IP Library Granted Patent US 9,628,489
Granted Patent B2
US 9,628,489 · App. 15/082,485 · Granted Apr 18, 2017

Remote access to resources over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,628,489
App. No.
15/082,485
Granted
Apr 18, 2017
Kind
B2
Abstract

Systems and techniques are provided for controlling requests for resources from remote computers. A remote computer's ability to access a resource is determined based upon the computer's operating environment. The computer or computers responsible for controlling access to a resource will interrogate the remote computer to ascertain its operating environment. The computer or computers responsible for controlling access to a resource may, for example, download one or more interrogator agents onto the remote computer to determine its operating environment. Based upon the interrogation results, the computer or computers responsible for controlling access to a resource will control the remote computer's access to the requested resource.

Claims (44)

1. A method for controlling access to a set of resource in a network, the method comprising:

assigning one or more zones of trust for each respective remotely hosted resource, wherein each of the assigned one or more zones of trust corresponds to one or more policies that identifies authorized users and authorized client operating environments that may access a particular remotely hosted resource,

executing instructions stored in memory, wherein the instructions are executed by a processor to:

authenticate a user to determine if the user is among the identified authorized users, wherein the user is requesting access to a particular remotely hosted resource via a computing device having a user client operating environment,

characterize the user client operating environment, wherein the characterization is performed using an interrogation agent, and wherein the characterization includes:

identifying provisioning objects currently stored on the user computing device, and

comparing the identified provisioning objects currently on the user computing device with a list of provisioning objects that would be needed before access to the remotely hosted resource is authorized, wherein the comparison is based on the authenticated identity of the user and the characterized user client operating environment, and

installing one or more missing provisioning objects to the user computing device when the comparison indicates that the user computing device lacks the one or more missing provisioning objects, wherein the installation places the user computing device in compliance with the assigned one or more zones of trust for the particular remotely hosted resource; and

providing the requested remotely hosted resource to the user at the user computing device.

2. The method of claim 1 , wherein a user interface is provided to an administrator and the user interface receives input from the administrator.

3. The method of claim 2 , wherein the user interface receives a selection of a rule that corresponds to an authorized user of the authorized users and a zone of trust of the one or more zones of trust.

4. The method of claim 2 , wherein the user interface identifies a destination, and the destination corresponds to a location of a server through which the particular remotely hosted resource that can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

5. The method of claim 2 , wherein the user interface identifies a destination that identifies that the particular remotely hosted resource can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

6. The method of claim 2 , wherein the user interface includes one or more selectable communication controls that identify one or more communication methods for accessing the particular remotely hosted resource.

7. The method of claim 6 , wherein the one or more communication methods include at least one of a hypertext transfer protocol (HTTP), a secure hypertext transfer protocol (HTTPS), a transmission control protocol (TCP), and an internet protocol (IP).

8. A non-transitory computer readable storage medium having embodied thereon a program executable by a processor for performing a method for controlling access to a set of resource in a network, the method comprising:

assigning one or more zones of trust for each respective remotely hosted resource, wherein each of the assigned one or more zones of trust corresponds to one or more policies that identifies authorized users and authorized client operating environments that may access a particular remotely hosted resource,

authenticating a user to determine if the user is among the identified authorized users, wherein the user is requesting access to a particular remotely hosted resource via a computing device having a user client operating environment,

characterizing the user client operating environment, wherein the characterization is performed using an interrogation agent, and the characterization includes:

identifying provisioning objects currently stored on the user computing device, and

comparing the identified provisioning objects currently on the user computing device with a list of provisioning objects that would be needed before access to the remotely hosted resource is authorized, wherein the comparison is based on the authenticated identity of the user and the characterized user client operating environment, and

installing one or more missing provisioning objects to the user computing device when the comparison indicates that the user computing device lacks the one or more missing provisioning objects, wherein the installation places the user computing device in compliance with the assigned one or more zones of trust for the particular remotely hosted resource; and

providing the requested remotely hosted resource to the user at the user computing device.

9. The non-transitory computer readable storage medium of claim 8 , wherein a user interface is provided to an administrator and the user interface receives input from the administrator.

10. The non-transitory computer readable storage medium of claim 9 , wherein the user interface receives a selection of a rule that corresponds to an authorized user of the authorized users and a zone of trust of the one or more zones of trust.

11. The non-transitory computer readable storage medium of claim 9 , wherein the user interface identifies a destination, and the destination corresponds to a location of a server through which the particular remotely hosted resource that can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

12. The non-transitory computer readable storage medium of claim 11 , wherein the user interface identifies a destination that identifies that the particular remotely hosted resource can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

13. The non-transitory computer readable storage medium of claim 11 , wherein the user interface includes one or more selectable communication controls that identify one or more communication methods for accessing the particular remotely hosted resource.

14. The method of claim 13 , wherein the one or more communication methods include at least one of a hypertext transfer protocol (HTTP), a secure hypertext transfer protocol (HTTPS), a transmission control protocol (TCP), and an internet protocol (IP).

15. An apparatus for controlling access to a set of resource in a network, the apparatus comprising:

a memory;

a processor, wherein the execution of instructions out of the memory by the processor:

assigns one or more zones of trust for each respective remotely hosted resource, wherein each of the assigned one or more zones of trust corresponds to one or more policies that identifies authorized users and authorized client operating environments that may access a particular remotely hosted resource,

authenticates a user to determine if the user is among the identified authorized users, wherein the user is requesting access to a particular remotely hosted resource via a computing device having a user client operating environment,

characterizes the user client operating environment, wherein the characterization is performed using an interrogation agent, and wherein the characterization includes:

identifying provisioning objects currently stored on the user computing device, and

comparing the identified provisioning objects currently on the user computing device with a list of provisioning objects that would be needed before access to the remotely hosted resource is authorized, wherein the comparison is based on the authenticated identity of the user and the characterized user client operating environment, and

installs one or more missing provisioning objects to the user computing device when the comparison indicates that the user computing device lacks the one or more missing provisioning objects, wherein the installation places the user computing device in compliance with the assigned one or more zones of trust for the particular remotely hosted resource, and

a communication interface that provides the requested remotely hosted resource to the user at the user computing device.

16. The apparatus of claim 15 , wherein a user interface is provided to an administrator and the user interface receives input from the administrator.

17. The apparatus of claim 16 , wherein the user interface receives a selection of a rule that corresponds to an authorized user of the authorized users and a zone of trust of the one or more zones of trust.

18. The apparatus of claim 16 , wherein the user interface identifies a destination, and the destination that corresponds to a location of a server through which the particular remotely hosted resource can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

19. The apparatus of claim 16 , wherein the user interface identifies a destination that identifies that the particular remotely hosted resource can be accessed according to a rule that corresponds to at least one policy of the one or more policies.

20. The apparatus of claim 16 , wherein the user interface includes one or more selectable communication controls that identify one or more communication methods for accessing the particular remotely hosted resource.

Assignments (20)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2017
From: AVENTAIL LLC
To: SONICWALL US HOLDINGS INC.
Reel/Frame 043950/0437 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
MERGER Recorded Mar 28, 2016
From: AVENTAIL CORPORATION
To: AVENTAIL LLC
Reel/Frame 038113/0921 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2016
From: HOPEN, CHRIS; TOMLINSON, GARY; ANANDAM, PARVEZ; FLAGG, ALAN; O'REILLEY, JUDE MICHAEL DYLAN; YOUNG, BRIAN
To: AVENTAIL CORPORATION
Reel/Frame 038113/0776 →