IP Library Granted Patent US 11,700,264
Granted Patent B2
US 11,700,264 · App. 17/092,619 · Granted Jul 11, 2023

Systems and methods for role-based computer security configurations

Inventors: Randy Deninno (Rogers, MN); Mark Robert Tempel (Minneapolis, MN); Travis Peters (South Jordan, UT); Rob Juncker (Farmington, MN)
Assignee: Ivanti, Inc.
H04L63/105G06F21/316G06F21/552G06F21/604G06F21/629H04L63/10H04L63/101H04L63/102H04L63/20G06F2221/033G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,700,264
App. No.
17/092,619
Granted
Jul 11, 2023
Kind
B2
Abstract

An apparatus includes a processor operatively coupled to a memory. The processor detects a software application installed on a client computing device, and/or usage data. Detected usage data is associated with a current user of the client computing device and with the software application. The processor identifies a user role for the current user based on the software application and/or usage data. The processor applies a security configuration to the client computing device based on the user role. The security configuration limits access by the current user to a portion of the software application. The processor sends an identifier of the user role to an administrative server for storage in an Active Directory (AD) database.

Claims (54)

1. An apparatus, comprising:

a processor; and

a memory operatively coupled to the processor, the processor configured to:

detect at least one of:

a software application installed on a client computing device, or

usage data associated with a current user of the client computing device and associated with the software application;

identify, based on the at least one of the software application installed on the client computing device or the usage data, a user role for the current user of the client computing device;

predict, based on the user role for the current user of the client computing device, an expected behavior of the current user of the client computing device;

apply, based on the expected behavior, a privilege level for the current user to the client computing device, the privilege level being associated with the software application;

send an identifier of the user role to an administrative server for storage in an Active Directory (AD) database;

identify a security risk based on the user role and the usage data for the current user; and

responsive to detection of deviation from the expected behavior that is indicative of the security risk, automatically select and implement a mitigation technique configured to adjust the privilege level.

2. The apparatus of claim 1 , wherein the processor is further configured to send an alert to the administrative server in response to responsive to detection of the deviation from the expected behavior.

3. The apparatus of claim 1 , wherein the mitigation technique reduces access a set of resources that the current user of the client computing device is able to access.

4. The apparatus of claim 1 , wherein the processor is configured to detect the usage data based on a software usage log.

5. The apparatus of claim 1 , wherein the processor is further configured to monitor software usage by the current user of the client computing device over a predetermined period of time.

6. The apparatus of claim 1 , wherein the processor is further configured to receive, from a server, a signal encoding an instruction to implement the privilege level to the client computing device.

7. The apparatus of claim 1 , wherein the processor is configured to apply the privilege level to the client computing device by sending a signal encoding an instruction to implement the privilege level to the client computing device.

8. The apparatus of claim 1 , wherein the processor is configured to apply the privilege level to the client computing device by implementing the privilege level at the client computing device.

9. The apparatus of claim 1 , wherein the user role is a first user role, the processor further configured to:

monitor software use of the current user of the client computing device over a predetermined period of time; and

identify a second user role, different from the first user role, based on the monitored software use.

10. The apparatus of claim 1 , wherein the usage data includes:

a frequency of use of the software application,

a frequency of use of a feature of the software application,

a frequency of attempts to use a blocked feature of the software application,

a set of accessed features of the software application, or

a quantity of remote accesses of a desktop of the client computing device.

11. A method, comprising:

detecting at least one of a software application installed on a client computing device, or usage data associated with a current user of the client computing device and associated with the software application;

identifying, based on the at least one of the software application installed on the client computing device or the usage data, a user role for the current user of the client computing device;

predicting, based on the user role for the current user of the client computing device, an expected behavior of the current user of the client computing device;

applying, based on the expected behavior, a privilege level for the current user to the client computing device, the privilege level being associated with the software application;

sending an identifier of the user role to an administrative server for storage in an Active Directory (AD) database;

identifying a security risk based on the user role and the usage data for the current user; and

responsive to detection of deviation from the expected behavior that is indicative of the security risk, automatically selecting and implementing a mitigation technique configured to adjust the privilege level.

12. The method of claim 11 , further comprising sending an alert to the administrative server in response to responsive to detection of the deviation from the expected behavior.

13. The method of claim 11 , wherein the mitigation technique reduces access a set of resources that the current user of the client computing device is able to access.

14. The method of claim 11 , further comprising detecting the usage data based on a software usage log.

15. The method of claim 11 , further comprising monitoring software usage by the current user of the client computing device over a predetermined period of time.

16. The method of claim 11 , further comprising receiving, from a server, a signal encoding an instruction to implement the privilege level to the client computing device.

17. The method of claim 11 , further comprising applying the privilege level to the client computing device by sending a signal encoding an instruction to implement the privilege level to the client computing device.

18. The method of claim 11 , further comprising applying the privilege level to the client computing device by implementing the privilege level at the client computing device.

19. The method of claim 11 , wherein:

the user role is a first user role; and

the method further comprises:

monitoring software use of the current user of the client computing device over a predetermined period of time; and

identifying a second user role, different from the first user role, based on the monitored software use.

20. The method of claim 11 , wherein the usage data includes:

a frequency of use of the software application,

a frequency of use of a feature of the software application,

a frequency of attempts to use a blocked feature of the software application,

a set of accessed features of the software application, or

a quantity of remote accesses of a desktop of the client computing device.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 067457/0497 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071124/0331 →
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 067457/0472 →
SECOND LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 067457/0497 →
Continuity (3)
Continuation 15906573 · Feb 27, 2018
Provisional Application 62464222 · Feb 27, 2017
Related Publication 20210160249A1 · May 27, 2021