IP Library Granted Patent US 12,432,205
Granted Patent B2
US 12,432,205 · App. 18/476,896 · Granted Sep 30, 2025

Systems and methods for endpoint management

Inventors: Jon Oberheide (Ann Arbor, MI); Adam Goodman (Ann Arbor, MI); Michael Hanley (Ann Arbor, MI); Peter Johnson (Ann Arbor, MI); Omar Abduljaber (Ann Arbor, MI); James Barclay (Ann Arbor, MI)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0876H04L63/101H04L63/102H04L63/205H04W12/06G06F21/62H04L63/08H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,205
App. No.
18/476,896
Granted
Sep 30, 2025
Kind
B2
Abstract

A system and method for mitigating security vulnerabilities of a computer network by detecting a management status of an endpoint computing device attempting to authenticate to one or more computing resources accessible via the computer network includes: detecting an authentication attempt by the endpoint computing device to the computer network; during the authentication attempt, collecting management status indicia from the endpoint computing device, wherein the management status indicia comprise data used to determine a management status of the endpoint computing device; using the management status indicia to identify the management status of the endpoint computing device and identifying the management status of the endpoint computing device; and controlling access to the computer network based on (a) whether the authentication attempt by the endpoint computing device is successful and (b) the identified management status of the endpoint computing device.

Claims (47)

1. A method comprising:

detecting an authentication request on behalf of a user from an endpoint computing device associated with the user for accessing a computer resource;

in response to detecting the authentication request, authenticating the user using a first authentication process;

wherein the authenticating the user further comprises accessing a policy defining whether access to the computer resource requires determination of a management status of the endpoint computing device, the management status indicating whether a software management agent of a device management platform is installed on the endpoint computing device that is accessible to the endpoint computing device and that enforces one or more device management policies associated with an enterprise network;

wherein the authenticating the user further comprises collecting management status indicia that comprise data usable to determine the management status of the endpoint computing device, wherein the management status indicia is based on a digital certificate identifying the endpoint computing device, wherein the digital certificate is received from a device management platform corresponding to the enterprise network and installed on the endpoint computing device;

identifying the management status of the endpoint computing device based on the collected management status indicia;

controlling access to the computer resource based on the identified management status of the endpoint computing device, wherein the controlling access to the computer resource comprises determining whether to initiate a secondary authentication of the user in addition to the first authentication process, based on the identified management status of the endpoint computing device;

initiating the secondary authentication if the management status of the endpoint computing device is determined to be unmanaged; and

allowing the endpoint computing device access to the computer resource without initiating secondary authentication, if the management status of the endpoint computing device is determined to be managed.

2. The method of claim 1 wherein the first authentication process comprises receiving login credentials from the user and validating the login credentials.

3. The method of claim 1 wherein the secondary authentication comprises biometric authentication.

4. The method of claim 1 wherein the controlling access to the computer resource comprises initiating a workflow that configures the endpoint computing device as a managed device.

5. The method of claim 1 wherein the collected management status indicia comprise a remote attestation.

6. The method of claim 1 wherein the collected management status indicia comprises cryptographically signed data.

7. The method of claim 6 wherein the cryptographically signed data is generated using a shared secret.

8. One or more non-transitory computer readable storage media encoded with instructions that, when executed by one or more processors of a remote computer security platform, causes the one or more processors to perform operations including:

detecting an authentication request on behalf of a user from an endpoint computing device associated with the user for accessing a computer resource;

in response to detecting the authentication request, authenticating the user using a first authentication process;

wherein the authenticating the user comprises accessing a policy defining whether access to the computer resource requires determination of a management status of the endpoint computing device, the management status indicating whether a software management agent of a device management platform is installed on the endpoint computing device that is accessible to the endpoint computing device and that enforces one or more device management policies associated with an enterprise network;

wherein the authenticating the user further comprises collecting management status indicia that comprise data usable to determine the management status of the endpoint computing device, wherein the management status indicia is based on a digital certificate identifying the endpoint computing device, wherein the digital certificate is received from a device management platform corresponding to the enterprise network and installed on the endpoint computing device;

identifying the management status of the endpoint computing device based on the management status indicia;

controlling access to the computer resource based on the identified management status of the endpoint computing device, wherein the controlling access to the computer resource comprises determining whether to initiate a secondary authentication of the user in addition to the first authentication process, based on the identified management status of the endpoint computing device;

initiating the secondary authentication if the management status of the endpoint computing device is determined to be unmanaged; and

allowing the endpoint computing device access to the computer resource without initiating secondary authentication, if the management status of the endpoint computing device is determined to be managed.

9. The one or more non-transitory computer readable storage media of claim 8 wherein the first authentication process comprises receiving login credentials from the user and validating the login credentials.

10. The one or more non-transitory computer readable storage media of claim 9 wherein the secondary authentication comprises biometric authentication.

