Cloud based mobile device security and policy enforcement

US9609460B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9609460-B2
Application numberUS-201514797227-A
CountryUS
Kind codeB2
Filing dateJul 13, 2015
Priority dateMar 18, 2011
Publication dateMar 28, 2017
Grant dateMar 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Cloud based mobile device security and policy systems and methods use the “cloud” to pervasively enforce security and policy on mobile devices. The cloud based mobile device security and policy systems and methods provide uniformity in securing mobile devices for small to large organizations. The cloud based mobile device security and policy systems and methods may enforce one or more policies for users wherever and whenever the users are connected across a plurality of different devices including mobile devices. This solution ensures protection across different types, brands, operating systems, etc. for smartphones, tablets, netbooks, mobile computers, and the like.

First claim

Opening claim text (preview).

What is claimed is: 1. A mobile device security and policy enforcement method implemented by a processing node in a cloud based system, comprising: subsequent to communicatively coupling a mobile device to the processing node based on configuring the mobile device with a mobile configuration profile which natively supports updating configuration settings in a mobile operating system to cause communication of the mobile device through the cloud based system, monitoring data between the mobile device and an external network; enforcing policy relative to the data, wherein the policy is associated with a user of the mobile device, and inspecting the data for malicious content therein, wherein an authority node provides threat data for the malicious content and updates to the processing node; allowing the data responsive to the data complying with the policy and/or containing no malicious content such that the data is provided through the cloud based system to either the mobile device or the external network; and blocking the data in the processing node responsive to the data not complying with the policy and/or containing malicious content such that the data is not provided to either the mobile device or the external network, wherein the enforcing, the inspecting, the allowing, and the blocking is performed in the processing node independent of the mobile device. 2. The mobile device security and policy enforcement method of claim 1 , wherein the monitoring, the enforcing, the inspecting, the allowing, and the blocking are performed by the node without a platform-specific app on the mobile device. 3. The mobile device security and policy enforcement method of claim 1 , wherein the malicious content comprises one or more of viruses, spyware, malware, Trojans, botnets, spam email, phishing content, and blacklisted content. 4. The mobile device security and policy enforcement method of claim 1 , wherein the policy comprises one or more of inappropriate content, data leakage, data usage limits, time-of-day usage limits, location, operation of a particular application, and black lists of websites. 5. The mobile device security and policy enforcement method of claim 1 , wherein the policy comprises preventing installation of a particular application on the mobile device. 6. The mobile device security and policy enforcement method of claim 5 , wherein the particular application is blocked for one or more of failing to meet a minimum threshold for security and/or privacy and interfering with an enterprise network associated with the user. 7. The mobile device security and policy enforcement method of claim 1 , further comprising: receiving an update to the policy for the user or for a group of users comprising the users; and performing the enforcing with the updated policy. 8. The mobile device security and policy enforcement method of claim 1 , further comprising: receiving an update related to the malicious content from another node in the cloud based system; and performing the inspecting the data with the update. 9. The mobile device security and policy enforcement method of claim 1 , wherein the node forms an association with the mobile device. 10. A mobile device security and policy enforcement system comprising a processing node in a cloud based system, comprising: a network interface communicatively coupled to a processor; and memory storing instructions that, when executed, cause the processor to: subsequent to communicatively coupling to a mobile device based on configuring the mobile device with a mobile configuration profile which natively supports updating configuration settings in a mobile operating system to cause communication of the mobile device through the cloud based system, monitor data between the mobile device and an external network; enforce policy relative to the data, wherein the policy is associated with a user of the mobile device, and inspect the data for malicious content therein, wherein an authority node provides threat data for the malicious content and updates to the processing node; allow the data responsive to the data complying with the policy and/or containing no malicious content such that the data is provided through the system to either the mobile device or the external network; and block the data in the processing node responsive to the data not complying with the policy and/or containing malicious content such that the data is not provided to either the mobile device or the external network, wherein the policy is enforced, the data is inspected, and the data is allowed or blocked in the system independent of the mobile device. 11. The mobile device security and policy enforcement system of claim 10 , wherein the mobile device does not utilize a platform-specific app for mobile device security and policy enforcement. 12. The mobile device security and policy enforcement system of claim 10 , wherein the malicious content comprises one or more of viruses, spyware, malware, Trojans, botnets, spam email, phishing content, and blacklisted content. 13. The mobile device security and policy enforcement system of claim 10 , wherein the policy comprises one or more of inappropriate content, data leakage, data usage limits, time-of-day usage limits, location, operation of a particular application, and black lists of websites. 14. The mobile device security and policy enforcement system of claim 10 , wherein the policy comprises preventing installation of a particular application on the mobile device. 15. The mobile device security and policy enforcement system of claim 14 , wherein the particular application is blocked for one or more of failing to meet a minimum threshold for security and/or privacy and interfering with an enterprise network associated with the user. 16. The mobile device security and policy enforcement system of claim 10 , wherein the memory storing instructions that, when executed, further cause the processor to: receive an update to the policy for the user or for a group of users comprising the users; and enforce the policy with the updated policy. 17. The mobile device security and policy enforcement system of claim 10 , wherein the memory storing instructions that, when executed, further cause the processor to: receive an update related to the malicious content from another node in the cloud based system; and inspect the data with the update. 18. The mobile device security and policy enforcement system of claim 10 , wherein the node forms an association with the mobile device. 19. A mobile device, comprising: a network interface communicatively coupled to a processor; and memory storing instructions that, when executed, cause the processor to: subsequent to communicatively coupling to a processing node in a mobile device security and policy enforcement system based on configuring the mobile device with a mobile configuration profile which natively supports updating configuration settings in a mobile operating system to cause communication of the mobile device through the cloud based system, transmit data to an external network through the processing node, wherein responsive to the data (i) complying with policy associated with a user of the mobile device based on enforcement by the processing node and (ii) containing no malicious data therein based on inspection of the data for the policy and for the malicious data by the processing node independent of the mobile device, the processing node is configured to allow the data; responsive to responsive data from the external networ

Assignees

Inventors

Classifications

  • User profiles · CPC title

  • Subscription-based services using application servers or record carriers, e.g. SIM application toolkits · CPC title

  • Grouping of entities · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9609460B2 cover?
Cloud based mobile device security and policy systems and methods use the “cloud” to pervasively enforce security and policy on mobile devices. The cloud based mobile device security and policy systems and methods provide uniformity in securing mobile devices for small to large organizations. The cloud based mobile device security and policy systems and methods may enforce one or more policies …
Who is the assignee on this patent?
Sinha Amit, Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).