IP Library Granted Patent US 12,464,022
Granted Patent B2
US 12,464,022 · App. 18/056,996 · Granted Nov 4, 2025

Endpoint assessment deduplication

Inventors: Robin Rowe (Daresbury, GB); Jack Smith (Daresbury, GB)
Assignee: Ivanti, Inc.
H04L63/20H04L63/107H04L63/108H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,022
App. No.
18/056,996
Granted
Nov 4, 2025
Kind
B2
Abstract

Security compliance may be facilitated for multiple endpoints associated with a network. Multiple batch endpoint assessments may be performed. Each batch endpoint assessment of the multiple batch endpoint assessments may include receiving multiple status indicators associated with at least a subset of endpoints of the multiple endpoints. For each batch endpoint assessment of the multiple batch endpoint assessments, a status may be assigned to each endpoint of the multiple endpoints based on the plurality of status indicators. A state may be generated for each endpoint of the multiple endpoints based on the statuses assigned to the multiple endpoints.

Claims (58)

1 . A method of endpoint compliance evaluation and remediation for a network of endpoints having changing network communication states, the method comprising:

performing a first batch endpoint assessment at a first time during which a first subset and a third subset of the endpoints are active, and a second subset of the endpoints is inactive;

responsive to the first batch endpoint assessment, receiving a first set of assessment indicators from each of the endpoints, the first set including an indication of a compliant state from the first subset and the third subset that are active and an indication of a communicative state from the second subset that is inactive;

generating a first device status array based on the first set, the first device status array indicating statuses of the endpoints at the first time;

performing a second batch endpoint assessment at a second time, the second time being during an assessment period and following the first time, wherein the second subset and the third subset are active at the second time and the first subset is inactive at the second time;

responsive to the second batch endpoint assessment, receiving a second set of assessment indicators from each of the endpoints, the second set including an indication of a compliant state from the second and the third subsets that are active and an indication of a communicative state from the first subset that is inactive;

generating a second device status array based on the second set, the second device status array indicating the statuses of the endpoints at the second time;

generating a final device status array, the generating including populating the final device status array with the first device status array;

deduplicating statuses of the endpoints in the first set of assessment indicators and the second set of assessment indicators, wherein the deduplication includes:

comparing the second device status array and the first device status array to identify a compliant state difference between the first batch endpoint assessment and the second batch endpoint assessment; and

responsive to the identified compliant state difference of a particular endpoint including a change from a noncompliant state or a non-communicative state to a compliant state, updating a status of the particular endpoint to the compliant state in the final device status array; and

after the assessment period:

determining whether a second endpoint has a noncompliant state; and

responsive to the second endpoint having the noncompliant state, mitigating the second endpoint by initiating an action at the second endpoint to change a state of the second endpoint and bring the second endpoint into compliance.

2 . The method of claim 1 , wherein the deduplicating includes responsive to the identified compliant state difference of the particular endpoint including a change from a compliant state to a noncompliant state or to a non-communicative state, not updating a status of the particular endpoint in the final device status array.

3 . The method of claim 2 , wherein the deduplicating includes responsive to the identified compliant state difference of the particular endpoint including a change from a noncompliant state to a non-communicative state or from non-communicative state to a noncompliant state, updating the status of the particular endpoint to the state at the second time in the final device status array.

4 . The method of claim 1 , further comprising prior to the first batch endpoint assessment communicating a command to the endpoints to perform an action, wherein the first batch endpoint assessment is configured to determine whether the command is implemented at the endpoints.

5 . The method of claim 1 , wherein the assessment period includes three days.

6 . The method of claim 1 , wherein:

the first subset includes endpoints that interface with the network in a first geographic location; and

the second subset includes endpoints that interface with the network in a second geographic location that is geographically distinct from the first geographic location.

7 . The method of claim 1 , wherein:

the first subset includes endpoints associated with a first subset of users who interface with the network during a period of time including the first time; and

the second subset includes endpoints associated with a second subset of users who interface with the network during a period of time including the second time and that does not include the first time.

8 . The method of claim 1 , wherein the mitigating includes one or more or a combination of:

communicating a patch for installation;

modifying a setting at the second endpoint;

deleting a file or program on the second endpoint; and

installing a file or program on the second endpoint.

