Mobile device security, device management, and policy enforcement in a cloud based system

US10523710B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10523710-B2
Application numberUS-201615154328-A
CountryUS
Kind codeB2
Filing dateMay 13, 2016
Priority dateMar 18, 2011
Publication dateDec 31, 2019
Grant dateDec 31, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method for mobile device security, device management, and policy enforcement includes, responsive to configuring the mobile device for connectivity to the cloud system, monitoring data between the mobile device and the external network, wherein the cloud system connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyzing the data in real-time in the cloud system thereby not impacting performance of the mobile device; and controlling exchange of the data, in the cloud system, between the mobile device and the external network based on the analyzing.

First claim

Opening claim text (preview).

What is claimed is: 1. A cloud based method for mobile device security, device management, and policy enforcement of the mobile device communicatively coupled to an external network through a cloud system, the cloud based method comprising: responsive to configuring the mobile device for connectivity to the cloud system such that the cloud system is inline for all communications between the mobile device and the external network, monitoring data between the mobile device and the external network, wherein the cloud system connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyzing the data in real-time in the cloud system thereby not impacting performance of the mobile device; and controlling exchange of the data, in the cloud system that is in a separate network from the external network, between the mobile device and the external network, wherein the controlling includes each of blocking or allowing a mobile application on the mobile device via mobile device management functions between the cloud system and the mobile device, blocking or allowing a content item in the cloud system, and blocking or allowing access attempts in the cloud system, each of the blocking or allowing is based on policy and the analyzing. 2. The cloud based method of claim 1 , wherein the analyzing comprises detecting a security threat comprising one or more of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 3. The cloud based method of claim 1 , wherein the analyzing comprises detecting a policy violation comprising one or more access attempts to destinations not allowed per policy. 4. The cloud based method of claim 1 , wherein the analyzing comprises detecting a policy violation comprising one or more of blacklisted content, undesirable content, operation of a specific application, use of a specific social networking site, data usage, time of day, and location. 5. The cloud based method of claim 1 , wherein the configuring the connectivity comprises a tunneling protocol between the mobile device and the cloud system. 6. The cloud based method of claim 5 , wherein the tunneling protocol comprises a Virtual Private Network (VPN), and wherein the VPN is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 7. The cloud based method of claim 1 , wherein the configuring the connectivity comprises a Hypertext Transfer Protocol (HTTP) proxy. 8. The cloud based method of claim 7 , wherein the HTTP proxy is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 9. The cloud based method of claim 1 , further comprising: performing mobile device management on the mobile device via the cloud system to configure the mobile device for use with the external network, wherein the mobile device management comprises enforcement one or more policies on the mobile device. 10. The cloud based method of claim 9 , wherein the one or more policies comprise one or more of password access to the mobile device, screen lock of the mobile device, a remote wipe of the mobile device, and enablement and disablement of hardware or software features of the mobile device. 11. A cloud node in a cloud system configured to perform mobile device security, device management, and policy enforcement, the cloud node comprising: a network interface communicatively coupled to a mobile device and to an external network; a processor communicatively coupled to the network interface; and memory storing instructions that, when executed, cause the processor to responsive to the mobile device being configured for connectivity to the cloud node such that the cloud system is inline for all communications between the mobile device and the external network, monitor data between the mobile device and the external network, wherein the cloud node connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyze the data in real-time in the cloud node thereby not impacting performance of the mobile device; and control exchange of the data, in the cloud system that is in a separate network from the external network, between the mobile device and the external network, wherein the exchange of the data is controlled through each of blocking or allowing a mobile application on the mobile device via mobile device management functions between the cloud system and the mobile device, blocking or allowing a content item in the cloud system, and blocking or allowing access attempts in the cloud system, each of the blocking or allowing is based on policy and analysis of the data. 12. The cloud node of claim 11 , wherein the data is analyzed to detect a security threat comprising one or more of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 13. The cloud node of claim 11 , wherein the data is analyzed to detect a policy violation comprising one or more access attempts to destinations not allowed per policy. 14. The cloud node of claim 11 , wherein the data is analyzed to detect a policy violation comprising one or more of blacklisted content, undesirable content, operation of a specific application, use of a specific social networking site, data usage, time of day, and location. 15. The cloud node of claim 11 , wherein the configured for connectivity comprises a tunneling protocol between the mobile device and the cloud system. 16. The cloud node of claim 15 , wherein the tunneling protocol comprises a Virtual Private Network (VPN), and wherein the VPN is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 17. The cloud node of claim 11 , wherein the configured for connectivity comprises a Hypertext Transfer Protocol (HTTP) proxy. 18. The cloud node of claim 17 , wherein the HTTP proxy is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 19. The cloud node of claim 11 , wherein the memory storing instructions that, when executed, further cause the processor to perform mobile device management on the mobile device via the cloud system to configure the mobile device for use with the external network, wherein the mobile device management comprises enforcement one or more policies on the mobile device, wherein the one or more policies comprise one or more of password access to the mobile device, screen lock of the mobile device, a remote wipe of the mobile device, and enablement and disablement of hardware or software features of the mobile device. 20. A cloud system, comprising: a plurality of cloud nodes communicatively coupled to an external network and a plurality of mobile devices, each cloud node of the plurality of cloud nodes is configured to: responsive to the mobile device being configured for connectivity to the cloud node such that the cloud sys

Assignees

Inventors

Classifications

  • using dedicated hardware · CPC title

  • Secure firmware programming, e.g. of basic input output system [BIOS] · CPC title

  • interconnection devices, e.g. bus-connected or in-line devices · CPC title

  • by securing the transmission between two devices or processes · CPC title

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10523710B2 cover?
Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method for mobile device security, device management, and policy enforcement includes, responsive to configuring the mobile devi…
Who is the assignee on this patent?
Sinha Amit, Paul Narinder, Devarajan Srikanth, and 1 more
What technology area does this patent fall under?
Primary CPC classification G06F21/51. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 31 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).