Out of band end user notification systems and methods for security events related to non-browser mobile applications

US9621574B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9621574-B2
Application numberUS-201414461790-A
CountryUS
Kind codeB2
Filing dateAug 18, 2014
Priority dateApr 13, 2012
Publication dateApr 11, 2017
Grant dateApr 11, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A cloud based security method includes authenticating a mobile device through a cloud based security system; associating the mobile device with a user of the cloud based security system based on the authenticating; monitoring user requests from the mobile device by the cloud based security system; detecting security threats based on the monitoring; and sending an out of band end user notification to the mobile device responsive to detecting a security threat, wherein the out of band end user notification comprises information for the user related to the security threat.

First claim

Opening claim text (preview).

What is claimed is: 1. A cloud based security method, comprising: authenticating a mobile device through a cloud based security system via a secure agent on the mobile device; associating the mobile device with a user of the cloud based security system based on the authenticating; monitoring user requests from the mobile device by the cloud based security system, wherein the user requests are for non-browser mobile applications executed on the mobile device; detecting security threats in the non-browser mobile applications based on the monitoring; and sending an out of band end user notification to the mobile device responsive to detecting a security threat, wherein the out of band end user notification comprises information for the user related to the security threat, wherein the out of band end user notification is sent to the mobile device separate from the non-browser mobile application to notify the user of the security threats through steps of: sending a notification to a delegate server from the cloud based security system with associated data for a push notification to the mobile device; determining the user for the push notification from a first mapping of the user to the cloud based security system and determining the mobile device from a second mapping of the user to the mobile device using the secure agent; instructing a mobile Operation System platform associated with the mobile device to send the push notification to the mobile device based on the notification and the second mapping, wherein the push notification is sent to the mobile device by the mobile Operation System platform based on the instructing and the push notification is out-of-band from the cloud based security system. 2. The cloud based security method of claim 1 , further comprising: detecting the security threats comprising any of malware, spyware, viruses, trojans, botnets, email spam, data leakage, and policy violations. 3. The cloud based security method of claim 1 , wherein the non-browser mobile device applications are unable to display Hypertext Transfer Protocol (HTTP) responses for an end user notification. 4. The cloud based security method of claim 1 , further comprising: providing the secure agent to the mobile device. 5. The cloud based security method of claim 4 , further comprising: authenticating the mobile device through a cloud based security system; and utilizing the secure agent operating on the mobile device to map information associated with the mobile device and user to the cloud based security system. 6. The cloud based security method of claim 5 , further comprising: maintaining database information for the mobile device and the user by the cloud based security system through communication with the secure agent. 7. A cloud based security system, comprising: a central authority (CA) server, a cloud node (CN), and a delegate server communicatively coupled to a mobile operating system notification system, wherein each of the one or more CA servers, the one or more cloud nodes, and the delegate server are communicatively coupled to one another and each comprise at least one computer processor and memory; wherein the cloud node, using software executed by the at least one computer processor, is configured to: authenticate a mobile device, wherein the CA server is configured to associate a user of the mobile device based on authentication for a first mapping of the user to the cloud node and a second mapping of the user to the mobile device; monitor user requests from the mobile device, the user requests are for non-browser mobile applications executed on the mobile device, and upon detection of a security threat, provide a request to the delegate server; wherein the delegate server is configured to: receive the request from the cloud node with associated data for a push notification to the mobile device, determine the user for the push notification from the first mapping and the mobile device from the second mapping; instruct a mobile Operation System platform associated with the mobile device to send the push notification to the mobile device based on the notification and the second mapping, wherein the push notification is sent to the mobile device by the mobile Operation System platform based thereon and the push notification is out-of-band from the cloud based security system, wherein the push notification is sent to the mobile device separate from the non-browser mobile application to notify the user of the security threats, wherein the cloud node utilizes the secure agent to authenticate the mobile device and the CA server uses the secure agent to map information associated with the mobile device and user. 8. The cloud based security system of claim 7 , wherein the cloud node is configured to detect the security threats comprising any of malware, spyware, viruses, trojans, botnets, email spam, data leakage, and policy violations. 9. The cloud based security system of claim 7 , wherein the non-browser mobile device applications are unable to display Hypertext Transfer Protocol (HTTP) responses for an end user notification. 10. The cloud based security system of claim 7 , wherein the mobile device comprises a secure agent operating thereon. 11. A mobile device, comprising: a network interface communicatively coupled to a user and an external network; a computer processor; and memory storing computer executable instructions, and in response to execution by the processor, the computer executable instructions cause the computer processor to perform steps of: operate a secure agent associated with a cloud based security system; operate a non-browser mobile device application unable to display Hypertext Transfer Protocol (HTTP) responses for an end user notification; authenticate with the cloud based security system via the secure agent, wherein the cloud based security system performs a first mapping of the user to the cloud based security system and a second mapping of the user to the mobile device using the secure agent; receive the end user notification out of band from a mobile operating system notification system responsive to the cloud based security system detecting a security threat with the non-browser mobile device application, wherein the out of band end user notification is sent to the mobile device separate from the non-browser mobile applications as a push notification to notify the user of the security threats; and display the end user notification separate from the non-browser mobile device application, wherein the cloud based security system sends the end user notification to a delegate server which uses the first mapping and the second mapping to instruct a mobile Operation System platform to send the push notification based on the notification and the push notification is out-of-band from the cloud based security system. 12. The mobile device of claim 11 , wherein the security threats comprise any of malware, spyware, viruses, trojans, botnets, email spam, data leakage, and policy violations.

Assignees

Inventors

Classifications

  • Authentication · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • retaining data, e.g. retaining successful, unsuccessful communication attempts, internet access, or e-mail, internet telephony, intercept related information or call content · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9621574B2 cover?
A cloud based security method includes authenticating a mobile device through a cloud based security system; associating the mobile device with a user of the cloud based security system based on the authenticating; monitoring user requests from the mobile device by the cloud based security system; detecting security threats based on the monitoring; and sending an out of band end user notificati…
Who is the assignee on this patent?
Desai Purvi, Bansal Abhinav, Mahajan Vikas, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/1441. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 11 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).