Mobile device security, device management, and policy enforcement in a cloud based system

US10749907B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10749907-B2
Application numberUS-201916680766-A
CountryUS
Kind codeB2
Filing dateNov 12, 2019
Priority dateMar 18, 2011
Publication dateAug 18, 2020
Grant dateAug 18, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method includes monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network; enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer-readable medium having computer readable code stored thereon for programming a processor to perform steps of: monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network; enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device. 2. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of: blocking or allowing the traffic from the mobile device to the external network based on the policy. 3. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of: blocking or allowing the traffic from the external network to the mobile device based on the inspecting. 4. The non-transitory computer-readable medium of claim 1 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites. 5. The non-transitory computer-readable medium of claim 1 , wherein the inspecting content includes detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 6. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of: causing a notification on the mobile device responsive to the policy or the inspecting. 7. The non-transitory computer-readable medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of: allowing or disallowing various functions implemented locally on the mobile device. 8. The non-transitory computer-readable medium of claim 7 , wherein the various functions include any of installation of specified applications, use of specified applications, use of screen capture, use of voice dialing, use of games, use of social media, use of streaming media, web browser usage, and use of Wi-Fi and/or Bluetooth. 9. A server comprising: a network interface communicatively coupled to a mobile device and to an external network; a processor communicatively coupled to the network interface; and memory storing instructions that, when executed, cause the processor to monitor traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network; enforce policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and inspect content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device. 10. The server of claim 9 , wherein the instructions that, when executed, cause the processor to block or allow the traffic from the mobile device to the external network based on the policy. 11. The server of claim 9 , wherein the instructions that, when executed, cause the processor to block or allow the traffic from the external network to the mobile device based on the inspecting. 12. The server of claim 9 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites. 13. The server of claim 9 , wherein the content is inspected by any of detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets. 14. The server of claim 9 , wherein the instructions that, when executed, cause the processor to cause a notification on the mobile device responsive to the policy or the inspecting. 15. The server of claim 9 , wherein the instructions that, when executed, cause the processor to allow or disallow various functions implemented locally on the mobile device. 16. A method comprising: monitoring traffic between a mobile device and an external network in a cloud based system separate from the mobile device and the external network; enforcing policy with respect to the traffic from the mobile device to the external network to determine whether to block or allow the traffic from the mobile device to the external network; and inspecting content associated with the traffic from the external network to the mobile device to determine whether to block or allow the traffic from the external network to the mobile device. 17. The method of claim 16 , further comprising: blocking or allowing the traffic from the mobile device to the external network based on the policy. 18. The method of claim 16 , further comprising: blocking or allowing the traffic from the external network to the mobile device based on the inspecting. 19. The method of claim 16 , wherein the policy includes any of data usage, time-of-day, location, type of website, use of a particular application on the mobile device, data leakage protection, and a black list of websites. 20. The method of claim 16 , wherein the inspecting content include detecting a security risk including any of malware, spyware, viruses, email spam, data leakage, phishing content, Trojans, and botnets.

Assignees

Inventors

Classifications

  • G06F21/51Primary

    at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title

  • Provisioning of proxy services (store-and-forward switching systems in data switching networks H04L12/54) · CPC title

  • Push-based network services · CPC title

  • for accessing one among a plurality of replicated servers · CPC title

  • Proxies · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10749907B2 cover?
Mobile device security, device management, and policy enforcement are described in a cloud based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A cloud based method includes monitoring traffic between a mobile device and an external network in a cloud based system separate from the mob…
Who is the assignee on this patent?
Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/51. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 18 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).