IP Library › Granted Patent US 8,230,480
Granted Patent B2
US 8,230,480 · App. 10/832,107 · Granted Jul 24, 2012

Method and apparatus for network security based on device security status

Assignee: Avaya Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,230,480
App. No.
10/832,107
Granted
Jul 24, 2012
Kind
B2
Abstract

A method and apparatus are provided for network security based on a security status of a device. A security update status of a device is evaluated; and one or more of a plurality of security policies are selected to apply to the device based on the security update status. The available security philosophies may include, for example, a “protect the good” philosophy, an “encourage the busy” philosophy and a “shut off the non-compliant” philosophy. The security update status can evaluate, for example, a version level of one or more security features installed on the device or can be based on a flag indicating whether the device satisfies predefined criteria for maintaining one or more computer security protection features up-to-date.

Claims (68)

1. A method comprising:

discovering, by a first server, that a telecommunications terminal is attempting to connect to a network, wherein the telecommunications terminal is discovered based on a signal received from a network device that provides network connectivity to the telecommunications terminal;

receiving, by the first server, from the telecommunications terminal:

(i) a request to access the network, and

(ii) an identifier of the telecommunications terminal;

identifying, by the first server, an indication of a security measure that is implemented by the telecommunications terminal, wherein:

(i) the indication of the security measure is stored at the first server, and

(ii) the indication of the security measure is identified based on the identifier of the telecommunications terminal;

granting the telecommunications terminal access to the network when the first server determines that the indication of the security measure satisfies the security policy; and

restricting the telecommunications terminal from accessing the network when the first server determines that the indication of the security measure fails to satisfy the security policy;

wherein the network device restricts the telecommunications terminal from accessing the network in response to the determination that the indication of the security measure fails to satisfy the security policy.

2. The method of claim 1 wherein the first server enables the telecommunications terminal to communicate with, and only with, the first server and a second server when the indication of the security measure fails to satisfy the security policy.

3. The method of claim 2 wherein the second server pushes updates to the telecommunications terminal when the indication of the security measure fails to satisfy the security policy, and wherein the updates automatically update the security measure implemented by the telecommunications terminal.

4. The method of claim 2 wherein the telecommunications terminal pulls updates from the second server when the indication of the security measure fails to satisfy the security policy, and wherein the updates automatically update the security measure implemented by the telecommunications terminal.

5. The method of claim 1 further comprising:

restricting, by the first server, the telecommunications terminal's access to a Virtual Private Network (VPN) when the indication of the security measure fails to satisfy the security policy.

6. The method of claim 1 wherein the network device is different from:

(i) the first server, and

(ii) a second server that provides updates to the telecommunications terminal.

7. The method of claim 1 wherein, when the telecommunications terminal is powered-on, a client-side firewall only enables the telecommunications terminal to communicate with, and only with, the first server.

8. The method of claim 1 further comprising:

pushing, by the first server, a message to the telecommunications terminal when the indication of the security measure fails to satisfy the security policy, wherein the message provides information on how to satisfy the security policy.

9. The method of claim 1 wherein a client-side application monitors a network interface of the telecommunications terminal, and wherein the client-side application automatically transmits the request to the first server when the telecommunications terminal connects to the network.

10. The method of claim 1 wherein the telecommunications terminal identifies the first server, among a plurality of servers, to request access to the network based on a Dynamic Host Configuration Protocol (DHCP).

11. The method of claim 1 wherein granting or restricting the telecommunications terminal's access to the network is also based on a specific port of the network device that provides network connectivity to the telecommunications terminal, and wherein the network device is different from:

(i) the first server, and

(ii) a second server that provides updates to the telecommunications terminal.

12. The method of claim 1 further comprising:

receiving, by the first server, another request to access the network from the telecommunications terminal, wherein the telecommunications terminal is granted access to the network based on the fact that the security measure has been updated by the telecommunications terminal after being restricted from the network.

13. The method of claim 1 wherein the identifier is at least one of an Internet Protocol (IP) address and a Media Access Control (MAC) address of the telecommunications terminal.

14. The method of claim 1 wherein the indication of the security measure is an operating system that is implemented by the telecommunications terminal, and wherein:

(i) the indication of the security measure satisfies the security policy when a version of the operating system is up-to-date according to the security policy, and

(ii) the indication of the security measure fails to satisfy the security policy when the version of the operating system is not up-to-date according to the security policy.

15. The method of claim 1 wherein the indication of the security measure is virus scanner that is implemented by the telecommunications terminal, and wherein:

(i) the indication of the security measure satisfies the security policy when a version of the virus scanner is up-to-date according to the security policy, and

(ii) the indication of the security measure fails to satisfy the security policy when the version of the virus scanner is not up-to-date according to the security policy.

