IP Library Granted Patent US 10,171,648
Granted Patent B2
US 10,171,648 · App. 14/484,159 · Granted Jan 1, 2019

Mobile posture-based policy, remediation and access control for enterprise resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,171,648
App. No.
14/484,159
Granted
Jan 1, 2019
Kind
B2
Abstract

A mobile device management system that monitors the security state of one or more mobile devices and sets indicators related to such security state. Enterprise network applications, such as an email application, can access the security state information when making access control decisions with respect to a given mobile device.

Claims (43)

1. A computer-implemented method, comprising:

receiving at a remote management device, from a control agent installed on a mobile device, information indicating that a new application has been installed on the mobile device;

determining at the remote management device, at least in part by applying one or more policies, that the new application is not a recognized application; and

responsive to the determination that the new application is not a recognized application, setting a security state of the mobile device in a table, wherein the table is stored at the remote management device,

consulting, by an intermediate node, the table to determine the security state of the mobile device;

denying, by the intermediate node, access of the mobile device to a network application service based on the security state of the mobile device in the table; and

permitting mobile device traffic that identifies a port that corresponds to an authorized application;

accepting or rejecting, by an enterprise application of the mobile device, requests of the mobile device based on the security state of the mobile device in the table, in response to the enterprise application of the mobile device accessing the security state of the mobile device in the table;

causing, by the intermediate node, the new application to be blocked from launching on the mobile device; and

updating a security state information of the mobile device in the table based on the determination that the new application is not a recognized application when access is denied.

2. The method of claim 1 , further comprising transmitting a command to the control agent installed on the mobile device, the command operative to cause the control agent to delete one or more files on the mobile device.

3. The method of claim 1 , further comprising transmitting one or more notifications if the new application is not recognized.

4. The method of claim 1 , further comprising updating a security state table based at least in part on the determination that the new application is not a recognized application.

5. The method of claim 1 , wherein the intermediate node is configured to block traffic from the mobile device to the network application service based on the updated security state information.

6. The method of claim 1 , wherein the intermediate node is configured to consult the security state information of the mobile device to determine a current security state of the mobile device, and to filter traffic associated with the mobile device based at least in part on the current security state of the mobile device.

7. The method of claim 6 , wherein the network application service to which access is blocked comprises a first network application service, and the intermediate node is configured to allow access by the mobile device to a second network application service.

8. A mobile device management system, comprising: a communication interface; and

a hardware processor coupled to the communication interface and configured to:

receive via the communication interface, from a control agent installed on a mobile device, information indicating that a new application has been installed on the mobile device;

determine, at least in part by applying one or more policies, that the new application is not a recognized application; and

responsive to the determination that the new application is not a recognized application, setting a security state of the mobile device in a table, wherein the table is stored at a remote management device,

consult, by an intermediate node, the table to determine the security state of the mobile device;

deny, by the intermediate node, access of the mobile device to a network application service based on the security state of the mobile device in the table; and

permit mobile device traffic that identifies a port that corresponds to an authorized application;

cause, by the intermediate node, the new application to be blocked from launching on the mobile device: and

update a security state information of the mobile device in the table based on the determination that the new application is not a recognized application when access is denied

wherein in response to an enterprise application of the mobile device accessing the security state of the mobile device in the table, the enterprise application of the mobile device is configured to accept or reject requests of the mobile device based on the security state of the mobile device in the table.

9. The system of claim 8 , wherein the hardware processor is further configured to transmit a command to the control agent installed on the mobile device, the command operative to cause the control agent to delete one or more files on the mobile device.

10. The system of claim 8 , wherein the hardware processor is further configured to transmit one or more notifications if the new application is not recognized.

11. The system of claim 8 , wherein the hardware processor is further configured to update the security state in the table based at least in part on the determination that the new application is not a recognized application.

12. The system of claim 8 , wherein the intermediate node is configured to block traffic from the mobile device to the network application service based on the updated security state information.

13. The system of claim 8 , wherein the intermediate node is configured to consult the security state information of the mobile device to determine a current security state of the mobile device, and to filter traffic associated with the mobile device based at least in part on the current security state of the mobile device.

14. A computer program product to manage mobile devices,

the computer program product being embodied in a tangible, non-transitory computer readable storage medium, and comprising computer instructions for:

receiving, from a control agent installed on a mobile device, information indicating that a new application has been installed on the mobile device;

determining, at least in part by applying one or more policies, that the new application is not a recognized application; and

responsive to the determination that the new application is not a recognized application, setting a security state of the mobile device in a table, wherein the table is stored at a remote management device,

consulting, by an intermediate node, the table to determine the security state of the mobile device;

denying, by the intermediate node, access of the mobile device to a network application service based on the security state of the mobile device in the table; and

permitting mobile device traffic that identifies a port that corresponds to an authorized application;

accepting or rejecting, by an enterprise application of the mobile device, requests of the mobile device based on the security state of the mobile device in the table, in response to the enterprise application of the mobile device accessing the security state of the mobile device in the table;

causing, by the intermediate node, the new application to be blocked from launching on the mobile device; and

updating a security state information of the mobile device in the table based on the determination that the new application is not a recognized application when access is denied.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →