IP Library Granted Patent US 11,356,448
Granted Patent B1
US 11,356,448 · App. 16/382,068 · Granted Jun 7, 2022

Device and method for tracking unique device and user network access across multiple security appliances

Inventors: Kanti Varanasi (Sunnyvale, CA); Robin Singh (San Jose, CA); Naji Abdulla (San Jose, CA)
Assignee: Pulse Secure, LLC
H04L63/101H04L63/083H04L63/102H04L12/4641H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,448
App. No.
16/382,068
Granted
Jun 7, 2022
Kind
B1
Abstract

A private network includes a plurality of network security appliances participating in authenticating end users. Each network security appliance maintains a locally stored user list. A first network security appliance receives at least a portion of a non-local user list comprising second user identifier records for a second network security appliance of the plurality of network security appliances. The first network security appliance compares the local user list with the non-local user list received from the second network security appliance to identify one or more deviations. The first network security appliance merges the portion of the second user identifier records of the non-local user list corresponding with the one or more deviations with the first user identifier records of the local user list to generate an updated local user list. The first network security appliance authenticates a request to access the network using the updated local user list.

Claims (80)

1. A method, comprising:

maintaining, by a first network security appliance of a plurality of network security appliances, a local user list comprising first user identifier records for accessing a network, wherein the local user list has a predefined format;

dividing, by the first network security appliance, the local user list into a first set of hash blocks, wherein each of the first set of hash blocks is configured according to a predefined hash block format such that each hash block of the first set of hash blocks includes one portion of the first user identifier records;

applying, by the first network security appliance, a hashing function to each hash block of the first set of hash blocks to generate a local set of hash values that includes a first hash value for each hash block of the first set of hash blocks;

receiving, by the first network security appliance, a non-local set of hash values from a second network appliance of the plurality of network security appliances, wherein:

the non-local set of hash values is generated through application of the hashing function to a second set of hash blocks, and

the second set of hash blocks are configured according to the predefined hash block format in which each hash block of the second set of hash blocks includes one portion of a non-local list comprising second user identifier records for accessing a network that have the same predefined format;

comparing, by the first network security appliance, the local set of hash values with at least the portion of the non-local set of hash values to identify a deviation, the deviation including a difference between a first hash value of the local set of hash values and a corresponding first hash value of the non-local set of hash values;

generating, by the first network security appliance, an updated local user list, the generating including:

merging a portion of the first user identifier records that comprises content of the first hash value of the local set of hash values with a portion of the second user identifier records that comprises content of the first hash value of the non-local set of hash values, and

replacing the portion of the first user identifier records and the portion of the second user identifier records with the merged contents; and

authenticating, by the first network security appliance, a request to access the network using the updated local user list.

2. The method of claim 1 , wherein merging further comprises

adding, by the first network security appliance, a user identifier record of a first user identifier record that was previously not present in the first user identifier records.

3. The method of claim 1 , further comprising:

sharing, by the first network security appliance, with at least a second network security appliance, the merged contents.

4. The method of claim 1 , further comprising:

prior to receiving the non-local set of hash values:

determining, by the first network security appliance, that a virtual private network connection with a first end-user device is below a particular quality threshold; and

migrating, by the first network security appliance, the virtual private network connection to a second network security appliance.

5. The method of claim 1 , further comprising:

prior to receiving at least the non-local set of hash values:

receiving, by the first network security appliance, an indication that a virtual private network connection for a first end-user device is being migrated from a second network security appliance to the first network security appliance.

6. The method of claim 1 , wherein:

the first network security appliance comprises a leader security appliance,

each other network security appliance in the plurality of network security appliances comprises a follower security appliance, and

the method further comprises requesting, by the first network security appliance, that each follower security appliance regenerate hash values based on the updated local user list.

7. The method of claim 1 , wherein the updated local user list comprises one or more of usernames of authentic users, passwords of authentic users, device information corresponding with the usernames of authentic users, usernames of blocked users, and device information corresponding with the usernames of blocked users.

8. The method of claim 1 , wherein the generating further includes:

identifying, by the first network security appliance, a non-relevant deviation between the local set of hash values and the non-local set of hash values; and

refraining from merging, by the first network security appliance, portions of the first user identifier records and the second user identifier records that comprise content of the hash values corresponding with the non-relevant deviation.

9. A first network security appliance comprising: at least one processor; and

a storage device configured to store one or more modules operable by the at least one processor to:

maintain a local user list comprising first user identifier records for accessing a network, wherein the local user list has a predefined format, wherein the network comprises a plurality of network security appliances that includes the first network security appliance;

divide the local user list into a first set of hash blocks, wherein each of the first set of hash blocks is configured according to a predefined hash block format such that each hash block of the first set of hash blocks includes one portion of the first user identifier records;

apply a hashing function to each hash block of the first set of hash blocks to generate a local set of hash values that includes a first hash value for each hash block of the first set of hash blocks;

receive a non-local set of hash values from a second network appliance of the plurality of network security appliances, wherein:

the non-local set of hash values is generated through application of the hashing function to a second set of hash blocks, and

the second set of hash blocks are configured according to the predefined hash block format in which each hash block of the second set of hash blocks includes one portion of a non-local list comprising second user identifier records for accessing a network that have the same predefined format;

compare the local set of hash values with at least the portion of the non-local set of hash values to identify a deviation, the deviation including a difference between a first hash value of the local set of hash values and a corresponding first hash value of the non-local set of hash values;

generate an updated local user list, the generating including:

merging a portion of the first user identifier records that comprises content of the first hash value of the local set of hash values with a portion of the second user identifier records that comprises content of the first hash value of the non-local set of hash values, and

replacing the portion of the first user identifier records and the portion of the second user identifier records with the merged contents; and

authenticate a request to access the network using the updated local user list.