16. The method of claim 1 further comprising:

broadcasting, by the network device, a message to other network devices in the network when the telecommunications terminal is restricted from accessing the network, wherein the broadcasted message notifies the other network devices in the network that the security measure implemented by the telecommunications terminal fails to satisfy the security policy.

17. A method comprising:

discovering, by a first server, that a telecommunications terminal is attempting to connect to a network, wherein the telecommunications terminal is discovered based on a first signal received from a network device that provides network connectivity to the telecommunications terminal;

receiving, by the first server, from the telecommunications terminal:

(i) a request to access the network, and

(ii) an identifier of the telecommunications terminal;

identifying, by the first server, a first security policy of the telecommunications terminal based on the identifier;

transmitting, by the first server, a request for an indication of a security measure implemented by the telecommunications terminal;

receiving, by the first server, a response that includes the indication of the security measure implemented by the telecommunications terminal;

identifying, by the first server, a second security policy based on:

(i) the first security policy, and

(ii) the response that includes the indication of the security measure implemented by the telecommunications terminal; and

transmitting, by the first server, a second signal to the network device based on the second security policy, wherein the second signal instructs the network device to restrict the telecommunications terminal from accessing the network.

18. The method of claim 17 wherein the first server enables the telecommunications terminal to communicate with, and only with, the first server and a second server when the telecommunications terminal is restricted from accessing the network.

19. The method of claim 18 wherein the second server pushes updates to the telecommunications terminal when the telecommunications terminal is restricted from accessing the network, and wherein the updates automatically update the security measure implemented by the telecommunications terminal.

20. The method of claim 18 wherein the telecommunications terminal pulls updates from the second server when the telecommunications terminal is restricted from accessing the network, and wherein the updates automatically update the security measure implemented by the telecommunications terminal.

21. The method of claim 17 wherein the task of restricting the telecommunications terminal's access to the network further comprises restricting the telecommunications terminal's access to a Virtual Private Network (VPN).

22. The method of claim 17 wherein the network device is different from:

(i) the first server, and

(ii) a second server that provides updates to the telecommunications terminal.

23. The method of claim 17 wherein, when the telecommunications terminal is powered-on, a client-side firewall only enables the telecommunications terminal to communicate with, and only with, the first server.

24. The method of claim 17 wherein a client-side application monitors a network interface of the telecommunications terminal, and wherein the client-side application automatically transmits the request to the first server when the telecommunications terminal connects to the network.

25. The method of claim 17 wherein the telecommunications terminal identifies the first server, among a plurality of servers, to request access to the network based on a Dynamic Host Configuration Protocol (DHCP).

26. The method of claim 17 wherein granting or restricting the telecommunications terminal's access to the network is also based on a specific port of the network device that provides network connectivity to the telecommunications terminal, and wherein the network device is different from:

(i) the first server, and

(ii) a second server that provides updates to the telecommunications terminal.

27. The method of claim 17 further comprising:

receiving, by the first server, another request to access the network from the telecommunications terminal, wherein the telecommunications terminal is granted access to the network based on the fact that the security measure has been updated by the telecommunications terminal after being restricted from the network.

28. The method of claim 17 wherein the identifier is at least one of an Internet Protocol (IP) address and a Media Access Control (MAC) address of the telecommunications terminal.

29. The method of claim 17 further comprising:

broadcasting, by the network device, a message to other network devices in the network when the telecommunications terminal is restricted from accessing the network, wherein the broadcasted message notifies the other network devices in the network that the telecommunications terminal is restricted from accessing the network.

Assignments (24)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
BANKRUPTCY COURT ORDER RELEASING THE SECURITY INTEREST RECORDED AT REEL/FRAME 020156/0149 Recorded Jul 25, 2022
From: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
To: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES
Reel/Frame 060953/0412 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.; AVAYA TECHNOLOGY, LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
Reel/Frame 045032/0213 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
CONVERSION FROM CORP TO LLC Recorded May 12, 2009
From: AVAYA TECHNOLOGY CORP.
To: AVAYA TECHNOLOGY LLC
Reel/Frame 022677/0550 →
REASSIGNMENT Recorded Jun 26, 2008
From: AVAYA TECHNOLOGY LLC; AVAYA LICENSING LLC
To: AVAYA INC
Reel/Frame 021156/0082 →
SECURITY AGREEMENT Recorded Nov 28, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 020166/0705 →
SECURITY AGREEMENT Recorded Nov 27, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 020156/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2004
From: FAZAL, LOOKMAN Y.; KAPPES, MARTIN; KRISHNAKUMAR, ANJUR S.; KRISHNAN, P.
To: AVAYA TECHNOLOGY CORP.
Reel/Frame 015757/0477 →
Continuity (1)
Related Publication 20050246767A1 · Nov 3, 2005