11. The one or more non-transitory computer readable storage media of claim 8 wherein the controlling access to the computer resource comprises initiating a workflow that configures the endpoint computing device as a managed device.

12. The one or more non-transitory computer readable storage media of claim 8 wherein the collected management status indicia comprise a remote attestation.

13. The one or more non-transitory computer readable storage media of claim 8 wherein the collected management status indicia comprises cryptographically signed data.

14. The one or more non-transitory computer readable storage media of claim 13 wherein the cryptographically signed data is generated using a shared secret.

15. A system comprising:

an endpoint computing device; and

a remote computer security platform comprising one or more servers, the remote computer security platform configured to perform operations including:

detecting an authentication request on behalf of a user from the endpoint computing device associated with the user for accessing a computer resource;

in response to detecting the authentication request, authenticating the user using a first authentication process;

wherein the authenticating the user comprises accessing a policy defining whether access to the computer resource requires determination of a management status of the endpoint computing device, the management status indicating whether a software management agent of a device management platform is installed on the endpoint computing device that is accessible to the endpoint computing device and that enforces one or more device management policies associated with an enterprise network;

wherein the authenticating the user further comprises collecting management status indicia that comprise data usable to determine the management status of the endpoint computing device, wherein the management status indicia is based on a digital certificate identifying the endpoint computing device, wherein the digital certificate is received from a device management platform corresponding to the enterprise network and installed on the endpoint computing device;

identifying the management status of the endpoint computing device based on the management status indicia;

controlling access to the computer resource based on the identified management status of the endpoint computing device, wherein the controlling access to the computer resource comprises determining whether to initiate a secondary authentication of the user in addition to the first authentication process, based on the identified management status of the endpoint computing device;

initiating the secondary authentication if the management status of the endpoint computing device is determined to be unmanaged; and

allowing the endpoint computing device access to the computer resource without initiating secondary authentication, if the management status of the endpoint computing device is determined to be managed.

16. The system of claim 15 wherein the first authentication process comprises receiving login credentials from the user and validating the login credentials.

17. The system of claim 15 wherein the secondary authentication comprises biometric authentication.

18. The system of claim 15 wherein the controlling access to the computer resource comprises initiating a workflow that configures the endpoint computing device as a managed device.

