IP Library Granted Patent US 10,749,907
Granted Patent B2
US 10,749,907 · App. 16/680,766 · Granted Aug 18, 2020

Mobile device security, device management, and policy enforcement in a cloud based system

Inventors: Amit Sinha (San Jose, CA); Narinder Paul (Sunnyvale, CA); Srikanth Devarajan (San Jose, CA)
Assignee: Zscaler, Inc.
H04L63/20G06F21/51G06F21/56G06F21/567G06F21/572G06F21/606G06F21/6218G06F21/85H04L12/4633H04L12/4641H04L63/029H04L63/0227H04L63/0272H04L63/0281H04L63/102H04L63/1433H04L67/02H04L67/1002H04L67/26H04L67/28H04W4/50H04W76/10G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,749,907
App. No.
16/680,766
Granted
Aug 18, 2020
Kind
B2
Abstract

Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method includes monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network; enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device.

Claims (43)

1. A non-transitory computer-readable medium having computer readable code stored thereon for programming a processor to perform steps of:

monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network;

enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and

inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device.

2. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of:

blocking or allowing the traffic from the mobile device to the external network based on the policy.

3. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of:

blocking or allowing the traffic from the external network to the mobile device based on the inspecting.

4. The non-transitory computer-readable medium of claim 1 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites.

5. The non-transitory computer-readable medium of claim 1 , wherein the inspecting content includes detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets.

6. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of:

causing a notification on the mobile device responsive to the policy or the inspecting.

7. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of:

allowing or disallowing various functions implemented locally on the mobile device.

8. The non-transitory computer-readable medium of claim 7 , wherein the various functions include any of

installation of specified applications, use of specified applications, use of screen capture, use of voice dialing, use of games, use of social media, use of streaming media, web browser usage, and use of Wi-Fi and/or Bluetooth.

9. A server comprising:

a network interface communicatively coupled to a mobile device and to an external network;

a processor communicatively coupled to the network interface; and

memory storing instructions that, when executed, cause the processor to

monitor traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network;

enforce policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and

inspect content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device.

10. The server of claim 9 , wherein the instructions that, when executed, cause the processor to

block or allow the traffic from the mobile device to the external network based on the policy.

11. The server of claim 9 , wherein the instructions that, when executed, cause the processor to

block or allow the traffic from the external network to the mobile device based on the inspecting.

12. The server of claim 9 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites.

13. The server of claim 9 , wherein the content is inspected by any of detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets.

14. The server of claim 9 , wherein the instructions that, when executed, cause the processor to

cause a notification on the mobile device responsive to the policy or the inspecting.

15. The server of claim 9 , wherein the instructions that, when executed, cause the processor to

allow or disallow various functions implemented locally on the mobile device.

16. A method comprising:

monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network;

enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and

inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device.

17. The method of claim 16 , further comprising:

blocking or allowing the traffic from the mobile device to the external network based on the policy.

18. The method of claim 16 , further comprising:

blocking or allowing the traffic from the external network to the mobile device based on the inspecting.

19. The method of claim 16 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites.

20. The method of claim 16 , wherein the inspecting content include detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2019
From: SINHA, AMIT; PAUL, NARINDER; DEVARAJAN, SRIKANTH
To: ZSCALER, INC.
Reel/Frame 050980/0246 →
Continuity (6)
Continuation 15154328 · May 13, 2016
Continuation 13315002 · Dec 8, 2011
Continuation In Part 13051519 · Mar 18, 2011
Continuation In Part 13206337 · Aug 9, 2011
Continuation In Part 13243807 · Sep 23, 2011
Related Publication 20200084241A1 · Mar 12, 2020
Cited By (5)
US 12,197,529 US 12,348,378 US 12,593,210 US 12,647,392 US 12,676,795