9 . One or more computer-readable media configured to cause a system to perform or control operations of endpoint compliance evaluation and remediation for a network of endpoints having changing network communication states, the operations comprising:

performing a first batch endpoint assessment at a first time during which a first subset and a third subset of the endpoints are active, and a second subset of the endpoints is inactive;

responsive to the first batch endpoint assessment, receiving a first set of assessment indicators from each of the endpoints, the first set including an indication of a compliant state from the first subset and the third subset that are active and an indication of a communicative state from the second subset that is inactive;

generating a first device status array based on the first set, the first device status array indicating statuses of the endpoints at the first time;

performing a second batch endpoint assessment at a second time, the second time being during an assessment period and following the first time, wherein the second subset and the third subset are active at the second time and the first subset is inactive at the second time;

responsive to the second batch endpoint assessment, receiving a second set of assessment indicators from each of the endpoints, the second set including an indication of a compliant state from the second and the third subsets that are active and an indication of a communicative state from the first subset that is inactive;

generating a second device status array based on the second set, the second device status array indicating the statuses of the endpoints at the second time;

generating a final device status array, the generating including populating the final device status array with the first device status array;

deduplicating statuses of the endpoints in the first set of assessment indicators and the second set of assessment indicators, wherein the deduplication includes:

comparing the second device status array and the first device status array to identify a compliant state difference between the first batch endpoint assessment and the second batch endpoint assessment; and

responsive to the identified compliant state difference of a particular endpoint including a change from a noncompliant state or a non-communicative state to a compliant state, updating a status of the particular endpoint to the compliant state in the final device status array; and

after the assessment period:

determining whether a second endpoint has a noncompliant state; and

responsive to the second endpoint having the noncompliant state, mitigating the second endpoint by initiating an action at the second endpoint to change a state of the second endpoint and bring the second endpoint into compliance.

10 . The computer-readable media of claim 9 , wherein the deduplicating includes responsive to the identified compliant state difference of the particular endpoint including a change from a compliant state to a noncompliant state or to a non-communicative state, not updating a status of the particular endpoint in the final device status array.

11 . The computer-readable media of claim 10 , wherein the deduplicating includes responsive to the identified compliant state difference of the particular endpoint including a change from a noncompliant state to a non-communicative state or from non-communicative state to a noncompliant state, updating the status of the particular endpoint to the state at the second time in the final device status array.

12 . The computer-readable media of claim 9 , further comprising prior to the first batch endpoint assessment communicating a command to the endpoints to perform an action, wherein the first batch endpoint assessment is configured to determine whether the command is implemented at the endpoints.

13 . The computer-readable media of claim 9 , wherein the assessment period includes three days.

14 . The computer-readable media of claim 9 , wherein:

the first subset includes endpoints that interface with the network in a first geographic location; and

the second subset includes endpoints that interface with the network in a second geographic location that is geographically distinct from the first geographic location.

15 . The computer-readable media of claim 9 , wherein:

the first subset includes endpoints associated with a first subset of users who interface with the network during a period of time including the first time; and

the second subset includes endpoints associated with a second subset of users who interface with the network during a period of time including the second time and that does not include the first time.

16 . The computer-readable media of claim 9 , wherein the mitigating includes one or more or a combination of:

communicating a patch for installation;

modifying a setting at the second endpoint;

deleting a file or program on the second endpoint; and

installing a file or program on the second endpoint.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2023
From: ROWE, ROBIN; SMITH, JACK
To: IVANTI, INC.
Reel/Frame 062581/0480 →
Continuity (2)
Provisional Application 63281675 · Nov 21, 2021
Related Publication 20230164190A1 · May 25, 2023
References Cited (18)
US 9092616B2 · Kumar · 2015 [cited by examiner]
US 20070107043A1 · Newstadt · 2007 [cited by examiner]
US 20070143851A1 · Nicodemus · 2007 [cited by examiner]
US 20100306176A1 · Johnson · 2010 [cited by examiner]
US 20100333177A1 · Donley · 2010 [cited by examiner]
US 20110119517A1 · Beeco · 2011 [cited by examiner]
US 20130254833A1 · Nicodemus · 2013 [cited by examiner]
US 20160078068A1 · Agrawal · 2016 [cited by examiner]
US 20170142157A1 · Cao et al. · 2017 [cited by applicant]
US 20180101432A1 · Algie · 2018 [cited by examiner]
US 20190190929A1 · Thomas · 2019 [cited by examiner]
US 20190190936A1 · Thomas · 2019 [cited by examiner]
US 20200128020A1 · Abduljaber · 2020 [cited by examiner]
US 20220094600A1 · Khoo · 2022 [cited by examiner]
US 20220360594A1 · Cosgrove · 2022 [cited by examiner]
RFC 5209: Network Endpoint Assessment (NEA) (Year: 2008). [cited by examiner]
International Preliminary Report on Patentability and Written Opinion of the International Searching Authority for Application No. PCT/US2022/080236, dated May 2, 2024, 8 pages. [cited by applicant]
International Search Report and Written Opinion for Patent Application No. PCT/US2022/080236, dated Jan. 27, 2023, 13 pages. [cited by applicant]