10. The first network security appliance of claim 9 , wherein the one or more modules are further operable by the at least one processor to:

prior to receiving the non-local set of hash values:

determine that a virtual private network connection with a first end-user device is below a particular quality threshold; and

migrate the virtual private network connection to a second network security appliance.

11. The first network security appliance of claim 9 , wherein the one or more modules are further operable by the at least one processor to:

prior to receiving the non-local set of hash values, receive an indication that a virtual private network connection for a first end-user device is being migrated from a second network security appliance to the first network security appliance.

12. The first network security appliance of claim 9 , wherein:

the first network security appliance comprises a leader security appliance,

each other network security appliance in the plurality of network security appliances comprises a follower security appliance, and

the one or more modules are further operable by the at least one processor to request that each follower security appliance regenerate hash values based on the updated local user list.

13. A non-transitory computer readable storage medium storing instructions that, when executed by one or more processors of a first network security appliance, cause the one or more processors to:

maintain a local user list comprising first user identifier records for accessing a network, wherein the local user list has a predefined format, wherein the network comprises a plurality of network security appliances that includes the first network security appliance;

divide the local user list into a first set of hash blocks, wherein each of the first set of hash blocks is configured according to a predefined hash block format such that each hash block of the first set of hash blocks includes one portion of the first user identifier records;

apply a hashing function to each hash block of the first set of hash blocks to generate a local set of hash values that includes a first hash value for each hash block of the first set of hash blocks;

receive a non-local set of hash values from a second network appliance of the plurality of network security appliances, wherein:

the non-local set of hash values is generated through application of the hashing function to a second set of hash blocks, and

the second set of hash blocks are configured according to the predefined hash block format in which each hash block of the second set of hash blocks includes one portion of a non-local list comprising second user identifier records for accessing a network that have the same predefined format;

compare the local set of hash values with at least the portion of the non-local set of hash values to identify a deviation, the deviation including a difference between a first hash value of the local set of hash values and a corresponding first hash value of the non-local set of hash values;

generate an updated local user list, the generating including:

merging a portion of the first user identifier records that comprises content of the first hash value of the local set of hash values with a portion of the second user identifier records that comprises content of the first hash value of the non-local set of hash values, and

replacing the portion of the first user identifier records and the portion of the second user identifier records with the merged contents; and

authenticate a request to access the network using the updated local user list.

14. The non-transitory computer readable storage medium of claim 13 , wherein the instructions, when executed, further cause the one or more processors to:

prior to receiving at least the portion of the non-local set of hash values:

determine that a virtual private network connection with a first end-user device is below a particular quality threshold; and

migrate the virtual private network connection to a second network security appliance.

15. The non-transitory computer readable storage medium of claim 13 , wherein:

the first network security appliance comprises a leader security appliance,

each other network security appliance in the plurality of network security appliances comprises a follower security appliance, and

the instructions, when executed, further cause the one or more processors to request that each follower security appliance regenerate hash values based on the updated local user list.

16. The non-transitory computer readable storage medium of claim 13 , wherein prior to receiving the non-local set of hash values, receive an indication that a virtual private network connection for a first end-user device is being migrated from a second network security appliance to the first network security appliance.

17. The non-transitory computer readable storage medium of claim 13 , wherein the generating further includes:

identifying, by the first network security appliance, a non-relevant deviation between the local set of hash values and the non-local set of hash values; and

refraining from merging, by the first network security appliance, portions of the first user identifier records and the second user identifier records that comprise content of the hash values corresponding with the non-relevant deviation.

18. The non-transitory computer readable storage medium of claim 13 , wherein the updated local user list comprises one or more of usernames of authentic users, passwords of authentic users, device information corresponding with the usernames of authentic users, usernames of blocked users, and device information corresponding with the usernames of blocked users.

19. The non-transitory computer readable storage medium of claim 13 , wherein merging further comprises adding, by the first network security appliance, a user identifier record of a first user identifier record that was previously not present in the first user identifier records.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2019
From: VARANASI, KANTI; SINGH, ROBIN; ABDULLA, NAJI
To: PULSE SECURE, LLC
Reel/Frame 050070/0530 →
Continuity (1)
Provisional Application 62657322 · Apr 13, 2018
Cited By (5)
US 12,411,913 US 12,452,314 US 12,468,697 US 12,483,596 US 12,712,878