19. The system of claim 15 wherein the collected management status indicia comprise a remote attestation.

20. The system of claim 15 wherein the collected management status indicia comprises cryptographically signed data.

21. The system of claim 20 wherein the cryptographically signed data is generated using a shared secret.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: DUO SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 071935/0663 →
CHANGE OF NAME Recorded Jul 31, 2025
From: DUO SECURITY, INC.
To: DUO SECURITY LLC
Reel/Frame 072293/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: OBERHEIDE, JON; GOODMAN, ADAM; HANLEY, MICHAEL; JOHNSON, PETER; ABDULJABER, OMAR; BARCLAY, JAMES
To: DUO SECURITY, INC.
Reel/Frame 065070/0563 →
Continuity (6)
Continuation 17235066 · Apr 20, 2021
Continuation 16741858 · Jan 14, 2020
Continuation 15983399 · May 18, 2018
Continuation 15626421 · Jun 19, 2017
Provisional Application 62356075 · Jun 29, 2016
Related Publication 20240048560A1 · Feb 8, 2024
References Cited (83)
US 5754763A · Bereiter · 1998 [cited by applicant]
US 6662205B1 · Bereiter · 2003 [cited by applicant]
US 7213260B2 · Judge · 2007 [cited by applicant]
US 7483384B2 · Bryant et al. · 2009 [cited by applicant]
US 8001610B1 · Chickering et al. · 2011 [cited by applicant]
US 8510820B2 · Oberheide et al. · 2013 [cited by applicant]
US 8588422B2 · Beachem et al. · 2013 [cited by applicant]
US 8707384B2 · Jain et al. · 2014 [cited by applicant]
US 8707385B2 · Jain et al. · 2014 [cited by applicant]
US 8806638B1 · Mani · 2014 [cited by applicant]
US 8838759B1 · Eatough et al. · 2014 [cited by applicant]
US 8850017B2 · Ebrahimi et al. · 2014 [cited by applicant]
US 8850530B2 · Shahbazi · 2014 [cited by applicant]
US 8903365B2 · Stricklen et al. · 2014 [cited by applicant]
US 8935769B2 · Hessler · 2015 [cited by applicant]
US 8938799B2 · Kuo · 2015 [cited by applicant]
US 8955038B2 · Nicodemus et al. · 2015 [cited by applicant]
US 8955075B2 · Von et al. · 2015 [cited by applicant]
US 9043886B2 · Srinivasan et al. · 2015 [cited by applicant]
US 9077758B1 · McGovern et al. · 2015 [cited by applicant]
US 9172545B2 · Edstrom et al. · 2015 [cited by applicant]
US 9270674B2 · Lang et al. · 2016 [cited by applicant]
US 9344275B2 · Bar-El et al. · 2016 [cited by applicant]
US 9397892B2 · Kirner et al. · 2016 [cited by applicant]
US 9443073B2 · Oberheide et al. · 2016 [cited by applicant]
US 9501315B2 · Desai et al. · 2016 [cited by applicant]
US 9544143B2 · Oberheide et al. · 2017 [cited by applicant]
US 9668136B2 · Mistry · 2017 [cited by examiner]
US 9680864B2 · Khesin · 2017 [cited by applicant]
US 9723019B1 · Rathor · 2017 [cited by applicant]
US 9754097B2 · Hessler · 2017 [cited by applicant]
US 9762429B2 · Elmaliah · 2017 [cited by applicant]
US 9769538B2 · Killick · 2017 [cited by applicant]
US 9832221B1 · Newstadt et al. · 2017 [cited by applicant]
US 11019057B2 · Oberheide · 2021 [cited by examiner]
US 11831642B2 · Oberheide · 2023 [cited by examiner]
US 20030172291A1 · Judge et al. · 2003 [cited by applicant]
US 20030172294A1 · Judge · 2003 [cited by applicant]
US 20050063377A1 · Bryant et al. · 2005 [cited by applicant]
US 20070143851A1 · Nicodemus · 2007 [cited by examiner]
US 20070185978A1 · Montulli · 2007 [cited by applicant]
US 20080034413A1 · He et al. · 2008 [cited by applicant]
US 20080040790A1 · Kuo · 2008 [cited by applicant]
US 20080070495A1 · Stricklen et al. · 2008 [cited by applicant]
US 20090205011A1 · Jain et al. · 2009 [cited by applicant]
US 20090205012A1 · Jain et al. · 2009 [cited by applicant]
US 20100303240A1 · Beachem et al. · 2010 [cited by applicant]
US 20110219230A1 · Oberheide et al. · 2011 [cited by applicant]
US 20110231555A1 · Ebrahimi et al. · 2011 [cited by applicant]
US 20120198535A1 · Oberheide et al. · 2012 [cited by applicant]
US 20120317287A1 · Amitai et al. · 2012 [cited by applicant]
US 20130047219A1 · Shahbazi · 2013 [cited by applicant]
US 20130086657A1 · Srinivasan et al. · 2013 [cited by applicant]
US 20130254833A1 · Nicodemus et al. · 2013 [cited by applicant]
US 20130305392A1 · Bar-El et al. · 2013 [cited by applicant]
US 20140096215A1 · Hessler · 2014 [cited by applicant]
US 20140108788A1 · Edstrom et al. · 2014 [cited by applicant]
US 20140173025A1 · Killick · 2014 [cited by applicant]
US 20140181893A1 · Von Bokern et al. · 2014 [cited by applicant]
US 20140297840A1 · Qureshi · 2014 [cited by applicant]
US 20140298420A1 · Barton et al. · 2014 [cited by applicant]
US 20140310415A1 · Kirner et al. · 2014 [cited by applicant]
US 20150046989A1 · Oberheide et al. · 2015 [cited by applicant]
US 20150127832A1 · Kirner et al. · 2015 [cited by applicant]
US 20150146732A1 · Elmaliah · 2015 [cited by applicant]
US 20150199213A1 · Desai et al. · 2015 [cited by applicant]
US 20150213268A1 · Nance et al. · 2015 [cited by applicant]
US 20150244699A1 · Hessler · 2015 [cited by applicant]
US 20150326586A1 · Khesin · 2015 [cited by applicant]
US 20160021117A1 · Harmon et al. · 2016 [cited by applicant]
US 20160050214A1 · Chambers et al. · 2016 [cited by applicant]
US 20160088017A1 · Green et al. · 2016 [cited by applicant]
US 20160088021A1 · Jayanti Venkata et al. · 2016 [cited by applicant]
US 20160180343A1 · Poon et al. · 2016 [cited by applicant]
US 20180014197A1 · Arana · 2018 [cited by examiner]
WO 2007075850A2 · 2007 [cited by applicant]
WO 2014150073A2 · 2014 [cited by applicant]
Trend Micro (Trend Micro Endpoint Sensor 1.6 Installation Guide, 79 pages, Release Date: Aug. 2016) (Year: 2016). [cited by examiner]
Extended European Search Report for European Application No. 17820920.1, mailed Dec. 13, 2019, 8 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2017/038096, mailed Jan. 10, 2019, 14 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2017/038096, mailed Sep. 5, 2017, 15 pages. [cited by applicant]
Trend Micro, “Security Compliance for Unmanaged Endpoints,” retrieved from http://docs.trend micro.com/all/ent/officescan/v10.6/en-us/osce_10.6_olhsrv/ohelp/clients/osmgmt.htm, Jul. 5, 2018, 2 pages. [cited by applicant]
Wiki Archive, “Content Management Integration Points,” https://old.wiki/index.php/Content_Management_Integration_Points, Jan. 31, 2015, 8 pages. [cited by applicant]