IP Library Granted Patent US 12,726,488
Granted Patent B2
US 12,726,488 · App. 17/638,835 · Granted Sep 1, 2026

Autonomous policy enforcement point configuration for role based access control

Inventors: Viral Ileshkumar Shah (Bangalore, IN); Ganesh Nakhawa (Westford, MA); Krishna Nadh Manepalli (Bangalore, IN); Michael Riemer (Suamico, WI); Venkata Suresh Reddy Obulareddy (Bangalore, IN)
Assignee: Pulse Secure, LLC
H04L63/1416H04L63/102H04L63/1408H04L63/20H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,488
App. No.
17/638,835
Granted
Sep 1, 2026
Kind
B2
Abstract

An example profiler device includes one or more processors implemented in circuitry and configured to monitor network traffic entering and exiting the protected network zone; identify one or more endpoints that interface with the protected network zone; compare network traffic characteristics of network traffic associated with the endpoints to network traffic characteristics of known device types to determine device types corresponding to the endpoints; assign one or more network policies to the identified endpoints according to the determined device types; and distribute data representing the assigned network policies to a policy enforcement point (PEP) device to cause the PEP device to enforce the network policies on network traffic, associated with the identified endpoints, entering and exiting the protected network zone.

Claims (52)

1 . A method of providing network security, the method comprising:

monitoring network traffic passing through network access controller (NAC) to enter and exit a protected network zone, by a profiler unit that determines policies for protecting the protected network zone and distributes access policy elements to the NAC for enforcement;

generating, by the profiler unit, a database including known network traffic characteristics corresponding to identified endpoint of the protected network zone and known device types of the identified endpoints;

while monitoring the network traffic, detecting an access request to the protected network zone;

determining first endpoint-identifying information from the monitored network traffic including the detected access request, the determined endpoint-identifying information including one or more of a source media access control (MAC) address, a destination MAC, a communication protocol, an authentication protocol, or a Network Basic Input/output System (NetBIOS) address;

in response to the first endpoint-identifying information not being associated with previously determined endpoint-identifying information of the identified endpoint devices, determining that either a source device or a destination device of the monitored network traffic including the detected access request is a previously undetected endpoint;

comparing, by the profiler unit, first network traffic characteristics of the monitored network traffic including the detected access request to the known network traffic characteristics of the database;

responsive to the first network traffic characteristics matching first known network traffic characteristics of the known network traffic characteristics, determining a device type of the previously undetected endpoint device is a first known device type of a first identified device corresponding to the first known network traffic characteristics;

assigning, by the profiler unit, a network policy to the previously undetected endpoint device according to the determined device type; and

distributing, by the profiler unit to the NAC, data representing the assigned network policy to a policy enforcement point (PEP) device to cause the PEP device to enforce the network policy on network traffic flowing to and from the previously undetected endpoint device.

2 . The method of claim 1 , further comprising:

assigning one or more user role policy elements to the previously undetected endpoint device; and

distributing the user role policy elements to the PEP device.

3 . The method of claim 1 , wherein the distributing the data representing the assigned network policy comprises distributing data associating an identifier of the previously undetected endpoint device with the network policy assigned to the previously undetected endpoint device.

4 . A profiler device comprising one or more processors implemented in circuitry and configured to:

monitor network traffic passing through network access controller (NAC) to enter and exit a protected network zone;

generate a database including known network traffic characteristics corresponding to identified endpoint of the protected network zone and known device types of the identified endpoints;

while monitoring the network traffic, detect an access request to the protected network zone;

determine first endpoint-identifying information from the monitored network traffic including the detected access request, the determined endpoint-identifying information including one or more of a source media access control (MAC) address, a destination MAC, a communication protocol, an authentication protocol, or a Network Basic Input/output System (NetBIOS) address;

in response to the first endpoint-identifying information not being associated with previously determined endpoint-identifying information of the identified endpoint devices, determine that either a source device or a destination device of the monitored network traffic including the detected access request is a previously undetected endpoint;

compare first network traffic characteristics of the monitored network traffic including the detected access request to the known network traffic characteristics of the database;

responsive to the first network traffic characteristics matching first known network traffic characteristics of the known network traffic characteristics, determine a device type of the previously undetected endpoint device is a first known device type of a first identified device corresponding to the first known network traffic characteristics;

assign a network policy to the previously undetected endpoint device according to the determined device type; and

distribute to the NAC data representing the assigned network policy to a policy enforcement point (PEP) device to cause the PEP device to enforce the network policy on the network traffic flowing to and from the previously undetected endpoint device.

5 . The profiler device of claim 4 , wherein the one or more processors are further configured to:

assign one or more user role policy elements to the previously undetected endpoint device; and

distribute the user role policy elements to the PEP device.

