are determined from one or more access control lists (ACLs) received from a network access policy decision point (PDP) that include usage constraints related to one or more of: location of the host electronic device, type of connection, time of day, firmware agent mode, host electronic device mode, and is cryptographically bound to a pre-selected configuration of the firmware agent.

6. The system of claim 5 wherein at least one of the security agents comprises a software agent to be executed by the processor.

7. The system of claim 5 wherein at least one of the security agents comprises a hardware agent coupled with the processor.

8. The system of claim 5 wherein the remote device comprises a network access policy decision point (PDP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2005
From: DURHAM, DAVID; SAHITA, RAVI; GREWAL, KARANVIR; SMITH, NED; SOOD, KAPIL
To: INTEL CORPORATION
Reel/Frame 016773/0624 →
Continuity (1)
Related Publication 20070006282A1 · Jan 4, 2007