Dynamic enterprise boundary determination for external mobile devices

US9307451B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9307451-B1
Application numberUS-201414558388-A
CountryUS
Kind codeB1
Filing dateDec 2, 2014
Priority dateDec 2, 2014
Publication dateApr 5, 2016
Grant dateApr 5, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and arrangements for according access of a mobile device to an enterprise network. the presence of a mobile device relative to an enterprise network is detected, the enterprise network including a plurality of defined zones, wherein each zone is associated with a security level and with one or more resources. An agent of the mobile device is negotiated with to accord access to at least one of the defined zones. The negotiating includes: assessing at least one security constraint relative to the mobile device; and thereupon designating at least one zone to be accessible to the mobile device. Other variants and embodiments are broadly contemplated herein.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: detecting the presence of a mobile device relative to an enterprise network; and automatically negotiating with an agent of the mobile device to accord access to at least one defined zone associated with one or more resources of the enterprise network, wherein the at least one defined zone comprises a plurality of zones defined by security level and with respect to accessibility of at least one resource of the enterprise network; said negotiating comprising: assigning the mobile device to a quarantine zone; examining the mobile device for policy compliance; assessing at least one security constraint of the mobile device; and thereupon designating at least one zone to be accessible to the mobile device; and assigning one or more credentials to the mobile device subsequent to said negotiating, wherein the one or more credentials are employable in according future access of the mobile device to one or more of the defined zones. 2. The method according to claim 1 , wherein the at least one security constraint comprises at least one policy associated with the mobile device. 3. The method according to claim 1 , wherein the at least one security constraint comprises at least one policy associated with the enterprise network. 4. The method according to claim 1 , wherein said negotiating comprises inputting from the mobile device a list comprising one or more service requests. 5. The method according to claim 1 , comprising issuing a request to the mobile device for remediation action in response to examining the mobile device for policy compliance and detecting at least one item of non-compliance. 6. The method according to claim 5 , comprising according access to at least one defined zone in response to a notification of successful remediation action from the mobile device. 7. The method according to claim 1 , wherein said negotiating comprises detecting at least one change associated with the mobile device and re-negotiating at least one credential associated with the mobile device. 8. The method according to claim 7 , wherein the at least one change comprises one or more of: a state of the mobile device, and a resource requirement of the mobile device. 9. The method according to claim 1 , wherein said negotiating comprises dynamically determining the suitability of one or more enterprise resources to be accessed by the mobile device. 10. An apparatus for according access of a mobile device to an enterprise network, said apparatus comprising: at least one processor; and a non-transitory computer readable storage medium having computer readable program code embodied therewith and executable by the at least one processor, the computer readable program code comprising: computer readable program code configured to detect the presence of a mobile device relative to the enterprise network; computer readable program code configured to automatically negotiate with an agent of the mobile device to accord access to at least one defined zone associated with one or more resources of the enterprise network, wherein the at least one defined zone comprises a plurality of zones defined by security level and with respect to accessibility of at least one resource of the enterprise network; the negotiating comprising: assigning the mobile device to a quarantine zone; examining the mobile device for policy compliance; assessing at least one security constraint relative to the mobile device; and thereupon designating at least one zone to be accessible to the mobile device; and assigning one or more credentials to the mobile device subsequent to the negotiating, wherein the one or more credentials are employable in according future access of the mobile device to one or more of the defined zones. 11. A computer program product for according access of a mobile device to an enterprise network, said computer program product comprising: a non-transitory computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising: computer readable program code configured to detect the presence of a mobile device relative to the enterprise network; computer readable program code configured to automatically negotiate with an agent of the mobile device to accord access to at least one defined zone associated with one or more resources of the enterprise network, wherein the at least one defined zone comprises a plurality of zones defined by security level and with respect to accessibility of at least one resource of the enterprise network; the negotiating comprising: assigning the mobile device to a quarantine zone; examining the mobile device for policy compliance; assessing at least one security constraint relative to the mobile device; and thereupon designating at least one zone to be accessible to the mobile device; and assigning one or more credentials to the mobile device subsequent to the negotiating, wherein the one or more credentials are employable in according future access of the mobile device to one or more of the defined zones. 12. The computer program product according to claim 11 , wherein the at least one security constraint comprises at least one policy associated with the mobile device. 13. The computer program product according to claim 11 , wherein the at least one security constraint comprises at least one policy associated with the enterprise network.

Assignees

Inventors

Classifications

  • Discovery of network devices, e.g. terminals · CPC title

  • H04W48/02Primary

    Access restriction performed under specific conditions · CPC title

  • H04W28/20Primary

    Negotiating bandwidth · CPC title

  • Access security · CPC title

  • Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9307451B1 cover?
Methods and arrangements for according access of a mobile device to an enterprise network. the presence of a mobile device relative to an enterprise network is detected, the enterprise network including a plurality of defined zones, wherein each zone is associated with a security level and with one or more resources. An agent of the mobile device is negotiated with to accord access to at least …
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04W48/02. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 05 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).