IP Library Granted Patent US 8,434,128
Granted Patent B2
US 8,434,128 · App. 13/030,593 · Granted Apr 30, 2013

Flexible security requirements in an enterprise network

Inventor: Kevin J. Kennedy (Spring Lake, NJ)
Assignee: Avaya Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,434,128
App. No.
13/030,593
Filed
Feb 18, 2011
Granted
Apr 30, 2013
Kind
B2
Art Unit
2439
USPC
726/1
Abstract

A system and method are provided to monitor and prevent potential enterprise policy and/or rule violations by subscribers.

Claims (91)

1. A method, comprising:

determining, by at least one of a policy agent and a policy enforcement server in an enterprise network, that a selected stimulus has occurred, the stimulus being one or more of a passage of a selected time interval, an an occurrence of an event relevant to a degree of sensitivity of a selected communication, and/or content, to an enterprise corresponding to the enterprise network;

in response to the determined stimulus, changing, by at least one of the policy agent and the policy enforcement server, a security requirement associated with the selected communication and/or content;

determining, by the policy agent, that a nonsubscriber of the enterprise network is a member of a trusted group, the trusted group comprising, as members, at least one subscriber of the enterprise network and at least one nonsubscriber and each member of the trusted group being trusted by the enterprise; and

in response to the nonsubscriber being a member of the trusted group, the policy agent at least one of (a) sending the selected communication and/or content and (b) providing the nonsubscriber access to the selected communication and/or content, wherein the trusted group is no longer recognized after at least one of (a) occurrence of a predetermined event adversely impacting a degree of trust between the enterprise and nonsub scriber and (b) passage of a determined period of time and wherein a security mechanism is at least one of deleted, disabled, and denied permission to execute in response to the at least one of (a) occurrence of a predetermined event and (b) passage of a determined period of time.

2. The method of claim 1 , wherein the stimulus is the passage of the selected time interval.

3. The method of claim 1 , wherein the stimulus is the occurrence of the event relevant to the degree of sensitivity of the selected communication and/or content.

4. The method of claim 1 , wherein the security requirement is one or more of an authentication requirement to access the selected communication and/or content, a limitation on potential recipients of the selected communication and/or content, and a cryptography requirement.

5. The method of claim 1 , further comprising:

analyzing, by the policy agent corresponding to a first node of the enterprise network and a subscriber of the enterprise network, the selected communication and/or content to identify a behavioral instance potentially relevant to a policy and/or rule;

notifying, by the policy agent, a policy enforcement server of the identified determined behavioral instance;

receiving, by the policy agent and from the policy enforcement server, a policy measure to be implemented; and

implementing, by the policy agent, the received policy measure.

6. The method of claim 5 , wherein the policy measure to be implemented comprises one or more of the following:

modification of an existing security measure for the one or more of the selected communication and/or content,

implementation of a new and/or additional security measure for the one or more of the selected communication and/or content,

use of a different network path and/or channel than currently chosen to effect transmission or transfer of the one or more of the selected communication and/or content,

implementation of an action to remedy a prior policy or rule violation,

block, delay, and/or buffer the one or more of the selected communication and/or content,

mark or delete a portion of the one or more of the selected communication and/or content prior to access by one or more other parties,

send a notice of policy and/or rule violation to one or more selected destinations,

embed a flag indicating an area of redundant and processor intensive encryption or security transcoding,

prevent access of the one or more of the selected communication and/or content by the one or more selected parties,

prevent the subscriber from selecting, by dragging and dropping, selected content into a communication,

provide read-only access to the one or more of the selected communication and/or content,

set a hop restriction on the one or more of the selected communication and/or content whereby, when the hop restriction is met or exceeded and/or a hop counter is incremented or decremented to a selected value, the one or more of the selected communication and/or content is dropped or otherwise prohibited from delivery to an intended recipient,

tear down a communication channel before transmission of the one or more of the selected communication and/or content,

redirect the one or more of the selected communication and/or content to a different destination, and

display different portions of the one or more of the selected communication and/or content to different ones of the one or more of the selected parties based on a respective degree of trust or privilege of each party.

7. The method of claim 1 , wherein the security requirement is one or more of:

whether authentication is required;

what degree and/or type(s) of authentication is required;

whether a black list is to be used;

what black list is to be used;

whether a white list is to be used;

what white list is to be used;

whether an access control list is to be used;

what access control list is to be used;

whether encryption is to be used;

an encryption level and/or strength to be used;

what encryption algorithm is to be used;

a communication medium to be used;

a communication path to be used; and

a communication modality to be used.

8. A non-transitory computer readable medium comprising processor executable instructions to perform the determining, notifying and applying steps of claim 1 .