6 . The profiler device of claim 4 , wherein to distribute the data representing the assigned network policy, the one or more processors are configured to distribute the data representing the assigned network policy comprise instructions that cause the processor to distribute data associating an identifier of the previously undetected endpoint device with the network policy assigned to the previously undetected endpoint device.

7 . A non-transitory computer-readable storage medium comprising instructions that, when executed, cause a processor to:

monitor network traffic passing through network access controller (NAC) to enter and exit a protected network zone;

generate a database including known network traffic characteristics corresponding to identified endpoint of the protected network zone and known device types of the identified endpoints;

while monitoring the network traffic, detect an access request to the protected network zone;

determine first endpoint-identifying information from the monitored network traffic including the detected access request, the determined endpoint-identifying information including one or more of a source media access control (MAC) address, a destination MAC, a communication protocol, an authentication protocol, or a Network Basic Input/output System (NetBIOS) address;

in response to the first endpoint-identifying information not being associated with previously determined endpoint-identifying information of the identified endpoint devices, determine that either a source device or a destination device of the monitored network traffic including the detected access request is a previously undetected endpoint;

compare first network traffic characteristics of the monitored network traffic including the detected access request to the known network traffic characteristics of the database;

responsive to the first network traffic characteristics matching first known network traffic characteristics of the known network traffic characteristics, determine a device type of the previously undetected endpoint device is a first known device type of a first identified device corresponding to the first known network traffic characteristics;

assign a network policy to the previously undetected endpoint device according to the determined device type; and

distribute to the NAC data representing the assigned network policy to a policy enforcement point (PEP) device to cause the PEP device to enforce the network policy on the network traffic flowing to and from the previously undetected endpoint device.

8 . The non-transitory computer-readable storage medium of claim 7 , further comprising instructions that cause the processor to:

assign one or more user role policy elements to the previously undetected endpoint device; and

distribute the user role policy elements to the PEP device.

9 . The non-transitory computer-readable storage medium of claim 7 , wherein the instructions that cause the processor to distribute the data representing the assigned network policy comprise instructions that cause the processor to distribute data associating an identifier of the previously undetected endpoint device with the network policy assigned to the previously undetected endpoint device.

10 . The method of claim 2 , wherein the assigned network policy includes a restriction to access the protected network zone based on a user attribute of user of the previously undetected endpoint device.

11 . The method of claim 10 , wherein the user attribute includes one or more or a combination of a user age, a user security clearance, a user department, and a user role.

12 . The method of claim 1 , further comprising responsive to an incomplete device type determination based on the comparison between the first and the second network traffic characteristics, assigning a default user role to the previously undetected endpoint device.

13 . The profiler device of claim 5 , wherein the assigned network policy includes a restriction to access the protected network zone based on a user attribute of user of the previously undetected endpoint device.

14 . The profiler device of claim 13 , wherein the user attribute includes one or more or a combination of a user age, a user security clearance, a user department, and a user role.

15 . The profiler device of claim 4 , wherein the one or more processors are further configured to assign a default user role to the previously undetected endpoint device responsive to an incomplete device type determination based on the comparison between the first and the second network traffic characteristics.

16 . The non-transitory computer-readable storage medium of claim 8 , wherein:

the assigned network policy includes a restriction to access the protected network zone based on a user attribute of user of the previously undetected endpoint device; and

the user attribute includes one or more or a combination of a user age, a user security clearance, a user department, and a user role.

17 . The non-transitory computer-readable storage medium of claim 7 , wherein the instructions, when executed, cause the processor to assign a default user role to the previously undetected endpoint device responsive to an incomplete device type determination based on the comparison between the first and the second network traffic characteristics.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2025
From: SHAH, VIRAL ILESHKUMAR; NAKHAWA, GANESH; MANEPALLI, KRISHNA NADH; RIEMER, MICHAEL; OBULAREDDY, VENKATA SURESH REDDY
To: PULSE SECURE, LLC
Reel/Frame 071745/0882 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
Continuity (2)
Provisional Application 62893166 · Aug 28, 2019
Related Publication 20220337603A1 · Oct 20, 2022
References Cited (9)
US 7664048B1 · Yung et al. · 2010 [cited by applicant]
US 8893258B2 · Rao · 2014 [cited by examiner]
US 20060026682A1 · Zakas · 2006 [cited by applicant]
US 20160352731A1 · Mentze · 2016 [cited by examiner]
US 20200344203A1 · Mermoud · 2020 [cited by examiner]
US 20200358794A1 · Vasseur · 2020 [cited by examiner]
US 20240154970A1 · Cheethirala · 2024 [cited by examiner]
International Search Report & Written Opinion for Application No. PCT/US2020/048609, dated Oct. 29, 2020, 8 pages. [cited by applicant]
Communication under Rule 71(3) EPC (the Notice of Allowance) for European Application No. 20772148.1, dated Apr. 11, 2024, 7 pages. [cited by applicant]