Policy-based meta-data driven co-location of computation and datasets in the cloud
US-9462056-B1 · Oct 4, 2016 · US
US10523710B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10523710-B2 |
| Application number | US-201615154328-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 13, 2016 |
| Priority date | Mar 18, 2011 |
| Publication date | Dec 31, 2019 |
| Grant date | Dec 31, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method for mobile device security, device management, and policy enforcement includes, responsive to configuring the mobile device for connectivity to the cloud system, monitoring data between the mobile device and the external network, wherein the cloud system connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyzing the data in real-time in the cloud system thereby not impacting performance of the mobile device; and controlling exchange of the data, in the cloud system, between the mobile device and the external network based on the analyzing.
Opening claim text (preview).
What is claimed is: 1. A cloud based method for mobile device security, device management, and policy enforcement of the mobile device communicatively coupled to an external network through a cloud system, the cloud based method comprising: responsive to configuring the mobile device for connectivity to the cloud system such that the cloud system is inline for all communications between the mobile device and the external network, monitoring data between the mobile device and the external network, wherein the cloud system connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyzing the data in real-time in the cloud system thereby not impacting performance of the mobile device; and controlling exchange of the data, in the cloud system that is in a separate network from the external network, between the mobile device and the external network, wherein the controlling includes each of blocking or allowing a mobile application on the mobile device via mobile device management functions between the cloud system and the mobile device, blocking or allowing a content item in the cloud system, and blocking or allowing access attempts in the cloud system, each of the blocking or allowing is based on policy and the analyzing. 2. The cloud based method of claim 1 , wherein the analyzing comprises detecting a security threat comprising one or more of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 3. The cloud based method of claim 1 , wherein the analyzing comprises detecting a policy violation comprising one or more access attempts to destinations not allowed per policy. 4. The cloud based method of claim 1 , wherein the analyzing comprises detecting a policy violation comprising one or more of blacklisted content, undesirable content, operation of a specific application, use of a specific social networking site, data usage, time of day, and location. 5. The cloud based method of claim 1 , wherein the configuring the connectivity comprises a tunneling protocol between the mobile device and the cloud system. 6. The cloud based method of claim 5 , wherein the tunneling protocol comprises a Virtual Private Network (VPN), and wherein the VPN is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 7. The cloud based method of claim 1 , wherein the configuring the connectivity comprises a Hypertext Transfer Protocol (HTTP) proxy. 8. The cloud based method of claim 7 , wherein the HTTP proxy is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 9. The cloud based method of claim 1 , further comprising: performing mobile device management on the mobile device via the cloud system to configure the mobile device for use with the external network, wherein the mobile device management comprises enforcement one or more policies on the mobile device. 10. The cloud based method of claim 9 , wherein the one or more policies comprise one or more of password access to the mobile device, screen lock of the mobile device, a remote wipe of the mobile device, and enablement and disablement of hardware or software features of the mobile device. 11. A cloud node in a cloud system configured to perform mobile device security, device management, and policy enforcement, the cloud node comprising: a network interface communicatively coupled to a mobile device and to an external network; a processor communicatively coupled to the network interface; and memory storing instructions that, when executed, cause the processor to responsive to the mobile device being configured for connectivity to the cloud node such that the cloud system is inline for all communications between the mobile device and the external network, monitor data between the mobile device and the external network, wherein the cloud node connects to the mobile device independent of a type, platform, or operating system associated with the mobile device; analyze the data in real-time in the cloud node thereby not impacting performance of the mobile device; and control exchange of the data, in the cloud system that is in a separate network from the external network, between the mobile device and the external network, wherein the exchange of the data is controlled through each of blocking or allowing a mobile application on the mobile device via mobile device management functions between the cloud system and the mobile device, blocking or allowing a content item in the cloud system, and blocking or allowing access attempts in the cloud system, each of the blocking or allowing is based on policy and analysis of the data. 12. The cloud node of claim 11 , wherein the data is analyzed to detect a security threat comprising one or more of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 13. The cloud node of claim 11 , wherein the data is analyzed to detect a policy violation comprising one or more access attempts to destinations not allowed per policy. 14. The cloud node of claim 11 , wherein the data is analyzed to detect a policy violation comprising one or more of blacklisted content, undesirable content, operation of a specific application, use of a specific social networking site, data usage, time of day, and location. 15. The cloud node of claim 11 , wherein the configured for connectivity comprises a tunneling protocol between the mobile device and the cloud system. 16. The cloud node of claim 15 , wherein the tunneling protocol comprises a Virtual Private Network (VPN), and wherein the VPN is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 17. The cloud node of claim 11 , wherein the configured for connectivity comprises a Hypertext Transfer Protocol (HTTP) proxy. 18. The cloud node of claim 17 , wherein the HTTP proxy is natively supported by an operating system of the mobile device and an enterprise associated with the external network pushes profile to the mobile device for the configuring, enabling access to the external network through the mobile device. 19. The cloud node of claim 11 , wherein the memory storing instructions that, when executed, further cause the processor to perform mobile device management on the mobile device via the cloud system to configure the mobile device for use with the external network, wherein the mobile device management comprises enforcement one or more policies on the mobile device, wherein the one or more policies comprise one or more of password access to the mobile device, screen lock of the mobile device, a remote wipe of the mobile device, and enablement and disablement of hardware or software features of the mobile device. 20. A cloud system, comprising: a plurality of cloud nodes communicatively coupled to an external network and a plurality of mobile devices, each cloud node of the plurality of cloud nodes is configured to: responsive to the mobile device being configured for connectivity to the cloud node such that the cloud sys
using dedicated hardware · CPC title
Secure firmware programming, e.g. of basic input output system [BIOS] · CPC title
interconnection devices, e.g. bus-connected or in-line devices · CPC title
by securing the transmission between two devices or processes · CPC title
Computer malware detection or handling, e.g. anti-virus arrangements · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.