9. A system, comprising:

at least one of a policy agent and a policy enforcement server, in an enterprise network, operable to:

determine that a selected stimulus has occurred, the stimulus being one or more of a passage of a selected time interval, and an occurrence of an event relevant to a degree of sensitivity, to an enterprise corresponding to the enterprise networks, of a selected communication, and/or content;

in response to the determined stimulus, change a security requirement associated with the selected communication and/or content;

wherein the policy agent is operable to:

determine that a nonsubscriber of the enterprise network is a member of a trusted group, the trusted group comprising, as members, at least one subscriber of the enterprise network and at least one nonsubscriber and each member of the trusted group being trusted by the enterprise; and

in response to the nonsubscriber being a member of the trusted group, at least one of (a) send the selected communication and/or content and (b) provide the nonsubscriber access to the selected communication and/or content, wherein the trusted group is no longer recognized after at least one of (a) occurrence of a predetermined event adversely impacting a degree of trust between the enterprise and nonsubscriber and (b) passage of a determined period of time and wherein a security mechanism is at least one of deleted, disabled, and denied permission to execute in response to the at least one of (a) occurrence of a predetermined event and (b) passage of a determined period of time.

10. The system of claim 9 , wherein the stimulus is the passage of the selected time interval.

11. The system of claim 9 , wherein the stimulus is the occurrence of the event relevant to the degree of sensitivity of the selected communication and/or content.

12. The system of claim 9 , wherein the security requirement is one or more of an authentication requirement to access the selected communication and/or content, a limitation on potential recipients of the selected communication and/or content, and a cryptography requirement.

13. The system of claim 9 , wherein the policy agent is operable to:

analyze the selected communication and/or content to identify a behavioral instance potentially relevant to a policy and/or rule;

notify a policy enforcement server of the identified determined behavioral instance;

receive, from the policy enforcement server, a policy measure to be implemented; and

implement the received policy measure.

14. The system of claim 13 , wherein the policy measure to be implemented comprises one or more of the following:

modification of an existing security measure for the one or more of the selected communication and/or content,

implementation of a new and/or additional security measure for the one or more of the selected communication and/or content,

use of a different network path and/or channel than currently chosen to effect transmission or transfer of the one or more of the selected communication and/or content,

implementation of an action to remedy a prior policy or rule violation,

block, delay, and/or buffer the one or more of the selected communication and/or content,

mark or delete a portion of the one or more of the selected communication and/or content prior to access by one or more other parties,

send a notice of policy and/or rule violation to one or more selected destinations,

embed a flag indicating an area of redundant and processor intensive encryption or security transcoding,

prevent access of the one or more of the selected communication and/or content by the one or more selected parties,

prevent the subscriber from selecting, by dragging and dropping, selected content into a communication,

provide read-only access to the one or more of the selected communication and/or content,

set a hop restriction on the one or more of the selected communication and/or content whereby, when the hop restriction is met or exceeded and/or a hop counter is incremented or decremented to a selected value, the one or more of the selected communication and/or content is dropped or otherwise prohibited from delivery to an intended recipient,

tear down a communication channel before transmission of the one or more of the selected communication and/or content,

redirect the one or more of the selected communication and/or content to a different destination, and

display different portions of the one or more of the selected communication and/or content to different ones of the one or more of the selected parties based on a respective degree of trust or privilege of each party.

15. The system of claim 9 , wherein the security requirement is at least one of:

whether authentication is required;

what degree and/or type(s) of authentication is required;

whether a black list is to be used;

what black list is to be used;

whether a white list is to be used;

what white list is to be used;

whether an access control list is to be used;

what access control list is to be used;

whether encryption is to be used;

an encryption level and/or strength to be used;

what encryption algorithm is to be used;

a communication medium to be used;

a communication path to be used; and

a communication modality to be used.

Assignments (21)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2026
From: AVAYA LLC
To: PULSELINK SYSTEMS LLC
Reel/Frame 074909/0627 →
INTELLECTUAL PROPERTY PARTIAL RELEASE AND REASSIGNMENT Recorded Feb 4, 2026
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC (F/K/A AVAYA INC.); AVAYA MANAGEMENT L.P.
Reel/Frame 074981/0940 →
INTELLECTUAL PROPERTY PARTIAL RELEASE AND REASSIGNMENT Recorded Feb 4, 2026
From: CITIBANK, N.A.
To: AVAYA LLC (F/K/A AVAYA INC.); AVAYA MANAGEMENT L.P.
Reel/Frame 074944/0573 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2011
From: KENNEDY, KEVIN J.
To: AVAYA INC.
Reel/Frame 025834/0914 →
Continuity (2)
Provisional Application 61306685 · Feb 22, 2010
Related Publication 20110209196A1 · Aug 25, 2011